app-aozora-yoro (Messenger) — Terms of Service
DRAFT — not legal advice; counsel review required.
Governing law: Japan
- Effective date: 2026-07-02
- Last updated: 2026-07-28
- Service operator: AWAI Network, L.L.C., a Delaware limited liability company (Delaware file number 10704996) — the same operator as app-aozora. Gftd Japan 株式会社 supplies infrastructure and software but is not the Service operator. Full operator record:
legal/company.md. - Service: app-aozora-yoro, the messenger companion to app-aozora, served under
aozora.appitself (embedded/path-based, e.g./messages). A legacy standalone domain,yoro.etzhayyim.com, is being retired and now just redirects intoaozora.apprather than serving a separate live surface.
1. About the Service
app-aozora-yoro ("yoro Messenger") is the private/semi-private messaging surface that accompanies the app-aozora social network. It provides an inbox, 1:1 and group direct threads, reactions, read receipts, and contact discovery. It uses the same identity graph and AT Protocol boundary as app-aozora — your DID, account, and contacts are shared with app-aozora — but it is a separate conversation surface, not the public feed.
These Terms supplement the app-aozora Terms of Service, which also apply. They are governed by the laws of Japan; where applicable, GDPR (EU/UK) and CCPA/CPRA (California) also apply.
2. Eligibility and accounts
You access yoro Messenger with your existing app-aozora identity (DID) and the same authentication (CACAO primary, optional WebAuthn/passkey device binding). The eligibility and account rules of the app-aozora Terms apply, including the minimum age [DECISION NEEDED — see app-aozora Terms §2: no age gate exists anywhere in account creation today].
3. Messages and content
- Conversations are modeled as explicit records (
app.aozora.convo.*: conversations, members, messages, reactions, read receipts, attachments). You can send text, rich text (facets), and embedded records/attachments. - Messages and attachments you send are User Content. You are responsible for what you send, and the Acceptable Use and prohibited-content rules of the app-aozora Terms apply to messages, including the prohibition on illegal content, CSAM, harassment, and infringing material.
- Copyright / DMCA: the takedown and counter-notice procedure in the app-aozora Terms applies to reported content in messaging.
4. Encryption and how messages are handled
- Direct (1:1) messages default to end-to-end encryption, and this is implemented and live (confirmed from the current, shipped send/receive code, not just design intent): the client establishes a session via X3DH and encrypts every message with a Double Ratchet (post-compromise security — a compromised key doesn't expose future messages once the ratchet advances) before it ever reaches our servers.
- Group threads use a sender-keys encryption scheme, established lazily on the first message sent rather than asserted when the group is created. Some group/project threads may instead be explicitly marked as plaintext shared-room conversations.
- What the host stores: for encrypted threads, our worker stores only ciphertext and indexes the metadata needed to operate the service — conversation and message identifiers, sender DID, participants/membership, timestamps, read/delivery receipts, and unread counts. This metadata is not encrypted even for end-to-end-encrypted threads. The worker is designed to be a relay and metadata indexer, not a plaintext vault. For plaintext shared-room threads, message content is stored and readable by the host.
- Delivery/read receipts and unread state are visible to conversation participants and processed by us to operate the messenger.
- Message content is limited to 10,000 characters / 1,000 graphemes (lexicon-enforced).
5. Notifications
We send in-app (and, if enabled, push/device) notifications for new messages, mentions, and requests, via Web Push (RFC 8291/8292). Confirmed from the current implementation: push payloads carry only a generic body ("You have a new message" / "You have a new group message"), the app name as title, and the conversation ID — never the message content or a preview of it.
6. Agents, human-in-the-loop, and what agents can access
app-aozora-yoro also serves as a human-in-the-loop (HITL) approval surface for automated agents in the ecosystem. Automated agents (for example, the terminal-agent) can surface decisions to you through a decision inbox (/tasks/inbox): the agent posts a question, context, and options, and you resume the agent by selecting an option or writing a free-text answer.
- When you use the HITL inbox, an agent can access only the decision content it surfaces to you and the answer you provide in that flow. Agent access is gated by an API key you hold. Confirmed from the architecture: the HITL pipeline is a separate, isolated proxy service with no code path into your conversations, PDS records, or contacts — an agent genuinely cannot read your private conversations or contacts through this surface.
- Automated/organism accounts may also participate in conversations.
[DECISION NEEDED: we do not currently have any user-facing UI mechanism that labels/distinguishes automated participants in a thread — this sentence describes an aspiration, not a shipped feature. Confirm whether to soften this language or prioritize building the disclosure before publishing.] - Agent output may be AI-generated and inaccurate; approving an agent action is your decision and responsibility.
7. Contact discovery
We seed your people list and recipient suggestions from relay-imported accounts and profiles and from your follow graph. Confirmed: we do not import your device/phone contacts — discovery is purely network/graph-derived.
8. Moderation, suspension, safety
We may act on reported content and abusive conduct, including muting, blocking support, restriction, or termination, consistent with the app-aozora Terms. For encrypted threads, moderation relies on participant reports and metadata rather than message content.
9. Disclaimers, liability, indemnification, changes, governing law
The disclaimers, limitation of liability, indemnification, changes, and governing-law/jurisdiction provisions of the app-aozora Terms of Service apply to yoro Messenger and are incorporated by reference. Governing law is Japan; the Tokyo District Court (東京地方裁判所) is the court of exclusive jurisdiction of first instance, subject to mandatory consumer rules.
10. Contact
AWAI Network, L.L.C., a Delaware limited liability company (Delaware file number 10704996). Contact: hello@gftd.co.jp (a temporary operational address; an AWAI-controlled address will replace it). Registered agent and registered office: Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States — statutory service-of-process address only.
Gftd Japan 株式会社 (Gftd Japan K.K.), GranTokyo South Tower 11F, 1-9-2 Marunouchi, Chiyoda-ku, Tokyo 100-6611, Japan (Corporate Number 1011101086505) supplies infrastructure and software for the Service and is not the Operator.
The foreign-company-registration and consumer-law [CONFIRM] items recorded in the app-aozora Terms of Service §16–17 and legal/company.md apply here too, since this Service shares that operator, governing law and forum.