Governance
Privacy Policy
Describes how the public mill door handles information. Not legal advice. No SOC 2 / ISO 27001 claim — we document practices honestly instead of inventing certifications. Companion: /terms · one-pager /security (hosting, purge matrix, subprocessors, logs).
Fit for purpose (read this first)
For a small pilot and ordinary, non-sensitive documents, this policy is meant to be reasonably transparent. It is not strong enough by itself as the sole protection for trade secrets, personal records, regulated data, or documents under contractual confidentiality.
This page is not a data-processing agreement (DPA), NDA, BAA, or customer-specific security schedule. For sensitive material, ask for a signed path covering legal entity details you need, subprocessors, processing location, encryption expectations, access logging, backups, breach notification SLAs, deletion verification, and liability — [email protected] — before you upload. See also § Sensitive / confidential documents.
Stance (lead with this)
KBMill is a manufacturing plant for knowledge packages, not an ad network and not a “trade your privacy for a free chat” product.
- We do not use advertising or analytics tracking cookies.
- We do not sell your personal information.
- We do not build a marketing profile from your browsing to sell ads.
- Documents you upload are processed to produce a portable package you keep, then purged on the schedule below — not kept as a hosted knowledge base.
Essential/functional cookies or similar storage may be used only as needed to run the site, security (e.g. CDN), and payments (e.g. Stripe Checkout on Stripe’s pages).
Legal identity on this door: Carroll Miller, doing business as KBMill. No separate LLC / corporation name is posted on this policy. Contact is by email ([email protected]); no public mailing address is published. If your diligence requires a signed entity block or mailing address on paper, that is part of the signed path above — not this web policy alone.
1. Who this policy covers
This policy describes how we handle information when you:
- Visit kbmill.com (mill, Notes, FAQ, Terms, etc.)
- Use the hopper (upload, classify, Go, retrieve, download)
- Pay via Stripe
- Optional: leave a comment, or give an email for Ready / pickup notify
- Contact us at [email protected]
It does not cover third-party sites we link to (e.g. public brick library on GitHub, Hugging Face demos) — those have their own policies.
2. Information we collect
2.1 You provide
| Category | Examples | Why |
|---|---|---|
| Account / access | Invite password (if gated); coupon codes | Operate the pilot door |
| Job inputs | Files you upload; optional job label | Manufacture the brick |
| Optional notify | Email address if you opt in for Ready/pickup notice | Tell you the job is ready / help you return |
| Comments | Name, email, message (if you use the comment form) | Operator feedback — lands on this plant |
| Payment | Handled by Stripe (card details on Stripe’s Checkout — we do not store full card numbers) | Pay-on-success holds / capture |
| Email correspondence | Messages you send to [email protected] | Support and business |
2.2 Collected automatically (minimal)
| Category | Examples | Why |
|---|---|---|
| Technical logs | IP address, user agent, timestamps, request paths, error logs | Security, abuse prevention, debugging the plant |
| Job/plant records | Job id, class/price, status chips, ledger events (authorize/capture/void), pickup-code hash (not the raw code at rest after issue) | Run pay-on-success and retrieve |
| CDN / security | Whatever our HTTPS front (e.g. Cloudflare) needs for TLS, DDoS, bot basics | Keep the door up |
We do not load third-party advertising pixels or analytics trackers (no Google Analytics, Meta Pixel, etc.).
2.3 Categories of personal information (plain + CCPA-style labels)
For attorney readability, the same facts in common CCPA category language (collection only as described above):
| CCPA-style category | Do we collect? | Examples here |
|---|---|---|
| Identifiers | Yes | Email (optional/notify/comment), IP, invite/session-related ids |
| Customer records / commercial info | Yes | Job class, price, Stripe payment references, ledger events |
| Internet / electronic activity | Yes (limited) | Server logs of pages/API hits on kbmill.com |
| Professional / employment | Generally no | Unless you put it in uploaded docs or comments |
| Contents of uploaded documents | Yes (when you mill) | Your files — processed then purged per §5 |
| Payment card number (full PAN) | No on mill | Stripe Checkout only |
| Precise geolocation / biometrics / etc. | No (not sought) | — |
| Inferences for advertising profiles | No | — |
Sensitive personal information is not sought. If you upload documents that contain sensitive data, you choose to submit them under the mill processing model in §5.
2.4 What we intentionally do not collect for marketing
- Behavioral advertising profiles
- Cross-site tracking for ads
- Sale of visitor lists
3. Cookies and similar technologies
| We use | We do not use |
|---|---|
| Strictly necessary / security / session as required to operate the site and plant | Advertising cookies |
| Payment flow on Stripe’s hosted Checkout (Stripe’s cookies on Stripe’s domain) | Analytics suites that profile you for marketing |
| CDN/security cookies our HTTPS front may set | “Accept tracking to use the mill” dark patterns |
Plain claim you can put on FAQ too:
We don’t use advertising or analytics tracking cookies.
If that ever changes, we will update this policy before turning trackers on — not after.
3.1 Do Not Track (CalOPPA disclosure)
Some browsers send a Do Not Track (DNT) signal. There is no single industry standard for DNT response.
Our practice: We do not use advertising or cross-site analytics tracking cookies. We do not alter mill processing based on DNT. Essential logs and security controls may still operate. If we ever add advertising/analytics tracking, we will update this section and state whether we honor DNT and/or Global Privacy Control (GPC) for sale/share opt-out.
3.2 Third parties and cross-site collection
Advertising/analytics third parties on kbmill.com: None (no ad pixels / no Google Analytics).
Service providers that may set their own cookies or receive data when you use features:
| Party | When | Cross-site advertising tracking by them on our door? |
|---|---|---|
| Cloudflare | Visiting kbmill.com | Not used by us for ads; security/CDN/tunnel function |
| Stripe | Checkout / pay | Stripe’s pages and processors — see Stripe’s policy |
Named processor detail (roles, what they see, location honesty): §7 Sharing & named processors.
Other sites we link to (GitHub, Hugging Face, etc.) are outside this policy; they may set their own cookies when you leave kbmill.com.
4. How we use information
- Manufacture a residual-honest portable knowledge package from files you submit
- Authorize / capture / void payment under pay-on-success (hold at Go; capture if we produce; void on fail)
- Operate retrieve (pickup code) so you can return after long jobs
- Security & abuse prevention (rate limits, refuse illegal/abusive material, zip-bomb guards)
- Improve the plant using operational signals — job class/price, status, fail class / fail reason, timing, ledger events, and filenames as supplied — not by selling your documents and not by retaining full document text, OCR output, chunk text, or embeddings after purge as a debug corpus (see /security § Logs)
- Respond to comments and email
- Legal / accounting records required for a real business (Stripe ledger, tax as applicable)
We do not use your uploaded documents to train a public foundation model for the open internet, and we do not host your corpus as an ongoing SaaS chat product.
While a job is alive, extracted text / OCR / embeddings exist as manufacture artifacts under that job’s directories, then fall under the purge clock.
5. Uploads, processing, purge (the mill contract)
This is the heart of KBMill privacy:
- You upload a bounded pile (caps apply — see FAQ).
- We process on the operator-controlled plant (see § Processors & location) to produce a ZIP and related job artifacts.
- Ready: you download within 72 hours; then we purge that job’s plant materials on the schedule below.
- Failed jobs: cleared sooner (24 hours).
- After a successful build, upload copies in the job inbox are cleared early; the manufactured brick / ZIP remain until the Ready purge window ends.
- You keep the ZIP you downloaded. Purge removes our copies under the plant work root — not the file on your machine.
- This public mill is not an air-gap / ITAR path; uploads transit our HTTPS front door (Cloudflare) and sit on plant disk until purge. Regulated corpora that cannot use that path need an on-prem / isolated conversation — not this hopper.
Optional notify email: used to tell you the job is Ready / support retrieve — not for marketing blasts. Today, Ready notify may be queued on the plant for later delivery; it is not a reason to keep your document corpus.
5.1 What “purge” deletes (and what it does not)
When purge runs (daemon on the plant, typically every ~15 minutes), for an expired job we delete under our hopper work root:
- The job directory (uploads / working files for that job)
- The manufactured brick / knowledge package directory for that job (when present under the plant kbs root)
- The export ZIP file for that job (when still on disk)
- Pickup-code registration tied to that job (hash index entry)
We do not intentionally keep customer-job backups of hopper work for restore. There is no scheduled “backup the customer pile forever” product feature on this pilot door.
Purge does not claim:
- Cryptographic erasure of every sector, SSD wear-leveling remnant, OS swap, core dump, or crash artifact
- Deletion of Cloudflare edge/security logs that may retain IP / request metadata under their retention
- Deletion of Stripe payment records (those stay with Stripe / our ledger needs)
- Deletion of short operational server logs (may include IP, path, error text — not your full PDF as a matter of design, but logs are not a document archive)
- That a forensic adversary with physical disk access after delete cannot recover fragments — residual media risk remains on any real computer
If you need deletion certificates, attested wipe, or contractual purge SLAs, that is signed-path territory — not this web policy alone.
5.2 Who can see uploaded content (human access)
- Sole operator: Carroll Miller operates this plant. The operator can access job materials on plant disk while they exist (ops, debugging a failed job, abuse / malware review, pay disputes). There is no large employee “content review team.”
- No routine contractor reading of your docs: We do not farm customer mill uploads out to a crowd of outside reviewers. If that ever changed, we would update this policy before doing so.
- Automated manufacture: Processing is software-driven. Human eyes are not required for every successful job; humans may open materials when the plant needs an operator.
- Professionals: CPA / attorney may see business records (ledger, invoices, disputes) as needed — not a standing right to browse every upload.
- You: Anyone with your job retrieve / pickup path can download while the package is Ready — treat those codes and URLs as secrets.
6. Payments (Stripe)
- Card entry and payment processing: Stripe, Inc.
- We receive payment status, amounts, job metadata we attach (e.g. job id / class) — not full PAN storage on the mill.
- Stripe’s privacy policy applies to data Stripe processes: https://stripe.com/privacy
- Sales tax may be calculated/collected via Stripe Tax where configured; remittance posture is ours with our CPA.
7. Sharing & named processors
We share information only as needed to run the service. For this public door, the processors / recipients we actually rely on are:
| Party | Role | What they typically see | Where (honest) |
|---|---|---|---|
| Cloudflare, Inc. | DNS, CDN, TLS termination, tunnel to the plant, bot/DDoS basics | Connection metadata (IP, TLS, request path); HTTP traffic as it passes the edge. Not used by us as an ad network. | Cloudflare’s global edge network (their locations / policies apply). See Cloudflare’s privacy/security docs. |
| Stripe, Inc. | Checkout, authorize / capture / void, tax tools when configured, Stripe fraud tools | Payment data on Stripe’s pages; we receive status / amounts / payment references — not full PAN storage on the mill | Stripe’s processors / regions per Stripe. stripe.com/privacy |
| Operator plant (Carroll Miller / KBMill) | Manufacture, job store, purge, ledger files on disk | Your uploads and derivatives while the job exists; job metadata; optional notify email if you provide one | United States — operator-controlled machine(s) reached via the Cloudflare tunnel. Not a multi-region SaaS farm. Not air-gapped. |
| Email / webhook notify (only if wired) | Optional Ready / pickup notice | Your email address + minimal job-ready signal — not the document corpus as the notify payload | If/when SMTP or a notify webhook is enabled, that provider’s terms apply. The mill can run without sending mail. |
| CPA / attorney | Accounting, tax, legal as needed | Business records (ledger, invoices, disputes) — not a standing browse of uploads | As engaged by the operator |
| Law enforcement / legal process | When required by law or to protect rights/safety | Whatever a lawful demand covers | — |
We do not currently list a separate third-party “document processing SaaS” that receives your PDFs for the default public mill path. If we add remote manufacture workers (e.g. rented GPU plant instances) that receive job materials, we will name them here before that path is used for customer jobs on this door.
We do not sell personal information and do not share it for cross-context behavioral advertising.
Public proof shelf (GitHub brick library / HF evals) contains sample packages we choose to publish — not your private mill jobs.
We do not publish a full set of signed DPAs with every edge provider on this web page. Contractual data-protection schedules for enterprise diligence are part of the signed path.
8. Retention
| Data | Retention |
|---|---|
| Job uploads & plant derivatives / export ZIP | Until purge (Ready 72h / fail 24h) unless law requires a longer hold |
| Intentional customer-job backups | None as a product feature on this pilot door |
| Payment / ledger records | As needed for accounting, tax, disputes (business records) |
| Optional notify email + notify queue entries | As needed to deliver Ready notice / operate retrieve; not a document archive |
| Comments / operator email | As needed to operate and improve; you may ask us to delete where applicable |
| Server / plant operational logs | Short operational window unless investigating abuse or a security incident |
| CDN / Stripe provider-side logs | Per those providers’ retention — outside our purge daemon |
9. Security (honest, not theater)
What we actually do on this pilot door:
- HTTPS at the public door (TLS terminated at Cloudflare; tunnel to the plant)
- Plant not exposed as an open WAN mill port — reached through the tunnel configuration
- Per-job working directories under the hopper work root; path guards on purge/delete
- Caps and refuse-before-run (file count / size / type) — oversized or unsupported drops are not processed
- Rate limits on Go / classify / comment / retrieve; zip-bomb / hostile-archive guards in the plant path
- Offline-oriented manufacture posture on the plant (local cache / no mandatory hub phone-home mid-job for manufacture — see Notes / FAQ). Online wraps the door; the mill is not designed as “always-online SaaS chat.”
- Optional stronger isolation (e.g. container sandbox) may be used when configured; it is not marketed as a certified enclave
- Operator password can protect ledger / purge operator surfaces; customer mill actions use the public door gates (invite / coupon / card / rate limits as configured)
What we do not claim here:
- SOC 2 / ISO 27001 / FedRAMP / HITRUST or similar
- Customer-managed encryption keys, or a published encryption-at-rest standard beyond “files live on the operator plant disk”
- 24/7 SOC, formal vulnerability-scan SLA, or penetration-test certificates on a schedule
- That Cloudflare + single-operator plant = enterprise confidential computing
No security is perfect; residual risk remains. Report issues to [email protected] (put “Security” in the subject).
9a. Security incidents / breach notification
If we become aware of unauthorized access to your mill uploads or job materials on this plant, we will notify affected customers without unreasonable delay, using the email we have on file (notify email, comment email, or payment-related contact where available) and/or a notice on kbmill.com when email is missing.
That is an operator commitment for this pilot — not a contractual SLA with liquidated damages, and not a substitute for statutory notice duties that may apply in your jurisdiction. Enterprise breach-notification timelines belong in a signed agreement.
9b. Sensitive / confidential documents
Do not treat this privacy policy as enough for trade secrets, personal/medical/financial records, regulated corpora, or documents you are contractually forbidden to send to a small pilot mill.
For that class of material: use an isolated / on-box path after talking to the operator, or keep processing on machines you control (public brick tools / your own stack). Email [email protected] for a signed discussion — DPA / confidentiality / security schedule / liability — before upload.
Workspace copy says the same thing in shorter form: sensitive piles do not belong on a remote showroom hopper.
10. Your choices and requests
- Don’t upload what you can’t entrust to this processing model
- Skip optional notify email
- Use coupon / invite paths as offered during pilot
- Download promptly; purge is real
- Browser controls for cookies; rejecting non-essential tracking is easy here because we don’t run an ad stack
How to review or request changes (CalOPPA-style process)
Email [email protected] with “Privacy request” in the subject. You may ask us to:
- Tell you what personal information we still hold about you (e.g. comment email, notify email, non-purged business records)
- Correct inaccurate contact information
- Delete personal information we still hold, subject to legal/accounting retention (Stripe/ledger) and subject to purge already having removed job files on schedule
We will respond within a reasonable time. Job uploads already scheduled for purge may already be gone.
California note (plain language)
CalOPPA: Commercial sites that collect personal information from California residents generally must post a privacy policy meeting CalOPPA’s content rules — this document is written to cover those disclosures.
CCPA/CPRA: Applies to “businesses” that meet statutory thresholds (approx. as publicly summarized: ≳$26.6M revenue, or ≥100k CA consumers’ PI bought/sold/shared, or ≥50% revenue from selling/sharing CA PI — confirm current figures with counsel). Early pilot operations may sit below those thresholds. We still describe practices honestly.
- We do not sell personal information and do not share it for cross-context behavioral advertising.
- If/when we are a CCPA “business,” we will add any required Do Not Sell or Share / Your Privacy Choices link, honor GPC as required, and support Know / Delete / Correct (and other applicable rights) through at least the methods the law requires (email is one method; we may add a webform).
Descriptive only — counsel should confirm coverage as you grow.
11. Children
The mill is aimed at adults and businesses. We do not knowingly target children under 13 (or under 16 where relevant). If you believe a child provided data, contact us to delete it.
12. International / EU visitors
kbmill.com is operated for a US-centered mill door. If you visit from elsewhere, the same processing model applies. We do not currently run an EU-targeted ad or analytics stack.
This section is not a GDPR compliance commitment and not an offer of EU-specific controller/processor terms, SCCs, or an EU representative. If we formally offer services into the EEA/UK as a product path, we will update this policy and any required notices before claiming that coverage.
13. Changes
We may update this policy. The Effective / last updated date at the top will change.
How we notify of material changes (CalOPPA): We will post the revised policy at https://kbmill.com/privacy with a new date. For material changes that expand tracking or sale/share practices, we will update this page before those practices go live. Continued use of the mill after the new effective date constitutes notice of the updated policy; for significant changes we may also note the update on the mill FAQ or homepage.
14. Contact
Carroll Miller, d/b/a KBMill
Email (privacy, security, signed-path requests): [email protected]
Web: https://kbmill.com
No public mailing address posted; email is the contact channel. Entity / address on paper is available through a signed conversation when diligence requires it.