みんなのAI本体・Mobile:プライバシーの説明(2026年9月18日改定)
効力発生日:2026年9月18日。対象は、みんなのAIの家庭PC本体と、その同じAIへ接続するiPhone・Android向けアプリです。運営者は株式会社エナジーコネクト(東京都港区新橋2-20-15)です。家庭PCの処理の説明は本体とMobileに共通し、端末・カメラ等の説明はMobile向けです。以下には開発中の設計と、2026年9月13日にownerが採択した初回セットアップおよびHome→Mobile出力の境界が含まれます。実機、最終署名版、提供前の機能に関する未確認事項は、その旨を本文に明記します。
適用範囲と自宅のAI
Mobileは自宅PCで動く同じ一つの家庭AIへの入口です。家庭PCで会話を処理する設計であり、接続できない場合に別のクラウドAIや端末内AIへ自動で切り替える仕様ではありません。
このページのWeb/API Store向け説明にあるクラウドAIへの送信、チャット履歴の非永続保存、AWSでの保存、Webアカウント削除は、家庭PCの会話や記憶に一律には適用されません。Mobileから別途Webサービスや外部APIを利用する場合は、その処理について各サービスの説明も確認してください。
端末と家庭PCで扱う情報
端末では、入力中の文章、応答、表示中の会話・共有情報・伝言、本人認証の一時情報を扱います。初版はこれらの本文を端末の永続的な履歴やオフライン閲覧用データとして保存しない設計です。家庭との接続情報、端末鍵の参照、登録済み資格情報の参照、未確認操作の結果を確認するための識別情報は、端末の保護領域に保持する対象です。OSごとの保存・バックアップ除外・消去の実機確認は未完了です。
会話の結果確認に伴うOS本人確認が中断された場合、同じ未完了の本人確認と、その中断中に届いた結果だけを、元の有効期限内で端末の一時メモリに保持する設計です。画面の本文・PIN・通常セッションは引き継がず、再確認と明示操作なしに送信しません。取消・ロック・期限切れ・アプリ終了等で破棄します。これは会話の結果確認に限る設計であり、共有情報・伝言や一般的なバックグラウンド保持の説明ではありません。
家庭PCは、登録家族・端末の識別情報、認証用の公開鍵・証明情報、本人の会話とAIの返答、記憶、明示的な共有情報・伝言、処理結果と復旧に必要な記録を扱います。会話には本人に紐づく暗号化保存の実装があり、端末で履歴を保存しないことは、家庭PCでも保存しないという意味ではありません。会話・記憶の処理には、認証、回答生成、継続した会話、本人が許可した共有、結果確認・復旧という目的があります。
端末登録と、その端末を使う人物の認証は別です。登録した本人のパスキー認証等を用い、共有端末では本人用PINも確認する設計です。一つの家庭AIを使うことは、家族の会話や記憶を全員へ公開することを意味しません。別の家族への開示には、その情報の共有範囲と本人の権限の確認が必要です。保護者による未成年の会話閲覧や生命安全に関する通知は、Mobileで利用可能な機能として案内していません。
初回のprivate内容を開く前のセットアップは、home trustの保存からdevice_verified、最初の人物credentialの保存、別の通常本人認証の完了までを一つの進行中sessionとして扱う設計です。その間に表示できるapp-owned controlは「Desktop QRを読み取る」と「同じ操作の保存結果を確認する」の最大二つだけで、端末候補、人物登録、取消証拠をphaseごとに割り当てます。scannerの自動起動、結果の自動poll、進行中effectの自動再送、人物一覧、private表示は行いません。各phaseは保存済みexact stateを再読して決定し、background/lock、人物・端末・home変更、unreadable/corrupt stateではprivate gateを開かず、通常本人認証とcurrent sessionのreadback後に二つのcontrolを隠します。これは採択された設計であり、source-connected/focused-tested/Android debug buildまで確認済みですが、実camera、実端末、署名配布、本番の完了を示しません。
会話の保存や記憶の更新と、モデルを更新する自己学習・貢献学習は別の処理です。ownerが採択した製品前提では、学習は製品利用に含まれ、適格なローカル学習に別途opt-inやメモリ同意トグルを要求しません。ただし、学習の取得元、用途、開示範囲、外部送信、停止・削除の扱いは処理ごとの個別境界と必要な同意に従って確定・説明します。家族内での共有許可や通常会話の認証を、別の人物のデータや外部送信への許可へ拡張しません。この説明は、Mobileからこれらの学習機能を利用できるという案内ではありません。
本人の会話・記憶と、家庭AIが共有する能力の改善は同じ処理ではありません。私的な会話本文をそのまま家族共通知識へ自動転用せず、共有可能な経験にする場合も同意、由来、プライバシーと開示範囲を確認する設計です。家庭PC内の処理と中央サービスへの学習貢献も区別し、貢献する情報、送信先、同意・撤回方法と削除への影響は、提供する機能に合わせて説明します。
通信、中継、外部サービス
端末と家庭PCの間は暗号化し、中継サービスが会話本文を復号せずに通信を運ぶ設計です。ただし中継や接続先では、IPアドレス、接続時刻、通信量などの通信に伴う情報を観測し得ます。中継の運営・委託先、処理国、記録項目、保存期間、本番環境での検証は、機能提供に向けた確認事項です。「データ収集なし」「完全匿名」を意味しません。
家庭AIから外部APIやツールを利用する処理は、家庭PC内での会話処理と区別します。外部へ渡す入力、認証情報、利用・決済情報等は、その機能、本人の権限・同意、送信先に応じて定まります。Mobileの全会話がAnthropic等へ自動送信されるという説明ではありません。送信先ごとの取扱いは利用可能な機能と合わせて確定する必要があります。
端末証明やパスキーにはApple・Google等のOS機能を利用する設計です。OS・認証サービス自身の処理は各提供者の方針にも従います。アプリに組み込むSDKを含め、配布版が実際に送信する情報を確認してからストアのプライバシー表示を確定します。
AI回答の通報(提供前の設計)
登録された本人が自分に表示された保存済みAI回答を選び、分類と開発者への開示を確認して明示的に通報した場合だけ、家庭PCはその回答本文、分類、照合に必要な世帯・本人の識別ハッシュ、操作・回答の識別情報、本文ハッシュ、時刻を株式会社エナジーコネクトの専用通報窓口へ送る設計です。Mobileは回答本文を通報の通信要求に含めず、家庭PCが本人の保存済み回答を再確認します。利用者の質問文、前後の会話、添付、氏名、認証情報は開発者へ送りません。
受付された通報は専用鍵で暗号化して保存し、指定された運営担当者だけがモデレーションのために閲覧します。保存期間は受付から90日で、満了後に削除します。受付は違反認定、回答の削除・修正、緊急対応、本人への返信を約束するものではありません。この機能は本番の保護・運用確認が終わるまで利用可能とは案内しません。
カメラ、音声、診断情報
カメラは、自宅PCに表示された端末登録・本人登録用QRコードを、利用者が読み取り操作を選んだときに読み取るために使用します。読み取った接続情報を家庭との登録・確認処理に使います。カメラ権限はOS設定で変更できます。
Mobileの音声会話は設計・検証中です。音声による本人再確認は利用可能な機能として案内しておらず、話者類似度を本人認証へ昇格させません。音声認証情報の採否は未確定です。計画する方式は、スマホの生音声を暗号化して家庭PCへ送り、生音声を永続保存せず処理するものです。会話として採用された本人の発話とAIの返答は、本人に紐づく会話履歴へ保存し、記憶すべき情報は既存の同意・開示ルールに従って扱います。計画する音声の取得・再生は、アプリが前面にあり端末のロックが解除され、指定された本人のcurrent sessionとauth revisionが有効な間だけ行います。別アプリへの切替、background、画面消灯、OS lockでは停止し、app/adapterのraw PCMと未確定transcriptを破棄します。foregroundへ戻っても以前のVoice sessionを再開せず、同じ操作の本文を含まないcleanup readbackと新たな本人認証を完了した後に、利用者が明示的に新しい操作を開始します。この停止・破棄境界は採択設計ですが、nativeのpermission・録音表示・audio session/route/interruption処理、音声認証情報の有無、実装・保持期間・削除手続き、提供前の検証は未完了であり、確定後に説明します。生音声を永続保存しない設計でも、音声認証用の特徴情報等を一切扱わないことを意味しません。
Home→Mobileの付き添いVoice replacementは設計のみで、capabilityは未広告です。限定出力として採択された設計は、同じ進行中sessionの24 kHz、mono、signed 16-bit little-endian PCMの合成AI応答と、同じownerに既に保存されたcurrent会話projectionから読む現在字幕だけを、同じhousehold/person/device/session/auth revisionにcurrentな登録済みpersonal Mobile一台へ、そのlive sessionの応答再生とaccessibility上の現在字幕表示のためだけに送るものです。未確定transcript、別人物の会話・記憶、人物一覧、tool/payment内容、raw local storeは送らず、shared端末、別人物・別household、運営cloud、一般Web、push、別Mobile AIを宛先やfallbackにしません。MobileではPCM/字幕を永続化、offline履歴化、学習、分析、crash report、log、queue、retryに使いません。app/adapter所有RAMは各方向5秒以下で、consume、cancel、disconnect、background/lock、route/person変更、認証失効時に停止・破棄します。relayは本文を復号せず、remote Voiceの実装・実機・配布・本番有効化は未確認です。
本人の話し方に合わせる音声学習は、本人認証、取得元の音声利用条件、音声専用の受入条件に従う別の処理です。これは適格なローカル学習の追加opt-inやメモリ同意トグルを求める記載ではありません。生音声を自宅PCへ転送する許可だけで、その音声を学習に使えるとは扱いません。計画する適応対象は話速・間・抑揚などの出力であり、声色、AIの人格、推論や返答内容を本人別に変更するものではありません。私的な音声、話し方の統計、音声適応データ、選好・評価証拠を共有・販売・外部配布する設計ではありません。Mobileから転送された音声の学習への利用条件と実装・検証は未完了です。
診断は会話本文、PIN、認証トークン、鍵、通信内容を含めない設計です。Androidの現行sourceでは、mobile_scanner 7.4.1の既定bundled Google ML Kit barcode-scanning 17.3.0(resolved runtimeではplay-services-mlkit-barcode-scanning 18.3.1とbarcode-scanning-common 17.0.0)が使われ、ML Kit初期化とGoogle DataTransport/CCTを含む診断・利用状況メトリクスの処理があり得ます。Googleの説明では画像・認識結果はGoogleへ送らず端末内で処理しますが、ML Kitはdevice/app情報、インストール識別子、性能、API設定・サイズ、feature version、event/error等のメトリクスを診断・利用状況分析のためGoogleへ送信するとされています。送信・保存条件は最終署名build、SDK通信、ストア申告で確認が必要です。iOSはApple Visionとcollection/trackingなしのPrivacyInfo.xcprivacyをsourceで確認していますが、最終artifactの全通信を証明しません。
保存期間と削除・利用停止の相談
Mobileは、入力中の文章、応答、表示中の会話・共有情報・伝言、PCM、字幕を、端末の永続的な履歴、オフライン閲覧用データ、queue、retry、log、crash report、学習・分析用データとして保存しません。未完了の本人確認とその結果を端末の一時メモリに保持する場合も、取消、ロック、期限切れ、アプリ終了、切断、認証失効または対象変更で破棄します。
アプリのアンインストール、端末の連携解除、家庭の登録ユーザーの削除、会話・記憶の削除、SiglumeのWebアカウント削除は、それぞれ別の操作です。端末の連携解除または家庭側で端末を削除した場合、端末の保護領域にある家庭接続情報、端末鍵の参照、登録済み資格情報の参照は無効化されます。家庭PCの会話・記憶・家族の登録、認証、復旧記録や購入権利は別に管理され、端末解除やWebアカウント削除だけでは削除されません。
削除・開示・訂正・利用停止に関する相談は、問い合わせフォームの冒頭に「みんなのAI Mobile/個人情報に関する請求」と書き、希望する対象(端末の連携、家庭PCの本人データ、Webアカウント、問い合わせ記録など)を示してください。本人確認と対象範囲を確認したうえで対応します。家庭PC側のデータの削除は家庭側の削除手続きが必要で、サポートが遠隔で閲覧・削除できるとは限りません。一般的な権利請求は、このプライバシー説明に記載する原則30日以内を目安に扱います。
本体・Mobileのサポート・個人情報に関する相談
Minnano AI home application and Mobile: privacy information (revised September 18, 2026)
Effective September 18, 2026. This section covers the みんなのAI (Minnano AI) home-PC application and the iPhone and Android app connecting to that same AI, operated by Energy Connect Co., Ltd., 2-20-15 Shinbashi, Minato City, Tokyo, Japan. Home-PC processing information is shared by the home application and Mobile; phone and camera information is Mobile-specific. It includes designs still in development, including the owner-adopted setup and Home-to-Mobile output boundaries from September 13, 2026. Items that still require verification on a real device, in a final signed build, or before a feature is provided are identified in the text.
Scope and your home AI
Mobile is an entrance to the same single household AI running on your home PC. Conversations are designed to be processed on that PC. If the home AI is unavailable, the app does not automatically switch to a separate cloud or on-device AI.
The Web/API Store descriptions on this page of cloud AI transmission, non-persistent chat history, AWS storage, and Web account deletion do not apply uniformly to conversations or memories on your home PC. If you separately use Web services or external APIs, also consult the information for those services and that processing.
Information on the phone and home PC
The phone handles drafts, responses, displayed conversations, shared information, messages, and temporary authentication information. The initial design does not persist this content as phone history or for offline viewing. Home connection information, device key references, registered credential references, and identifiers used to check unresolved operations are intended for protected device storage. Storage, backup exclusion, and erasure still require verification on each supported OS and real device.
If OS authentication for conversation-result recovery is interrupted, the design retains only that same pending authentication and its result received during the interruption in temporary device memory, within the original expiry. Displayed content, PINs and ordinary session authority are not carried over. Sending requires fresh validation and an explicit action. Cancellation, locking, expiry or process termination discards it. This is limited to conversation-result recovery, not shared information, messages, or general background retention.
The home PC handles registered member and device identifiers, public authentication keys and proofs, personal conversations and AI replies, memories, explicitly shared information and messages, results, and recovery records. Person-bound encrypted conversation storage exists in source. Not keeping phone history does not mean that the home PC keeps no history. Processing purposes include authentication, generating replies, conversation continuity, sharing authorized by the person, and result verification and recovery.
Device pairing and authentication of the person using it are separate. The design uses the registered person's passkey and, on a shared device, their personal PIN. Sharing one household AI does not make every conversation or memory public to the family. Disclosure requires checking the information's sharing scope and the person's authority. Guardian access to a minor's conversations and life-safety notifications are not presented as available Mobile features.
Before private content is opened, first setup is designed as one in-progress session from saving home trust through device_verified, saving the first person's credential, and completing separate ordinary person authentication. At most two app-owned controls are shown during that phase: scan the Desktop QR and confirm the saved result of the same operation. Device candidates, enrollment, and cancellation evidence are assigned to those phase-bound controls. The scanner is not auto-started; results are not auto-polled; effects are not auto-resubmitted; and no roster or private content is shown. Each phase is decided by rereading saved exact state. A background or lock event, person/device/home change, or unreadable/corrupt state keeps the private gate closed. After ordinary authentication and current-session readback, both controls are removed. This adopted design boundary is source-connected and focused-tested (including an Android debug build), but it is not evidence of real-camera or real-device completion, signed distribution, or production availability.
Saving conversations or updating memories is separate from self-learning or contribution learning that updates a model. Under the owner-adopted product premise, learning is included in product use and eligible local learning does not require a separate opt-in or memory-consent toggle. The source, purpose, disclosure scope, external transmission, stopping, and deletion treatment for learning remain individual processing boundaries that must be finalized and explained with any required consent. Permission to share within the household or authentication for an ordinary conversation is not extended to another person's data or external transmission. This information does not present these learning features as available from Mobile.
Personal conversations and memories are distinct from improvements to capabilities shared by the household AI. The design does not automatically turn raw private conversation content into knowledge available to the family. Any shareable experience remains subject to consent, provenance, privacy, and disclosure checks. Local processing is also distinct from contributing training material to a central service. The material contributed, recipients, consent and withdrawal procedures, and effects of deletion must be explained for the features offered.
Connections, relay, and external services
The design encrypts traffic between phone and home PC, with a relay carrying traffic without decrypting conversation content. A relay or connection endpoint may still observe connection information such as IP addresses, times, and traffic volume. Relay operators and contractors, processing countries, logged fields, retention, and production verification remain feature-delivery checks. This does not mean no data is collected or that use is completely anonymous.
External APIs and tools used by the home AI are separate from conversation processing on the home PC. Inputs, authentication, usage, and payment information sent externally depend on the feature, the person's authority and consent, and the recipient. This is not a statement that all Mobile conversations are automatically sent to Anthropic or another provider. Recipient-specific practices must be finalized alongside available features.
Device attestation and passkeys use OS facilities, including those provided by Apple and Google. The providers' own processing is also governed by their policies. Store privacy disclosures must be finalized after checking the distributed app's actual transmissions, including embedded SDKs.
Reporting an AI response (planned; not yet available)
Only when an authenticated registered person selects one exact saved AI response shown to them, chooses a category, confirms disclosure to the developer, and explicitly reports it does the design have the home PC send that response text and category to Energy Connect Co., Ltd.'s dedicated report service. The transfer also includes household and reporter identity hashes, operation and response identifiers, the response-text hash, and timestamps needed to verify the report. Mobile does not include the response text in its report request; the home PC rereads the saved response for that person. The user's prompt, surrounding conversation, attachments, name, and authentication material are not sent to the developer.
An accepted report is stored encrypted under a dedicated key. Only designated operations staff may view it for moderation. The retention period is 90 days from receipt, after which it is deleted. Acceptance does not promise a violation finding, removal or correction of the response, emergency action, or a personal reply. This feature is not presented as available until production protections and operations have been verified.
Camera, voice, and diagnostics
The camera reads QR codes for device pairing and person enrollment displayed on the home PC when you choose to scan. Decoded connection information is used for registration and verification with the home. Camera permission can be changed in OS settings.
Mobile voice conversations are under design and evaluation. Voice-based identity re-check is not presented as an available feature, and speaker similarity is not elevated into identity authentication; whether any voice-authentication data will be handled remains undecided. The planned approach encrypts raw phone audio for transmission to the home PC and processes it without persistent raw-audio storage. The person's utterances accepted as a conversation and the AI's replies are saved in that person's conversation history; memory updates follow existing consent and disclosure rules. Planned voice capture and playback operate only while the app is in the foreground, the device is unlocked, and the exact personal session and auth revision are current. On background, switching to another app, screen-off, or OS lock, it stops and discards app/adapter raw PCM and any uncertain transcript. Returning to the foreground does not resume the old Voice session; a content-free cleanup readback for the same operation and fresh person authentication must complete before the person explicitly starts a new one. This adopted stop/discard boundary is a design decision, but native permission, recording indication, audio-session/route/interruption handling, whether voice-authentication data is handled, implementation, retention and deletion procedures, and pre-availability verification remain incomplete and will be explained once finalized. A design without persistent raw-audio storage does not mean that no derived voice-authentication data could be processed.
The Home-to-Mobile companion-Voice replacement is design-only and its capability is not advertised. The adopted limited output is only the synthesized AI response in the same in-progress session as 24 kHz, mono, signed 16-bit little-endian PCM, plus the current caption read from the current conversation projection already saved for the same owner. It goes to one registered personal Mobile that is current for the same household, person, device, session, and auth revision, solely for response playback and the current caption for accessibility in that live session. Uncertain transcripts, another person's conversations or memories, rosters, tool or payment content, and raw local stores are not sent. A shared device, another person or household, an operator cloud, general Web, push, or another Mobile AI is neither a destination nor a fallback. Mobile does not persist the PCM or caption or use them for offline history, learning, analytics, crash reports, logs, queues, or retries. App and adapter RAM is at most five seconds in each direction and stops and discards on consume, cancel, disconnect, background or lock, route or person change, or authentication invalidation or expiry. The relay does not decrypt content; remote Voice implementation, real-device behavior, distribution, and production activation remain unverified.
Adapting spoken output to a person's preferences is a separate process subject to authentication, the source audio's permitted use, and voice-specific acceptance conditions. This does not require a separate opt-in or memory-consent toggle for eligible local learning. Permission to transmit raw audio to the home PC does not by itself authorize using that audio for learning. Planned adaptation affects output such as speech rate, pauses, and intonation; it does not personalize voice identity, the AI's personality, reasoning, or response content. Private audio, speaking-style statistics, voice adaptation data, preferences, and evaluation evidence are not designed for sharing, sale, or external distribution. The conditions, implementation, and verification for learning from audio transferred by Mobile are incomplete.
Diagnostics are designed to exclude conversation content, PINs, authentication tokens, keys, and network payloads. Current Android source uses mobile_scanner 7.4.1's default bundled Google ML Kit barcode-scanning 17.3.0; the resolved runtime also contains play-services-mlkit-barcode-scanning 18.3.1 and barcode-scanning-common 17.0.0, with ML Kit initialization and Google DataTransport/CCT diagnostic/usage-metric components in the merged manifest. Google states that ML Kit processes images and recognition results on-device and does not send them to Google, while ML Kit sends device/app information, per-installation identifiers, performance, API configuration/size, feature versions, events, and errors to Google for diagnostics and usage analytics. Final signed-artifact, SDK-network, retention, consent, and store-disclosure verification remains required. iOS source uses Apple Vision and a PrivacyInfo.xcprivacy declaring no collection/tracking/accessed APIs, but this does not establish all-platform non-collection or final artifact behavior.
Retention, deletion, and privacy requests
Mobile does not retain drafts, responses, displayed conversations, shared information, messages, PCM, or captions as persistent phone history, offline-viewing data, queue, retry, log, crash-report, learning, or analytics data. If the same pending authentication and its result are held in temporary device memory for conversation-result recovery, cancellation, locking, expiry, app termination, disconnection, auth invalidation, or a target change discards them.
Uninstalling the app, unlinking a device, deleting a registered household user, deleting conversations or memories, and deleting a Siglume Web account are separate actions. When a device is unlinked or deleted from the home side, references to home connection information, device keys, and registered credentials in protected device storage are revoked. Home-PC conversations, memories, household membership, authentication and recovery records, and purchase rights are managed separately and are not deleted by device unlinking or Web account deletion alone.
For deletion, access, correction, or cessation-of-use inquiries, begin the contact form message with ‘Minnano AI Mobile / Privacy Request’ and specify the target, such as a device link, your home-PC data, Web account, or support records. We handle the request after verifying identity and scope. Home-side deletion requires the home-side deletion procedure, and support may not be able to remotely access or erase home-PC data. General privacy-rights requests are handled with the principle of responding within 30 days stated in this privacy policy.
Home application and Mobile support and privacy requests