Mithrandir Privacy Notice — launch-v1 Operator: Marcin Wysocki / DEMWH Contact: marcin.wysocki1991@gmail.com Mithrandir processes account identifiers, API-key metadata, operator-defined budgets, service usage, audit records, payment-order metadata and any artifacts intentionally submitted to the service. Stored artifact content is treated as untrusted data and is not promoted to control authority. Purpose: provide the service, enforce security and spending policy, maintain continuity, investigate failures and reconcile payments. Retention: artifacts are retained only within the configured TTL/service limits; audit and payment records may be retained longer where needed for security, reconciliation or legal obligations. Payments: the service may process public blockchain addresses, transaction hashes and payment authorization metadata. Private keys and seed phrases are not required by Mithrandir. Sharing: infrastructure and payment facilitators receive only the data required to provide their respective functions. Mithrandir does not sell personal data to advertisers. Deletion: supported artifacts and task state can be deleted through the authenticated API. Some audit/payment records may need to be retained for integrity, dispute handling or legal requirements. Security: encryption, tenant separation, replay controls and the v17 Cognitive Membrane reduce risk but do not constitute an absolute security guarantee. Questions or rights requests: contact marcin.wysocki1991@gmail.com.