Skip to main content

Privacy & Cookie Policy

Last updated: June 2026

Mythos AI Security (“Mythos,” “we,” “us,” or “our”) operates this website. This Privacy & Cookie Policy explains what information we collect through the website, how we use it, how we use cookies and analytics technologies, and the choices available to visitors.

This policy applies only to this website and the forms available on it. It does not apply to any separate product, platform, pilot, private demo environment, customer deployment, or contractual service unless that service specifically links to this policy.

1. Information we collect

We collect limited information from visitors in the following ways.

Information you submit directly

If you submit a contact, demo-request, investor-inquiry, or similar form, we may collect the information you choose to provide, such as:

  • Name
  • Work email address
  • Role, title, or job function
  • Organization, company, or firm name
  • Company size, industry, timeline, or inquiry type
  • Message content or other context you choose to include

Please do not submit classified information, controlled government information, sensitive security details, confidential customer data, protected health information, financial account information, or other sensitive personal information through public website forms.

Technical and security metadata

We may collect limited technical metadata needed to operate, secure, and protect the website, such as:

  • IP address
  • Browser and device information
  • Timestamp of request
  • Referring page or URL
  • Form-submission timing and rate-limiting signals
  • Basic server logs and security events

We use this information to help prevent spam, abuse, fraud, automated scraping, denial-of-service activity, and unauthorized access attempts.

Analytics information

If you consent to analytics cookies, we use Google Analytics 4 to understand how visitors use the website. Analytics information may include:

  • Pages viewed
  • Approximate region or country
  • Browser and device type
  • Referring source
  • Session and interaction events
  • General engagement metrics

We do not intentionally send names, email addresses, phone numbers, form message contents, or other directly identifying information to Google Analytics.

2. How we use information

We use information collected through the website to:

  • Respond to your inquiry
  • Schedule or follow up on demo requests
  • Review investor, partner, or business-development inquiries
  • Improve website performance, content, navigation, and usability
  • Understand general visitor interest and traffic patterns
  • Prevent spam, abuse, and security threats
  • Maintain records of correspondence
  • Comply with legal, regulatory, or contractual obligations

We do not sell your information.

We do not use website form submissions for third-party advertising.

3. Google Analytics

We use Google Analytics 4 (“GA4”) to measure website traffic and understand how visitors interact with the site.

Google Analytics may use cookies or similar technologies to distinguish visitors, persist session state, and generate aggregated analytics reports. GA4 commonly uses cookies such as:

CookieProviderPurposeDefault expiration
_gaGoogle AnalyticsUsed to distinguish users2 years
_ga_NZ4W73J9MGGoogle AnalyticsUsed to persist session state2 years

Our Google Analytics tag loads on all pages, but it runs in a consent-aware mode. Until you opt in through our cookie controls — and if you decline, or your browser sends a Global Privacy Control signal — it does not set analytics cookies and does not collect information that identifies you; Google may still receive limited anonymous, aggregated measurement signals that do not use cookies. Analytics cookies are set only after you consent.

Google states that Google Analytics 4 does not log or store IP addresses. Google may use IP addresses transiently for security and approximate geographic processing, but GA4 is designed not to make IP addresses available in Analytics reporting.

We do not currently use Google Analytics advertising features, Google Signals, remarketing, or Google Ads conversion tracking unless we separately disclose and enable those tools through the cookie settings.

You can also use Google’s Analytics opt-out browser add-on where supported. Google states that the add-on prevents Google Analytics JavaScript running on websites from sharing visit activity with Google Analytics.

4. Cookies and similar technologies

Cookies are small files placed on your browser or device. Similar technologies may include scripts, tags, local storage, pixels, or other browser-based identifiers.

We group cookies into the following categories.

Necessary cookies

Necessary cookies are required for the website to load, operate, secure forms, remember cookie preferences, and prevent abuse. These are always active.

Cookie / storage itemPurposeDuration
Cookie consent preference (stored in your browser)Stores your cookie choicesPersists until you clear it or our consent version changes
Security or rate-limiting dataHelps prevent spam and abuseSession to limited duration

Analytics cookies

Analytics cookies help us understand how visitors use the website. These are optional and are off unless you opt in.

CookieProviderPurposeDuration
_gaGoogle AnalyticsDistinguishes users for analytics2 years
_ga_NZ4W73J9MGGoogle AnalyticsPersists session state2 years

Marketing cookies

We do not currently use marketing cookies for behavioral advertising or remarketing.

If we add marketing, advertising, conversion-tracking, or retargeting technologies later, we will update this policy and keep those tools off unless you opt in where required.

5. Cookie choices

You can manage optional cookies at any time through the Cookie Settings control on the website or in the footer.

You may:

  • Accept optional analytics cookies
  • Reject optional analytics cookies
  • Change your cookie preferences later
  • Clear cookies through your browser settings
  • Use browser-level privacy controls or extensions

We honor the Global Privacy Control (GPC) signal where detected. If your browser sends a GPC signal, optional analytics and marketing cookies will remain off by default.

Browser settings may also allow you to block or delete cookies. Blocking necessary cookies may affect website functionality.

6. Service providers

We use service providers to operate the website and process inquiries.

Resend

We use Resend to transmit website form submissions to Mythos by email. Resend may process email addresses, message metadata, and message content as needed to deliver those messages.

Google Analytics

We use Google Analytics to provide analytics reports about website traffic and usage when analytics cookies are accepted.

Hosting, security, and infrastructure providers

Our website hosting, deployment, security, and infrastructure providers may process limited technical data needed to operate and secure the website.

We require service providers to process information only as needed to provide services to us, comply with applicable law, or protect their services.

7. Legal bases for processing

Where laws such as the GDPR or UK GDPR apply, we rely on the following legal bases:

  • Consent for optional analytics cookies and similar technologies.
  • Legitimate interests for website security, spam prevention, basic business communications, and responding to inquiries.
  • Contract or pre-contractual steps when you request information about services, demos, partnerships, or potential business relationships.
  • Legal obligation where we must retain or disclose information to comply with applicable law.

8. Data retention

We keep information only for as long as reasonably necessary for the purposes described in this policy.

Typical retention periods are:

  • Contact, demo, and investor inquiries: retained as long as needed to respond, manage the relationship, maintain business records, or comply with legal obligations.
  • Security logs and technical metadata: retained for a limited period needed for security, troubleshooting, and abuse prevention.
  • Cookie consent records: retained for the duration needed to remember and document your preferences.
  • Google Analytics data: retained according to our Google Analytics settings and Google’s applicable retention controls.

Retention periods may vary depending on the nature of the inquiry, legal requirements, security needs, and business-record obligations.

9. How we share information

We may share information:

  • With service providers who help operate the website, deliver form submissions, provide analytics, host the site, or secure our systems.
  • With professional advisors, such as attorneys, accountants, or consultants, where needed.
  • In connection with a business transaction, such as financing, merger, acquisition, corporate reorganization, or due diligence.
  • To comply with law, legal process, court orders, regulatory requests, or government requests.
  • To protect the rights, safety, property, or security of Mythos, our users, our systems, or others.

We do not sell personal information.

We do not share personal information for cross-context behavioral advertising.

10. Your privacy choices and rights

Depending on where you live, you may have rights to request that we:

  • Confirm whether we process information about you
  • Provide access to information you submitted
  • Correct inaccurate information
  • Delete information, subject to legal or business-record exceptions
  • Restrict or object to certain processing
  • Withdraw consent for optional cookies
  • Opt out of sale, sharing, targeted advertising, or profiling where applicable

To make a request, contact us at info@mythosaisecurity.com.

We may need to verify your request before responding. We will not discriminate against you for exercising privacy rights.

11. International visitors

Mythos is based in the United States. If you access the website from outside the United States, your information may be processed in the United States or other jurisdictions where our service providers operate.

Those jurisdictions may have data-protection laws different from those in your location.

12. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information submitted through the website.

No website, email transmission, or internet-based service can be guaranteed to be completely secure. Do not submit sensitive, classified, regulated, or highly confidential information through public website forms.

13. Children

This website is intended for business and professional visitors. It is not directed to children, and we do not knowingly collect personal information from children under 13.

14. Changes to this policy

We may update this Privacy & Cookie Policy from time to time. The “Last updated” date above reflects the latest version.

If we make material changes to how we collect, use, or share information, we will update this page and, where appropriate, provide additional notice.

15. Contact

Questions about this policy or privacy requests can be sent to:

Mythos AI Security
Email: info@mythosaisecurity.com