Data Privacy, Protection, and AI Governance
Last updated: 7 September 2026
MugatuAI LLC (“MugatuAI”, “we”, “us”) — publisher of MugatuAI Signal.
This addendum governs how MugatuAI LLC handles Customer Data in connection with MugatuAI Signal. It supplements our standard Terms of Service and Privacy Policy for enterprise deployments.
Y.1 Customer Data Ownership
As between the parties, Customer retains all right, title, and interest — including all Intellectual Property Rights — in and to all electronic data, files, prompts, code snippets, sensitive business information, personal data, or other materials submitted, transmitted, or ingested by or on behalf of Customer through the Software ("Customer Data"). Mugatu AI acquires no ownership, title, or interest in or to any Customer Data.
Y.2 Prohibition on Public Model Training and Weight Optimization
Mugatu AI explicitly covenants, represents, and warrants that:
- It shall not use, disclose, ingest, transfer, or process Customer Data (in whole or in part, raw or transformed) to train, retrain, fine-tune, optimize, validate, or update any public, third-party, commercial, or foundational artificial intelligence models, machine learning systems, or large language models (LLMs).
- Customer Data will not be shared with, routed to, or retained by third-party model providers, foundation model vendors, or downstream artificial intelligence API providers without Customer's prior express written authorization.
- Under no circumstances shall Customer Data contribute to any persistent model weights, latent vector stores, shared token libraries, or training datasets accessible by other Mugatu AI customers or third parties.
Y.3 Data Retention, Ephemeral Processing, and Storage Limitations
Customer Data processed by the Software is strictly ephemeral and transient:
- Mugatu AI does not retain, persist, log, cache, or store Customer Data on its servers, databases, or cloud infrastructure beyond the immediate, real-time computational execution required to deliver the core functionality of the Software.
- To the extent the Software utilizes local processing, client-side execution, browser-level masking, or endpoint governance protocols, all transformations, security enforcement checks, and inspections of Customer Data shall occur strictly within Customer’s local environment or designated compute boundary.
- Once the discrete computational transaction, verification, or session is complete, all memory buffers holding Customer Data are immediately expunged and deallocated.
Y.4 Confidentiality and Information Security Safeguards
Mugatu AI shall maintain commercially reasonable and enterprise-grade administrative, technical, and physical safeguards designed to:
- protect the security, confidentiality, and integrity of Customer Data against accidental, unauthorized, or unlawful access, alteration, disclosure, destruction, or breach;
- ensure that any metadata or telemetry collected pursuant to Section X.4 (Statistical and Telemetry Data) is strictly stripped of any Customer Data, confidential inputs, credentials, intellectual property, and natural person identifiers prior to ingestion.
Y.5 Compliance with Data Protection Laws
Each party shall comply with all applicable state, federal, and international data protection and privacy laws (including, to the extent applicable, the EU General Data Protection Regulation [GDPR], the California Consumer Privacy Act as amended by the CPRA, and related data security statutes). To the extent processing involves Personal Data as defined under applicable law, the parties agree to execute a Data Processing Addendum (DPA) incorporating the Standard Contractual Clauses, if applicable.