Invite jobs running Public pilot mill · Workspace open
KBMILL Privacy Enter the plant

Governance

Privacy Policy

Effective / last updated: 2026-09-14 (hardened same day for purge scope, access, processors, breach notice) · Operator: Carroll Miller, d/b/a KBMill · [email protected]

Describes how the public mill door handles information. Not legal advice. No SOC 2 / ISO 27001 claim — we document practices honestly instead of inventing certifications. Companion: /terms · one-pager /security (hosting, purge matrix, subprocessors, logs).

Fit for purpose (read this first)

For a small pilot and ordinary, non-sensitive documents, this policy is meant to be reasonably transparent. It is not strong enough by itself as the sole protection for trade secrets, personal records, regulated data, or documents under contractual confidentiality.

This page is not a data-processing agreement (DPA), NDA, BAA, or customer-specific security schedule. For sensitive material, ask for a signed path covering legal entity details you need, subprocessors, processing location, encryption expectations, access logging, backups, breach notification SLAs, deletion verification, and liability — [email protected] — before you upload. See also § Sensitive / confidential documents.

Stance (lead with this)

KBMill is a manufacturing plant for knowledge packages, not an ad network and not a “trade your privacy for a free chat” product.

Essential/functional cookies or similar storage may be used only as needed to run the site, security (e.g. CDN), and payments (e.g. Stripe Checkout on Stripe’s pages).

Legal identity on this door: Carroll Miller, doing business as KBMill. No separate LLC / corporation name is posted on this policy. Contact is by email ([email protected]); no public mailing address is published. If your diligence requires a signed entity block or mailing address on paper, that is part of the signed path above — not this web policy alone.

1. Who this policy covers

This policy describes how we handle information when you:

It does not cover third-party sites we link to (e.g. public brick library on GitHub, Hugging Face demos) — those have their own policies.

2. Information we collect

2.1 You provide

CategoryExamplesWhy
Account / accessInvite password (if gated); coupon codesOperate the pilot door
Job inputsFiles you upload; optional job labelManufacture the brick
Optional notifyEmail address if you opt in for Ready/pickup noticeTell you the job is ready / help you return
CommentsName, email, message (if you use the comment form)Operator feedback — lands on this plant
PaymentHandled by Stripe (card details on Stripe’s Checkout — we do not store full card numbers)Pay-on-success holds / capture
Email correspondenceMessages you send to [email protected]Support and business

2.2 Collected automatically (minimal)

CategoryExamplesWhy
Technical logsIP address, user agent, timestamps, request paths, error logsSecurity, abuse prevention, debugging the plant
Job/plant recordsJob id, class/price, status chips, ledger events (authorize/capture/void), pickup-code hash (not the raw code at rest after issue)Run pay-on-success and retrieve
CDN / securityWhatever our HTTPS front (e.g. Cloudflare) needs for TLS, DDoS, bot basicsKeep the door up

We do not load third-party advertising pixels or analytics trackers (no Google Analytics, Meta Pixel, etc.).

2.3 Categories of personal information (plain + CCPA-style labels)

For attorney readability, the same facts in common CCPA category language (collection only as described above):

CCPA-style categoryDo we collect?Examples here
IdentifiersYesEmail (optional/notify/comment), IP, invite/session-related ids
Customer records / commercial infoYesJob class, price, Stripe payment references, ledger events
Internet / electronic activityYes (limited)Server logs of pages/API hits on kbmill.com
Professional / employmentGenerally noUnless you put it in uploaded docs or comments
Contents of uploaded documentsYes (when you mill)Your files — processed then purged per §5
Payment card number (full PAN)No on millStripe Checkout only
Precise geolocation / biometrics / etc.No (not sought)
Inferences for advertising profilesNo

Sensitive personal information is not sought. If you upload documents that contain sensitive data, you choose to submit them under the mill processing model in §5.

2.4 What we intentionally do not collect for marketing

3. Cookies and similar technologies

We useWe do not use
Strictly necessary / security / session as required to operate the site and plantAdvertising cookies
Payment flow on Stripe’s hosted Checkout (Stripe’s cookies on Stripe’s domain)Analytics suites that profile you for marketing
CDN/security cookies our HTTPS front may set“Accept tracking to use the mill” dark patterns

Plain claim you can put on FAQ too:

We don’t use advertising or analytics tracking cookies.

If that ever changes, we will update this policy before turning trackers on — not after.

3.1 Do Not Track (CalOPPA disclosure)

Some browsers send a Do Not Track (DNT) signal. There is no single industry standard for DNT response.

Our practice: We do not use advertising or cross-site analytics tracking cookies. We do not alter mill processing based on DNT. Essential logs and security controls may still operate. If we ever add advertising/analytics tracking, we will update this section and state whether we honor DNT and/or Global Privacy Control (GPC) for sale/share opt-out.

3.2 Third parties and cross-site collection

Advertising/analytics third parties on kbmill.com: None (no ad pixels / no Google Analytics).

Service providers that may set their own cookies or receive data when you use features:

PartyWhenCross-site advertising tracking by them on our door?
CloudflareVisiting kbmill.comNot used by us for ads; security/CDN/tunnel function
StripeCheckout / payStripe’s pages and processors — see Stripe’s policy

Named processor detail (roles, what they see, location honesty): §7 Sharing & named processors.

Other sites we link to (GitHub, Hugging Face, etc.) are outside this policy; they may set their own cookies when you leave kbmill.com.

4. How we use information

We do not use your uploaded documents to train a public foundation model for the open internet, and we do not host your corpus as an ongoing SaaS chat product.

While a job is alive, extracted text / OCR / embeddings exist as manufacture artifacts under that job’s directories, then fall under the purge clock.

5. Uploads, processing, purge (the mill contract)

This is the heart of KBMill privacy:

  1. You upload a bounded pile (caps apply — see FAQ).
  2. We process on the operator-controlled plant (see § Processors & location) to produce a ZIP and related job artifacts.
  3. Ready: you download within 72 hours; then we purge that job’s plant materials on the schedule below.
  4. Failed jobs: cleared sooner (24 hours).
  5. After a successful build, upload copies in the job inbox are cleared early; the manufactured brick / ZIP remain until the Ready purge window ends.
  6. You keep the ZIP you downloaded. Purge removes our copies under the plant work root — not the file on your machine.
  7. This public mill is not an air-gap / ITAR path; uploads transit our HTTPS front door (Cloudflare) and sit on plant disk until purge. Regulated corpora that cannot use that path need an on-prem / isolated conversation — not this hopper.

Optional notify email: used to tell you the job is Ready / support retrieve — not for marketing blasts. Today, Ready notify may be queued on the plant for later delivery; it is not a reason to keep your document corpus.

5.1 What “purge” deletes (and what it does not)

When purge runs (daemon on the plant, typically every ~15 minutes), for an expired job we delete under our hopper work root:

We do not intentionally keep customer-job backups of hopper work for restore. There is no scheduled “backup the customer pile forever” product feature on this pilot door.

Purge does not claim:

If you need deletion certificates, attested wipe, or contractual purge SLAs, that is signed-path territory — not this web policy alone.

5.2 Who can see uploaded content (human access)

6. Payments (Stripe)

7. Sharing & named processors

We share information only as needed to run the service. For this public door, the processors / recipients we actually rely on are:

PartyRoleWhat they typically seeWhere (honest)
Cloudflare, Inc. DNS, CDN, TLS termination, tunnel to the plant, bot/DDoS basics Connection metadata (IP, TLS, request path); HTTP traffic as it passes the edge. Not used by us as an ad network. Cloudflare’s global edge network (their locations / policies apply). See Cloudflare’s privacy/security docs.
Stripe, Inc. Checkout, authorize / capture / void, tax tools when configured, Stripe fraud tools Payment data on Stripe’s pages; we receive status / amounts / payment references — not full PAN storage on the mill Stripe’s processors / regions per Stripe. stripe.com/privacy
Operator plant (Carroll Miller / KBMill) Manufacture, job store, purge, ledger files on disk Your uploads and derivatives while the job exists; job metadata; optional notify email if you provide one United States — operator-controlled machine(s) reached via the Cloudflare tunnel. Not a multi-region SaaS farm. Not air-gapped.
Email / webhook notify (only if wired) Optional Ready / pickup notice Your email address + minimal job-ready signal — not the document corpus as the notify payload If/when SMTP or a notify webhook is enabled, that provider’s terms apply. The mill can run without sending mail.
CPA / attorney Accounting, tax, legal as needed Business records (ledger, invoices, disputes) — not a standing browse of uploads As engaged by the operator
Law enforcement / legal process When required by law or to protect rights/safety Whatever a lawful demand covers

We do not currently list a separate third-party “document processing SaaS” that receives your PDFs for the default public mill path. If we add remote manufacture workers (e.g. rented GPU plant instances) that receive job materials, we will name them here before that path is used for customer jobs on this door.

We do not sell personal information and do not share it for cross-context behavioral advertising.

Public proof shelf (GitHub brick library / HF evals) contains sample packages we choose to publish — not your private mill jobs.

We do not publish a full set of signed DPAs with every edge provider on this web page. Contractual data-protection schedules for enterprise diligence are part of the signed path.

8. Retention

DataRetention
Job uploads & plant derivatives / export ZIPUntil purge (Ready 72h / fail 24h) unless law requires a longer hold
Intentional customer-job backupsNone as a product feature on this pilot door
Payment / ledger recordsAs needed for accounting, tax, disputes (business records)
Optional notify email + notify queue entriesAs needed to deliver Ready notice / operate retrieve; not a document archive
Comments / operator emailAs needed to operate and improve; you may ask us to delete where applicable
Server / plant operational logsShort operational window unless investigating abuse or a security incident
CDN / Stripe provider-side logsPer those providers’ retention — outside our purge daemon

9. Security (honest, not theater)

What we actually do on this pilot door:

What we do not claim here:

No security is perfect; residual risk remains. Report issues to [email protected] (put “Security” in the subject).

9a. Security incidents / breach notification

If we become aware of unauthorized access to your mill uploads or job materials on this plant, we will notify affected customers without unreasonable delay, using the email we have on file (notify email, comment email, or payment-related contact where available) and/or a notice on kbmill.com when email is missing.

That is an operator commitment for this pilot — not a contractual SLA with liquidated damages, and not a substitute for statutory notice duties that may apply in your jurisdiction. Enterprise breach-notification timelines belong in a signed agreement.

9b. Sensitive / confidential documents

Do not treat this privacy policy as enough for trade secrets, personal/medical/financial records, regulated corpora, or documents you are contractually forbidden to send to a small pilot mill.

For that class of material: use an isolated / on-box path after talking to the operator, or keep processing on machines you control (public brick tools / your own stack). Email [email protected] for a signed discussion — DPA / confidentiality / security schedule / liability — before upload.

Workspace copy says the same thing in shorter form: sensitive piles do not belong on a remote showroom hopper.

10. Your choices and requests

How to review or request changes (CalOPPA-style process)

Email [email protected] with “Privacy request” in the subject. You may ask us to:

We will respond within a reasonable time. Job uploads already scheduled for purge may already be gone.

California note (plain language)

CalOPPA: Commercial sites that collect personal information from California residents generally must post a privacy policy meeting CalOPPA’s content rules — this document is written to cover those disclosures.

CCPA/CPRA: Applies to “businesses” that meet statutory thresholds (approx. as publicly summarized: ≳$26.6M revenue, or ≥100k CA consumers’ PI bought/sold/shared, or ≥50% revenue from selling/sharing CA PI — confirm current figures with counsel). Early pilot operations may sit below those thresholds. We still describe practices honestly.

Descriptive only — counsel should confirm coverage as you grow.

11. Children

The mill is aimed at adults and businesses. We do not knowingly target children under 13 (or under 16 where relevant). If you believe a child provided data, contact us to delete it.

12. International / EU visitors

kbmill.com is operated for a US-centered mill door. If you visit from elsewhere, the same processing model applies. We do not currently run an EU-targeted ad or analytics stack.

This section is not a GDPR compliance commitment and not an offer of EU-specific controller/processor terms, SCCs, or an EU representative. If we formally offer services into the EEA/UK as a product path, we will update this policy and any required notices before claiming that coverage.

13. Changes

We may update this policy. The Effective / last updated date at the top will change.

How we notify of material changes (CalOPPA): We will post the revised policy at https://kbmill.com/privacy with a new date. For material changes that expand tracking or sale/share practices, we will update this page before those practices go live. Continued use of the mill after the new effective date constitutes notice of the updated policy; for significant changes we may also note the update on the mill FAQ or homepage.

14. Contact

Carroll Miller, d/b/a KBMill

Email (privacy, security, signed-path requests): [email protected]

Web: https://kbmill.com

No public mailing address posted; email is the contact channel. Entity / address on paper is available through a signed conversation when diligence requires it.