Legal
Privacy Policy
Last updated · 8 September 2026
Who we are
Roushi is a knowledge layer for portfolio operators, built and operated by KumoKodo. It is currently in private beta and access is limited to an explicit allow-list. In this policy "we" means KumoKodo, and "you" means anyone using roushi.ai.
Questions go to sam@kumokodo.ai.
What we collect
Before you sign in, the public pages collect nothing that identifies you unless you consent to analytics. Our host keeps short-lived request logs, including IP address, for security and reliability.
When you sign in, we use GitHub OAuth. From GitHub we receive your name, email address and avatar URL, plus the OAuth tokens needed to keep you signed in. We never see your GitHub password, and we do not read your repositories.
When you use Roushi, we store what you put into it: entities, notes, rules, goals, playbooks and the relationships between them. This is your knowledge base. It is the product, and it is yours.
Analytics, and the two different kinds
We are precise about this because the two tools behave differently:
- Google Analytics is off until you accept it. The tag is not loaded at all until you agree, so if you decline, no request is ever made to Google and no analytics cookie is set. You can change your mind from the Cookie preferences link in the footer.
- Vercel Web Analytics runs without consent, and we think that is honest. It sets no cookies, stores no identifier on your device, and cannot follow you to another site. It gives us aggregate page counts and nothing that points at a person, so there is nothing meaningful to consent to. We disclose it rather than hide it.
We honour the Global Privacy Control signal. If your browser sends GPC we treat it as an opt-out, keep Google Analytics off, and do not show you a banner asking you to reconsider.
AI processing of your content
Roushi uses OpenAI models to generate embeddings for search and to answer questions about your knowledge base. This means the content of entities and notes you query against is sent to OpenAI for processing. It is sent to produce your result and for no other purpose.
We do not use your content to train any model, and we do not permit our providers to. If your knowledge base holds something you would not send to a third-party API, do not put it in Roushi.
Cookies
Signed in, we set a session cookie so you stay signed in. It is strictly necessary and there is nothing to opt out of. Signing out clears it. Google Analytics cookies are set only if you accept analytics, and never before.
Who else touches it
| Provider | What for | What they get |
|---|---|---|
| GitHub | Sign-in | Confirms who you are; we receive name, email and avatar |
| Neon | Database hosting | Your account and your knowledge base, encrypted at rest |
| OpenAI | Embeddings and answers | The content being indexed or queried |
| Resend | Your email address and the message | |
| Vercel | Hosting and cookieless analytics | Request logs including IP; aggregate page counts |
| Analytics, only if you accept | Nothing at all unless you have consented |
We do not sell your personal information and we do not share it for advertising. There are no ad pixels on this site.
How long we keep it
- Your knowledge base: until you delete it or ask us to close your account.
- Account and session records: until the account is closed, then removed within 30 days.
- Server logs: a short rolling window held by our host.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to a particular use, or withdraw analytics consent at any time. Withdrawing consent is exactly as easy as giving it: it is one click in the footer.
Email sam@kumokodo.ai. We will acknowledge within 10 business days and complete the request within 45. Because Roushi is a private beta with a small number of accounts, in practice it will be much faster.
Security
Access is allow-listed, so an account cannot be created simply by signing in with any GitHub account. Data is encrypted in transit and at rest. No system is perfectly secure, and we will tell affected users promptly if that ever proves relevant.
Changes
If we change this policy we will update the date at the top, and email active users if the change materially affects how your content is handled.
Contact
sam@kumokodo.ai — or read the Terms of Service.