Nine Suns Inc. (“Mighty,” “we,” “us,” or “our”) provides document and content trust-detection software for customer-operated Enterprise Private Deployment. This policy covers the trymighty.ai website, accounts, licensing, authorized evaluation and support channels, and company operations.
For website, account, billing, and company-operation data, Mighty generally determines why and how the data is processed. For Customer Content in a Private Deployment, the customer controls the environment and processing. Mighty handles Customer Content only when an authorized support or other contracted channel actually transfers it to Mighty.
1. Information We Collect
Website, Account, and Organization Information
We collect information used to operate the Mighty website and administer business relationships, including name, business email address, organization, role, authentication events, settings, support communications, and information provided through demo or procurement requests.
Google and GitHub Sign-In
Google sign-in requests the openid, email, and profile scopes. We receive the provider account ID, name, email address, email-verification status, and profile image. We do not request Google Drive, Gmail, Calendar, Contacts, Photos, or YouTube access.
GitHub sign-in requests the user:email scope. We receive the GitHub account ID, login, name, email address, email-verification information, and avatar. We do not request repository, gist, or organization access.
Provider access, refresh, and ID tokens are used during the sign-in exchange and are not retained as linked provider access credentials after the callback. Mighty stores the profile fields required for its own account and session system.
Billing and Contract Information
Stripe may process card payments where card billing is offered. We do not store full card numbers. We may receive limited customer, invoice, subscription, payment-status, and transaction information. Enterprise customers may pay by invoice, ACH, wire, or bank transfer under a signed Order Form.
Website and Operational Data
We collect IP address, browser and device information, cookie identifiers, page and feature interactions, timestamps, security events, and diagnostic data when you use the website, an authorized evaluation surface, or a Mighty-operated account service.
2. How We Use Information
We use information to:
- Respond to demos, procurement, security, and support requests
- Authenticate users and administer accounts and contracts
- Provide licensing, update delivery, support, and billing
- Protect our systems, investigate abuse, and maintain audit records
- Measure reliability and improve the website and product
- Communicate about operations, security, billing, and support
- Comply with law and enforce our agreements
Google and GitHub account data is used only for authentication, account administration, profile display, security, and account communications. It is not sold, used for advertising, or admitted to AI or machine-learning training. Our use of Google data follows the Google API Services User Data Policy, including its Limited Use requirements.
3. Current Service and Data Boundary
Mighty is currently offered for customer-operated Enterprise Private Deployment. The customer controls its production environment and Customer Content. Customer Content is not exported to Mighty or used for Mighty model training by default.
Enterprise Private Deployment
The customer controls its hosting environment, identity system, network, encryption keys, Customer Content, operational logs, backups, retention, deletion, production deployment, and production decisions. Mighty provides software, updates, security information, documentation, and the support described in the applicable Order Form.
Licensing and update checks must be limited to the disclosed operational metadata needed for those functions. Customer Content is not sent to Mighty, an analytics provider, or an external model provider through the supported default configuration.
Existing Mighty-Hosted Subscriptions
Mighty previously offered, and until October 1, 2026 continues to accept, direct purchase of a Mighty-hosted subscription plan. Where a customer holds such a subscription, Mighty operates the service and therefore does receive and process that customer's Customer Content in order to provide it. The statement above, that Customer Content is not sent to Mighty, describes the customer-operated private deployment and does not apply to those hosted subscriptions.
For hosted subscriptions, Customer Content is processed only to deliver the service the customer asked for, is not sold, is not shared for cross-context behavioral advertising, and is not used to train shared or general-purpose models. It is retained and deleted under the schedule described in the retention section of this policy. Direct purchase of new hosted subscriptions ends on October 1, 2026.
Mighty-Hosted Development and Evaluation Systems
Mighty may operate development, testing, demonstration, evaluation, and company-administration systems. These systems are not represented as a customer production hosting service. Customer production content must not be submitted to them unless a separate written agreement expressly authorizes the processing and its safeguards.
Support Access and Support Copies
A support upload or remote-access session is a separate, customer-approved channel. The support record must identify its purpose, scope, authorized access, retention or access window, and closure. Providing a support copy does not authorize training or unrelated product use.
4. Model Improvement
Customer Content from Enterprise Private Deployment, including content received through an authorized support channel, is not used to develop, train, tune, or improve a shared or general-purpose model by default. No third-party service or model provider is authorized to train its models on that Customer Content.
Mighty may improve its products using wholly synthetic material, properly licensed material, internal test data, and other sources for which Mighty has documented rights and safeguards. Any future proposal to use customer-derived material requires a separately signed, specific authorization and a new privacy, security, legal, data-governance, and release review before collection or use begins.
6. Retention and Deletion
Customer Content in Enterprise Private Deployment remains under the customer's retention, deletion, backup, and legal-hold controls. Mighty does not set a retention period for data that it does not receive or control.
Mighty retains account, licensing, billing, security, website, procurement, and support information for the documented purpose, the business relationship, applicable contracts, dispute handling, and tax, accounting, or other legal obligations. Different categories use different periods, and backups may expire on separate bounded schedules.
When Mighty receives Customer Content through an authorized support process, it is restricted to the support purpose and removed or rendered inaccessible from active systems after that purpose and the documented retention period end, subject to bounded backup expiration and valid legal holds.
Mighty does not currently promise a universal self-service deletion or export workflow or one deletion deadline for every record. To request access, correction, export, account closure, or deletion, contact hi@trymighty.ai. We will verify the request and respond as required by applicable law or the governing agreement.
7. Privacy Rights and Requests
Depending on where you live and subject to legal exceptions, you may have rights to access, correct, delete, or obtain a copy of personal data, or to object to or restrict certain processing. You may also opt out of marketing communications.
If Mighty handles personal data solely to support a customer-operated deployment, that customer generally controls the request. We may direct you to the customer and assist it as required by the governing agreement. Send requests to hi@trymighty.ai. We may verify identity and authority before acting.
8. Cookies, Analytics, and Browser Signals
The website may use necessary cookies for security and operation and configured measurement services such as Google Analytics 4, Apollo.io, and Datadog RUM. These services may receive browser, device, network, and interaction information according to their configured purpose and terms.
Mighty does not record website sessions. Session replay, which captures a visual recording of what a visitor does on a page, is disabled in the monitoring configuration and is not enabled for any visitor.
Mighty does not currently represent that a public preference center or Global Privacy Control signal is enforced end to end. Until the relevant product control is implemented and verified, contact hi@trymighty.ai about an applicable opt-out request. Browser controls may also limit cookies, but disabling them can affect website operation.
9. Security
Mighty uses safeguards appropriate to the information and systems it controls, including identity and access controls, encryption for supported administrative and public paths, vulnerability management, logging, secure development, and change review. No system can be guaranteed completely secure. Private Deployment customers remain responsible for securing and operating their own environments as described in the shared-responsibility terms and documentation.
10. Children
Mighty is a business service and is not directed to children. Do not submit a child's personal information unless the customer has determined that the processing is lawful, necessary, and covered by the governing agreement. Contact hi@trymighty.ai if you believe a child's information was provided directly to Mighty improperly.
11. United States and International Processing
Mighty currently targets customers in the United States. Website, business, authentication, support, and provider data may nevertheless be processed in locations used by the applicable provider. A template or public statement does not by itself incorporate Standard Contractual Clauses or represent that a particular transfer mechanism has been executed. Any required mechanism must be documented in the applicable agreement before reliance.
12. High-Impact Use
Mighty may provide advisory signals for lending, mortgage, underwriting, insurance, claims, or similar workflows. Mighty does not make the customer's final decision. Outputs may be incomplete or incorrect and must not be the sole basis for a decision with legal or similarly significant effects.
Customers must validate the configured use, use qualified human review, independently determine the decision and reasons, maintain appropriate records, monitor performance, and provide notices and appeal rights required by law. Nothing in this notice shifts a duty that applicable law places directly on Mighty.
13. Changes to This Policy
We may update this policy prospectively and will provide notice appropriate to a material change. A new Customer Content use is not authorized retroactively merely because this notice changes. A signed agreement may supplement this notice and allocate responsibilities between Mighty and a customer, but it does not make this notice inaccurate or limit rights that applicable law gives an individual.
14. Contact
Nine Suns Inc.
Delaware, USA
Privacy, security, and general inquiries: hi@trymighty.ai
