HexScope

Privacy Policy

July 23, 2026

The contents of this document may be updated without notice. If you have any questions, please contact us using the details at the end of this document.

Hexagonal Computation, Inc. (the "Company") handles the personal information it collects in providing "HexScope | AI Brand Tracker" (the "Service") in accordance with this Privacy Policy (this "Policy").

This Policy is drawn up with reference to Japan’s Act on the Protection of Personal Information (APPI) and, where it applies, the European Union’s General Data Protection Regulation (GDPR).

  1. 1.Controller information

    The business that handles personal information is as follows.

    The Company has not designated a Data Protection Officer (DPO) or an EU representative at this time. For inquiries about the handling of personal information, please contact us using the details below and at the end of this document.

    • Company: Hexagonal Computation, Inc. (六角電算株式会社)
    • Company site: https://hexagonal-computation.com
    • Email: contact@hexagonal-computation.com
  2. 2.Information we collect

    In providing the Service, the Company collects the following information.

    • Email address: entered into the report request form as the destination for a Report. To show the remaining free allowance and whether the entered address is new, the entered email address is sent to the Company’s API before the send button is pressed (approximately 400 milliseconds after the email address becomes valid in format).
    • Target domain: the domain to be measured, entered into the Service’s input form.
    • Payment-related information: the Stripe customer ID, payment ID, amount, currency, and payment status generated during paid use. Card details such as the card number are sent directly to Stripe and do not pass through the Company’s servers or databases.
    • Authentication identifiers: an anonymous identifier issued per browser for use of the Service, together with the number of uses and the selected language.
    • Analytics information: the items described in "Cookies and measurement" below.
    • IP address and user agent: obtained when you access the Service, through the Company’s server logs, analytics, and requests to external delivery services such as web fonts.
  3. 3.Purposes of use

    The Company uses the personal information it collects for the following purposes.

    • To generate a Report and send it to the specified email address
    • To check the remaining free allowance and to charge fees
    • To respond to inquiries about the Service
    • To prevent misuse of the Service and to ensure its security
    • To analyze how the Service is used and to improve the Service
  4. 4.Legal bases for processing (where the GDPR applies)

    For Users to whom the GDPR applies, the Company processes personal data on the following legal bases.

    • Providing Reports and processing payments: performance of a contract (GDPR Article 6(1)(b))
    • Retention of transaction records: compliance with a legal obligation (Article 6(1)(c))
    • Ensuring security and preventing misuse, and analysis to improve the Service: the Company’s legitimate interests (Article 6(1)(f)). Those legitimate interests are to provide the Service securely and continuously and to maintain and improve its quality.
  5. 5.Provision to third parties and processors

    Except as required by law, the Company does not provide personal data to third parties without first obtaining the individual’s consent.

    To the extent necessary to achieve the purposes of use, the Company entrusts operations to, or relies on processing by, the following providers.

    • OpenAI (ChatGPT / gpt-4o): obtaining AI responses for measurement
    • Google (Gemini / gemini-2.5-pro; Firebase and Google Cloud; Google Tag Manager and Google Analytics; Google Fonts): obtaining AI responses for measurement, execution and storage infrastructure, analytics, and delivery of web fonts
    • Perplexity (sonar-pro): obtaining AI responses for measurement
    • Anthropic (Claude): obtaining AI responses for measurement and internal analysis
    • Resend: email delivery of Reports and similar (sender noreply@hexscope.ai)
    • Stripe: payment processing
  6. 6.Information sent to AI Platforms

    For measurement, the Company sends the body text extracted from the public pages of the domain entered by the User (up to approximately 8,000 characters) to an AI Platform and generates a brand name and questions from it. The generated questions are sent to each AI Platform, and the body of their responses is then sent to an AI Platform again in order to aggregate how the Measurement Target is mentioned.

    The email address entered by the User and payment-related information are not sent to AI Platforms. However, if the public pages of the target domain contain personal information of third parties, it may be sent as part of the body text of those public pages.

  7. 7.Where information is stored

    Information that the Company stores itself is stored on Google Cloud (Japan region, asia-northeast1). Storage by processors (such as Stripe, Resend, and Google Analytics) takes place in each provider’s own environment.

    Information about users, measurement run records, measurement settings, and payments is stored in the Firestore collections users / analysisRuns / analysisRecipes / payments.

    Measurement analysis artifacts, and delivery records including the destination email address of a Report, are stored in the "artifacts" location in Cloud Storage.

  8. 8.Provision to third parties abroad

    The processors listed above include providers located outside Japan, or that handle personal data outside Japan. The main destination country concerned is the United States.

    For information on the personal-information protection systems of these destination countries, please refer to the survey results on foreign systems published by Japan’s Personal Information Protection Commission (https://www.ppc.go.jp/personalinfo/legal/guidelines_offshore/). The handling of personal data at the destination providers is governed by each provider’s published privacy policy and data processing terms.

    If you wish to request further information about how data is handled at these destinations, please contact us using the details at the end of this document.

  9. 9.Cookies and measurement

    The Company uses cookies and browser local storage to retain your language preference, understand referral sources, carry out analytics, and optimize display.

    The main cookies the Company uses are hexscope_lang (language preference, valid for one year) and hx_attr (referral source, valid for 90 days, scope .hexscope.ai). In local storage, the Company stores referral sources (hx_attribution_first / hx_attribution_last) and a display-optimization assignment (hx_ab_id).

    The items stored in your browser are utm_source / utm_medium / utm_campaign / utm_term / utm_content, gclid, the referrer, the landing path, and the referral-source category. The items sent to the analytics service are the referral-source category (first touch and last touch), the display-optimization assignment, the URL of the page being viewed (including its query string), scroll depth, page views, the measurement run ID, and the remaining free allowance. These measurement events do not include email addresses, but they do include the target domain entered by the User.

    The Company uses Google Tag Manager and Google Analytics on hexscope.ai and blog.hexscope.ai. The fallback tag that loads when JavaScript is disabled is loaded without the domain check. You can disable cookies in your browser settings, but if you do, parts of the Service may not work correctly.

  10. 10.Retention period

    The Company retains the personal information it collects for the period necessary to achieve the purposes of use and for the period required by law.

    Requests to delete specific information are accepted at the contact point at the end of this document, and we will inform you individually whether and how we can act on them. At present the Service does not provide a self-service function for deleting your information.

  11. 11.Security measures

    The Company takes the following measures to prevent unauthorized disclosure, loss, or damage of the personal information it handles and to otherwise manage its security.

    • Organizational measures: the Company designates the persons responsible for handling personal information.
    • Personnel measures: the Company limits those who handle personal information to those who need it for their work.
    • Technical measures: the Company controls access to information and encrypts communications. Writes to databases and storage areas are restricted so that they take place only through administrative privileges, and reads are limited to the User the information relates to.
    • Understanding the external environment: the Company stores personal data in Japan (asia-northeast1) and also handles it in countries such as the United States through its processors. The Company implements security measures with an understanding of the personal-information protection systems of those countries.
  12. 12.Your rights

    You may request disclosure, correction, addition, deletion, suspension of use, or other action regarding your personal information held by the Company. Please contact us using the details at the end of this document.

    Users to whom the GDPR applies also have the right of access to their personal data, and rights to rectification, erasure, restriction of processing, objection to processing, and data portability. For processing based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

    Users to whom the GDPR applies have the right to lodge a complaint with a supervisory authority.

    The Company does not carry out automated decision-making (including profiling) that produces legal effects concerning Users or similarly significantly affects them within the Service.

  13. 13.Japan’s adequacy status (for Users in the EU)

    Japan is a country recognized by the European Commission as ensuring an adequate level of protection for personal data. Transfers of personal data from the European Economic Area to the Company in Japan may therefore be made on the basis of that recognition.

    Onward transfers from Japan to third countries (such as the United States) are governed by the measures set out in "Provision to third parties abroad" above.

  14. 14.Children’s privacy

    The Service is not intended for use by anyone under 16 years of age. Please do not use the Service if you are under 16.

  15. 15.Changes to this Policy

    The Company may change this Policy. The content after a change applies from the time it is posted within the Service. If the Company makes a significant change, it will give notice of that within the Service.

Contact and complaints

For inquiries about this Policy and the handling of personal information, requests such as disclosure, and complaints, please contact us using the details below.

  • Company: Hexagonal Computation, Inc. (六角電算株式会社)
  • Company site: https://hexagonal-computation.com
  • Email: contact@hexagonal-computation.com