Legal
Privacy policy
Last updated: October 2, 2026
This policy explains how RecursionAI LLC (“RecursionAI,” “we,” “us”) handles information in connection with Midium Cloud, Midium Desktop, Vaults, and the Midium website (together, the “Services”).
The short version
Midium Desktop runs inference and your local Vaults on your machine. Prompts, outputs, files and any data ingested or generated are not discoverable by others, including the Midium team. Hardware running Midium Desktop can operate with no network connection once models are downloaded, making truly air-gapped AI fully attainable. Token-billed and dedicated cloud inference do not retain prompt data or generated response data. Hosted Vault contents persist until you delete them. We do not train on vault contents. When you send the contact form, we store what you send in Midium’s CRM so we can reply.
Information processed on your device
When you run Midium Desktop, prompts, completions, files, indexes, conversation history, and local Vaults are handled on your hardware and are not transmitted to RecursionAI. We have no access to this data.
Midium Cloud
Token-billed and dedicated cloud inference are processed to return a response, then discarded. We do not keep customer prompts or generated outputs as a product feature, log, or training corpus. We may process limited account, billing, and operational metadata required to run the service (for example, token counts and member counts for invoicing).
Vaults
Vaults are persistent context stores for a team’s codebase knowledge. You (and agents acting for you) write that context into them. Hosted Vaults on dedicated capacity are stored so they can be retrieved later — until you delete the vault or its items. We do not use vault contents to train models. Local Vaults never leave the licensed machine.
Private Relay
To operate Private Relay we see limited connection metadata, such as which devices are online, their network IPs, connection times, and relayed byte counts. We never see request contents, prompts, outputs, or Vault data.
Contact form inquiries
When you send the contact form, we collect the following.
| What we collect | Why |
|---|---|
| What you type: name, work email, company, role, topic, message, and the tier and intent you chose | To answer your inquiry, qualify it, and follow up |
| The plan you were looking at and any quiz answers you brought from the capacity page (optional) | To understand what you need before we reply |
| Your checkbox choices: the required agreement to be contacted about this inquiry, and the optional product updates box (unchecked by default) | To contact you about this inquiry, and to send product updates only if you ticked the optional box. Only the optional box counts as marketing consent |
| Where you came from: the page and button that opened the form, UTM campaign parameters, referrer, landing page, first-visit time, and submission time | To understand which pages bring inquiries |
| Country and region, from the IP geolocation headers our host Vercel adds to each request | To qualify and follow up on your inquiry |
| A one-way hash of your IP address (SHA-256 with a secret salt). The raw IP address is not stored | To prevent abuse |
Where it goes. Each submission is sent to Midium’s CRM, a database hosted on Supabase in the US. If the CRM can’t store a submission, the full submission is emailed to inquiries@midium.dev through Resend. The Midium team receives email alerts about new inquiries, and our email runs on Google Workspace. The site is hosted on Vercel.
Abuse prevention. To limit repeated submissions, the site holds your IP address in server memory only; it is not written to disk or sent to the CRM. A submission that fills in a hidden field meant for bots is discarded and not stored.
How long we keep it. We keep inquiry data as long as we need it to answer your inquiry and run our relationship with you, and until you ask us to delete it.
Your choices. Email inquiries@midium.dev to access, correct, or delete what we hold about you. We can export it or erase it on request. Product update emails carry an unsubscribe link.
Website
Vercel, which hosts the site, may keep standard request logs (IP address, user agent, pages requested) so we can run the site and investigate abuse. We do not use that traffic to reconstruct prompts or model outputs.
We use Vercel Web Analytics to count page views. It records the page, the referring page, and the browser, operating system, device type, and country. It does not set cookies.
Cookies and browser storage
The site sets no advertising or tracking cookies. On your first visit, it saves the time, landing page, and referrer, plus the first UTM campaign parameters it sees, in your browser’s local storage (keys starting with midium_). They stay on your device unless you send the contact form, which includes them. Clearing site data for midium.dev removes them.
If you sign in, the site also uses:
midium_session: an HTTP-only cookie that keeps you signed in, for up to 7 days.midium_workspace: an HTTP-only cookie that remembers the workspace you selected, for up to 7 days.sidebar_state: a cookie that remembers whether the dashboard sidebar is open, for up to 7 days.midium-dashboard-theme: a local storage entry that remembers your light or dark theme in the dashboard.
Contact
Questions: inquiries@midium.dev.