Privacy Policy
This Privacy Policy explains how NicNames, Inc. ("NicNames," "CDN.MN," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information in connection with CDN.MN.
Data Controller / Business
NicNames, Inc. 131 Continental Drive, Suite 301 Newark, Delaware 19713 United States Telephone: +1 (302) 883-8888 Privacy contact: privacy@cdn.mn
This Policy applies to the CDN.MN marketing website, Account dashboard, website analyzer, image optimization and delivery service, APIs, MCP tools, Agent registration and authorization, command-line and software-development tools, support, billing, and related services that link to it.
This Policy does not apply to a third-party website, Origin, repository, payment page, or integration that has its own privacy policy.
1. Our privacy roles
1.1 NicNames as controller or business
NicNames generally determines the purposes and means of processing personal information used for:
- Account creation and administration;
- authentication and session management;
- Workspace membership;
- Agent registration, authorization, approval, and revocation;
- billing and tax administration;
- customer support and communications;
- website operation;
- fraud, abuse, and security prevention;
- legal compliance; and
- our own service analytics and business operations.
For this processing, NicNames acts as a controller, business, or equivalent responsible entity under applicable privacy law.
1.2 NicNames as processor or service provider
When a Customer configures CDN.MN to retrieve, optimize, cache, or deliver Customer Content or CDN request data and determines the purpose and means of that processing, the Customer generally acts as controller or business and NicNames acts as processor or service provider.
The Customer is responsible for:
- providing legally required notices;
- establishing a lawful basis;
- honoring end-user choices;
- configuring domains, URLs, access, retention, and logging;
- responding to end-user requests; and
- ensuring that the Customer's use of CDN.MN complies with law.
The CDN.MN Data Processing Addendum governs processor activities where applicable.
2. Information we collect
2.1 Account and Workspace information
We may collect:
- email address;
- name, if provided;
- company or organization;
- country or region;
- Account identifier;
- Workspace identifiers;
- Workspace membership and role;
- Site and Origin configuration;
- language, timezone, and preferences;
- communication preferences;
- invitations;
- support identifiers; and
- Account status.
2.2 Authentication and session information
We collect or generate:
- one-time sign-in-code records;
- code creation, expiration, consumption, and attempt information;
- session identifiers and hashed session-token records;
- login and logout times;
- session expiration and revocation;
- IP address;
- user-agent string;
- browser and device information;
- security and fraud signals; and
- approximate location derived from IP address.
One-time codes are stored as a keyed HMAC rather than plain text and expire after ten minutes. Human sessions use a high-entropy token stored in a secure, HttpOnly cookie; the database stores only a cryptographic hash of the token.
2.3 Origin, domain, and service configuration
We may collect:
- Origin hostname and path;
- DNS TXT and HTTP-file verification information;
- verification status and history;
- generated CDN hostname;
- custom domain information, when available;
- transformation settings;
- width lists;
- quality and format settings;
- cache and purge configuration;
- source and delivery status;
- configuration changes and rollback data;
- plan entitlements;
- integration settings; and
- certificate and routing status.
2.4 CDN request and delivery data
When a request is made through CDN.MN, we may process:
- requested hostname;
- URL path;
- URL query parameters;
- Origin URL;
- request method;
- timestamp;
- IP address;
- approximate geographic region;
- user-agent string;
- browser or device characteristics;
- referrer, when supplied;
- accepted content formats and encodings;
- protocol and TLS information;
- response status;
- response format;
- bytes delivered;
- cache status;
- Origin response information;
- latency;
- transformation parameters;
- request identifier;
- security signals; and
- error and diagnostic information.
Customers should not place passwords, private keys, payment data, health data, government identifiers, or other secrets in publicly accessible asset URLs or query strings.
2.5 Customer Content
Depending on Customer configuration, we may process:
- JPEG, PNG, WebP, AVIF, and GIF images;
- file names and paths;
- image dimensions;
- EXIF and other embedded metadata;
- color-profile and orientation information;
- generated optimized variants;
- Agent instructions and configuration; and
- other Customer Content supported by a feature made available under the applicable plan.
We process Customer Content to provide, secure, meter, troubleshoot, and support the Service.
We do not use Customer Content to train generalized artificial-intelligence models unless the Customer separately and expressly opts in.
2.6 Website analyzer data
When a person or Agent submits a public website or image to the website analyzer, we may collect:
- submitted URL;
- page title and technical metadata;
- public pages and image assets discovered;
- asset URLs;
- source and rendered dimensions;
- format;
- transferred bytes;
- response and cache headers;
- Origin information;
- estimated optimized sizes;
- generated preview images;
- scan errors;
- findings and recommendations;
- scan time;
- submitter IP address;
- rate-limit identifier;
- Account or Agent association, if applicable; and
- exported report data.
The analyzer is designed for publicly reachable resources. Do not submit private-network URLs, authenticated resources, or URLs containing secrets.
2.7 Agent and automated-client information
When an Agent or automated client interacts with CDN.MN, we may collect:
- Agent name and description;
- software and version;
- Agent provider, if supplied;
- registration identifier;
- user-code and device-code metadata;
- claim status;
- associated user and Workspace;
- requested, approved, denied, and revoked scopes;
- per-scope approval policy;
- token identifier and cryptographic hash;
- token audience;
- token creation, use, expiration, and revocation times;
- MCP, API, CLI, and SDK operations;
- dry-run and idempotency information;
- proposed changes;
- warnings;
- approval requests and decisions;
- execution results;
- verification steps;
- rollback information;
- errors;
- audit events;
- IP address and user agent; and
- security and rate-limit signals.
A pending Agent claim expires after fifteen minutes. An issued Agent access token expires after twenty-four hours unless revoked earlier.
2.8 Repository and integration information
If Customer connects a repository, DNS provider, deployment platform, or other integration, we may receive:
- provider account and installation identifiers;
- organization and repository name;
- branch and commit metadata;
- file paths and selected file content necessary for the requested task;
- AGENTS.md or similar repository instructions;
- framework and build-system information;
- permissions;
- webhook events;
- pull-request and deployment metadata;
- test and build results;
- changed-file information;
- integration logs; and
- provider-token metadata.
We access connected-service information only within the permissions granted through that provider and the Customer's instructions.
2.9 Billing and transaction information
We and our payment processor may collect:
- billing name;
- company;
- billing address;
- country and tax jurisdiction;
- tax identifiers;
- plan;
- usage;
- credits;
- balance;
- auto-reload settings;
- payment-method token;
- payment-method type and limited details;
- invoice and receipt data;
- transaction identifiers;
- payment status;
- refunds;
- disputes;
- failed-payment information; and
- fraud-risk signals.
Full payment-card details are collected and processed by the payment processor rather than stored directly by CDN.MN.
2.10 Support, abuse, legal, and security communications
We collect information you provide through:
- support requests;
- privacy requests;
- abuse and copyright reports;
- vulnerability reports;
- legal notices;
- emails;
- surveys;
- product feedback; and
- other communications.
This may include message content, attachments, identifiers, technical records, and contact information.
2.11 Website and device information
When you visit our websites, we may collect:
- IP address;
- browser and device type;
- operating system;
- language;
- referring page;
- pages requested;
- date and time;
- session-cookie information;
- theme preference stored in local browser storage;
- security events; and
- diagnostic information.
At the Effective Date, CDN.MN does not use advertising cookies or cross-site behavioral tracking on its own pages.
3. How we collect information
We collect information:
- directly from you;
- from your organization or Workspace administrator;
- from an Agent you authorize;
- automatically from your browser, device, or API client;
- from Customer-configured Origins and public resources;
- from payment, email, security, and identity providers;
- from connected repositories, DNS, or deployment platforms;
- from our infrastructure and service providers; and
- from public sources where lawful.
4. How we use information
We use personal information to:
- create and administer Accounts, Workspaces, Sites, and roles;
- authenticate users and maintain sessions;
- register, authorize, scope, approve, audit, and revoke Agents;
- retrieve, validate, transform, cache, and deliver Customer Content;
- verify Origins and domains;
- operate the website analyzer and generate reports and previews;
- provide APIs, MCP tools, CLI, SDKs, and integrations;
- measure requests, delivery, transformations, cache performance, and savings;
- calculate credit, usage, charges, and plan entitlements;
- process payments, invoices, refunds, and billing communications;
- provide support and respond to requests;
- send authentication, service, security, billing, legal, and policy notices;
- detect, investigate, and prevent fraud, abuse, attacks, credential misuse, and policy violations;
- debug, monitor, maintain, and improve reliability;
- develop and evaluate new features;
- enforce agreements and protect legal rights;
- comply with law, legal process, and regulatory requirements;
- create aggregated or deidentified statistics; and
- communicate about CDN.MN products where permitted.
5. Legal bases for processing
Where applicable law requires a legal basis, we rely on:
5.1 Contract
Processing necessary to provide the Service, administer Accounts, perform Customer instructions, process billing, and fulfill an Order.
5.2 Legitimate interests
Processing necessary for:
service operation and improvement;
security and fraud prevention;
abuse detection;
authentication;
support;
billing administration;
business communications;
network and system monitoring; and
protection of legal rights,
provided those interests are not overridden by applicable rights.
5.3 Consent
Processing based on consent where required, including optional marketing or nonessential tracking if introduced.
You may withdraw consent, but withdrawal does not affect prior lawful processing.
5.4 Legal obligation and legal claims
Processing necessary to comply with tax, accounting, sanctions, court, regulatory, or other legal obligations or to establish, exercise, or defend legal claims.
6. How we disclose information
6.1 Service providers and subprocessors
We disclose information to contracted providers that support:
- cloud hosting and compute;
- databases and storage;
- content delivery;
- email delivery;
- DNS and certificates;
- monitoring and logs;
- payment processing;
- fraud prevention;
- customer support;
- security;
- repository and deployment integrations; and
- professional services.
A current list of subprocessors and their functions is published in the CDN.MN Subprocessor List.
Providers may process information only under applicable contractual and legal obligations.
6.2 Customer administrators
Workspace owners and authorized administrators may access information concerning:
- Authorized Users;
- Agent registrations and permissions;
- Sites and Origins;
- domains;
- configuration;
- usage;
- billing;
- integrations; and
- audit events.
6.3 Customer-directed integrations
We disclose information to a third-party integration when Customer connects or directs us to use it. The third party's terms and privacy policy also apply.
6.4 Legal, safety, and rights protection
We may disclose information where we reasonably believe disclosure is necessary to:
- comply with law, regulation, subpoena, court order, or legal process;
- respond to a lawful government request;
- enforce agreements and policies;
- investigate fraud, abuse, infringement, or a security incident;
- protect the rights, safety, or property of NicNames, Customers, users, or the public; or
- establish, exercise, or defend a legal claim.
Where lawful and appropriate, we may notify the affected Customer.
6.5 Business transactions
We may disclose or transfer information in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality protections.
6.6 With direction or consent
We may disclose information as otherwise directed or authorized by you.
6.7 Aggregated and deidentified information
We may use and disclose aggregated or deidentified information that does not reasonably identify an individual. We will not attempt to reidentify information we have committed to maintain as deidentified except to test the effectiveness of deidentification.
7. No sale, cross-context sharing, or generalized AI training
We do not sell personal information for money.
At the Effective Date, we do not share personal information for cross-context behavioral advertising or use it for targeted advertising on third-party sites.
We do not use Customer Content or private repository content to train generalized artificial-intelligence models without a separate, express opt-in.
If these practices change, we will update this Policy and provide legally required notice and choice before the change applies.
8. Cookies and similar technologies
We use a strictly necessary session cookie to authenticate signed-in users. The cookie is:
- named __Host-cdnmn_session;
- HttpOnly;
- Secure;
- SameSite=Lax;
- restricted to path /; and
- subject to the session lifetimes described above.
We also use local browser storage to remember the selected light, dark, or automatic theme.
A third-party hosted checkout may set its own necessary, security, fraud-prevention, or preference technologies under the payment provider's privacy policy.
More detail appears in the CDN.MN Cookie Notice.
9. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including contractual, billing, tax, security, fraud-prevention, abuse, dispute, and legal needs.
Our principal retention periods are published in the CDN.MN Data Retention Schedule. At the Effective Date, they include:
- one-time sign-in-code validity: ten minutes;
- active human sessions: seven days idle and thirty days absolute;
- pending Agent claims: fifteen minutes;
- Agent access tokens: twenty-four hours;
- application operational logs: thirty days;
- raw CDN access logs: ninety days;
- anonymous analyzer records and previews: up to thirty days;
- billing and tax records: seven years;
- Account and Workspace data: during the relationship and ordinarily up to thirty days after confirmed deletion, subject to exceptions; and
- backups: ordinarily overwritten or deleted within ninety days.
Cached optimized variants may remain until purge, expiry, eviction, Site deletion, or Account closure. Edge cache behavior may include a default thirty-day cache lifetime and a longer maximum lifetime, while deletion from origin storage follows our deletion workflow.
We may retain limited information longer where necessary to:
- comply with law;
- collect fees;
- resolve disputes;
- enforce agreements;
- prevent fraud or repeat abuse;
- maintain security;
- preserve audit evidence;
- honor a legal hold; or
- protect legal claims.
10. Cache and deletion propagation
Customer Content may exist temporarily at multiple edge locations, in processing systems, queues, origin cache storage, or backups.
A purge or deletion request initiates invalidation or removal, but complete propagation is not instantaneous.
We may retain identifiers, hashes, usage aggregates, billing records, security events, or abuse evidence after Customer Content is removed where reasonably necessary and lawful.
11. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These include, as appropriate:
- encryption in transit;
- encryption at rest;
- access controls;
- least-privilege permissions;
- server-side revocable sessions;
- scoped Agent tokens;
- cryptographic hashing of session and Agent tokens;
- keyed protection of one-time codes;
- audit logging;
- network restrictions;
- Origin and redirect validation;
- rate limiting;
- resource limits;
- vulnerability management;
- monitoring and incident response;
- backups; and
- confidentiality obligations.
No security measure is perfect. You are responsible for securing your Account, email, devices, Origins, domains, Agents, repositories, integrations, and payment-provider account.
Security concerns may be reported to security@cdn.mn.
12. International data transfers
NicNames is established in the United States. Information may be processed in the United States and other countries where we or our providers operate.
Where applicable law requires a transfer mechanism, we may use:
- adequacy decisions;
- the European Commission's Standard Contractual Clauses;
- the United Kingdom International Data Transfer Addendum or Agreement;
- contractual safeguards; or
- another lawful transfer mechanism.
The CDN.MN Data Processing Addendum includes processor transfer terms for eligible business Customers.
13. Your privacy rights
Depending on your jurisdiction and the circumstances, you may have rights to:
- know whether we process personal information;
- access personal information;
- correct inaccurate information;
- delete information;
- receive a portable copy;
- restrict processing;
- object to processing;
- withdraw consent;
- opt out of sale, sharing, or targeted advertising;
- limit certain uses of sensitive personal information;
- appeal a denied request; and
- complain to a privacy regulator.
Submit a request to privacy@cdn.mn.
We may verify your identity and authority before completing a request. We may deny or limit a request where permitted by law, including where we cannot verify identity, must retain information, or the request would adversely affect another person's rights.
Authorized agents may submit requests where permitted by law. We may require proof of authority and direct identity verification.
We will not unlawfully discriminate against you for exercising a privacy right.
14. Customer end users
If your information appears in Customer Content or CDN request data controlled by a CDN.MN Customer, the Customer generally controls that information.
You should first contact the website or service that caused the data to be processed. We will assist the Customer with valid requests as required by contract and law.
15. United States state privacy notices
Where a U.S. state comprehensive privacy law applies, this Policy describes the categories of personal information we collect, sources, purposes, recipients, and retention criteria.
Depending on the law, applicable categories may include:
- identifiers;
- customer-record information;
- commercial information;
- Internet or electronic-network activity;
- approximate geolocation;
- professional or employment-related information;
- inferences relating to service use; and
- sensitive personal information such as Account credentials and precise authorization records.
We use and disclose those categories for the purposes and recipients described in this Policy.
We do not knowingly sell or share the personal information of persons under sixteen.
At the Effective Date, CDN.MN does not sell personal information or use cross-context behavioral advertising. If we introduce a practice that requires an opt-out, we will provide a clear "Your Privacy Choices" mechanism and honor applicable browser-based opt-out preference signals.
A denied state privacy request may be appealed by emailing privacy@cdn.mn with subject "Privacy Appeal."
16. Children
The Service is intended for adults acting in a business or professional capacity and is not directed to children.
We do not knowingly allow anyone under eighteen to create an Account. We do not knowingly collect personal information directly from children under thirteen through Account registration.
If you believe a child has provided personal information directly to us, contact privacy@cdn.mn.
Customers may not use CDN.MN to operate a child-directed service or process children's personal information in violation of applicable law.
17. Sensitive and regulated data
Do not submit highly sensitive personal information unless necessary, lawful, and expressly supported under an applicable Order.
Unless separately agreed in writing, the Service is not intended for:
- protected health information regulated by HIPAA;
- full payment-card numbers;
- government-classified information;
- biometric templates used for identification;
- Social Security numbers or equivalent government identifiers;
- passwords, private keys, or access tokens in public URLs; or
- data requiring a specialized regulated environment.
18. Automated processing
We may use automated systems to:
- detect fraud and abuse;
- identify security threats;
- enforce rate and resource limits;
- assess Account, payment, or request risk;
- classify file formats;
- calculate optimization opportunities;
- route operational review; and
- execute authorized Agent actions.
We do not intend to make decisions producing legal or similarly significant effects about individuals solely through automated processing.
Where applicable law provides a right concerning such a decision, contact privacy@cdn.mn.
19. Communications
19.1 Service communications
We may send transactional messages concerning:
- authentication;
- security;
- Agent claims and approvals;
- billing and credits;
- usage;
- domains and Origins;
- incidents;
- support;
- legal terms; and
- Account status.
You cannot opt out of communications necessary to provide or secure an active Account.
19.2 Marketing communications
We may send product news or offers where permitted. You may unsubscribe through the message or by contacting us. Unsubscribing from marketing does not stop necessary service communications.
20. Third-party services and links
A third-party service connected to CDN.MN processes information under its own privacy policy and terms. We are not responsible for third-party privacy practices that we do not control.
21. Changes to this Policy
We may update this Policy.
We will post the updated version and change the Effective Date or Last Updated date. For a material change, we will provide reasonable additional notice and obtain consent where required before the change applies.
22. Contact and complaints
Privacy questions, requests, and appeals:
privacy@cdn.mn
NicNames, Inc. Attention: Privacy 131 Continental Drive, Suite 301 Newark, Delaware 19713 United States +1 (302) 883-8888
You may also have a right to complain to the privacy or data-protection authority in your jurisdiction.