# cloud-murakumo — Privacy Policy

> **DRAFT — This is not legal advice. Review by qualified counsel is required before publication.**

Last updated: 2026-08-30

Governing law: **[COUNSEL CONFIRMATION REQUIRED]**

Public site / service operator: **Kotoba Labs Inc**. Sales contact: **Ryo Awai**.

This Privacy Policy explains how the operator of murakumo.cloud (the "Operator",
"we") handles personal information in connection with
the **cloud-murakumo** distributed GPU cloud and inference infrastructure service
(the "Service"), including the murakumo.cloud site.

This repository does not contain an Inc filing for Kotoba Labs Inc. 法人情報,
address, phone and 代表者 are disclosed on request and are not invented here.
Applicable privacy law depends on the user, processing activity and operating
location. This draft addresses the Japanese **Act on the Protection of Personal
Information (APPI, 個人情報保護法)**, the EU/EEA **General Data Protection
Regulation (GDPR)** and the **California Consumer Privacy Act as amended by the
CPRA (CCPA/CPRA)** where each applies; qualified counsel must confirm the final
scope.

Note: cloud-murakumo is primarily **backend infrastructure**. In most cases an
integrating product (e.g. `ai-gftd-apex` via `ai-gftd-router`) is the
end-user-facing controller and its privacy notice governs end users; we typically
act as a processor/service provider for job Inputs and outputs submitted to us.

---

## 1. Data controller / business operator

- **Data controller / business operator:** Kotoba Labs Inc. 法人情報, address,
  phone and 代表者 are disclosed on request. Legal notice details remain
  subject to counsel confirmation.
- **Infrastructure processor/vendor:** none designated. The Operator operates
  the hosted gateway and fleet itself. (Third-party sub-processors such as
  hosting and payment providers are listed where they apply.)
- **GDPR controller/processor:** Kotoba Labs Inc; our role (controller vs.
  processor) depends on the data — see the note above. No EU-UK GDPR Art. 27
  representative is designated at this time.
- **Data protection contact / DPO:** No DPO is designated at this time; contact
  us at support@murakumo.cloud.

## 2. Data we collect

- **Account / actor identity.** The actor or account identifier attributed to
  each job and recorded in the run ledger. [CONFIRM: whether this includes any
  directly identifying fields such as email/name, or only an opaque
  product-delegated identifier.]
- **Job Inputs.** Prompts, reference inputs (including referenced content CIDs),
  and parameters submitted for inference/generation. Prompts may contain personal
  data that the caller chooses to include; the caller is responsible for its
  lawful provision.
- **Outputs / artifacts.** Generated artifacts (image, video, 3D, audio, voice)
  stored as content-addressed objects on artifact volumes (object storage /
  content-addressed storage).
- **Run ledger / usage telemetry.** Per-run records: run id, function, model,
  actor, run state, GPU-seconds, artifact CIDs, computed cost, and timestamps —
  queryable historically (Datomic as-of) for accounting and audit.
- **Operational diagnostics.** Node/placement, engine, elapsed time, and
  throughput metrics used for scheduling and cost analysis.
- **Smartphone participation telemetry.** A pseudonymous did:key, declared
  capability, job completion time, verification verdict and earned usage. The
  browser admission policy may inspect battery/network/device capability
  locally; raw battery state and temperature are not uploaded unless a later
  consent screen explicitly states otherwise.
- **Payment data.** Stripe processes card and payment details for credit
  purchases. We receive transaction identifiers, purchased SKU, amount,
  currency, payment/refund status, and the account DID needed to credit or
  reverse the ledger. We do not receive or store complete card numbers.

We do not intentionally collect special-category / sensitive data. Do not submit
secrets or sensitive personal data into prompts, references, or job metadata.

## 3. Purposes and legal basis

We process personal information to:

- execute inference and generation jobs and return artifacts;
- schedule and place workloads across the GPU fleet and manage autoscaling;
- meter usage, enforce quotas, and account for cost (run ledger);
- secure the Service and prevent abuse; and
- comply with legal obligations.

**APPI:** processing is within the identified utilization purposes (Arts. 17–18).

**GDPR** (where applicable): contract performance (Art. 6(1)(b)); legitimate
interests in operating, scheduling, and securing the Service and metering cost
(Art. 6(1)(f)); legal obligation (Art. 6(1)(c)); and, where we act as processor,
processing on documented instructions of the controller (Art. 28).

**CCPA/CPRA:** processing for business purposes. [CONFIRM: we do not "sell" or
"share" personal information — confirm no sale/sharing or targeted advertising
occurs.]

## 4. Sharing and subprocessors

We share personal information only with subprocessors that process it on our
behalf, and as required by law. Likely subprocessors:

| Subprocessor | Function | Data involved |
|---|---|---|
| **Hugging Face** | Model-weight hosting/download into the fleet cache | Model artifacts (not user PII by default) |
| **Backblaze B2** (object storage) | Artifact and volume storage | Job outputs, cached weights |
| Content-addressed graph service (`kotobase.net`) | Distributed job queue and run persistence | Job/run metadata, actor identity |
| GPU fleet nodes | Distributed inference execution | Inputs, outputs, run metadata |
| **Cloudflare** | murakumo.cloud static site delivery / DNS | Site request metadata |
| **Stripe** | Payment processing, fraud screening, refunds and chargebacks | Payment identifiers, amount/currency, billing details and payment status |

[CONFIRM: complete and current subprocessor list, including the actual GPU fleet
hosting arrangement/region and any
analytics tooling. Do not treat this table as exhaustive or final without
verification — several entries are inferred from repository configuration.]

Artifacts and referenced content stored as CIDs may be retrievable by third
parties through content-addressed / IPFS networks; this is inherent to content
addressing.

## 5. International transfer

The Operator is organized in Delaware, United States. Infrastructure operations
and fleet nodes may be located in Japan, including the Tokyo region, and
subprocessors may process data in other countries. [CONFIRM: principal place of
business, actual processing regions and transfer safeguards per subprocessor.]

- **APPI:** foreign third-party provision follows APPI Art. 28 conditions
  (consent with prescribed information, equivalent-standard countries, or
  equivalent safeguards). [CONFIRM safeguard basis.]
- **GDPR:** transfers rely on adequacy (Japan holds an EU adequacy decision) or
  appropriate safeguards such as Standard Contractual Clauses. [CONFIRM per
  subprocessor.]

## 6. Retention

- Run-ledger records are retained for accounting, audit, and historical
  (as-of) query. [CONFIRM: retention period for run-ledger and diagnostics.]
- Job Inputs and generated artifacts are retained per configuration. [CONFIRM:
  whether prompts are retained after job completion and for how long; whether
  artifacts persist indefinitely as content-addressed objects.]
- Content-addressed artifacts may remain retrievable after deletion of local
  references.
- [CONFIRM: specific numeric retention periods. Do not state a period until
  confirmed.]

## 7. Security

- [CONFIRM: transport encryption (TLS) posture for job submission and backend
  runtime endpoints; several runtime endpoints are private/env-configured.]
- GPU acquisition, scale-up, and deletion are gated as approval-required
  financial side-effects; quotas are enforced fail-closed.
- [CONFIRM: encryption-at-rest for artifact/volume storage and access controls
  on the run ledger and fleet nodes.]
- Contributors must not commit secrets or sensitive data.

## 8. Your rights

Subject to applicable law and identity verification, you (or, where we are a
processor, the controlling product on your behalf) may request access,
correction, deletion, portability, and restriction/objection:

- **APPI:** disclosure, correction, addition/deletion, and suspension of use
  (Arts. 33–35); utilization-purpose notice (Art. 32).
- **GDPR:** rights under Arts. 15–21 and the right to complain to a supervisory
  authority.
- **CCPA/CPRA:** rights to know, delete, correct, and opt out of sale/sharing,
  and non-discrimination for exercising rights.

Where an integrating product is the controller, direct rights requests to that
product; we will support it as processor. To contact us directly: support@murakumo.cloud. We will explain the limits of erasure for
content-addressed artifacts.

## 9. Cookies

[CONFIRM: whether the murakumo.cloud site sets any cookies or similar
technologies and any consent mechanism. The site is described as a static/pure-
compute SPA and may set none — confirm before publication.]

## 10. Children

The Service is backend infrastructure not directed to children. [CONFIRM: minors
handling, including APPI 2026-amendment protections for under-16s where
applicable.]

## 11. Changes to this Policy

We may update this Policy; material changes are indicated by updating the "Last
updated" date and, where appropriate, by additional notice.

## 12. Contact

Operational email: support@murakumo.cloud.

- Site / service operator: Kotoba Labs Inc
- Sales contact: Ryo Awai
- 法人情報 / address / phone / 代表者: disclosed on request at
  support@murakumo.cloud. This repository does not contain an Inc filing
  for Kotoba Labs Inc; those values are not invented here.

No DPO or EU-UK GDPR Art. 27 representative is designated at this time.
