Privacy Policy
Table of Contents
Effective date: April 19, 2026 Last updated: August 11, 2026
mutual (“we,” “us,” or “our”) operates the website at mutual.solutions . This policy explains what data we collect, why, and what we do with it.
We collect only what we need to run our waitlist, evaluation program, AI chatbot, and hardware pre-orders. We do not use cookies, analytics, advertising, or behavioral tracking.
What changed on August 11, 2026. We opened hardware pre-orders on August 9, 2026, and this policy had not caught up. It now describes the data collected at checkout (§2.9), lists Stripe and Google Workspace as processors (§2.6), and corrects a line in §3 that said we collect nothing beyond our forms and chatbot. That line was written before we had a store and it was no longer true. If you pre-ordered before this date, §2.9 describes what we hold about you.
1. Who we are #
mutual builds cryptographic camera modules for content authenticity. Two legal entities operate under the name, and this policy covers both:
| Entity | Role |
|---|---|
| mutual Solutions, Inc., a Delaware corporation (USA) | Seller of record for AnchorCam hardware. Named on every pre-order invoice and receipt. |
| 뮤추얼솔루션즈, a Korean sole proprietorship, business registration 578-60-00870 | Korean operations |
Privacy officer (개인정보 보호책임자): Yejun Jang, CEO Email: hello@mutual.solutions
For anything at all, including a specific order or receipt, email
hello@mutual.solutions
. That is the support address on
your receipt and at checkout. Some order correspondence in August 2026 was sent from
yejun@mutual.solutions; replying to those threads still reaches us.
2. What we collect and why #
2.1 Waitlist & evaluation signups #
When you submit our waitlist or evaluation form, we collect and persistently store the information you provide. Each field has a specific purpose:
| Field | Where it comes from | Why we collect it |
|---|---|---|
| All forms | To contact you about the product, evaluation invitations, or launch updates. Primary purpose. | |
Product interest (e.g. anchor, forensic-evaluation) | All forms | To tell us which product you signed up for so we can send relevant updates and prioritize roadmap. |
| Page URL you signed up from | All forms | Aggregate analytics. Knowing which pages drive signups lets us improve content. (See §2.4 Analytics.) |
| Name | Evaluation form only | To address you personally and qualify candidates for the limited evaluation program. |
| Organization | Evaluation form only | To assess fit for the evaluation program (we prioritize specific industries: forensics, journalism, insurance). |
| Timestamp | All forms | Ordering, anti-fraud, knowing when to follow up. |
These records live in our database (Google Cloud Firestore, region us-east1) and are kept until you ask us to delete them or until the relevant program concludes. To request deletion, email the privacy officer above with the email address you used to sign up.
2.2 AI chatbot (Mr. M): message storage #
When you use the Mr. M chatbot, the messages you type are sent to Google’s Gemini API to generate responses, and we also save the conversation in our own database for three specific purposes:
- Q&A continuity (UX): so the chatbot can refer back to earlier messages in the same conversation and you don’t have to re-explain yourself.
- Debugging poor answers: when Mr. M gives wrong, confusing, or unhelpful answers, admins review the transcript to fix the underlying prompt, fill in knowledge gaps, or correct factual errors.
- FAQ improvement: common questions are identified and added to Mr. M’s knowledge base so future visitors get better answers faster.
How it works:
- Live processing: Your messages go to Google’s Gemini API in real time. Google processes them under Google’s API Terms of Service .
- Storage on our side: Each message (your prompt + Mr. M’s response) is written to a chat-session record in Firestore, tied to a session identifier we generate per browser session.
- Retention: Chat messages are retained for 30 days in Firestore so admins can debug recent conversations. After 30 days, they are automatically and permanently deleted by a daily scheduled job. We do not keep an archive copy. You can request earlier deletion at any time.
- Conversation memory in your browser: Up to 20 recent messages are kept in your browser’s memory during the chat session for context.
2.3 Abuse prevention (rate limiting & IP hashing) #
To prevent abuse, we briefly process your IP address:
- The raw IP address is held in memory only for the duration of the request and is never written to a database in raw form.
- A salted hash of your IP is stored alongside waitlist/chat records so we can detect repeated abuse without retaining identifiable IP data. The salt is rotated daily so hashes from yesterday cannot be linked to hashes from today.
- We do not use your IP address for any other purpose.
2.4 Analytics #
We perform aggregate, first-party analytics only. No third-party trackers, no per-user behavioral profiling, no cross-site tracking. What we do collect:
| Metric | What it tells us |
|---|---|
| Daily counts of waitlist signups, chat sessions, form submissions, errors | How the product is being received and where issues happen |
Which page each waitlist signup came from (sourcePage) | Which content drives the most interest |
| Chat usage statistics (sessions/day, average length, token cost) | Sizing the chatbot service and budgeting |
These are stored as aggregate counters in Firestore (the counters/ collection) and as the sourcePage field on waitlist records. We do not use Google Analytics, Plausible, Fathom, Segment, Mixpanel, Amplitude, or any other third-party analytics SDK. We do not set tracking cookies. We do not build per-visitor behavioral profiles.
2.5 Local storage (browser) #
We store a few values in your browser’s localStorage / sessionStorage. These never leave your device:
| Key | What it stores | Purpose |
|---|---|---|
mrm-seen | "1" (a flag) | Remembers that you opened the chatbot so the notification badge doesn’t show again |
mrm-sid | random session id | Lets all your messages in one browsing session attach to the same chat record |
appearance | "light" or "dark" | Remembers your theme preference |
You can clear these at any time through your browser settings.
2.6 Infrastructure providers #
Our website and backend run on the following providers, each of which may process standard connection data (IP addresses, browser type, timestamps) as part of normal web operations:
| Provider | What it handles | Privacy policy |
|---|---|---|
| Cloudflare | DNS, edge proxy, the api.mutual.solutions Workers (waitlist + chatbot endpoints) | Cloudflare Privacy Policy |
| Firebase / Google Cloud | Hosting, Firestore database, Cloud Functions | Google Cloud Privacy Notice |
| Google Gemini API | Mr. M chatbot inference | Google API Terms |
| Stripe | Hosted checkout, card processing, invoices and receipts for pre-orders (§2.9) | Stripe Privacy Policy |
| Google Workspace | Our email. Order correspondence, invoices and support replies are sent and received here | Google Cloud Privacy Notice |
2.7 Third-party scripts #
We load two open-source libraries from jsDelivr CDN (marked for markdown, dompurify for sanitization) only on pages where the chatbot is shown. jsDelivr may receive your IP address when serving these files. See jsDelivr’s privacy policy
.
2.8 Fonts #
All fonts are self-hosted on our domain (Inter, Nanum Square, JetBrains Mono) or use the system font stack. We do not load any external font CDN, so no third party receives your IP address through font requests.
2.9 Hardware pre-orders and payments #
When you pre-order AnchorCam hardware, checkout is hosted by Stripe, not by us. Your card number goes to Stripe directly. We never see it and we never store it.
Stripe passes us the following, and we keep it as the order record:
| Field | Why it is collected |
|---|---|
| Name | To identify the order and to address you on it |
| To send your invoice and receipt, and to tell you when a board is ready to ship | |
| Billing address | Required to authorise the card and to screen for fraud |
| Shipping address | To ship the unit when production starts |
| Phone number | Contact for the carrier at delivery, and to reach you if a shipment fails |
| Order amount, quantity, timestamp, invoice number | The order record itself, and our accounting and tax obligations |
About tax IDs. Until August 11, 2026, our checkout asked for a business name and a tax registration number, and depending on the billing country it marked them required. That was a misconfiguration on our side: we do not run automatic tax calculation and had no use for the field. At least one buyer was unable to complete checkout because of it and reported so publicly, and others entered placeholder values to get past it. We removed the field on August 11, 2026. Tax IDs submitted before then are attached to those buyers’ invoices in Stripe. If you entered one — including a placeholder — and want it removed or corrected, email us and we will reissue the invoice.
Where it lives. Stripe processes this on our behalf as our payment processor, and is separately an independent controller for its own fraud-prevention and legal obligations. Stripe may process and store this data in the United States and other countries where it operates. See the Stripe Privacy Policy .
Correspondence about your order — invoices, receipts, refund requests — is sent and received through Google Workspace, which hosts our email (§2.6).
We do not sell or rent buyer data, and we do not share it with advertisers, data brokers, or marketing platforms. It goes to the processors listed in §2.6 in order to take your order, contact you about it, and meet our tax obligations, and nowhere else.
Refunds. Every pre-order is refundable in full on request before the unit ships. Asking for a refund does not delete the order record — see §6, we are required to keep it.
3. What we do NOT collect #
- Third-party analytics or tracking SDKs (no Google Analytics, Plausible, Fathom, Mixpanel, Amplitude, Segment, etc.)
- Behavioral profiling or per-visitor browsing history
- Cross-site tracking pixels or fingerprinting
- User accounts or registration for visitors
- Advertising or marketing trackers
- Any data outside what you explicitly submit through our forms, our chatbot, or our checkout
- Your card number. Checkout is hosted by Stripe and card details never reach us (§2.9)
A note on cookies: Cloudflare sets a small
__cf_bmcookie (≤30 minutes) for bot detection on our domain. This is a security cookie, not a tracking cookie. It’s used to distinguish humans from bots and is not used to profile you. Aside from this and your local theme/session preferences (§2.5), we set no cookies of our own.
4. Legal bases for processing (GDPR) #
For visitors from the EEA, UK, or Switzerland:
| Processing activity | Legal basis (GDPR Art. 6(1)) |
|---|---|
| Waitlist & evaluation form submissions | (a) Consent: you actively submit the form and check the consent box |
| Chatbot message processing via Google Gemini | (a) Consent: you choose to send messages |
| Chat message storage in our database | (b) Contract / (f) Legitimate interest: providing the chatbot service and improving its quality |
| Hashed IP for rate limiting | (f) Legitimate interest: preventing abuse |
| localStorage values | (f) Legitimate interest: basic functionality |
| Taking and fulfilling a pre-order (name, addresses, phone, order record) | (b) Performance of a contract: we cannot take or ship your order without it |
| Keeping order, invoice and payment records after the sale | (c) Legal obligation: tax and accounting law |
| Fraud screening at checkout | (f) Legitimate interest: preventing fraudulent card use, carried out by Stripe |
5. International data transfers #
When you use Mr. M, your messages are sent to Google’s Gemini API. Google may process this data in the United States or other countries where Google operates. Our Firestore database is also operated by Google Cloud and may store data in the United States (region us-east1).
Pre-orders. The seller of record is a Delaware corporation, and Stripe is a US company. If you pre-order from outside the United States, your order data is transferred to and stored in the United States, and may be processed in other countries where Stripe operates. Our email is hosted by Google Workspace on the same basis.
6. Data retention #
| Data | Retention |
|---|---|
| Waitlist & evaluation submissions | Kept until you request deletion or we close the relevant program |
| Chat session messages | 30 days in Firestore, then permanently deleted by a daily scheduled job. No archive copy is kept. |
| Hashed IPs (in records) | Same as the parent record (salt rotates daily) |
| Raw IP addresses | Held in memory only; never persisted |
| localStorage values | Stored in your browser until you clear them |
| Order, invoice and payment records | Kept for as long as tax and accounting law requires us to keep them, which outlasts both the order and any refund. These are the one category we cannot delete on request while that obligation runs. We can stop using them for anything other than that obligation — see §7. |
| Order correspondence (email) | Kept in our mailbox alongside the order record, on the same basis |
7. Your rights #
Under GDPR (EEA/UK/Swiss visitors) #
You have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. You may withdraw consent at any time by stopping use of the chatbot or by emailing us to delete your waitlist/evaluation entry. You may lodge a complaint with your local data protection authority.
Under PIPA (개인정보 보호법) #
You have the right to request access to, correction of, deletion of, or suspension of processing of your personal information through the privacy officer listed above.
One limit, stated plainly #
Everything above applies to your order data too, with one exception we want you to hear from us rather than discover: we cannot erase an order, invoice or payment record on request while tax and accounting law requires us to keep it (§6). What we can do is stop using it for anything beyond that obligation, correct it if it is wrong, and give you a copy. Refunding your order does not change this. Every other category in this policy — waitlist entries, chat messages — we delete on request.
We respond to all rights requests within 30 days. To make a request, email hello@mutual.solutions with the email address you used to sign up or to order.
8. Children’s privacy #
We do not knowingly collect personal information from children under 14 (Korea) or under 16 (EEA).
9. Changes to this policy #
If we change this policy, we will update the “Last updated” date at the top. For significant changes (new data collection, new providers, retention changes), we will provide notice on our website.
10. Contact #
Email: hello@mutual.solutions — privacy requests, orders, receipts, everything
Privacy officer (개인정보 보호책임자): Yejun Jang (장예준), CEO