Naumio · Terms

Privacy notice

Effective September 22, 2026 · current public website and browser-only CropCheck · planned hosted connector beta

The hosted connector beta is not publicly active. Its restricted infrastructure is being tested with synthetic material. This notice describes the intended processing boundary before activation; it does not claim Muse approval, customer availability, or production use.

What this covers

MTA Ultra IT LLC doing business as Naumio operates the public website at naumio.com and the separate free browser tool at naumio-cropcheck.pages.dev. This notice covers those services.

CropCheck

The current public CropCheck tool lets you choose an image in your browser, preview fixed crop sizes, and download a PNG. Its current product copy says images are processed in your browser. The current browser app does not provide an account, payment, or image-upload flow to Naumio. Browser extensions, the operating system, and files you choose to download are outside Naumio's control.

Keep responsibility for source-image rights and downloaded files. Review every output before using it. A crop preview is not a promise about a marketplace's display or acceptance.

Website requests and provider handling

The Naumio website is served as a static Cloudflare Pages site. Cloudflare may process an IP address, requested URL, timestamp, browser/device/request metadata, and security signals to deliver and protect the static site. The current site provides navigation, public assets, service descriptions, and a mail link to info@naumio.com; it does not currently provide a customer upload form or automated purchase flow. Cloudflare's own practices are described in its Privacy Policy.

Email

If you email info@naumio.com, Microsoft 365 processes sender and recipient addresses, headers, subject, message body, and attachments to receive, route, secure, and answer email. See Microsoft's Privacy Statement. Do not send confidential, regulated, or unnecessary personal information.

Planned hosted connector beta

The planned beta would accept material a caller intentionally submits: image bytes and crop settings for CropCheck; or structured job/report fields, source identifiers, full source notes and selected excerpts for Service Closeout. Full notes are processed as input even when omitted from the ordinary PDF and record. Selected excerpts and identifiers can remain in those outputs; an optional full-note backup is a separate disclosure requiring separate authorization. CropCheck outputs may include image and output hashes, which can link material even when image metadata is removed. No output is automatically anonymized or checked for sensitive content.

Both preparation operations can already return usable PNG or PDF bytes; CropCheck export can return a ZIP and manifest. Preparation is therefore a content-disclosure step, not a harmless preview. The content digest checks consistency, not a person's identity, review, consent, or permission for private backup. A hosted adapter must authenticate and authorize preparation, export and any separate backup disclosure. The current core has no stored job, artifact URL, expiry, delete endpoint, delivery receipt, or secure-wipe mechanism; export requires the original input again.

The restricted route being brought up is designed to use a dedicated Cloudflare Worker for caller authentication and fixed-route controls, a separate Cloudflare Access service credential, and an outbound-only Tunnel to a server-side adapter. This notice itself does not establish public connector availability or Muse approval; those require separate endpoint and provider readback. The caller would supply one bearer credential; distinct Access and origin credentials remain server-side, not extra caller inputs. The cores do not send submitted content to an AI model, email service, or payment processor; the full hosted and provider handoff still requires verification. We do not state a server country or region before provider readback confirms it.

The tested adapter is configured without a persistent customer-payload volume, database, object store, or backup workflow. Processing can use memory and bounded temporary memory-backed files; the host also has swap, so this is not a promise that no trace reaches persistent storage. The accepted application source does not log request bodies or credentials, while size-rotated operational logs and provider security or request metadata may remain. Size-based rotation is not a fixed deletion time. Browser downloads and any provider-held copies persist outside the core. Actual proxy, host, diagnostic, swap, backup, temporary-file and provider lifetimes must be confirmed before activation; no forensic erasure or zero-retention claim is made.

Returned downloads remain with the caller and are outside Naumio's control. Initial beta use, if activated, is restricted to non-sensitive fictional or public-safe material. Do not submit confidential, regulated, private customer, or unnecessary personal information. The public browser-only CropCheck remains a separate service that processes the selected image in the browser.

Questions

Questions about access, correction, or deletion may be sent to info@naumio.com. MTA Ultra IT LLC doing business as Naumio may reasonably verify identity and may retain information as needed to respond, provide support, maintain security and operational records, resolve disputes, or comply with law. Providers may retain copies under their policies. Retention is needs-based; no response-time guarantee is made, and statutory rights that cannot legally be waived remain available.