Legal
Legion Privacy Policy
Version 1.0 ยท Effective October 7, 2026
What personal information Legion collects from renters, providers and waitlist sign-ups, why, who it is shared with, how long it is kept, and your choices.
1. About this policy
This Privacy Policy explains how Mechanus Labs Inc. ("Ambient," "we," "us") collects, uses, and discloses information when you use Legion. Legion is our GPU rental marketplace at legion.ambient.xyz, and the policy covers its website, web app, APIs, command-line tools, and the Legion agent. It applies to:
- renters;
- providers;
- people who join the Legion waitlist.
It should be read with the Data Handling page. That page explains where rentals run and what providers can and cannot access.
This policy covers Ambient's handling of information. Providers operate their own hosts. Information you place in a rental is on hardware that Ambient does not own or control (see Section 6.3).
2. The short version
- Limited account information. We collect what we need to run Legion: your Google sign-in details, billing records, SSH public keys, and the logs and telemetry needed to operate, secure, and bill the service.
- We don't look inside your workloads in the normal course. Legion does not routinely inspect the contents of rentals. We do record operational and network metadata, such as connections and the destinations a rental contacts. In an abuse investigation or where the law requires it, we may preserve and examine more (see Section 8).
- No sale, no advertising. We do not sell personal data. We do not use your workloads to train models or for advertising.
- Providers don't get your account details. A provider's host runs your rental, but the provider does not receive your name or email address from Legion.
3. What we collect
3.1 Account and sign-in
You sign in to Legion with Google. From Google we receive:
- your email address;
- your name;
- whether Google has verified your email address; and
- if you use a Google Workspace account, its domain.
We also keep:
- your organization and membership details;
- your role (for example renter or provider);
- your beta-approval status;
- your account settings; and
- API keys, which we store securely.
3.2 Waitlist
If you join the waitlist, we collect your email address, and anything else the form asks for, and use it to contact you about Legion. We send waitlist and service email through Mailgun.
3.3 Acceptance of our terms
When you accept the Terms of Use, the Acceptable Use Policy, or a new version of either, we record:
- your account and email address;
- the document and the version you accepted;
- the time; and
- the IP address and browser user agent you used.
We keep this as a record of your agreement.
3.4 Billing and credits
We keep:
- your credit balance and top-ups;
- per-rental charges and usage;
- adjustments and refunds;
- for providers, earnings and payout records; and
- the identity, tax, and payment details we need in order to pay providers.
3.5 SSH access
We collect and store the SSH public keys you add to Legion. We never receive your private keys.
When you connect to a rental, Legion issues short-lived SSH certificates. The browser terminal uses a key that is generated and held in your browser, and we issue a short-lived certificate for it.
We record:
- the certificates we issue;
- terminal access grants; and
- connection events (who connected to which rental, when, and from which IP address).
3.6 Logs and usage
We keep logs of:
- your use of the website, app, and API, including IP addresses, user agents, request identifiers, timestamps, and errors;
- rental lifecycle events (created, started, stopped, deleted, failed);
- usage and metering records;
- administrative actions; and
- security events such as failed sign-ins and rate-limit events.
3.7 Network telemetry for each rental
Each rental runs under a network policy. For each rental we record:
- egress decisions, that is, whether an outbound connection was allowed or denied; and
- the destinations the rental contacted, identified by DNS names and TLS Server Name Indication (SNI) values, with the time of contact.
This tells us where a rental connected, not what it sent. We use it to enforce network policy, to detect and investigate abuse, and to respond to abuse reports.
3.8 Hosts (providers)
For each host, we collect:
- hardware information (for example GPU model and count, memory, CPU, storage, and driver versions);
- benchmark results;
- health and availability (heartbeats);
- the host's network addresses;
- operational telemetry from the Legion agent; and
- listing details.
3.9 Container images
Container images that rentals use are pulled through Legion's registry mirror. The mirror stores copies of those images, and we record which image each rental used. Legion currently supports images that are publicly available from the registries listed in the app.
3.10 Support and communications
If you contact us, we keep the correspondence.
4. Information we do not collect in the normal course
Legion does not routinely collect or inspect the contents of your workloads. That includes the files in your container, what your processes compute, and the data your rental sends and receives.
Our connection logs and network telemetry record metadata (who, when, and which destination), not the content of your sessions or traffic.
Section 8 describes the circumstances in which we may preserve and examine content.
5. How we use information
We use information to:
- provide Legion: authenticate you, approve beta access, run, connect to, and manage rentals, list and allocate hosts, and pull images;
- bill and pay: meter usage, charge credits, and calculate and pay provider earnings;
- keep Legion secure and reliable: enforce network policy, detect and prevent fraud and abuse, investigate incidents, and troubleshoot;
- enforce our Terms of Use and Acceptable Use Policy, including the steps described in Section 8;
- communicate with you: service notices (for example when a rental fails), waitlist and beta access emails, and responses to your inquiries; and
- comply with legal obligations.
We do not sell personal data. We do not use your workloads to train models or for advertising.
6. Sharing and disclosure
6.1 Service providers (subprocessors)
We use vendors to operate Legion. They process information on our behalf:
- Google, for sign-in;
- Mailgun, for waitlist and service email;
- Amazon Web Services (AWS), for hosting Legion's control plane, its databases, and its logs;
- Cloudflare, for serving the Legion website and web app, and for security and network delivery.
We may update this list as our vendors change.
6.2 Providers
When you rent, the host's provider operates the machine your rental runs on. Legion gives the host what it needs to run the rental:
- the container image;
- the rental's configuration and resource limits; and
- the SSH public keys and certificate settings that let you connect.
Legion does not give providers your name, email address, or billing details.
Because the provider controls the hardware, the data in your rental is on their machine. The Terms of Use and the Acceptable Use Policy prohibit providers from accessing it. See Data Handling for what that does and does not mean in practice.
6.3 Renters
Renters see a host's listing information. Legion does not give renters a provider's name, email address, or payout details.
6.4 Legal, safety and abuse
We may preserve and disclose information, as described in Section 8, if we believe in good faith that it is necessary to:
- comply with law, regulation, or legal process;
- protect the security, integrity, and rights of Ambient, our users, providers, or others;
- investigate fraud, abuse, or violations of our Terms of Use or Acceptable Use Policy; or
- report apparent child sexual abuse material to the National Center for Missing & Exploited Children, as U.S. law requires.
6.5 Business transfers
If Ambient is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
7. Data retention
- Account data: kept while your account is open, and afterwards for as long as needed for the purposes below.
- Waitlist email: kept until you are admitted to Legion or ask us to remove it.
- Records of acceptance: kept for as long as needed to show what you agreed to.
- Billing and payout records: kept for as long as needed for billing, accounting, tax, and legal compliance.
- Logs, audit records, and network telemetry: kept only as long as necessary for operations, security, abuse investigation, billing, and legal compliance. They are then deleted.
- Workloads: a rental's data is held on the provider's host, not on Legion's systems. Legion removes it from the host when the rental is deleted (see Data Handling).
- Mirrored container images: kept for as long as needed to serve rentals and operate the mirror.
Preserved material. Material preserved for an investigation, a legal hold, or a legal requirement is kept for as long as that purpose requires, even if it would otherwise have been deleted (see Section 8).
Backups. When we delete information from active systems, residual copies may persist temporarily in backups and are deleted as backups rotate.
8. Preservation and disclosure for legal and abuse reasons
If we suspect illegal activity or misuse of Legion, or if the law requires it, we may preserve, retain, and secure information relevant to the matter, as set out in Section 2 of the Acceptable Use Policy. That can include:
- account and billing records;
- logs and network records; and
- the contents of rentals, containers, and images, on Legion's systems or on hosts connected to Legion.
We may examine preserved material in order to investigate. We may disclose it to law enforcement and other authorities, and cooperate with their investigations, as the law permits or requires.
9. Cookies and similar technologies
Legion uses essential cookies and similar technologies needed to operate the website and sign-in, for example session and security cookies. Our network provider may also set security cookies.
Legion's web app does not load third-party analytics or advertising scripts. If we introduce optional analytics in the future, we will give appropriate notice and choices where the law requires it.
10. Security
We use technical and organizational safeguards designed to protect information, including:
- encryption in transit;
- access controls;
- least-privilege practices; and
- short-lived credentials for access to rentals.
No system is completely secure. See Data Handling for the specific risks of running workloads on third-party hosts.
11. International users
Legion is a global service. Legion's control plane runs on AWS, and hosts are located wherever their providers operate them, which may be in a different country from you. Your information may therefore be processed in countries other than the one you live in. Where required, we rely on appropriate transfer mechanisms for cross-border data transfers.
12. Your rights and choices
Depending on where you live, you may have rights to:
- access, correct, or delete your personal information;
- object to or restrict certain processing; or
- receive a copy of your personal information.
To make a request, or to close your account and have your data deleted, email support@ambient.xyz.
- Verification. We may need to verify your identity before acting on a request.
- Limits. We may keep information where the law requires or permits it. This includes billing records, records of your acceptance of our terms, and material preserved under Section 8.
- Running rentals. Deleting your account ends your rentals, which deletes their data from hosts (see Data Handling).
13. Children
Legion is not directed to children, and you must be at least the age of majority in your jurisdiction to use it. We do not knowingly collect personal information from children under 13, or under the applicable age of digital consent where you live.
14. Changes to this policy
We may update this Privacy Policy from time to time. Each version has a version number and an effective date. We will give additional notice where the law requires it.
15. Contact
For privacy questions or requests, including deletion requests: support@ambient.xyz