On this page

Cabinet Cutlist

Cabinet Cutlist Privacy Policy

This policy covers local data, file sharing and Workshop subscription verification in the Cabinet Cutlist Android app.

The subscription-processing sections apply to version 0.11.0 or later when the Workshop plan is offered. The current Google Play production release does not accept Workshop subscription purchases.

Updated October 7, 2026

Application and provider

This policy applies to Cabinet Cutlist (com.cairoplus.cutlist), provided by 株式会社CairoPlus (CairoPlus Inc., cairo-plus). Contact info@cairo-plus.com about privacy.

Local job data and sharing

The app processes and stores shelf/cabinet dimensions, parts, board stock, layouts, job history, templates, costs, estimate customer names and notes on your device to provide its functions. It does not sell job data, provide advertising, obtain an advertising ID or run provider usage analytics.

You choose files, export destinations and receiving apps. Exported PDFs, CSVs and backups can contain the selected job's dimensions, amounts, customer names and notes. Receiving apps, storage providers and print services handle selected information under their own settings and policies.

Records are kept in app-private storage; recovery or Undo history may remain. Clearing app storage in Android settings or uninstalling removes private device data. Delete exported files, external backups and shared copies separately. Templates and estimate drafts are saved separately from workshop backups. Before changing devices, check and save the information you need individually.

Workshop plan and Google Play

The Cabinet Cutlist Workshop plan is an optional Google Play auto-renewing subscription, separate from the one-time app purchase. It does not require a CairoPlus email/password account. Google Play processes payment and manages the subscription. The app does not obtain or store card numbers or bank-account details. It checks subscription status on app launch and resume, periodically while in use, and when you purchase, restore or check again. Existing one-time features remain available without a Workshop subscription.

Information used to verify purchases

For purchase verification, restoration, abuse prevention and acknowledgement, the app processes product IDs, purchase tokens, purchase state and times, signed purchase JSON that may contain order information, signatures and an opaque purchase identifier. At checkout, a random identifier is stored in device preferences separate from workshop data and passed to Google Play. It is not an email address or advertising ID. The app queries Google Play's owned purchases and sends signed JSON, its signature, purchase token and purchase identifier over HTTPS to https://sync.cairo-plus.com. The server queries Google's official Play API using the purchase token, checks product, plan, state and expiry, and acknowledges valid purchases. It does not send original purchase JSON or its signature as extra data to Google. CairoPlus does not store raw purchase tokens, original JSON, signatures, purchase identifiers or order IDs in its database or operational logs. Purchases are queried afresh, and verified access is held only in memory for a short period of at most 15 minutes. Workspace backups, imports and Undo cannot create purchase rights.

Verification-data retention and protection

CairoPlus's verifier retains the purchase token's SHA256 digest, fixed product/plan/region, subscription state, expiry, acknowledgement and test-purchase status, verification stage/time and minimal record metadata. Hashing does not make this purchase-related identifier anonymous. An expiry is set seven days after the last verification; physical deletion after expiry is asynchronous. Abuse prevention retains hashed identifiers derived from IP addresses or purchase digests, and request counts, with a two-hour expiry. IP addresses are not used to infer location. Processing uses API Gateway, Lambda and DynamoDB in AWS's Tokyo region over HTTPS. Continuous metadata backups cover the preceding seven days, and minimal operational error logs are configured for seven-day retention. Deletion is not instantly reflected in backups or operational copies. HTTP access logs do not record purchase bodies or secrets.

Job data and external services

Purchase verification does not automatically upload cabinet dimensions, parts, board stock, job history, templates, material/labor costs, estimate customer names or notes, PDFs or CSVs. These remain on your device unless you choose an export or sharing destination. The Google Play Billing Library processes diagnostic information about API success/failure and service connections; Google uses it to improve the library's performance and support errors. Google's purchase records and diagnostics, including their retention and deletion, follow Google's policies. References: https://developer.android.com/google/play/billing/release-notes and https://policies.google.com/privacy.

Cancellation, restoration and deletion

Cancel automatic renewal in Google Play. Ordinary cancellation keeps Workshop access until the paid term expires. Expiry, payment hold, refund or revocation does not delete existing one-time features, saved jobs, estimates, templates or files you already created. Restoration uses Google Play's owned purchases; there is no separate CairoPlus account-deletion operation. Clearing app storage or uninstalling deletes device records and the checkout identifier. Delete your exported files and external copies separately. Contact info@cairo-plus.com about retention or deletion of CairoPlus purchase-verification data. Do not email purchase tokens, signed purchase JSON or other secrets. A support request or local-data deletion does not cancel Google Play billing or delete Google's purchase records or diagnostics.

Cabinet Cutlist authorized demonstration access

This section applies when using authorized demonstration access in Cabinet Cutlist 0.12.0 or later. Authorized reviewers may enter a reusable review code for free demonstration access to workshop features. This is separate from Google Play purchases and subscriptions. Demonstration verification does not create a subscription or acknowledge a purchase. No CairoPlus email/password account is required.

To verify demonstration access, the app sends the entered code, an opaque installation identifier, a request identifier, and app/feature-scope identifiers over HTTPS to CairoPlus's service at https://sync.cairo-plus.com. Raw codes and installation identifiers are handled in request memory and are not stored in the server database or operational logs. The installation identifier is not an email address or advertising ID and may be retained in device settings separate from job data. Workspace backups cannot create demonstration rights.

The server retains an administrative SHA256 code hash, feature scope, active/inactive status and necessary update-control metadata as configuration. The administrative hash remains until replaced or removed; revocation may retain an inactive hash. Unlike purchase-verification metadata, this administrative code record has no automatic seven-day deletion expiry. Abuse prevention stores hashes derived from IP addresses and installation identifiers plus request counts, with a two-hour deletion expiry. Hashing does not make all identifier-related processing ephemeral. IP addresses are not used to infer location. Physical deletion after expiry is asynchronous. The existing backup retention also applies to these server records; deletion or revocation is not instantly reflected in backups or operational copies. Processing uses API Gateway, Lambda and DynamoDB in AWS's Tokyo region.

On the device, the code and verified demonstration access are held only in the app process's memory, not in job files, backups, saved screen state or subscription preferences. Each verified access lease lasts at most five minutes; this is not a five-minute expiry of the reusable code. After a lease expires or is invalidated, fresh server verification is required before using the demonstration again. Backgrounding the app, clearing demonstration access or failed verification clears the access lease. Clearing demonstration access does not delete saved jobs or original bought features, and does not cancel a separately purchased Google Play subscription.

Demonstration verification does not automatically upload cabinet dimensions, parts, board stock, job history, templates, costs, estimate customer details or notes, PDFs or CSVs. Clear app storage or uninstall to remove the device identifier. Contact info@cairo-plus.com about retention or deletion of server information. Do not email review codes or purchase secrets. A support request or deleting device data does not delete Google Play purchase records or cancel a subscription.

Workshop pricing and renewal

The Japan Workshop plan is JPY 980 per month with automatic monthly renewal and no free trial. It is optional and separate from the one-time app purchase. It covers parts generated from outside dimensions, saved/reusable specifications, job costing, estimate PDFs and cost breakdown CSVs. Check eligible plans and the final price in the app and Google Play purchase sheet before confirming a purchase.

An internet connection is required for purchases, restoration and verification of Workshop access. Workshop operations remain unavailable before payment and verification are complete or when access cannot be verified. Existing one-time app functions and saved data remain available.

Manage or cancel automatic renewal in Google Play. Ordinary cancellation stops future renewal while access continues until the paid period ends. Uninstalling or requesting deletion of data does not cancel the subscription. Price changes are notified and any required consent obtained under Google Play's rules. Check updated prices and purchase status in Google Play.

Manage or cancel a subscription in Google PlayGoogle Privacy PolicyGoogle Play Billing diagnostic information

Privacy inquiries

Contact info@cairo-plus.com about retention or deletion of information handled by CairoPlus. Include only information needed for a reply or investigation. The company privacy policy also describes support emails and the website contact form.

info@cairo-plus.com

Company and website privacy policy

Back to Cabinet Cutlist