This is a reference translation provided for convenience. The Japanese version is the legally binding original. If the two differ, the Japanese version governs.
PR Elle LLC (合同会社 PR Elle) (the "Company") complies with Japan's Act on the Protection of Personal Information and other relevant laws and regulations with respect to personal information obtained in the course of providing the WordPress plugin "Sorabun" and related services (the "Service"), and handles such information as set out below.
1. Company Information
| Company name | PR Elle LLC (合同会社 PR Elle) |
| Representative |  |
| Address | La Porte Aoyama 2F-7, 5-51-8 Jingumae, Shibuya-ku, Tokyo, Japan 東京都渋谷区神宮前5丁目51番8号 ラ・ポルト青山2F-7 |
| Personal Information Protection Manager | 福田優佳 (Yuka Fukuda) |
2. Information Collected
2-1. Information Collected at Purchase and Account Registration
- Email address
- My Page login password (stored hashed; the Company has no way to know the plaintext)
- The plan purchased, contract status, and date and time of purchase
- The customer ID and payment-session ID issued by the payment processor
About Credit Card Information
The card number, expiration date, and security code are obtained and processed directly by Stripe, Inc., the payment processor. The Company does not obtain or retain this information.
2-2. Information Collected During License Authentication
- The License Key
- The URL of the WordPress site on which the plugin was activated (collected to manage the number of Target Sites)
- The date and time of authentication
2-3. Information Automatically Collected When You Use the Website
- Access logs such as IP address, browser type and language, referrer URL, and access date and time
3. Data the Plugin Sends Externally
This section explains, separately by destination, the data transmitted in the course of the Plugin's operation.
3-1. Sent to the Company's Servers
During license authentication, deauthorization, and update checks, only the License Key and the site URL are sent to the Company's license server.
3-2. Sent Directly to External AI Services (Not Routed Through the Company)
Content data such as the keywords entered for article generation, article text, image-generation instructions, and text to be converted to speech is sent directly from the User's own server to each AI provider, using the User's own API key. It does not pass through the Company's servers, and the Company never obtains or stores this content.
The main providers to which data may be sent are as follows. The actual destination varies depending on the functions and provider the User has configured.
- Google LLC (Gemini API: article generation, image generation)
- OpenAI, L.L.C. (OpenAI API: image generation, speech synthesis)
- Anthropic PBC / xAI Corp. / DeepSeek (when selected as the writing AI)
- Supadata (when using content extraction from YouTube or a URL)
- Serper.dev / SerpApi / Google Custom Search (when using retrieval of search rankings)
- DataForSEO (when using retrieval of search volume)
- ScreenshotOne / ApiFlash (when using screenshot capture)
- Fish Audio (when using synthesis of podcast audio)
Handling by these providers is governed by each provider's own privacy policy. For functions where no API key has been configured, no corresponding transmission occurs.
3-3. Stored Within the User's Site
Generated articles, images, and audio, entered API keys, and various setting values are stored in the database and media library of the User's WordPress site. API keys are stored encrypted. The Company has no ability to access any of this.
4. Purposes of Use
The Company uses information it obtains for the following purposes.
- Providing the Service, and authenticating and managing licenses
- Delivering software updates
- Billing usage fees, processing payments, and managing contracts
- Responding to inquiries and providing support
- Sending important notices, notice of changes to the Terms, and guidance regarding the purchase process
- Detecting and preventing unauthorized use
- Improving the Service and considering new features (used as statistical information that cannot identify any individual)
5. Provision to Third Parties and Outsourcing
Except where required by law, the Company does not provide personal information to a third party without first obtaining the individual's consent. However, to the extent necessary to provide the Service, the Company outsources the handling of information to the following providers.
| Outsourcing partner | Outsourced work / information provided |
| Stripe, Inc. |
Payment processing. Email address and information necessary for payment are provided to this company. Card information is obtained directly by this company. |
| Cloudflare, Inc. |
Provision of the license server and data-storage infrastructure. Account information and license information are stored on this company's infrastructure. |
| Resend, Inc. |
Sending of email. The destination email address and the message body pass through this company. |
These providers may store information outside Japan. The Company exercises appropriate oversight over its outsourcing partners.
6. Use of Cookies, etc.
- On the Company's My Page, cookies are used to maintain login state. These are necessary for the provision of the Service.
- Cookies can be disabled through your browser settings, but doing so will make some functions, such as logging in to My Page, unavailable.
7. Retention Period
- Account information / license information: retained after the end of the contract until the period required by law for retention, and the period needed to handle any disputes, has elapsed, and then deleted.
- An email address registered partway through the purchase process (retained to provide guidance about completing the purchase): automatically deleted no later than 60 days after registration.
- Access logs: deleted after a certain period has elapsed from the time of collection.
8. Security Control Measures
- All communications are encrypted using TLS.
- My Page passwords are stored as salted hash values.
- Access to administrative screens that handle personal information is limited to personnel who need it.
- API keys that the plugin stores within a User's site are stored encrypted.
9. Requests for Disclosure, Correction, Deletion, etc.
- The individual concerned may request, with respect to their own personal information held by the Company, notice of the purpose of use, disclosure, correction, addition, or deletion of the content, suspension of use or erasure, and suspension of provision to third parties.
- Please direct requests to the contact point in Section 11. After confirming the identity of the requester, the Company will respond without delay in accordance with applicable law.
- The Company may be unable to respond to a request as provided by law. In that case, the Company will notify the requester together with the reason.
10. Changes to this Policy
The Company may change this Policy in response to amendments to laws and regulations or changes to the content of the Service. When making a material change, the Company will give notice by posting on the Company's website or by notice to the registered email address. The revised content applies from the time it is posted on the Company's website.
11. Contact for Inquiries
| Contact point | Sorabun Support Desk |
| Email address | support@sorabun.com |
| Business hours | Accepted by email at any time (responses are handled in order on business days) |