PRIVACY POLICY
1. SCOPE
This Privacy Policy explains how Kitsune Security (“Kitsune,” “we,” “us,” or “our”) handles personal information when you visit Eutrya websites, join a waitlist, create an account, purchase or manage a Founder membership, contact us, or use connected Eutrya services.
Eutrya Phase 1 is local by design. Local objectives, notes, evidence, and operating context remain on your device unless you deliberately export them or invoke a connected feature. This Policy applies when information is sent to or processed by our websites, accounts, hosted features, or service providers.
2. INFORMATION WE COLLECT
Information you provide
- Account and contact information, such as email address and authentication requests.
- Waitlist information, consisting of the email address and consent state you submit.
- Support communications and information you choose to include.
- Content submitted to connected or hosted workflows.
Billing and entitlement information
- Selected Founder tier, billing cadence, locked amount, reservation state, subscription identifiers, payment status, cancellation state, and release entitlement.
- Stripe processes payment-card and bank details. We do not intentionally store complete payment-card numbers or security codes in Eutrya systems.
Technical information
- IP address, device and browser information, timestamps, request metadata, security events, and diagnostic logs needed to deliver and protect the Services.
- Authentication and session data stored through essential browser or account mechanisms.
- Usage and execution metadata for hosted workflows, such as request identifiers, workflow type, status, resource usage, and error state.
3. HOW WE USE INFORMATION
We use personal information to:
- authenticate users and maintain account sessions;
- create server-authoritative Checkout sessions and account-bound Founder reservations;
- verify signed payment events, prevent duplicate grants, manage renewals and cancellations, and release paid access when authorized;
- provide local, connected, and hosted product functionality;
- send transactional, release, waitlist, billing, security, and support communications;
- detect fraud, abuse, unauthorized access, and reliability problems;
- debug, maintain, and improve the Services; and
- comply with law, enforce agreements, and protect users, Kitsune, and others.
4. PAYMENTS AND FOUNDER RESERVATIONS
Stripe processes Checkout and payment information. Stripe sends us account and lifecycle events needed to record reservations, subscription state, refunds, disputes, and cancellations. A successful payment creates a presale entitlement with access pending release; the success-page redirect does not independently create access.
We retain billing and entitlement records as needed to provide the membership, maintain an audit trail, resolve disputes, prevent duplicate grants, and meet financial, tax, and legal obligations.
5. CONNECTED AND HOSTED WORKFLOWS
When you deliberately invoke a connected or hosted workflow, we may transmit the content and instructions needed to fulfill that request to infrastructure, compute, or model providers. Do not submit secrets, personal information, or third-party material unless it is necessary, lawful, and within your authority.
Agent output may be stored with request, trace, usage, or result metadata when necessary for delivery, replay prevention, support, safety review, and billing. Local-only Phase‑1 context is not uploaded merely because the local software is installed.
6. SERVICE PROVIDERS AND DISCLOSURES
We may disclose information to service providers that process it for us, including:
- Stripe for payments, subscriptions, fraud prevention, and billing communications;
- Supabase for authentication, database, entitlement, and server-function infrastructure;
- Cloudflare for website delivery, performance, abuse prevention, and network security;
- transactional email providers for sign-in, billing, release, and support messages; and
- compute or model providers when you invoke a connected workflow.
We may also disclose information when required by law; to investigate fraud, security incidents, or abuse; to protect legal rights or safety; or as part of a merger, financing, acquisition, reorganization, or asset transfer subject to appropriate safeguards.
We do not sell personal information or use it for cross-context behavioral advertising.
7. COOKIES AND LOCAL STORAGE
We use essential browser storage, authentication tokens, and similar technologies needed to sign users in, preserve session state, prevent abuse, and operate the Services. We do not currently use third-party advertising cookies. Third-party Checkout or authentication pages may use their own essential technologies under their policies.
8. RETENTION
We retain information only as long as reasonably needed for the purposes described in this Policy, including providing an active account or membership, preserving payment and security records, resolving disputes, and meeting legal obligations. Retention periods vary by record type.
Waitlist information is retained until you unsubscribe, request deletion, or the release communication purpose ends, subject to suppression records needed to honor opt-out requests. Local Phase‑1 data remains under your control on your device unless exported or connected.
9. YOUR CHOICES AND RIGHTS
You may unsubscribe from optional marketing or release communications using an available link or by contacting us. Transactional and security messages may still be sent when necessary for your account or purchase.
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection regarding personal information. You may also have a right to appeal or complain to a regulator. We may verify your identity before acting and may retain information where law or legitimate security, billing, or dispute needs require it.
10. SECURITY
We use administrative, technical, and organizational safeguards designed to protect personal information, including server-side price authority, signed webhook verification, account binding, restricted credentials, and access controls. No system is perfectly secure, and we cannot guarantee absolute security.
11. CHILDREN
The Services are not directed to children under 18, and we do not knowingly collect personal information from children. Contact us if you believe a child has submitted information.
12. UNITED STATES PROCESSING
Kitsune operates from the United States. Information may be processed in the United States and other countries where our service providers operate. Those locations may have different privacy laws from your jurisdiction.
13. CHANGES
We may update this Policy as the Services or legal requirements change. The current version will state its effective date. We will provide reasonable notice of material changes where required.
14. CONTACT
For privacy questions or requests, contact [email protected] or use the support channel shown in your Eutrya account or receipt.