skip to content
// legal

Privacy policy

Effective September 16, 2026

This Privacy Policy explains how Midkernel, Inc., a Delaware corporation ("Midkernel," "we," "us") collects, uses, and shares information when you use midkernel.com, the Midkernel product app, Midkernel Scan, Midkernel Threat Intel, Midkernel plugins or marketplace listings, and related communications (together, the "Service").

Questions: hello@midkernel.com. Security: security@midkernel.com.

What we collect

Account and contact data

Name, email, organization name, authentication identifiers (for example via GitHub or other sign-in), and billing-related contact details when you create an account, join a workspace, buy credits, or contact us.

Payment data

Credit packs are purchased only with native USDC on Base. Midkernel assigns an organization deposit address and verifies transfers to that address. We process the deposit address, transfer amount, transaction hash, matched credit pack, verification status and related credit-ledger records. We do not collect payment-card numbers or your wallet's private keys.

Transfers are recorded on the public Base blockchain. Blockchain records are outside Midkernel's control and cannot be deleted through a Midkernel data-deletion request. We use blockchain data access services to verify deposits.

Repository and Scan data (Customer Content)

If you connect GitHub (or another supported source) and run Scan, we process: repository metadata you authorize; repository contents cloned into a single-use sandbox for the duration of a run; workflow inputs, profile selection, model selection (including overrides), and sandbox image identifiers; and the report, artifacts, and run log (which may include excerpts of files the workflow read).

The Midkernel GitHub App requests read access to code and metadata for repositories you select. It does not request write access. Organization-wide access occurs only if you choose it. We do not claim pull-request comment or other write permissions as part of the Service today.

Threat Intel usage

Account/workspace identifiers and usage needed to show ranked threat classes derived from public sources. We do not claim to originate every item.

Product telemetry

Operational logs needed to run the Service: feature usage, errors, performance, IP address, device/browser type, and approximate location derived from IP where needed for security and abuse prevention.

Website analytics and cookies

The marketing site is designed to set no first-party cookies of its own. We may use cookieless analytics (for example Vercel Web Analytics). Third-party embeds (if any) may set their own cookies.

Communications

Email, scheduling (for example Cal.com), and newsletter content and metadata when you contact or subscribe.

Support access to runs

Midkernel staff open a customer's run only for a support request you filed; that access is recorded.

Why we collect it

  • Provide the Service — authenticate you, run scans, generate reports and logs, show Threat Intel, operate plugins, and maintain workspaces.
  • Bill and account for credits — verify native USDC deposits on Base, grant the corresponding pack credits, deduct credits for runs (low = 10, balanced = 25, max = 50 unless in-product pricing differs), and prevent fraud.
  • Secure and operate infrastructure — monitor abuse, debug failures, enforce Terms.
  • Communicate — support, security, and transactional notices; marketing email only with appropriate consent or as otherwise permitted by law.
  • Improve and develop the Service — For Scan runs paid for with purchased credits, including credits bought through verified native USDC deposits on Base, you grant Midkernel permission under the Terms to use Customer Content and Service data (including reports, logs, artifacts, and metadata) to improve and develop the Service (including routing, ranking, evaluation, workflows, and related models or systems). Midkernel does not currently operate a dedicated training pipeline; this is a permitted purpose / license for current operations and near- to mid-term roadmap use. Admin, internal testing, or other non-paid grant runs are not treated as purchased for this purpose unless Midkernel states otherwise in-product. Midkernel aims to minimize how long it retains raw Scan artifacts in Midkernel-operated systems (see Retention). Model traffic during a run uses OpenRouter commercial APIs; Midkernel's policy is not to opt its OpenRouter usage into provider training programmes, which does not control downstream providers' independent practices.
  • Comply with law.

Retention

Unless a longer period is required by law or agreed in a signed customer contract:

  • Scan reports, logs, and artifacts in Midkernel-operated systems are retained for 90 days by default and are deleted on request or when you delete the project, subject to residual backups that age out on a short cycle. Midkernel designs for low retention of raw Scan artifacts for platform and improvement purposes.
  • Derived or aggregated Service-improvement data (when created under the Terms) may be retained longer than raw artifacts.
  • Third parties in the Scan path (including GitHub, cloud providers such as AWS, OpenRouter, and model providers) may retain data under their own policies for periods Midkernel does not control. Midkernel is not responsible for those third-party retention practices.
  • Account and billing records are retained as needed for accounting, tax, dispute, and legal obligations.
  • Support correspondence is retained as needed to resolve your request and for business records.

Subprocessors and sharing

We share information with vendors who help us run the Service. Categories include: sandbox/compute for Scan runs (including cloud providers such as AWS); hosting (Vercel); DNS/edge (Cloudflare); managed Postgres; OpenRouter and underlying model providers; email (Resend); blockchain data access for native USDC payment verification on Base; analytics (Vercel Web Analytics); scheduling (Cal.com) when you book with us.

When you connect a repository for white-box security testing / Scan, Customer Content may be processed by Midkernel and by those third parties as needed to run the Service. Their privacy and retention terms apply to their processing.

We may also share information with your workspace members per roles you configure; if you direct us to; for legal reasons; or in a merger, acquisition, or asset sale with continuing confidentiality protections.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising as commonly defined under U.S. state privacy laws.

Our Data Processing Addendum (DPA) lives at /legal/dpa.

International transfers

Midkernel, Inc. is a Delaware corporation with a New York footprint and may process data in the United States and other countries where our vendors operate. Where required, we use appropriate transfer mechanisms for international transfers of personal data.

Analytics and cookies

midkernel.com aims to set no first-party cookies of its own and may use cookieless analytics. Essential cookies or local storage may be required for the authenticated product app (session security). Blocking essential storage may break login.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal data, to object to or restrict certain processing, and to appeal a denial. Email hello@midkernel.com. We may verify your request. If we process personal data as a processor for your organization, we may refer certain requests to your organization as controller.

California / U.S. state notices: We collect the categories under What we collect for the purposes under Why we collect it. We do not sell personal information. Requests: hello@midkernel.com.

Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children under 16.

Security

We use measures appropriate to the Service, including isolated single-use sandboxes for Scan runs, access controls, and recorded staff access to customer runs for support. We do not claim SOC 2 or ISO 27001 certification at this time. Product controls: https://midkernel.com/trust — Trust and this Policy should stay aligned when purposes change.

Changes

We may update this Privacy Policy. For material changes, we will provide reasonable notice.

Contact

Midkernel, Inc. — New York, NY

Email: hello@midkernel.com

Security: security@midkernel.com