Legal
Legion Data Handling
Version 1.0 ยท Effective October 7, 2026
Where Legion rentals run, how they are isolated, what Legion logs, what providers can and cannot access, and what happens to your data when a rental ends.
1. About this page
This page summarizes how Legion handles workloads and data. Legion is the GPU rental marketplace operated by Mechanus Labs Inc. ("Ambient," "we," "us"). Read it before you decide what to run on Legion.
It complements the Privacy Policy, the Terms of Use, and the Acceptable Use Policy. If this page and those documents conflict, those documents control.
2. Core points
- Your workload runs on someone else's machine. Rentals run on hosts owned and operated by independent providers, not on Ambient's infrastructure.
- Isolation limits what rentals can reach, but cannot fully protect you from the host's owner. Legion isolates each rental from other rentals and from the provider's network. A provider with physical or administrative control of a host can still, technically, reach what runs on it. Our terms prohibit providers from doing so.
- Legion logs metadata, not your workload. We record connections, lifecycle and usage events, and the network destinations each rental contacts. We do not routinely inspect the contents of rentals.
- Deleting a rental deletes its data from the host, unless the data is preserved for an investigation or a legal requirement.
- Back up your own data. Legion does not back up workloads.
3. Where workloads run
When you start a rental, your container runs on the host you chose. That host belongs to a provider. Hosts sit in providers' homes, offices, or data centers, wherever their providers operate them, and may be in a different country from you.
This means:
- the provider controls the host's hardware, operating system, power, and network connection;
- your container image, your files, and any data you load are stored on the host's disks and held in its memory and GPU memory while the rental runs; and
- Legion's control plane, which runs on AWS, manages the rental, but the workload itself is not on Ambient's systems.
Before you put data on Legion, decide whether it is appropriate for third-party hardware. If it is sensitive, regulated, or confidential, protect it yourself, for example by encrypting it and managing the keys outside the rental. Do not place data on Legion that you are not permitted to put on hardware operated by a third party.
4. Isolation measures
Legion uses the following measures to separate rentals from each other and from the host's environment:
- Containers. Each rental runs in its own container with its own resource limits for GPUs, CPU, memory, and process count. Some privileged capabilities are removed.
Per-rental network policy. Each rental has its own network:
- containers of different rentals cannot reach each other;
- a rental cannot reach the host itself, the provider's local network, or cloud metadata services; and
- outbound traffic is subject to Legion's network policy, which can allow or deny destinations.
- No direct exposure. You reach your rental only through Legion's gateway or the browser terminal, not through ports opened on the provider's network.
- Short-lived credentials. Access to a rental uses SSH certificates that Legion issues for a short period. The browser terminal uses a key held in your browser and a short-lived certificate. Hosts authenticate to Legion with their own credentials, which Legion can revoke.
- Host approval. During the beta, every provider and every host must be approved by Ambient before it can take rentals.
These measures reduce risk. They do not make a host a trusted environment.
5. What providers can and cannot access
What Legion gives the provider. Legion gives a host only what it needs to run your rental:
- the container image;
- the rental's configuration and resource limits; and
- the SSH public keys and certificate settings that let you connect.
Legion does not give providers your name, email address, or billing details.
What providers may not do. Under the Terms of Use and the Acceptable Use Policy, providers must not access, inspect, copy, intercept, record, or modify your workload, files, memory, storage, credentials, or network traffic. They must not tamper with the Legion agent or its network rules. A provider who breaks these rules faces suspension and termination, preservation of evidence, and referral to the authorities.
What providers can technically do. A provider has physical and administrative control of their machine, so Legion cannot technically prevent a determined provider from reaching data on it, including data:
- on disk;
- in memory or GPU memory; or
- in traffic that leaves the container unencrypted.
Legion does not offer confidential-computing or hardware-attested isolation from the host's owner. Plan accordingly (see Section 3).
6. What Legion logs
Legion records operational metadata needed to run, secure, and bill the service. This includes:
- account and sign-in events;
- connection and audit records: SSH certificates issued, browser terminal access grants, and connections (who connected to which rental, when, and from which IP address);
- rental lifecycle and usage: created, started, stopped, deleted, failed, and the usage that is billed;
- network telemetry per rental: whether each outbound connection was allowed or denied, and the destinations contacted, identified by DNS names and TLS SNI values;
- host information: hardware, benchmarks, health, and agent telemetry;
- administrative actions taken by Ambient staff; and
- API and web requests, including IP addresses and user agents.
These records describe what happened, not what your workload contained. They are not designed to capture what you type in a session or the content of your traffic. They are kept only as long as necessary for operations, security, abuse investigation, billing, and legal compliance. The Privacy Policy has more detail.
7. When a rental ends
- Stopping a rental stops its container. The rental's workspace stays on the host so that you can restart it.
Deleting a rental instructs the host's Legion agent to remove:
- the container;
- the rental's workspace; and
- the rental's network and network rules.
The gateway stops accepting connections to it. A rental may also be deleted by Ambient as the Terms of Use allow, for example when your account closes or your credits run out and are not restored.
Some limits apply:
- Not a secure erase. Removal is ordinary deletion by the host's operating system. It is not a forensic wipe of disks, memory, or GPU memory, and Legion cannot control backups or snapshots that a provider takes of their own machine.
- Offline hosts. If a host goes offline or leaves Legion before a deletion reaches it, the data stays on that host until the agent can act on it, which Legion cannot guarantee.
- Preserved data. Data preserved for an investigation or a legal requirement is not deleted while it is preserved (see Section 9).
If you need data to be unrecoverable from a host, encrypt it and destroy the key yourself.
8. Container images and the registry mirror
Hosts do not pull renter images directly from public registries. Images are pulled through Legion's registry mirror:
- the mirror fetches a copy of the image, stores it, and serves it to the host;
- Legion records which image each rental used; and
- Legion currently supports images that are publicly available from the registries listed in the app. Do not put secrets in an image.
Mirrored images are kept for as long as needed to serve rentals and operate the mirror. We may block an image that violates the Acceptable Use Policy, and we may preserve it as evidence.
9. Incidents and abuse
If we detect or are told about a security incident, illegal activity, or misuse, we may take the steps in the Acceptable Use Policy without notice. They include:
- stopping or isolating rentals, withdrawing hosts, revoking credentials, and blocking images or destinations;
- suspending and terminating accounts;
- preserving, retaining, and securing workloads, containers, images, data, files, logs, and network records, on Legion's systems or on connected hosts, through the agent or by requiring the provider to preserve them; and
- disclosing preserved material to law enforcement and other authorities, and cooperating with their investigations, as the law permits or requires.
We report apparent child sexual abuse material to the National Center for Missing & Exploited Children, as U.S. law requires.
If an incident affects your personal information, we will notify you and the relevant authorities where the law requires it.
10. Vendors
Legion uses:
- Google, for sign-in;
- Mailgun, for email;
- Amazon Web Services, for the control plane, databases, and logs; and
- Cloudflare, for the website, web app, and network security.
Workloads do not run on these vendors. They run on provider hosts. Mirrored container images, and any material preserved under Section 9, are stored on Legion's own systems.
11. Contact
Questions, security reports, or abuse reports: support@ambient.xyz. For abuse, put "Legion abuse" in the subject.
For details, see the Privacy Policy, the Terms of Use, and the Acceptable Use Policy.