プライバシーポリシー
スーパー画像編集画蔵君(ブラウザ拡張機能)

最終更新日: 2026年10月9日 / 提供者: 株式会社カリロエ(KARIROE, K.K.)

この文書は、Microsoft Edge アドオンで配布する拡張機能 「スーパー画像編集画蔵君」についてのプライバシーポリシーです。 同じ内容は、App Store(Safari)・Chrome ウェブストアで 配布する同じ拡張機能にも、そのまま当てはまります。

開いた画像・書き出した画像が、このブラウザの外へ出ることはありません。
編集も書き出しも、すべてこのパソコンの中で終わります。
通信するのは 1 か所だけです。 書き出しのときに「証明(Content Credentials)を付ける」を利用者が選んだ場合に限り、 署名をもらうために株式会社カリロエ(KARIROE, K.K.)のサーバーへ通信します。 送るのは 32 バイトのハッシュだけで、画像も、元の画像も、編集の内容も送りません。 既定では選ばれていません。選ばなければ、通信は一切起きません。

受け取った情報の使い方(限定的な使用)

この拡張機能が受け取る情報(開いた画像と、証明の署名のときに送る 32 バイトのハッシュ)は、 この拡張機能の目的のためだけに使います。

ストアごとの決まり

この拡張機能は、Microsoft Edge アドオン・App Store(Safari)・ Chrome ウェブストアで配布します。取り扱いは 3 つとも同じで、上に書いたとおりです。 ここには、それぞれのストアが求めている言い方を並べます。

Microsoft Edge アドオン

Chrome ウェブストア(Limited Use)

この拡張機能が受け取る情報の利用は、Chrome ウェブストアの利用者データに関するポリシー (Chrome Web Store User Data Policy)の Limited Use(限定的な使用)の要件を含め、これに従います。

English: The use of information received by this extension will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Information the extension receives (the images you open, and the 32-byte hash sent only when you choose to sign) is used only for the extension's single purpose: editing images and, when you choose it, attaching Content Credentials. It is not transferred to third parties (except sending the hash to the KARIROE, K.K. signing server for the signature, or where required by law), no human reads it, and it is never used for advertising (including personalized advertising), sold to data brokers, or used to determine creditworthiness or for lending.

App Store(Safari)

Apple の「App のプライバシー」の意味でのデータの収集はありません。 署名のときに送る 32 バイトのハッシュは、署名を返すためだけに使い、サーバーに残しません。

1. 収集する情報

利用者を特定できる情報は、収集しません。

アクセス解析、広告、クラッシュレポート、利用統計のたぐいは一切組み込んでいません。 画像編集ツールにありがちな「クラウドに保存」「共有リンクを作る」「SNSに投稿」といった、 画像を外部へ預ける機能は、方針として実装していません。

証明の署名のときに送るもの(利用者が選んだときだけ)

送るもの中身
ハッシュ32 バイト。署名の対象を表す数字の列。ここから画像は復元できません
アプリの名前と版gazou <版>(gazou のあとに、そのときの拡張機能の版が付きます)
合言葉拡張機能に埋め込まれた文字列。利用者ごとには変わりません

送らないもの: 画像・元の画像・ファイル名・編集の内容・撮影情報(EXIF・位置)・アカウント情報。

送り先は株式会社カリロエのサーバー(Google Cloud Run、東京)です。 サーバーに残るのは、署名した時刻・アプリ名・証明書の通し番号だけです。 IP アドレスは記録しない設定にしています。どの利用者かは分かりません。

通信が要るのは、証明の署名に使う秘密鍵を拡張機能の中に置けないためです。 鍵が配られれば誰でも「画蔵君で編集した」と偽れるようになります。鍵はサーバー(Google Cloud KMS)の中から出しません。

書き出したファイルの証明に入るもの(利用者が選んだときだけ)

証明を付けて書き出したファイルには、元の画像の証明(写丸君の撮影の証明など)・元のファイル名(材料の名前として)・編集の種類が入ります(サーバーには送りません)。 元の写真の一部でも見えなくなる編集をしたときは、元の写真の証明の中の縮小画像と撮影情報を消します(隠した部分が縮小画像から見えないように)。 消さないのは「色の調整」と「回転・反転」だけで、しかも元の写真のレイヤーがそのまま全部見えているときだけです。 隠す・切り抜く・大きさを変える・重ねる・描く・文字を入れる・修復・マスク、元の写真のレイヤーを動かす・縮める・非表示にする・不透明度を下げる・合成の方法を変える、上に別のレイヤーや図形を重ねる、などのときは消します。 撮影場所が入っているときも撮影情報を消します。画蔵君が新しく縮小画像を入れることはしません。

顔を探す・人物だけ残すとき(通信しません)

「顔を探して隠す」「人物だけ残す(AI)」は、拡張機能に同梱したモデル(顔: OpenCV の YuNet、人物: MODNet)を このパソコンの中だけで動かします。画像も結果も、どこにも送りません。 Google の MediaPipe は、使用状況の数値を Google へ送る仕組みがあるため使っていません。

画像の来歴・撮影情報を読むとき(通信しません)

開いた画像に C2PA の証明(Content Credentials)や撮影情報(EXIF)が入っていれば、それを読んで「来歴」の画面に出します。 この読み取りと検証は、すべてこのパソコンの中で終わります。 検証に使うソフト(Content Authenticity Initiative の c2pa-web)も、信頼する発行元の一覧も 拡張機能に同梱しており、外部へは一切取りに行きません。

2. 開いた画像の扱い

読み込んだ画像は、編集画面のタブの中だけで処理されます。

保存・クリップボードへのコピー・PDF出力・一括処理は、すべて利用者がボタンを押した時だけ、 利用者のパソコンの中で実行されます。

PDF と AI ファイルの読み込みには Mozilla の PDF.js を使っていますが、 同梱したファイルを読み込んで使っており、外部から取得することはありません。 解析はすべて利用者のパソコンの中で行われます。

3. 端末内に保存する情報

保存する内容保存先目的
レシピ(加工の手順) ブラウザの保存領域(storage.local。このパソコンの中) 同じ加工を次回も使えるようにするため

これだけです。

レシピに保存されるのは、利用者が指定した加工の設定だけです。 具体的には回転の角度、倍率、切り抜きの範囲(割合)、色の調整値、入れた図形の種類・位置・色・ 文字の内容、書き出しの形式です。画像そのものは保存しません。

閲覧履歴、URL、ページの内容、入力内容、Cookie、認証情報は一切読み取っておらず、 保存もしていません。

ブラウザの同期機能は使用していません (storage.sync ではなく storage.local を使っています)。 保存された内容が他の端末やネットワーク上に出ることはありません。

4. 権限を要求する理由

権限理由
storage レシピをこのパソコンの中に保存するため。これ以外の用途では使用しません

ホスト権限(ウェブサイトへのアクセス)は要求していません。 この拡張機能はウェブページを読み取ることができません。 ツールバーのアイコンを押したときに、拡張機能自身の編集画面をタブで開くだけです。 証明の署名の通信は、署名のサーバーの側で拡張機能からの呼び出しを許可しているため、ホスト権限なしで行えます。

5. 保存した情報の削除方法

5-2. ウェブ版について(2026年10月9日から)

画蔵君は、インストールしないで使えるウェブ版も公開しています(https://callirrhoe.jp/app/gazou-kun/editor/)。中身は拡張機能と同じで、扱い方も同じです。

6. ソースコード

この拡張機能は MIT ライセンスで公開しています。上記の内容はすべてソースコードで確認できます。 同梱している他者のソフトウェア(PDF.js ほか)とそのライセンスは NOTICE.md に一覧があります。

7. 本ポリシーの変更

変更する場合は、この文書の最終更新日を改めたうえで公開します。

8. 連絡先

X: @UR_Ikko

Privacy Policy — Super Image Editor Gazou

Last updated: October 9, 2026 / Provider: UR_Ikko

Images you open or export never leave your browser. All editing and exporting happens on your own computer.
There is exactly one network connection, and only if you choose it. When you tick "attach Content Credentials" at export time, the extension asks the signing server of KARIROE, K.K. for a signature. It sends only a 32-byte hash — never the image, the original image, or your edits. The option is off by default; if you leave it off, no network traffic happens at all.

How received information is used (limited use)

Information this extension receives (the images you open, and the 32-byte hash sent only when you choose to sign) is used only for the extension's single purpose.

Content Credentials signing (only when you choose it)

Sent: a 32-byte hash (the image cannot be reconstructed from it), the app name and version (gazou <version>, where <version> is the extension's version at the time), and a fixed key embedded in the extension (the same for every user). Not sent: the image, the original image, file names, your edits, EXIF or location data, or account information.

The server (Google Cloud Run, Tokyo) keeps only the time of signing, the app name and the certificate serial number. IP addresses are not logged. The signing key never leaves Google Cloud KMS.

"Find and hide faces" and "Keep person only (AI)" run bundled models (OpenCV YuNet and MODNet) entirely on your computer; nothing is sent anywhere. Google's MediaPipe is not used, because it reports usage metrics to Google.

When you export with Content Credentials, the file itself contains the original image's credentials (e.g. the capture proof from Shamaru), the original file name (as the ingredient title) and the kinds of edits you made. If any part of the original photo stops being fully visible, the original's thumbnail and capture metadata are redacted from the credentials so the hidden area cannot be seen in a thumbnail. Only colour adjustments and rotation/flip are kept, and only while the original photo's layer is still shown whole: hiding, cropping, resizing, compositing, drawing, adding text, retouching and masking — and moving, shrinking, hiding, fading or changing the blend mode of that layer, or covering it with another layer or a shape — all trigger the redaction. Capture metadata is also redacted whenever it contains a location. Gazou never adds new thumbnails.

Reading the provenance (C2PA) and EXIF of images you open happens entirely on your computer. The verifier (c2pa-web) and the trust lists are bundled; nothing is fetched from the network.

Images you open

Images are processed only inside the editor tab. They are never uploaded (signing sends only a hash), and they are not written to extension storage. Closing the tab discards them.

Saving, copying to the clipboard, exporting to PDF and batch processing all happen locally on your own computer, and only when you press the corresponding button.

PDF and AI files are parsed with Mozilla's PDF.js, which is bundled with the extension; nothing is fetched from the network. All parsing happens on your own machine.

Features found in comparable tools — cloud storage, share links, posting to social networks — are deliberately not implemented.

Data stored on your device

Only one thing: your saved recipes, kept in the browser's own storage (storage.local).

A recipe holds only the editing settings you chose: rotation angle, scale, crop region (as a ratio), colour adjustments, the shapes you added with their positions, colours and text, and the export format. Image data itself is never stored.

Browsing history, URLs, page content, keystrokes, cookies and credentials are never read or stored. Browser sync is not used — this is storage.local, not storage.sync, so nothing leaves this device.

Permissions

Host permissions are not requested. This extension cannot read web pages. Clicking the toolbar icon simply opens the extension's own editor in a tab. The signing server explicitly allows calls from the extension (CORS), so no host permission is needed for signing.

Deleting your data

Delete individual recipes from the recipe panel in the editor, or remove the extension from your browser's extensions page (edge://extensions in Microsoft Edge) to erase all of them.

Web version (from October 9, 2026)

Gazou-kun is also available as a web page that needs no installation (https://callirrhoe.jp/app/gazou-kun/editor/). It is the same program and handles data the same way: images you open or export stay in your browser and are never uploaded; recipes are kept in this browser's local storage; Content Credentials signing sends the same 32-byte hash only when you choose it. Opening the page leaves the usual access log entry (IP address, time, browser type) on the web server. The page contains no analytics or advertising, and its Content-Security-Policy only allows connections to this site and our signing server.

Source code

Published under the MIT license. Third-party components and their licenses are listed in NOTICE.md.

Contact

X: @UR_Ikko