Privacy Policy

Last updated: August 15, 2026

1. Principles

Typing Musou ('this site') treats protecting user privacy as a core responsibility. This policy describes what information we collect, how we use it, how we manage it, and your rights. The Service is intended for users located in Japan, and this policy is operated in accordance with Japan's Act on the Protection of Personal Information (APPI) and related laws and regulations. The Service is open to users of all ages, but children under 13 must use the Service only with the consent and supervision of a parent or legal guardian; the handling of children's personal information is set out in Article 12. The information we handle falls into two categories of a different nature. Because the rules that apply and the point of contact for disclosure and deletion differ between them, we distinguish them here at the outset.

  • Information handled in the relationship between you and this site — your account, profile, gameplay records from battles and the dojo, inquiry content, and the like. This is information we collect and use for our own purposes, and we are the personal information handler responsible for it. Most of this policy concerns this category.
  • Information handled under entrustment from a school — rosters, enrolment records, submissions, and grading records entrusted to us by a school or its founding body in connection with the school edition (classes, assignments, gradebook, Google Classroom integration, and so on). For this category the school is the personal information handler and we act as its processor. We do not use this information beyond the school's instructions and the scope of the service agreement. Details are set out in Article 11.

2. Information we collect

We may collect the following information. Note that we do not store passwords; authentication is delegated to Google. For the handling of collected information when used to train AI models, please refer to Articles 3 and 6. For the items relating to the school edition, please also refer to Article 11.

  • Google account information — upon Google sign-in, we receive the Google account identifier (sub), email address, display name, and profile picture URL. Not collected in guest mode.
  • Profile information — username, selected character/title/effect, avatar icon, and friend code. Configurable by the user.
  • Gameplay data — battle history (WPM, accuracy, win/loss, rating changes), dojo training sessions, owned items and in-game currency, transaction log, seasonal rankings, and friend relationships.
  • Keystroke data — per-key attempt counts and miss counts (and the miss rates derived from them), together with keystroke records collected for research. Collected in order to visualise which keys you struggle with, to suggest practice, and for the research use set out in Article 6. We do not record the text you type.
  • Inquiry content — category, message body, optional email address, and user agent, retained so the operator can reply.
  • Technical information & logs — IP address, browser/device info, access timestamps, request records (access logs), and anti-cheat logs. Collected automatically for security and abuse prevention. Collected IP addresses may be queried against public registries such as WHOIS for the purpose of identifying the organization that administers the originating network.
  • Access analytics data — via Google Analytics 4 (GA4) and Microsoft Clarity (Clarity), we collect page visits, time on page, viewport size, referrer, country/region inferred from IP address, and browser cookie IDs (GA4: `_ga` etc.; Clarity: `_clck`, `_clsk`, `MUID` etc.). Clarity additionally records session replays (mouse movement, clicks, scrolls, taps) and heatmaps. Text inside form inputs (including passwords) is masked client-side by Clarity and is neither transmitted nor recorded.
  • Cookies & local storage — used for login session management (NextAuth JWT), saving game settings, and access analytics (GA4 / Clarity).
  • [School edition] Information a student enters when joining a class — roster number and a display name used only inside the class. Entered by the student and editable by them at any time. Shown to the class teacher and to the other students in the class.
  • [School edition] Information imported from a Google Classroom roster — only where a teacher has connected Google Classroom: the names of the students on that course roster, their school email addresses, their Google Classroom user identifiers, and the course name and identifier. Used to match the Google Classroom roster against enrolment in the Service, and shown only to the class teacher and other teachers at the school. If no connection is made, none of this is collected.
  • [School edition] Teacher information entrusted to us at contract time — the names, work email addresses, and assignments (year group, subject, etc.) of teachers, provided to us as a roster when a school or its founding body enters into an agreement. Used to link a teacher to their school and classes when they sign in. We may hold this before the individual concerned has begun using the Service.
  • [School edition] Learning and assessment records — assignment completion status and timestamps, whether an assignment was completed by its due date, the text of submissions together with a snapshot of the student's weak keys at the time of submission, scores and exemptions entered by a teacher and which teacher entered them, and individual comments and returns from a teacher to a student.
  • [School edition] School and contract information — school name, prefecture, contract status and expiry, billing and payment records, and a history of operator actions (who did what, and when). Where a Google sign-in occurs on a school domain, we may also retain a hint used to infer that affiliation.
  • [School edition] Credentials used to access Google Classroom — only where a teacher has connected Google Classroom: the email address and identifier of the Google account that granted consent, and the access grant issued by Google (a refresh token). Tokens are stored encrypted. We never collect these from students.

3. Purposes of use

Collected information is used solely for the following:

  • Providing game features such as matchmaking, friends, leaderboard aggregation, and data sync
  • Authentication via Google, session management, and security
  • Detecting and responding to abuse such as cheating, macros, and rating manipulation
  • Investigating, recording, and responding to conduct prohibited by the Terms of Service (harassment, defamation, impersonation, posting inappropriate content, abuse of multiple accounts, etc.), including account suspension and corrective action. Such investigations may involve cross-referencing access logs, inquiry contents, and gameplay data
  • Protecting the rights, property, and safety of this site, its users, or third parties; complying with legal obligations; resolving disputes; and responding to inquiries from law enforcement and other public authorities
  • Improving service quality and considering new features
  • Responding to inquiries and sending important notices
  • Access analytics, usage pattern understanding, and UX improvement via Google Analytics 4 and Microsoft Clarity (including drop-off and interaction-friction analysis)
  • Training, evaluation, and improvement of AI models operated within the Service (matchmaking CPU behavior optimization, typing-assist features, anti-cheat models, etc.)
  • Statistical analysis, academic research, and third-party sharing or publication of anonymized gameplay data, and use or provision as training datasets for machine-learning and artificial-intelligence models (see Article 6 for details)
  • Screening usernames against the prohibited conduct set out in the Terms of Service (this involves sending the name to an external AI service; see Article 8 for what is sent, where, and how it is used for training)
  • In the school edition: running classes, distributing assignments, aggregating and displaying progress, producing growth records, analysing weak keys, and supporting teachers in instruction and assessment (see Article 11 for details)
  • In the school edition, where a teacher has connected Google Classroom: posting assignments to Google Classroom, returning grades, retrieving submission states, and posting announcements to the class
  • Concluding, performing, and administering agreements with schools and their founding bodies (including contract status, billing and payment administration, and responding to inquiries)

4. Third-party disclosure & processors

We do not share personal information with third parties without user consent, except in the following cases:

  • When required by law
  • When we receive a statutory inquiry from law enforcement, a court, or another public authority (including an investigative inquiry under Article 197(2) of Japan's Code of Criminal Procedure and a bar-association inquiry under Article 23-2 of the Attorney Act)
  • When necessary to protect life, body, or property (including where the Operator reports or consults with law enforcement regarding an incident in which this site or its users were harmed)
  • Disclosure to service providers required to operate the Service — including Google LLC for authentication, a self-hosted PostgreSQL database operated by the Operator on Oracle Cloud Infrastructure (Japan region) for primary data storage, Google Analytics 4 (Google LLC) and Microsoft Clarity (Microsoft Corporation) for access analytics, OpenAI, L.L.C. for username screening, and Google LLC for the Google Classroom integration in the school edition. These processors handle data only to the extent necessary — except that content sent to OpenAI, L.L.C. is used to train that company's models (see Article 8).
  • [School edition] Disclosure to teachers at the student's school — when a student joins a class, that student's learning records are shown to the class teacher and to other teachers at the school. This is the very purpose of the school edition, but from the student's own standpoint it is a disclosure to a third party, so we state it as a separate item. What is shown, and what is not, is set out in Article 11.
  • [School edition] Disclosure to Google Classroom — where a teacher has connected Google Classroom, the content of assignments, the grade derived from that student's completion status, and — where the teacher chooses to do so — the text of announcements to the class are sent to the Google Classroom course managed by the school. The destination is an environment the school itself administers, and whether anything is sent depends on the teacher's action. Returning grades is optional per assignment and is off by default.

5. Transfer of personal information to third parties located outside Japan

Among the processors listed in Article 4, Google LLC, Microsoft Corporation, and OpenAI, L.L.C. are located in the United States. As part of the entrusted processing, certain personal information such as authentication identifiers, access logs, interaction records, and usernames may be processed on servers located outside Japan. The same applies to communication with Google LLC for the school edition where a teacher has connected Google Classroom. Note that the database we operate is located in Japan (Oracle Cloud Infrastructure, Japan region): rosters, submissions, and grading records entrusted to us by schools are stored in Japan. Pursuant to Article 28 of Japan's Act on the Protection of Personal Information, we provide the following information.

  • Destination country — the United States of America.
  • Personal-data-protection regime in the destination country — The United States does not have a comprehensive federal personal-information-protection law equivalent to Japan's APPI; protection is provided through sector-specific federal laws (finance, healthcare, telecommunications, etc.) and state laws (such as the California Consumer Privacy Act / CPRA). For details, please refer to the 'Survey of foreign personal information protection regimes' published by Japan's Personal Information Protection Commission (https://www.ppc.go.jp/personalinfo/legal/kaiseihogohou/).
  • Safeguards taken by the recipient — Google LLC, Microsoft Corporation, and OpenAI, L.L.C. publish privacy protection programs aligned with OECD privacy guidelines. We confirm the contents of each provider's terms of service and data processing agreements (DPA) before entrusting data. Please refer to each provider's privacy policy for details (Google: https://policies.google.com/privacy / Microsoft: https://privacy.microsoft.com/ / OpenAI: https://openai.com/policies/privacy-policy/). Note that content sent to OpenAI, L.L.C. is used to train that company's models (see Article 8).

6. Anonymously processed information — research use & third-party sharing

This site may statistically process collected gameplay data into 'anonymously processed information' as defined in Article 43 of Japan's Act on the Protection of Personal Information (APPI) — that is, information processed so that no specific individual can be identified and the original personal information cannot be restored — and may then sell, share, or distribute it to third parties, and use or publish it in academic papers, research presentations, public datasets, training datasets for machine-learning and artificial-intelligence models, and similar outputs. The aim is to contribute to research in typing skill development, esports, human–computer interaction, natural-language processing, and machine learning.

  • Categories processed — typing speed (WPM), accuracy, win/loss, rating trajectories, mistype patterns, play time distributions, dojo stage progress, and other statistical data derived from gameplay.
  • Items removed or substituted — Google account identifier (sub), email address, real name or display name, profile picture, IP address, username, friend code, inquiry content, and any other information that could identify a person are never included.
  • Disclosure on third-party provision — when anonymously processed information is provided to a third party, the categories of items provided and the provision method will be published on this page, and the recipient will be informed that the information is 'anonymously processed information.'
  • No re-identification — this site will not re-identify specific individuals by matching created anonymously processed information with other data.
  • Information entrusted to us by schools is excluded — as set out in Article 1, information we handle under entrustment from a school (rosters, enrolment records, roster numbers, in-class display names, submissions, grades entered by teachers, teacher comments, and contract information) is excluded from the creation of anonymously processed information. This is information that should be handled only within the school's instructions, and we neither use it for research nor provide it to third parties, even in anonymized form. This Article applies only to gameplay records belonging to your own account (battles, dojo, keystroke data, and the like).

7. Analytics & cookies

This site uses access-analytics services Google Analytics 4 ('GA4') and Microsoft Clarity ('Clarity'). These services collect browser identifiers, access information, and interaction data through cookies and local storage.

  • Access analytics (GA4) — measures page views, in-SPA navigation, and custom events (battle start/end, dojo, login, purchase, etc.). IP addresses are anonymized by Google. You can opt out of GA4 via the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout).
  • Session analytics (Microsoft Clarity) — records session replays (mouse movement, scroll, tap interactions) and heatmaps. Form input contents (including passwords and other personal information) are masked client-side and are neither transmitted to nor recorded by Microsoft. You can opt out of Clarity via your browser's tracking-prevention features or by blocking the `clarity.ms` domain.
  • Universal opt-out options — these analytics can also be disabled by clearing/blocking cookies, blocking third-party cookies, using private/incognito mode, or sending a 'Do Not Track' signal from your browser.

8. AI username screening & use of your input for model training

When you set or change your username, we send the entered name to an external AI service (an API provided by OpenAI, L.L.C.) to automatically screen it against the prohibited conduct in the Terms of Service (defamation, impersonation, obscenity, etc.). This screening is advisory; the Operator makes the final decision.

  • The username under this Article is the only thing we send to an external AI service — the username screening described here is the sole case in which this site sends information to an external AI service. We never send learning records, assignment completion status, submissions, grades entered by teachers, keystroke data, battle records, inquiry content, or roster information to any external AI service. The same is true when you use the school edition. The models used for opponent CPU behaviour and for abuse detection run within the Service, and no information is sent externally for that processing.
  • What is sent — only the username text itself. We do not send account identifiers, email addresses, IP addresses, battle records, or any other information. The recipient therefore cannot tell who entered the name.
  • When it is sent — only when you set or change your name. Nothing is sent unless you change it. Nothing is sent when the submitted name matches your current name, when you revert to the initial name ('名無しの侍'), or when our own filter already rejected the name as an obvious prohibited term.
  • Use for AI model training — we use this API under terms (a free usage tier) whereby the content sent is used by OpenAI, L.L.C. to improve and train its models. Your entered username may therefore be used to train that company's models. Please keep this in mind when choosing a name, and in particular never include your real name, address, phone number, email address, or any other personal or sensitive information in your username.
  • If you do not want your input sent — simply do not change your username; a name you have already set is never sent under this Article. If you wish to change your name but do not want it sent to the AI service, please contact us via the contact page.
  • Disputing a decision — if you believe a name was rejected in error, please contact us via the contact page and the Operator will review it individually.
  • Attempt limit — name changes are limited to 3 per rolling 24 hours. An attempt rejected by the AI screening also counts toward this limit.

9. User rights

Users have the following rights regarding their own personal information. Requests for disclosure and similar actions are accepted via the contact page. For identity verification, we may ask you to be signed in with the Google account associated with the relevant account or to provide equivalent verification. We will respond, in principle, within two weeks of receipt, via email to the address you specify (please indicate if you prefer a written response). There is no fee for disclosure-type requests. However, we may decline disclosure-type requests in any case falling under Article 33(5) of Japan's Act on the Protection of Personal Information (cases where disclosure would risk harm to the life, body, property, or other rights or interests of the data subject or a third party; cases where disclosure would significantly impede the proper conduct of this site's business; or cases where disclosure would violate other laws or regulations).

  • Request disclosure of retained personal data and notification of purposes of use
  • Request correction, addition, or deletion of content
  • Request suspension of use or of third-party disclosure
  • Delete your account — you can do this yourself at any time from "Delete account" in the settings screen. Deletion takes effect immediately and cannot be undone. Because you can carry it out yourself, we do not require identity verification for it; what is erased and what is retained is set out in Section 10 below.
  • Point of contact for information we handle under entrustment from a school — as set out in Article 1, the school is the personal information handler for information entrusted to us in the school edition (rosters, enrolment records, submissions, grading records, and so on). Requests for disclosure, correction, or deletion of that information are, in principle, accepted through the school the student attends. Where such a request reaches us directly, we refer it to the school and act on the school's instructions. For information belonging to your own account (profile, gameplay records, and so on), we accept requests directly under this Article.

10. Data retention & protection

Account and gameplay data are retained while the account is active, under encrypted transport (HTTPS) and appropriate access controls. When you delete your account, everything under "What is erased" below is erased immediately. However, records that are bound up with other users' records, and records we must keep for a limited period to prevent abuse or to meet legal obligations ("What remains after deletion" below), are retained after being detached from information that identifies you, such as your name, display name, and email address. Data already anonymized and disclosed to or published by third parties under Section 6 cannot be technically re-identified and is therefore outside the scope of deletion.

  • What is erased — your username, email address, and Google account identifier; rating, rank, and season records; battle history and results; owned items (characters, icons, titles, effects); Musou Coins and transaction history; character enhancements; friends and friend requests; dojo records; login-bonus state; and keystroke data collected for research.
  • What remains after deletion — your opponents' own battle records (your identifier is stripped from them); anti-cheat logs (up to one year); penalty records; reports (which are also a record for the other party involved); friend-referral records (counts only, to prevent repeat claiming of rewards); and inquiry content (three years after resolution, detached from your account).
  • What remains after deletion if you use the school edition — your class enrolment record, roster number, submissions, assignment completion status, grades entered by teachers, and teacher comments. These are also the teacher's records, and deleting them would remove the enrolment itself from the roster and gradebook, leaving no way to tell who had left. The roster number is likewise kept so that the ordering of the roster holds. After account deletion your entry on the roster is shown as a deleted user.
  • What is erased if you use the school edition — your in-class display name, and any hint retained to infer school affiliation from a Google sign-in on a school domain. Names and school email addresses imported from a Google Classroom roster are erased when school data is deleted at the school's request (see Article 11).
  • Server logs — retained for up to 90 days.

11. Handling of personal information in the school edition

We provide the school edition — classes, assignments, the gradebook, Google Classroom integration and related features — under an agreement with a school or its founding body. This Article explains, for the students and guardians who use those features, who can see what and how long it is kept. For school and board-of-education staff we separately publish a fuller document, 'Handling of personal information in the school edition', setting out the categories of information handled, sub-processors, security measures, and the deletion procedure (https://typingmusou.com/en/school/privacy).

  • Our standing — for the rosters, enrolment records, submissions, and grading records entrusted to us by a school, the school is the personal information handler and we act as its processor. We do not use them beyond the school's instructions and the scope of the service agreement. Your own account and gameplay records, by contrast, remain governed by the relationship between you and this site even after you join a class.
  • How we obtain the information — by one of three routes: (i) a student enters a class join code and enters their own roster number and in-class display name; (ii) a teacher connects Google Classroom and imports the roster (names and school email addresses); (iii) a school entrusts us with a roster of its teachers at contract time. Route (ii) applies only where a teacher makes the connection; where none is made, we obtain nothing from Google Classroom.
  • What the class teacher and other teachers at the school can see — roster number, in-class display name, assignment completion status and timestamps, whether work was completed by its due date, the text of submissions, scores and exemption status, weak-key analysis, practice records such as the 60-second challenge, and the growth record. The growth record is built from every practice record on the account, including practice done before joining the class and practice done at home. Teachers are not shown who you played against outside class or the content of those matches, but the amount of practice and the degree of improvement shown to them include activity outside school. Viewing is open to teachers at the school; adding or changing records is limited to the class teacher.
  • What other students in the class can see — roster number, in-class display name, and the in-class ranking. The in-class ranking includes, as one of its metrics, the rating earned in ranked matches, which is a figure that moves through play outside school. The teacher can switch the metric, and may instead rank by practice volume or by 60-second challenge records.
  • What is never shown outside the school edition — roster numbers, in-class display names, names and school email addresses imported from a Google Classroom roster, and teachers' names and work email addresses are not shown anywhere outside the school edition (battles, leaderboards, public profiles, and so on). We continuously verify that these do not escape the school edition by means of an automated check over our source code.
  • What our operator can see — only what is necessary for incident response, abuse investigation, and answering inquiries. Operator actions on school data (importing or reverting a roster, removing a member, deleting school data, and so on) are recorded in an audit history.
  • If the agreement ends — on cancellation we do not delete school data. What stops appearing is the school screens only; a student's own account, in-game currency, rating, and gameplay records are entirely unaffected. If the school signs up again, everything returns as it was.
  • Deletion at a school's request — only on an explicit request from the school or its founding body do we delete that school's school-edition data (classes, enrolment records, roster numbers, in-class display names, rosters, assignments, submissions, and grading records). Even then we do not touch students' own accounts or gameplay records. The deletion is recorded, and that record serves as the basis for our completion report. Billing and payment records are retained as our own accounting records; they contain no personal information.
  • External AI services — we never send learning records, assignment completion status, submissions, grades entered by teachers, keystroke data, or roster information to any external AI service. The username screening in Article 8 is the sole case in which we send anything to an external AI service.

12. Children's privacy

We handle children's information with care, including where the Service is used in schools. The Service is intended for users located in Japan and is operated in accordance with Japan's Act on the Protection of Personal Information and related laws, but we also set out below our position on the standards expected internationally of a service supplied to educational institutions.

  • No advertising — the Service displays no advertising of any kind, whether directed to children or otherwise. Nor do we use the information we collect for behavioural or other advertising purposes, or provide it to third parties for such purposes.
  • No purchases by students — our in-game currency is virtual, cannot be exchanged for cash, and there is no facility to buy it with real money. No path exists by which a student can make a payment.
  • Children under 13 — children under 13 should use the Service with the consent and supervision of a parent or legal guardian. Where the Service is used through the school edition, explanation to guardians and the collection of any consent required are carried out by the school, which stands in a position to decide on the use of educational tools on the guardian's behalf. In that case we handle information on the school's instructions, on the basis that the school has obtained guardian consent or is authorised to consent on the guardian's behalf.
  • Our position under the US Children's Online Privacy Protection Act (COPPA) — we do not intend to collect personal information directly from children under 13 without the consent of a parent or of the school. Where the Service is used through a school, we act as an agent of the school and handle information only for the educational purposes the school specifies. Guardians may request review of their child's information, cessation of further collection, and deletion, through the school the child attends.
  • Our position under the US Family Educational Rights and Privacy Act (FERPA) — the learning records and assessment records entrusted to us by a school are treated as education records under the school's control. We do not use them contrary to the school's instructions, do not disclose them to third parties without the school's authorisation, and on termination will delete or return them at the school's request (see Article 11).
  • Inquiries from guardians — inquiries relating to the school edition are, in principle, accepted through the school the student attends. Where going through the school is impractical, please contact us directly via the contact page.

13. Personal-information handler disclosure

The name and address of the personal information handler (Operator) for this Service (or, for a corporation, the corporate name, registered head-office address, and representative's name) and the complaint contact will be provided promptly when a data subject whose personal data is held by this site submits a request via the contact page and completes the identity verification set out in Article 9 (handling under Article 32(1) of Japan's Act on the Protection of Personal Information). We are unable to respond to requests from persons whose personal data is not held by this site. For the school edition, because schools and boards of education must be able to complete their own review, we provide the Operator's name, address, representative, and complaint contact promptly in writing on request or on conclusion of a contract; that procedure is set out in Article 2 of 'Handling of personal information in the school edition' (https://typingmusou.com/en/school/privacy). The complaint/inquiry window itself is the contact page linked at the end of this document.

14. Contact

For privacy questions, please use the contact page.

15. Changes to this policy

This policy may be updated to reflect legal changes or service updates. For significant changes, we will announce the updated content and the effective date on the site no later than 14 days before the effective date. Continued use of the site on or after the effective date constitutes acceptance of the updated policy.