Document 01 of 03

Privacy notice

Your prompts are not stored. This page says what we do keep instead, why, and for how long.

Version
Draft 2
Published
31 July 2026
Status
Not yet in force
Applies to
This site, and the service from launch
Draft

Written to be read now and reviewed by a privacy lawyer before the campaign opens. Draft 2 replaces two sentences that claimed more than any operator can honestly claim, and adds what this website keeps about you, what the US state privacy laws entitle you to, and how to appeal if we say no. Values marked in violet are set when the company is incorporated and the datacenter contract is signed. The final text replaces this one, and we will publish what changed.

01

The short version

Everything below is detail on these five lines. If the detail ever contradicts them, the detail is wrong and we will fix it.

  • Your prompts, your files, and the model's replies are not written to disk and are not used to train anything.
  • The node counts tokens and timestamps so the fair-usage system can work. That is the whole reason the counting exists.
  • There is no stored traffic for anyone to read, us included. Section 04 is honest about the one place your text does exist, which is memory, for as long as your request runs.
  • We sell nothing to anyone, and we run no advertising trackers on this site.
  • You can ask for your data or its deletion at any time, and we answer within 30 days.
02

Who we are

Nodemmunity is the working name of a project to buy one NVIDIA DGX B300, run it in a datacenter, and sell 1,500 people a three year seat on it. The company that will own the machine and answer for this notice is entity name pending, registered in jurisdiction pending. Both are filled in before the campaign opens, and this notice is republished with them in place.

Write to contact@nodemmunity.com about anything on this page. One person reads that inbox today, and you will get a human reply.

The company acts as the data controller for everything described here. Where a supplier processes data for us, section 07 names them.

If the company ends up registered outside the EU and the UK while serving members inside them, it appoints a representative in each under Article 27 of the GDPR and the UK equivalent, and publishes both here: EU representative pending and UK representative pending. You can write to a representative instead of to us, and they are obliged to answer.

There is no data protection officer, because a project of this size does not meet the threshold that requires one. If that changes, this paragraph changes with it and the name goes here.

03

What this notice covers

  1. Today it covers this website and the reservation deposit: the email address you give us, and the record that you paid $1.88.
  2. From launch it also covers the service: your API key, the metadata the gateway records, and the account you use to manage them.
  3. It does not cover the campaign platform. Seats are sold through Kickstarter, and pledges live under Kickstarter's own privacy policy until the money reaches us.
  4. It does not cover what you do with the model. The code you write and the data you feed it stay yours, and we never see either.
04

What the node never keeps

Zero retention is an architecture decision, not a policy promise, which is the only version of it worth anything. The gateway holds a request in memory long enough to serve it and then drops it. The gateway is built so that none of the following is written to disk:

  • Your prompts, and any file, repository, or attachment inside them
  • The model's completions
  • System prompts and tool definitions your client sends
  • Embeddings or any other derivative of your text

While your session is live, its key and value cache sits in GPU memory. If you stop typing for 30 seconds, that cache is compressed and moved to the host machine's RAM so another member can use the GPU, and it comes back when you send your next message. It is memory in both places, it is never a file, and it is discarded when your session ends.

The honest limit of that claim

Memory is where your text exists while a request runs, and anyone with administrative access to a live machine can in principle read what is in its memory. That is true of every hosted service on earth, including the large ones, and any provider telling you it is impossible is describing marketing rather than computers. So here is the accurate version. Two named people hold administrative access under section 10. Reaching it needs a VPN and a hardware key. Every session on the node is logged, the log is not something those two can quietly edit, and the count of administrative sessions goes in the monthly transparency post. What protects you is the absence of anything stored, plus a small number of accountable people, plus a record of when they logged in. It is not a law of physics and we are not going to describe it as one.

We do not train on your traffic. Any change to that would require a new notice and your explicit opt in, not a quiet edit to this page, and section 12 puts that beyond our reach while this company runs the node.

A bug that writes prompt text to a log is treated as a top severity incident: the service goes down until it is fixed, the logs are destroyed, and we publish what happened within seven days including how long it ran. Writing that procedure down is an admission that a bug is possible, which it is. A notice that promised it was not would be worth less than this one. We are also running a bug bounty for members from launch.

05

What the node keeps, and for how long

The fair-usage system needs to know how much compute each key has used and how many people are online. That is arithmetic on counters, and it needs none of your text.

Retention schedule, per member key
WhatWhyKept for
Key identifierAttributes usage to a seatLife of the seat, then 90 days
Request timestampFair-usage accounting and capacity planning90 days
Token counts, in and outThe stamina ledger90 days
Model and context lengthCapacity planning90 days
Source IP, coarse locationDetects key sharing and resale30 days
Error tracesDebugging, scrubbed of request content30 days

After those windows the per-request rows are deleted. What survives is aggregate: requests per day, tokens per day, uptime, and the mode the gateway was in. Those numbers carry no key and no address, and they are what the monthly transparency reports are built from.

Your own dashboard shows you the same ledger for your key, for the same 90 days.

06

What this website keeps

  1. Your email address, if you give it to us for a reservation or the waitlist, with the date and the page you gave it on. We use it to tell you when the campaign opens and nothing else. Every message has an unsubscribe link, and unsubscribing deletes the address.
  2. The record of your $1.88 deposit. Stripe takes the card details and we never see the number. What reaches us is your email, the amount, and whether it succeeded.
  3. Page counts. Analytics here are cookieless and aggregate. No cross-site identifier, no advertising pixel, no session recording, no fingerprinting.
  4. Nothing about children. This is a developer tool sold to adults. We do not knowingly collect anything from anyone under 18, and we delete it if we find it.
  5. How long the website side keeps things. A waitlist or reservation email lives until you unsubscribe or ask for it to go, and unsubscribing deletes it the same day. Deposit records live for as long as tax law requires us to keep a payment record, which is retention period pending once the jurisdiction is fixed, and then they go. Cloudflare's edge logs, which include your IP address, are kept for up to 30 days by Cloudflare and we do not copy them anywhere.
  6. Cookies. This site sets none. No consent banner appears because there is nothing to consent to, not because we skipped the banner. If we ever add a cookie that is not strictly necessary, a banner appears with it and it will be a real choice rather than a wall.
  7. Your browser is not fingerprinted. No session recording, no heatmaps, no cross-site identifier, no advertising pixel, no third-party script beyond the font files this page loads from Google Fonts, which see your IP address in the course of serving them. We are looking at self hosting the fonts to remove that last one.
07

Who else handles your data

Suppliers marked pending are chosen before the campaign opens, and this table is updated when they are. We will not add a supplier that requires us to hand over request content, because there is none to hand over.

WhoWhat they doWhat they get
StripeTakes the reservation depositYour card details, which go to them and never to us, plus your email
KickstarterRuns the campaignYour pledge record, under their privacy policy
CloudflareServes this websiteEdge request logs, including IP
Email providerSends waitlist and member mailYour email address
Colocation providerHouses and powers the machinePhysical access to hardware, no software access
AnalyticsCounts page views, cookielessAggregate page data with no identifier
Google FontsServes the two typefaces on these pagesYour IP address, in the act of serving a font file
Escrow agentHolds refund and sale moneyYour name and payment route, only at a payout

Every one of them is bound by a written contract that limits them to what the table says, forbids them from using your data for their own purposes, and requires them to delete it when we stop working together. Where a supplier sits outside the EU or the UK and processes data belonging to members inside them, the transfer runs on the standard contractual clauses described in section 08.

If we add or change a supplier who touches your personal data, we publish the change here and email members 30 days before it takes effect, with what the new supplier gets. You do not get a veto on a supplier, and pretending otherwise would be false, but a change you object to that materially affects you is a material change under section 17 of the terms, which comes with an exit and a refund.

08

Where your data sits

The machine will live in one Tier 3 datacenter in location pending. We publish the country and the operator before the campaign opens, because for some of you it decides whether you can buy a seat at all.

This website runs on Cloudflare's network, so the page you are reading was served from somewhere near you.

If you are in the EU or the UK, the transfer of your metadata to the datacenter country rests on the European Commission's standard contractual clauses where an adequacy decision does not cover it. We will publish a short data processing agreement alongside the final notice, and members who need one signed can ask.

09

Your rights

Ask for any of these at contact@nodemmunity.com and we answer within 30 days, free, without asking why you want it.

  • A copy of everything we hold on you, in a format you can read and move elsewhere
  • Correction of anything wrong
  • Deletion, subject to the records tax law requires us to keep about a payment
  • Restriction of processing, or an objection to it
  • Withdrawal of consent for marketing email, which the unsubscribe link also does in one click

The legal bases, for those who need them named: we process service metadata to perform the contract you bought, abuse signals under our legitimate interest in keeping the node available to 1,500 people, and marketing email on your consent. Where we rely on legitimate interest you can object, and we will either stop or explain in writing why we think the interest still holds.

If you are in the United States

California, Colorado, Connecticut, Virginia, and a growing list of other states give their residents rights that look much like the ones above: to know, to get a copy, to correct, to delete, to limit the use of sensitive information, and not to be treated worse for asking. We apply all of them to everyone, everywhere, because sorting members by state to decide who deserves which right is not a business we want to be in.

  • We do not sell personal information and we do not share it for cross-context behavioural advertising, in the sense California law gives both terms. There is no data broker in this business model and no version of it where one appears.
  • We honour a Global Privacy Control signal from your browser. There is nothing for it to switch off here, and we honour it anyway so that the setting means the same thing on this site as on any other.
  • We collect no sensitive personal information as those laws define it. Not race, health, biometrics, precise location, or the contents of your communications, which section 04 covers in full.
  • An authorised agent can act for you. We will ask for proof that you asked them to, and nothing more than that.

If we say no

We can refuse a request only where the law lets us, and if we do you get the reason in writing rather than a form letter. You can appeal by replying to that email with the word appeal. A different person reviews it and answers within 45 days, and if the answer is still no we tell you how to take it to your state attorney general or your data protection authority. That appeal route exists whether or not the law where you live requires one.

No automated decisions

Nothing here makes a decision about you by machine that has a legal or similarly significant effect. The gateway flags usage patterns, but section 08 of the terms is explicit that no key is ever terminated by a script and that a person reviews every flag, tells you what they saw, and gives you seven days to answer.

You can complain to your national data protection authority, or your state attorney general, at any time. We would rather you told us first, but that right does not depend on us.

10

Security

  1. Traffic to the endpoint runs over TLS. API keys are stored hashed, so a copy of our database does not let anyone use your key.
  2. Administrative access to the node needs a VPN and a hardware security key. Two people hold that access at launch, and the list of who is published.
  3. The gateway is penetration tested before launch, and the report is published with the findings fixed.
  4. If a breach ever touches your data, you hear from us within 72 hours of us confirming it, with what happened and what to do. Regulators hear from us in the same window.
  5. Zero retention is also the security story. A break-in finds counters, not code.
11

Deletion at the end of the term

When the 36 months are delivered, member accounts and their remaining metadata are deleted 90 days after the last day of service. We keep the payment records that tax law requires, and the aggregate uptime numbers behind the final transparency report.

The machine itself is wiped before it is sold, to a documented standard, by a third party who certifies it. That certificate is published in the sale dossier described in the terms of service, before any member is paid.

12

Changes to this notice

Every version stays online with its date, so you can see what changed and when. For a change that materially affects you, we email members 30 days before it takes effect and say plainly what is different.

Two things are not going to change while this company runs the node: we will not start retaining prompts, and we will not sell your data. If either ever needs to change, it will not happen by editing this page. It will happen by asking you.