Handling of personal information in the school edition

This document is written for school and board-of-education staff. It sets out the personal information handled by the school edition of Typing Musou (classes, assignments, the gradebook, Google Classroom integration, and related features), in the order such matters are usually raised during a cloud-service review.

Last updated: September 7, 2026

1. Status of this document

This document supplements our Privacy Policy (the 'main policy') with a fuller account of the school edition. It does not replace the main policy and should be read alongside it. Where this document and the main policy differ in respect of the school edition, this document prevails. Matters not covered here are governed by the main policy. The conditions of use for the school edition are set out in Article 10 of the Terms of Service.

2. Operator

The personal information handler for this Service ('we') is as follows.

Operatorタイピング無双
Representative横山誠
Contact / complaints[email protected]

The registered address (the representative's own address, as this is a sole proprietorship) will be provided promptly in writing on request — via the contact above or the contact page linked below — and is stated in the service agreement and quotation when a contract is concluded.

3. Our standing in relation to personal information

Where the school edition is used, the personal information handled by the Service falls into two categories with different standings. This distinction determines which party receives requests for disclosure, correction, and deletion.

  • Information entrusted to us by the school (we act as processor) — rosters, enrolment records, roster numbers, in-class display names, assignment completion status, submissions, grading records, teacher comments, and contract information. For these, your school (or its founding body) is the personal information handler and we handle them under entrustment. We do not use them beyond your instructions and the scope of the service agreement, do not repurpose them, and exclude them from the creation of anonymously processed information.
  • Information handled between the student and us (we are the handler) — the Service account, username, and gameplay records from battles and the dojo. These arise from the student's use of the Service as an individual user, and we continue to handle them on our own responsibility after the student joins a class. The school edition shows part of this record to teachers for the purpose of instruction.

4. Categories of personal information handled

The categories handled by the school edition are set out below, grouped by how they are obtained. The Google Classroom items arise only where a teacher performs the connection; where no connection is made, none of them is collected.

How it is obtainedCategoriesPurpose
Entered by the student when joining a classRoster number; display name used only inside the classOrdering the roster, identifying the student on the progress board, matching against the school roster
Generated automatically from the student's playAssignment completion status and timestamps, whether completed by the due date, a record of each individual practice run (kind of practice, speed, accuracy, timestamp, difficulty of the practice opponent), per-key attempt and miss countsAutomatic assessment of assignments, progress aggregation, growth records, weak-key analysis
Entered by the studentThe text of submissions and a snapshot of weak keys at the time of submissionReviewing and giving guidance on submitted work
Entered by the teacherScore overrides, exemptions, which teacher acted, individual comments and returnsRecording assessment, individual guidance
When a student signs in with a Google account on the school's domainA hint as to which school the student belongs to (the domain used to sign in)Suggesting the school when joining a class; never used to establish membership
The Google Classroom roster (only where a teacher connects it)Student and teacher names, school email addresses, Google Classroom user identifiers, course name and identifierMatching the Google Classroom roster against enrolment in the Service; setting up the teachers responsible for a class
A teacher roster entrusted to us at contract timeTeacher names, work email addresses, assignments (year group, subject, etc.)Linking a teacher to their school and classes at sign-in
When a teacher connects Google ClassroomThe email address and identifier of the consenting Google account, and the access grant issued by Google (refresh token)Posting assignments, returning grades, syncing rosters
Contract and billing administrationSchool name, prefecture, the name and contact email address of the school's representative, contract status and expiry, billing and payment records, operator action history and sales notesConcluding, performing, and administering the agreement; evidence for deletion requests

For information collected across the Service generally (Google account information, access logs, analytics data, and so on), please refer to Article 2 of the main policy. Where a student has not set an in-class display name, the roster and rankings show that student's in-game username instead (see §7). The Service does not collect special care-required personal information (medical history, disability status, or entries in a student's cumulative guidance record other than grades).

5. Purposes of use

The categories above are used only for the following purposes. We do not use them for serving advertising, measuring advertising performance, or profiling, and we do not sell them to third parties.

  • Running classes; distributing and automatically assessing assignments; aggregating and displaying progress; producing growth records; analysing weak keys
  • Supporting teachers in instruction and assessment (including producing the gradebook and CSV exports)
  • Where a teacher performs the connection: posting assignments to Google Classroom, returning grades, retrieving submission states, and posting announcements to the class
  • Concluding, performing, and administering the agreement with the school or its founding body (including contract status and billing administration)
  • Incident response, abuse investigation, and answering inquiries

6. Processors, sub-processors, and storage locations

Information entrusted to us by schools is stored in Japan. The providers we use are as follows. We confirm the terms of service and data processing arrangements each provider publishes before using them.

ProviderRoleInformation handledStorage location
Us (self-operated)Operating the application and databaseAll categories in §4 of this documentJapan
Oracle Corporation Japan (Oracle Cloud Infrastructure)Providing server infrastructure; we operate PostgreSQL ourselves on itAs above (as the location of the database we operate)Japan (Tokyo region)
Google LLC (Google account authentication)Sign-in authenticationAccount identifier, email address, display nameUnited States
Google LLC (Google Classroom API)Roster import, assignment posting, grade return (only where a teacher connects it)Course name, roster names and email addresses, assignment content, gradesUnited States (the Google Workspace your school administers)
Google LLC (Google Analytics 4)Access analyticsPage views, browser cookie IDs, and the like (see §9)United States
Microsoft Corporation (Microsoft Clarity)Interaction analyticsAs above (see §9)United States
OpenAI, L.L.C.Username screening only (see §8)Only the entered username textUnited States

The information required by Article 28 of Japan's Act on the Protection of Personal Information in respect of transfers to third parties located outside Japan (the personal-data-protection regime in the destination country and the safeguards taken by the recipient) is set out in Article 5 of the main policy.

7. Who can see what

This is the most important point in the school edition. Because the Service runs on the same account as the game, part of the record of practice a student does outside school is shown to teachers, as described below. Please be sure to cover this when informing students in advance; the Service also displays the same point on its class-join screen, immediately above the join button.

InformationClass teacherTeachers at the schoolOther students in the classStudents in other classes at the schoolOutside the school edition
Roster numberView and editViewViewNot shownNot shown
In-class display name (or the in-game username, if unset)View and editViewViewRankings onlyNot shown
Assignment completion, submissions, scores and exemptionsView and editViewNot shownNot shownNot shown
Teacher comments and returnsView and editViewNot shownNot shownNot shown
Weak-key analysisViewViewNot shownNot shownNot shown
Growth record and recent practice list (includes practice outside school)ViewViewNot shownNot shownNot shown
Rankings (position by rating and similar)ViewViewViewViewNot shown
Whether the student is currently connected, and what they are practisingViewNot shownNot shownNot shownNot shown
Names and school email addresses from the Classroom rosterViewViewNot shownNot shownNot shown
Teacher names and work email addressesViewViewNot shownNot shownNot shown

Only the class teachers may add or change records — including any year-group lead or subject teacher added as a class teacher; viewing is open to teachers at the same school. 'Outside the school edition' means screens outside the school features, such as battles, leaderboards, and public profiles.

  • About the name shown — rosters and rankings show the in-class display name where one exists, and otherwise the student's in-game username. The student enters the in-class display name when joining, and a teacher can rewrite it at any time, so a name unsuitable for the classroom can be corrected.
  • About the growth record and the practice list — the growth record compares the average of the first ten sessions with the average of the most recent ten, drawing on every practice record on the account. Teachers are additionally shown the last twenty practice runs individually (kind of practice, speed, accuracy, timestamp). Both include records from before the student joined the class and practice done at home or at the weekend. Teachers are not shown who the student played against or the content of those matches, but the timing and the degree of improvement include activity outside school. The Service displays the date range of each window on screen, so teachers can take that into account.
  • About rankings — the scope can be switched between the class, the whole school, and class-versus-class, and students and teachers see the same thing. Because the school-wide ranking is visible to students in other classes, it shows only the name (in-class display name or in-game username) and the position; roster numbers are never shown there. The default metric is the Service's rating, a figure that moves through ranked matches, and a teacher can switch it to practice volume or 60-second challenge records. The choice of scope and metric affects what students should be told, so please review it.
  • About the 'what they are doing now' display — to support supervision during a lesson, the class teacher's screen shows whether each student in the class is connected and what kind of practice they are currently doing. This information lives only in the server's transient memory and is never written to the database, so it cannot be looked up afterwards as a history and is not included in CSV exports. Only the class teachers (and school administrators) can see it; teachers of other classes cannot.
  • How we guarantee this stays inside the school edition — roster numbers, in-class display names, names and school email addresses imported from a Classroom roster, Google Classroom user identifiers, and teachers' names and work email addresses are never emitted outside the school edition. We continuously run an automated test that checks these items do not appear in code outside the school edition, so a breach is caught at build time.

8. Sending information to external AI services

The only case in which the Service sends information to an external AI service is the screening of usernames (the display name shown within the Service). Learning records, assignment completion status, the text of submissions, grades entered by teachers, comments, keystroke data, and roster names and email addresses are never sent to any external AI service.

  • When it is sent — only when a student sets or changes their username. Nothing is sent unless they change it, and a name already set is never sent afterwards.
  • What is sent — only the entered username text. Account identifiers, email addresses, IP addresses, school name, class name, and grades are not sent. The recipient cannot tell who entered the name.
  • How the recipient handles it — we use the OpenAI, L.L.C. API under terms whereby the content sent is used to improve and train that company's models. This is stated in Article 8 of the main policy and Article 5 of the Terms of Service. Please advise students not to include their real name, address, or other personal information in a username.
  • About models running inside the Service — opponent CPU behaviour and abuse detection use models we operate within the Service. No information is sent externally for that processing.

9. Access analytics

We use Google Analytics 4 and Microsoft Clarity to improve our screens. These operate when the Service is used from school devices as well. What is collected is browser identifiers and interaction data; names, roster numbers, grades, and the text of submissions are never sent. The cookies used are named in Article 2 of the main policy.

  • Google Analytics 4 — measures page views, in-app navigation, and custom events (battle start and end, dojo, sign-in, and so on). IP addresses are anonymized by Google and are not retained in a form we can inspect.
  • Microsoft Clarity — records session replays of mouse, scroll, and tap interaction, and heatmaps. On the school-edition screens, both the text inside form inputs (including the text of submissions) and the text rendered on screen (names, roster numbers, scores) are masked on the device before anything is sent. What reaches Microsoft is the page structure with its text obscured, plus the interaction trail.
  • How to disable it — blocking traffic to `clarity.ms` and `google-analytics.com` through your device management will stop this measurement. Browser tracking prevention (including the default settings in Edge and Safari) also blocks it in most cases. If your policy cannot accommodate this measurement, please contact us before adoption.

10. Retention, termination, and deletion

We keep students' accounts and school data clearly separated. Termination of the agreement with a school does not affect a student's own account.

  • While enrolled — school data is retained for the term of the agreement and for as long as you require it. Classes are archived at the change of school year, but records are not removed (CSV exports for past years remain available).
  • If the agreement is cancelled — we do not delete data. What stops appearing is the school screens only; students' accounts, in-game currency, rating, and gameplay records are entirely unaffected. If you sign up again, everything returns as it was. You can tell families that cancelling does not affect their children's accounts.
  • Deletion on request — only on an explicit request from your school or its founding body do we delete that school's school-edition data (classes, enrolment records, roster numbers, in-class display names, rosters imported from Classroom, assignments, submissions, grading records, and teacher comments). We confirm the scope and record counts with you before carrying it out. Even then we do not touch students' accounts or gameplay records.
  • Evidence of deletion — the deletion is recorded in our audit log together with the date, scope, and record counts. That record is designed to survive the removal of the school's own rows, so it can be supplied directly as the basis for a completion report.
  • What remains with us after deletion — billing and payment records (school name, invoice number, amount, issue/due/payment dates, and our own notes) are retained as our accounting records for the period required by tax and other legislation. They contain no student personal information.
  • If a student deletes their own account — the in-class display name and the hint as to which school they belong to are erased. The enrolment record, roster number, submissions, and grading records remain, because they are also the teacher's records; deleting them would remove the enrolment itself from the roster and gradebook, leaving no way to tell who had left. The roster entry is then shown as a deleted user. Rows imported from a Classroom roster (name and school email address) are a copy of the Classroom roster rather than information belonging to the account, so they are not removed by account deletion; they are, however, within the scope of a deletion request from your school (see 'Deletion on request' above).
  • Server logs — retained for up to 90 days.

11. Returning your data

Teachers can export rosters, progress, and the gradebook in CSV format while enrolled and at termination. CSV files are written in UTF-8 with a byte-order mark, so they open directly in the Japanese edition of Excel. On request at termination we will supply your school's data in CSV format. If the Service is discontinued, we will give advance notice and direct you to the same export route.

12. Security measures

The measures we take are as follows. If you need us to complete an information-security self-assessment form, please request it via the contact page.

  • Encryption in transit — all traffic is encrypted with HTTPS.
  • Protection at rest — the access grant for Google Classroom (refresh token) is stored encrypted with AES-256-GCM. The Service stores no passwords; authentication is delegated to Google accounts.
  • Access control — only the class teachers may add or change class records. Viewing is limited to teachers at the same school and never spans schools. While a contract is suspended, viewing is permitted and creation of new records is stopped.
  • Separation of privilege — all reads and writes to Google Classroom are performed as the teacher's account. Students are never asked for additional permissions, and we never access Classroom using a student's Google account.
  • Audit records — operator actions on school data (importing or reverting a roster, removing a member, updating school details, executing a deletion) are recorded with the actor, timestamp, and content. Changes of contract status are recorded likewise.
  • Mechanical guarantee that school information stays out of the game — an automated test continuously checks that roster numbers, in-class display names, roster names and school email addresses, and teachers' names and work email addresses do not appear in code outside the school edition. This is guaranteed by construction rather than by operational care.
  • Log retention — server logs are kept for up to 90 days and used only for incident response and abuse investigation.
  • Supervision of personnel — the Service is developed and operated by a single person, and access to school data is limited to the Operator. Operations are not entrusted to any third party (other than the provision of server infrastructure).
  • Understanding the external environment — information entrusted to us by schools is stored in Japan. As set out in §6, authentication, access analytics, username screening, and communication with Google Classroom involve providers located in the United States; we have informed ourselves of the personal-data-protection regime in the United States and exercise the necessary and appropriate supervision. An outline of that regime is given in Article 5 of the main policy.

13. Response to an incident

If personal data is leaked, lost, or damaged, or we identify a risk of that, we will promptly investigate the facts and contact your designated staff. Where the situation requires a report to Japan's Personal Information Protection Commission and notification of data subjects under Article 26 of the Act on the Protection of Personal Information, we will promptly notify you as processor and supply the information you need for your report. We will also act to contain the harm, determine the cause, implement measures to prevent recurrence, and report the outcome. Routine communication about outages and maintenance is provided via the contact page and in-service announcements.

14. Children's privacy

As a service supplied to educational institutions, we state the following.

  • No advertising — the Service displays no advertising of any kind. We do not use the information we collect for behavioural or other advertising purposes, nor provide it to third parties for such purposes.
  • No purchases by students — in-game currency is virtual, cannot be exchanged for cash, and cannot be bought with real money. No path exists by which a student can make a payment. Fees for the school edition are paid by your school under its agreement with us.
  • Guardian consent — where the Service is used through a school, explanation to guardians and the collection of any consent required are carried out by your school, which stands in a position to decide on the use of educational tools on the guardian's behalf. We handle information on your instructions, on the basis that you have obtained guardian consent or are authorised to consent on the guardian's behalf. If you need material to use when explaining the Service to guardians, please contact us.
  • Our position under COPPA (US Children's Online Privacy Protection Act) — we do not intend to collect personal information directly from children under 13 without the consent of a parent or of the school. Where the Service is used through a school, we act as an agent of the school and handle information only for the educational purposes the school specifies. Guardians may request review of a child's information, cessation of further collection, and deletion, through the school the child attends.
  • Our position under FERPA (US Family Educational Rights and Privacy Act) — the learning and assessment records entrusted to us by a school are treated as education records under the school's control. We do not use them contrary to the school's instructions, do not disclose them to third parties without the school's authorisation, and on termination will delete or return them at the school's request.

15. Handling of information received from Google APIs (Limited Use)

Where a teacher connects Google Classroom, the Service obtains information through Google APIs. Typing Musou's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • Permissions requested — the Classroom permissions are roster import (read courses, read rosters, read roster email addresses), assignment posting and grade return (student coursework, topics), and posting to the class (announcements, materials — this last group is optional, and the other features work without it): seven in total, and we request nothing beyond these. Alongside them we request the same basic permissions as Google sign-in (openid and viewing the email address), so that we can establish which Google account gave consent. The individual permission names and the setup procedure are listed in 'Setting up the Google Classroom integration (for school admins)'.
  • How the information is used — solely for the purposes in §5 of this document: matching rosters, posting assignments, returning grades, and displaying submission states. It is never used for advertising and is never sold or transferred to third parties. Human review occurs only where necessary, such as incident response at your request.
  • Disconnecting — a teacher may disconnect at any time. After disconnection the Service does not access Google Classroom, and the stored access grant is deleted.
  • Students give no consent — because all reads and writes to Classroom are performed as the teacher's account, students are never asked for additional permissions. Students need only an ordinary Google sign-in, and can alternatively join with a six-character class code without using a Google account at all.

16. Where to direct requests

For the information entrusted to us by your school in the school edition (rosters, enrolment records, submissions, grading records, and so on), your school is the personal information handler. Requests from students and guardians for disclosure, correction, cessation of use, or deletion should, in principle, be received by your school. Where such a request reaches us directly, we refer it to your school and act on your instructions. For information belonging to the student's own account (profile, gameplay records, and so on), we accept requests directly under Article 9 of the main policy. Requests from your school to us for disclosure, correction, or deletion of the information we hold are accepted at any time via the contact page.

17. Changes to this document

We may change this document in response to changes in the law, changes of processor, or the addition of features. The revised text is published on this page, with the date of last update shown at the top. Where we change the categories of personal information handled, the purposes of use, the processors, or the retention periods, we will as a rule notify the designated staff at schools under contract by email at least 30 days before the change takes effect. If your school does not agree to a change, you may terminate the agreement.

18. Contact

For questions about this document, please use the contact page.