Legal

Privacy Policy

Effective date: 2 August 2026Version 1.0

This Privacy Policy describes how Exa RAM ("Exa RAM", "we", "us" or "our") collects, uses, discloses and safeguards information in connection with the Exa RAM website, console, application programming interfaces, node agent software and related services (collectively, the "Service"). It applies to all users of the Service, including persons who contribute computing capacity to the network ("Node Operators") and persons who consume capacity through the API or console ("Customers").

Please read this Policy together with our Terms of Service. Section 6 contains material information about the distributed architecture of the Service and the consequences of that architecture for data submitted to the memory pool.

1.Scope and controller

Exa RAM acts as the controller in respect of personal data processed through the Service. This Policy does not apply to third-party websites, services or infrastructure that may be linked from or interoperate with the Service, which are governed by their own privacy notices. Inquiries may be directed to james@runexaram.com.

2.Categories of information collected

2.1 Account information

Accounts are created without registration, identity verification or payment credentials. We generate and store an account identifier, an API key, records of capacity reservations, and ledger entries recording metered usage. We do not request or store names, email addresses, postal addresses, telephone numbers or payment card details, except where a user voluntarily provides such information by corresponding with us.

2.2 Node telemetry

When a device connects to the network, the node software transmits technical characteristics necessary to schedule work and allocate capacity, namely: processor core count; operating system and platform identifiers; pledged memory and storage capacity per tier; and, where the runtime environment exposes it, graphics adapter vendor and architecture and the processor model string. Certain of this information, together with a randomly generated node identifier and a user-supplied node label, is displayed publicly on the grid dashboard for the duration of the session.

2.3 Connection and technical data

Operation of a networked service necessarily entails processing of internet protocol addresses, connection timestamps, protocol metadata and diagnostic logs. Such data is processed for the purposes of establishing connectivity, maintaining security, preventing abuse and diagnosing faults.

2.4 Customer content

"Customer Content" means data submitted by a Customer to the memory pool, together with associated placement metadata. Exa RAM does not inspect, index, analyse or otherwise process the substantive contents of Customer Content except as strictly necessary to store, replicate, migrate, transmit and delete it in accordance with Customer instructions.

2.5 Information we do not collect

We do not deploy advertising technologies, third-party analytics services, cross-site tracking mechanisms or behavioural profiling. Node software does not access files, documents, peripherals or other applications on a contributing device. Browser-based nodes execute within the browser security sandbox and can address only memory allocated by the page itself.

3.Purposes of processing

Information is processed for the following purposes:

4.Legal bases for processing

Where the General Data Protection Regulation (Regulation (EU) 2016/679) or the UK GDPR applies, we rely on the following legal bases: performance of a contract, in respect of processing necessary to deliver the Service requested; legitimate interests, in respect of network security, abuse prevention, service integrity and product improvement, subject to a balancing assessment; consent, in respect of voluntary contribution of a device to the network, which may be withdrawn at any time by disconnecting; and compliance with legal obligations, where processing is required by applicable law.

5.Cookies and local storage

The Service sets no cookies and employs no cookie-based tracking. The console uses browser local storage to retain an API key, so that a new account is not provisioned on each visit, and to retain cryptographic digests of data written by the user, so that the user's own browser may independently verify the integrity of data returned to it. Clearing site data removes both items. No local storage data is transmitted to us other than the API key accompanying authenticated requests.

6.Distributed storage architecture — material disclosure

The Service differs materially from conventional hosted storage. Customer Content submitted to the memory pool is divided into fixed-size chunks and placed in the volatile memory or local storage of independently operated devices contributed by third parties. Each chunk is placed on two distinct nodes for redundancy, and may be migrated between storage tiers, and therefore between devices, during its lifetime.

Customer Content is not encrypted at rest on contributing nodes in the current version of the Service. A Node Operator with sufficient technical means could therefore inspect chunks held on their own device. Client-side encryption is under development but is not yet implemented.

Accordingly, users must not submit personal data relating to any identified or identifiable natural person, special category data, health or financial records, authentication credentials, trade secrets, or any information subject to statutory, regulatory or contractual confidentiality obligations, to the memory pool. Customer Content should be limited to data the Customer would be prepared to treat as public. Users who submit information contrary to this restriction do so at their own risk and are responsible for any resulting non-compliance with data protection law.

Customer Content is inherently ephemeral. It resides on contributed devices rather than on dedicated infrastructure and is irrecoverably lost when all nodes holding a given chunk disconnect. The Service is not a backup service and must not be relied upon as a system of record.

7.Disclosure of information

We do not sell personal data. Information is disclosed only as follows:

8.International transfers

The network is global by design. Customer Content and connection data may be processed in any jurisdiction in which a contributing node or our infrastructure is located, including jurisdictions whose data protection laws differ from those of the user's own. Users should have regard to Section 6 when assessing the implications of this for their data. Where we transfer personal data internationally and safeguards are required, we rely on appropriate transfer mechanisms recognised under applicable law.

9.Security

We implement technical and organisational measures appropriate to the nature of the Service, including transport-layer encryption for data in transit, API key authentication and account-scoped authorisation for all Customer Content operations, replication of each chunk across two independent nodes with automated re-replication upon node failure, and cryptographic proof-of-possession challenges permitting users to verify independently that nodes hold the data attributed to them. The limitation described in Section 6 applies notwithstanding these measures. No method of transmission or storage is entirely secure, and we cannot guarantee absolute security.

10.Retention

Customer Content persists only while allocated and while nodes holding it remain connected; it is deleted from all replicas upon deallocation and is lost upon node departure. Node telemetry is retained only for the duration of the session, save for historical join and departure records retained for operational visibility. Account identifiers, reservations and ledger entries are retained while the account remains active and thereafter for such period as is necessary for legitimate business and legal purposes. Diagnostic logs are retained for a limited period proportionate to security and troubleshooting requirements.

11.Rights of data subjects

Subject to applicable law, individuals may have the right to request access to, or rectification or erasure of, personal data concerning them; to restrict or object to certain processing; to data portability; and to withdraw consent where processing is based on consent. Users may exercise operational control directly at any time by deleting allocations, which removes the data from all replicas, and by disconnecting a contributed device, which removes the node immediately.

Requests may be submitted to james@runexaram.com. We will respond within the period prescribed by applicable law. Residents of the European Economic Area and the United Kingdom have the right to lodge a complaint with their national supervisory authority. Residents of California may have additional rights under the California Consumer Privacy Act; we do not sell or share personal information as those terms are defined thereunder.

12.Children

The Service is not directed to children under the age of 13 (or the applicable minimum age in the user's jurisdiction), and we do not knowingly collect their personal data. If we become aware that such data has been collected, we will delete it.

13.Changes to this Policy

We may amend this Policy from time to time. The effective date above will be revised accordingly and, where changes are material, we will provide additional notice through the Service. Continued use following the effective date of an amended Policy constitutes acceptance of it.

14.Contact

Questions, requests and complaints concerning this Policy or our processing of personal data should be addressed to james@runexaram.com.