Makojima is the business that operates makojima.com and the account, learning, and Agents features made available there (the "Service"). In this Privacy Policy, "Makojima," "we," "our," and "us" refer to that business. This policy explains what the public Service handles, why it is handled, and the choices available to you.
This policy applies to the public Production Service. Non-production tests and internal operational tools are not public product features. If a Production feature is unavailable or has not been activated, this policy does not promise that it is available.
Information we collect
Account and profile information
When you create an account, we receive the name and email address you submit. Authentication is managed by our authentication provider, which stores the credentials and session information needed to sign you in. Makojima does not store your password in readable form. We may also store a display name and account identifiers needed to connect your account to your own records.
Authentication and security information
We process information needed to verify email addresses, reset passwords, manage sessions, enroll and challenge multi-factor authentication, issue one-time recovery codes, and review account-recovery requests. Security records may include pseudonymous rate-limit identifiers, event type, decision, timing, coarse request context, MFA factor metadata, recovery-case references, and audit history. Recovery phrases and one-time codes are not stored in readable form.
Security analysis generally uses keyed digests instead of raw identifiers. For denied requests and important authentication or MFA events, Makojima may also retain the raw IP address, city, user agent, a validated account UUID when available, and a sanitized path for 30 days. Ordinary successful browsing and successful non-security API calls are not placed in that raw forensic log. Query strings and fragments are discarded, and the sanitizer removes control characters, email addresses, UUIDs, and long numeric, hexadecimal, base64-like, or token-like path segments. Passwords, cookies, session and bearer tokens, request bodies, MFA and recovery codes, chat and file contents, provider error text, and precise latitude or longitude are never accepted by this forensic record.
Public browsing and analytics
When you visit public pages, ordinary infrastructure logs may process request information such as an IP address, user agent, requested path, time, response status, and coarse network or geographic context. We use Vercel Analytics and Speed Insights for cookieless traffic and performance measurement. The public lesson feed may store released catalog metadata and a last-visited time in your browser so it can paint quickly and show what is new. That public cache does not contain account identity or private progress.
My Feed also sends two bounded custom events through Vercel Analytics. Feed Rendered records the selected Shorts insertion point, the counts of long videos, Shorts, and all displayed cards, a length-limited ordering of public card keys, and whether that order was shortened to stay within the event limit. Feed Card Clicked records the activated public card key, its displayed position, the Shorts insertion point, its long-video or Short format, and its destination platform. We use these measurements to understand which public sequence was presented, compare content placement and format engagement, and improve the feed layout and publishing plan.
Makojima's event properties do not include search text, video titles, destination URLs, raw database identifiers, account or session identifiers, email addresses, IP addresses, cookies, or local-storage values. The events use Vercel's cookieless analytics pipeline, which may process ordinary request context and a short-lived request-derived visitor hash to produce anonymous aggregate statistics. The hash is not a Makojima account identifier, and Makojima does not use these events to reconstruct a browsing session across websites or build an advertising profile. Browser privacy tools or content blockers may prevent future analytics events from being sent.
Optional error monitoring may receive scrubbed technical diagnostics if it is configured. Its Production configuration removes user identity, request bodies, cookies, query strings, and common credential fields, and does not enable session replay, default personal-data collection, or tracing.
Learning activity and communications consent
The Production database can store course enrollment, lesson progress, answer attempts, scores, timestamps, and related learning records under your account. These records support the learning experience and account-level progress features that are actually released.
Settings also records whether you requested optional personalized communications and the policy version associated with that choice. A request is not the same as activation. Optional transport to Makojima's separate Mail system is disabled unless the Production-only service gate is enabled and the consent record is active and verified. If enabled, the interface sends only the approved account and learning projection through a signed, encrypted, server-to-server channel. Raw answers are encrypted for Mail before transport and are not sent to the email delivery provider.
Agents conversations and files
When you use Agents, we process the prompt you submit, the selected Agent and model, conversation history needed for context, generated responses, timestamps, usage records, and operational status. If you upload a supported file, we process that content to provide the requested feature. Conversations, messages, and attachment records are associated with your account and protected by server authorization and database row-level security.
Voice input and read-aloud synthesis run in your browser. Microphone audio is decoded and transcribed on your device, is not uploaded to Makojima or a speech provider, and is discarded after the attempt. The transcript remains an editable draft and reaches Makojima only if you press Send. Read-aloud text is also synthesized on the device. Your browser may download static model and runtime files from the listed content-delivery hosts; those hosts can receive ordinary download metadata such as your IP address, browser information, requested asset, and time, but Makojima does not include the recording, transcript, chat text, account identifier, or credentials in those requests.
Agents may not be able to answer when the model gateway is unavailable or not configured. We do not represent generated output as professional accounting, legal, tax, investment, medical, or other regulated advice.
Models, community releases, and API use
When you create or fine-tune a model, we may process uploaded datasets, training records, safe-format model artifacts, artifact hashes, base-model and license information, qualification and safety results, reviews, endpoint settings, hashed API-key fingerprints, and token usage. Raw API keys are shown once and are not stored. We scan submitted materials for malware, unsafe formats, personal information, secrets, and license conflicts. Uploaded code and unsafe serialized model formats are not executed as part of community publication.
Publishing makes the creator name, model description, attribution, license, fixed release identifier, base price, creator percentage, and safety or qualification status public. A person who copies a community release receives a hosted licensed endpoint for that fixed release and accepted price. Copying does not transfer model weights, ownership, redistribution rights, or automatic fine-tuning rights.
Creator verification, earnings, and payouts
Creator records can include country, adult-verification status, tax status, sanctions status, creator-agreement acceptance, provider reference, review timestamps, creator surcharge versions, usage settlements, earnings, withholding, provider fees, exchange rates, payout status, and masked payout destinations. Makojima stores provider identifiers and approval states, not readable government IDs, tax numbers, identity documents, payment cards, or bank-account numbers. Trolley, Stripe, and PayPal hold those sensitive originals in their hosted systems.
Creator earnings are separate from customer service credits. We preserve the cash value assigned to purchased-credit lots, allocate completed eligible use to its source lots, and use append-only corrections for refunds, disputes, payout reversals, withholding, and provider-fee changes. Free, promotional, refunded, and administrative credits have no creator cash value. Self-use and failed or cancelled inference do not create creator earnings.
How we use information
We use information to provide and secure the Service; authenticate accounts; preserve your settings and progress; operate Agents at your request; prevent fraud, automated abuse, and unauthorized access; diagnose failures; measure public delivery and performance; enforce our Terms of Service and Acceptable Use Policy; comply with law; and respond to support, privacy, accessibility, and recovery requests.
We do not sell personal information. We do not use account, learning, or Agents data for cross-context behavioral advertising. We do not make private account information part of public feed snapshots or shared public caches.
Agents and automated processing
Agents sends the content needed to generate a chat response to the configured model provider through server-controlled routes. The browser does not receive provider credentials. Voice transcription and read-aloud do not use those routes. Makojima may apply automated checks for authentication, rate limits, request size, allowed file types, usage limits, and safety or policy enforcement.
The current Production interface does not offer a user control that authorizes model training on private conversations, and this policy does not claim that private conversations are used to train a Makojima model. We may use de-identified operational totals and content that you deliberately submit as feedback to maintain safety and reliability, subject to applicable law and any notice presented with that feedback feature.
Cookies and local device storage
Authentication uses secure cookies so the server can recognize an active session. Browser local storage may hold only device-level presentation preferences and public content metadata, including the selected theme, the expanded or collapsed navigation state, and the public lesson-feed snapshot. Account names, email addresses, private progress, session secrets, and Agents conversations must not be written to that storage by these features.
For a category-by-category description and browser controls, read our Cookie Policy.
Service providers and disclosures
We use Vercel for application hosting, delivery, cookieless analytics, and performance measurement; Supabase for the Production database, authentication, and file storage; Cloudflare and R2 for approved model and infrastructure storage; Hugging Face for creator-requested model and dataset transfers; Stripe for customer checkout, tax calculation, subscriptions, credits, and Stripe creator cashouts; PayPal for creator cashouts; Trolley Tax and Trust for hosted adult, identity, tax, sanctions, withholding, and year-end-form work; configured model providers for requested inference; a separate Makojima Mail system and delivery provider for approved account email; and an optional scrubbed error-reporting provider. Each provider processes only the information needed for its function under the applicable provider agreement.
Sensitive originals held by Stripe, PayPal, and Trolley are not readable by Makojima application code. Provider backup deletion follows the verified provider schedule; Makojima will publish that confirmed period instead of promising a period a provider cannot meet.
Makojima's public Site and private Mail application use separate databases, credentials, and authorization boundaries. Makojima does not give Mail direct access to the Site database. Email-delivery providers receive only what is necessary to deliver an approved message; they do not receive raw learning answers through the learning bridge.
We may disclose information when reasonably necessary to comply with law or valid legal process, protect rights and safety, investigate abuse, prevent fraud, or complete a corporate transaction subject to appropriate safeguards and notice where required.
Data register summary
Account data includes email, profile, choices, authentication identifiers, and verification status. Learning data includes progress, answers, scores, preferences, and study settings. Agent data includes conversations, messages, attachments, Drive references, tool activity, instructions, and token usage. Model data includes datasets, artifacts, release details, reviews, endpoints, and hashed API-key fingerprints. Security data includes sessions, two-step factor metadata, hashed recovery codes, keyed network identifiers, rate limits, and audit events. Money data includes provider identifiers, subscriptions, credit lots, usage settlements, creator earnings, cashouts, fees, withholding, and status. The Service does not store readable passwords, raw API keys, payment-card numbers, bank-account numbers, government IDs, identity documents, or tax numbers.
Security and service separation
We use encrypted transport, managed encryption at rest, server-owned authorization, row-level database controls, isolated test data, per-request content security policy nonces, bot checks, honeypots, bounded request contracts, rate limits, and privacy-aware logs. Production data is separated from protected test and internal operational systems with distinct credentials and authorization boundaries.
No online service can guarantee absolute security. You are responsible for protecting your credentials, using a unique password, enabling available MFA, and promptly reporting suspected account compromise.
Retention and deletion
We keep information while your account is active and for as long as reasonably needed to provide the applicable feature, secure the Service, resolve disputes, enforce agreements, and meet legal obligations. Raw security records are normally kept for 30 days and pseudonymous security records for 90 days. After an account deletion becomes final, ordinary account, learning, Agent, private-model, and original-file content is deleted or de-identified within 30 days. Financial, tax, contract, payout, and required legal records are retained for seven years. A legal hold can pause deletion of affected records.
A published fixed model release remains while any accepted copied endpoint depends on it. After the final endpoint closes, the release is scheduled for deletion within 30 days unless a rights, safety, sanctions, investigation, or legal hold requires continued preservation.
Deleting a conversation or account-facing record does not necessarily erase security logs, backups, legal holds, or de-identified operational totals immediately. Settings provides an authenticated export containing JSON, CSV, and time-limited links to original user files. Download links expire after seven days. Account deletion requires reauthentication, two-step verification when enabled, and recovery codes, and includes a seven-day cancellation window. We send an essential account notice for a deletion request. Contact us if a released control fails or an applicable right requires additional handling.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information; withdraw a consent-based choice; object to or restrict certain processing; or appeal a privacy-request decision. We may need to verify your identity before fulfilling a request and may retain information where an exception applies.
You can change released profile and communication controls, export data, schedule deletion, or cancel a pending deletion in Settings, manage local presentation data through your browser, and contact us for a request that needs additional handling. Publishing a community model has a specific consequence: a fixed release can remain after account deletion while an accepted endpoint depends on it, with the creator identity de-identified where appropriate and financial or license records retained. Makojima does not discriminate against you for exercising an applicable privacy right.
Communications
Service and security messages include email verification, password reset, account recovery, MFA and security alerts, material policy notices, and other messages necessary to provide or protect an account. They are not marketing and may be sent regardless of an optional communications preference.
Optional communications with personalized learning insights and special offers for you require your affirmative request. Product updates, feature announcements, upgrade messages, promotions, and offers remain optional. Turning them off does not disable service or security messages. A requested preference may remain inactive until email verification and the separate Production transport gate are complete. See Terms: Communications for the contractual categories.
Children's privacy
The Service is not directed to children under 16, and users under 16 may not create an account. We do not knowingly collect personal information from a child under 16. Contact us if you believe a child has provided information so we can investigate and take appropriate action.
International use
Makojima is operated from the United States. If you access the Service elsewhere, information may be processed in the United States or other locations where our approved providers operate. Applicable protections and rights may differ by jurisdiction. Creator earning and cashout features use a default-deny country list and are enabled only after identity, tax, sanctions, payments, consumer-law, and model-export review for that country.
Changes to this policy
We may update this policy as the Production Service or legal requirements change. We will revise the last-updated date and provide additional notice when required. A new policy does not retroactively activate an unreleased feature or expand a consent beyond the choice presented to you.
Contact us
For privacy questions or requests, email legal@makojima.com. Product and account support goes to hello@makojima.com. Replies will come from the Makojima address responsible for the request. Do not send passwords, recovery phrases, one-time codes, payment details, or sensitive learning content by email.