Write the AI usage rules your company does not have yet
Most small companies have staff pasting customer data into free chatbots and no rule that says otherwise. This produces the rule — plain, short, and adapted to the tools you actually use.
- Runs entirely in your browser
- Works offline
- No upload
- No sign-up
- No watermark
Loading the tool…
How it works
- Name your tools by tier: approved for business data, allowed for non-confidential work only, not allowed.
- Tick the data classes that must never be entered and the permitted uses; set the reporting contact and review cadence.
- Read the generated policy, download it as Markdown or print it, and adapt it to your contracts.
Why nothing is uploaded
Every operation on this page is done by code running inside your browser tab, using the same engine that renders web pages. The file is read from disk into your tab’s memory, transformed there, and written back out as a download. It is never sent anywhere — not to us, not to a third party.
Verify it yourself
- Open your browser’s developer tools (F12) and select the Network tab.
- Load your file and run the tool.
- The only requests you will see fetch the tool’s own code — and, for a few heavy tools, their open-source engine from a public CDN — plus one small page-view ping to loreatec.jp (page address and title, nothing more). None of them carry your file.
Frequently asked questions
Why three tiers instead of a list of “safe” products?
Because what a product does with your data depends on the plan and changes over time; a policy that names products goes stale in months. The tiers put the decision where it belongs — on the plan you contracted and its terms — and give staff a rule for tools that are not listed: treat them as non-confidential only.
Does the tool judge how risky each AI service is?
No, and deliberately so. A “risk score” would rest on vendor claims we cannot verify and that change quarterly. The policy instead asks for the criteria that matter for tier A — no training on your inputs, retention terms, company account management, hosting region — and lets you check them against the current terms.
Is the document legally sufficient?
It is a solid, plain-language starting point in the structure companies actually use, not legal advice. Have it reviewed against your customer contracts and local law — in Japan, note the Personal Information Protection Commission’s guidance on entering personal data into generative-AI services, and the JDLA guideline as a widely used reference.
Where is my draft stored?
Nowhere but the page you are looking at. Download the Markdown to keep it.