Privacy Policy
What personal data Mithril processes, why, for how long, who receives it, and your rights (GDPR / UK GDPR, India DPDP, Southeast Asian PDP laws, CCPA/CPRA).
Effective date: 2026-09-25. Operator: Kotoba Labs Inc., a Delaware corporation (United States).
Draft. Published 2026-09-25 and pending review by counsel. It describes how the service works today and may change; the date above changes with every revision. Questions: legal@mithril.fund.
1. Who we are
Mithril (mithril.fund and its subdomains; kotoba.cloud is the former name and redirects here) is operated by Kotoba Labs Inc., a Delaware corporation (United States). For the processing described here we are the controller (GDPR / UK GDPR), the data fiduciary (India DPDP Act 2023) and the organisation responsible under the Southeast Asian laws in section 9. Where we process data on behalf of an enterprise customer under the Data Processing Addendum, the customer is the controller and we are its processor.
Privacy contact: privacy@mithril.fund. General support: support@mithril.fund. Our postal address is available on request at legal@mithril.fund.
2. What we collect
- Account and sign-in. Your principal identifier (a DID) and the sign-in methods you use at auth.mithril.fund. We do not use passwords. By method: Passkey — the WebAuthn public-key credential (never the private key); email link — your email address, which receives a single-use sign-in link valid for 15 minutes (we keep only a hash of the link's token until it is used or expires); Google — from Google's sign-in (scopes openid, email, profile) we receive your Google account id, email address and whether Google verified it, name and profile-picture URL; GitHub — from GitHub we receive your GitHub user id, login, name, avatar URL and your primary verified email address. For each linked sign-in method the account stores the provider, the provider's account id, the email address, a display name and when it was added or revoked; we do not store Google or GitHub access tokens after sign-in. A provider's email alone never merges two accounts. If you connect a wallet (for example a Base Account), we also process its address.
- Card verification. Accounts are verified by registering a live credit or debit card at Stripe Checkout (a $0 setup check). The card number, expiry and security code are entered at Stripe and never reach Mithril. Mithril stores the Stripe customer id, the verification status, the time it was verified and when it expires, and an evidence reference that contains the Stripe customer id and the card's last four digits. If you enable automatic recharge we also store the Stripe payment-method id and its funding type (credit / debit).
- Optional document verification. See section 5.
- Research and inference content. The prompts, messages and tool definitions you send, and the model output. The server executes no tools; tool calls are returned to you as text.
- Screening and audit records. The result of Acceptable Use Policy screening (a block and its receipt), request counts, token counts, and identifiers.
- Billing. Plan, credit balance and ledger, invoices and payment status from Stripe.
- Notification email (optional). One address you prove with an 8-character code. It is used for notices only and never to sign in.
- Support and contact. Support-chat messages; details you send in a sales or contact form (email, locale, source).
- Technical data. IP address, country (from Cloudflare), user agent and request logs processed by Cloudflare; a first-party visitor counter (see Cookies).
3. Why we use it, and the lawful basis (GDPR / UK GDPR)
| Purpose | Lawful basis |
|---|---|
| Provide the account, API and research service you signed up for; bill and collect payment | Contract (Art. 6(1)(b)) |
| Verify that an account belongs to a real card holder; screen requests against the Acceptable Use Policy; prevent fraud and abuse; secure the service | Legitimate interests (Art. 6(1)(f)) in keeping a dual-use security research service safe; for the screening of prohibited content, also legal obligations where applicable |
| Keep tax, accounting and sanctions-compliance records | Legal obligation (Art. 6(1)(c)) |
| Optional document and face verification (Stripe Identity) | Explicit consent (Art. 6(1)(a), Art. 9(2)(a)) |
| Advertising conversion measurement (Freebuff tag, only after an ad click) | Consent where required by law; otherwise legitimate interests |
| Notices to your optional notification email | Contract |
We do not use your prompts, outputs or files to train models, and we do not sell personal data.
4. Card data
Card data is handled by Stripe as a PCI DSS–validated payment processor under its own terms. Mithril's systems never receive, store or transmit full card numbers or security codes; our PCI scope is delegated to Stripe. What we keep is listed in section 2.
5. Biometric data (optional document verification)
Card registration is the default verification route. Where it is offered as an optional higher level, you may verify an identity document with Stripe Identity. If you choose it:
- Stripe Identity captures an image of your identity document and a selfie, and may create a face geometry template to compare them. That capture happens on Stripe's pages, under Stripe's consent screen and privacy notice, and the images and templates go to Stripe only.
- Mithril receives and stores only the verification session id, its status and its expiry (365 days). Mithril never receives the document images, the selfie or any face template.
- Purpose: confirming that the account holder is the person on the document, to open higher research allowances. Stripe retains and destroys the verification data under its own published retention schedule; we have configured no longer retention.
- Notice for Illinois (BIPA), Texas, Washington and similar laws: we do not collect, sell, lease, trade or profit from biometric identifiers or information. Those laws require biometric data to be destroyed when the purpose of collection is satisfied or within the period they set (for BIPA, within 3 years of your last interaction), whichever comes first. You may decline document verification and keep using the card route.
- A first-party capture console exists in our code base but is not published or accepting data.
To withdraw consent or ask for deletion, write to privacy@mithril.fund.
6. Who receives it
The providers that process data for us are listed, with purpose, data and region, on Subprocessors. We also disclose data where the law requires it, to protect the service and its users against abuse, and to a successor in a merger or acquisition under the same protections.
7. International transfers
We are a United States company and our providers process data in the United States and other countries. When we transfer personal data from the EEA, the UK or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) with our providers, together with the measures in the DPA security annex. Transfers from India, Singapore, Thailand, Indonesia, Vietnam and the Philippines are made under the contractual safeguards those laws accept.
Data residency
Not pinned: no storage or processing region is selected in code or configuration. Service data is processed on Cloudflare's global network and by the providers on /legal/subprocessors/, whose regions are not specified; data may be processed in the United States and other countries.
- No Cloudflare jurisdiction restriction (for example an EU jurisdiction for R2 or Durable Objects), location hint or placement is configured.
- Inference and screening providers are reached by URL; their regions are chosen in the providers' own consoles and are not recorded in the code.
- Customers who need a pinned region should ask at legal@mithril.fund before sending regulated data; we will not describe a region as pinned until the configuration pins it.
8. How long we keep it
| Data | Period | How it ends | Source |
|---|---|---|---|
| Research job records (prompts, outputs) | 6 hours | Deleted by the research authority's retention alarm. |
research_authority.cljk:1190
|
| Request ledger refusal records | 30 days | Swept automatically. |
research_authority.cljk:1376
|
| Screening status | 30 days by default (at most 365) | Expires; re-screening required. |
research.cljk:452-453
|
| Card / identity verification status and evidence reference | 365 days | Expires; re-verification required. |
research_authority.cljk:331
|
| Verification challenge | 15 minutes | Expires. |
research_authority.cljk:398
|
| Notification-email confirmation code | 15 minutes | Expires. |
contact.cljk:28
|
| Fake-account report evidence | 30 days after the report is resolved | Purged. |
fake_report_authority.cljk:28
|
| Audit log | 180-day retention target (shown at /secure/) | Not yet enforced by automated deletion; we delete on request. |
secure.cljk:365
|
| Purchased credit grants | 12 months from purchase | Unused credit lapses. |
billing_account.cljk:318-322
|
| Account, API-token metadata, billing ledger, notification email | While your account exists | No automated deletion; deleted or anonymised on account-closure request, except records we must keep by law. |
—
|
| Support-chat messages, sales-contact submissions, operational logs | No period set in code | Deleted on request; a fixed period is a known gap. |
—
|
9. Your rights
EEA and UK
You may ask to access, correct, erase, restrict or port your personal data, object to processing based on legitimate interests, and withdraw consent at any time. You may complain to your supervisory authority. We have not yet appointed an EU or UK representative under Art. 27 GDPR / UK GDPR, and we have not appointed a Data Protection Officer; write to privacy@mithril.fund for any GDPR matter.
India (Digital Personal Data Protection Act, 2023)
You may request a summary of your personal data and its processing, its correction, completion, updating or erasure, and nominate another person to exercise your rights. Grievances: privacy@mithril.fund; if unresolved you may approach the Data Protection Board of India.
Southeast Asia
- Singapore (PDPA 2012): access and correction requests; withdrawal of consent.
- Thailand (PDPA B.E. 2562): access, portability, objection, erasure, restriction, correction; complaints to the PDPC.
- Indonesia (Law No. 27 of 2022 on Personal Data Protection): information, access, correction, erasure, withdrawal of consent, objection to automated decisions.
- Vietnam (Decree 13/2023/ND-CP): information, consent and its withdrawal, access, deletion, restriction, objection, complaint.
- Philippines (Data Privacy Act of 2012): information, access, objection, erasure or blocking, rectification, portability, damages; complaints to the National Privacy Commission.
United States (CCPA / CPRA and other state laws)
In the last 12 months we collected the categories in section 2: identifiers, commercial information (billing), internet activity (request logs), sensitive personal information only if you choose document verification, and the content of your requests. We do not sell personal information. The Freebuff conversion tag may be a “sharing” for cross-context advertising when you arrive from a Freebuff ad; to opt out, write to privacy@mithril.fund. Global Privacy Control signals are not yet processed automatically. You may request to know, correct and delete, and we will not discriminate against you for exercising these rights.
How to make a request
Write to privacy@mithril.fund from your notification email or tell us your principal identifier. We verify the request against the signed-in account and answer within the period the applicable law sets (one month under GDPR, 45 days under CCPA).
10. Cookies and similar storage
| Name | Purpose | Lifetime | Set by |
|---|---|---|---|
kb_locale
|
Remembers your language choice | 1 year | mithril.fund |
kc_funnel
|
First-party visitor counter (counts, no profile) | 1 year | mithril.fund |
gftd_session
|
Signed-in session | Session lifetime set by the sign-in service | Sign-in service |
bfcid
|
Ad-click conversion (only after a Freebuff ad click) | 30 days | Freebuff script |
kotoba-theme
|
Light / dark theme (localStorage) | Until cleared | mithril.fund |
kc-funnel-*
|
Visitor / sign-up counter state (sessionStorage) | Browser session | mithril.fund |
We use no other analytics or advertising scripts.
11. Security, children, changes
Security measures are summarised in the DPA annex and on the Trust Center. The service is for security professionals and is not directed to anyone under 18. We will post changes here and change the effective date; material changes are also announced to the notification email of affected accounts.