Privacy · mureo.io

Privacy

This page describes how mureo.io — the website you are reading — handles visitor data today. It is not a perpetual promise. If our practices change, this page is updated with a new "Last updated" date. For the data posture of the mureo OSS framework (separate product, runs on your machine), see /security/.

Who runs this site

This website is operated by Logly, Inc. (ログリー株式会社) — the same company that operates mureo.jp and the commercial editions of mureo. Where this page says "we", it means Logly, Inc.

What this site collects today

There are two layers. The first is always on and uses no cookies. The second only runs if you choose to accept it.

Always on: Cloudflare cookieless analytics

We use Cloudflare Web Analytics in its cookieless mode. It sets no cookies and runs whether or not you accept the analytics banner. For each page view, it records:

  • The URL visited
  • The HTTP Referer header (if your browser sends one)
  • Screen and viewport dimensions
  • A coarse geography derived from IP; the IP itself is not stored
  • A browser / OS user-agent category

Data is aggregated at the edge and retained by Cloudflare for up to 6 months. We do not export it, join it with other sources, or attempt to de-anonymize it.

Only if you accept: Google Analytics 4

We load Google Analytics 4 through Google Tag Manager. This is off by default. It loads under Google Consent Mode v2, which we set to deny analytics storage until you press Accept analytics on the cookie banner. If you never accept, Google Analytics does not store anything and sets no cookies.

If you do accept, Google Analytics sets its own cookies (for example _ga and _ga_*) to tell repeat visits apart, and sends usage data to Google. We use it for traffic analysis and to measure which pages lead to a conversion. We keep advertising signals (ad storage, personalization) denied even after you accept, so this is analytics only, not ad targeting.

When you contact us

The contact form on the commercial page is the one place where we ask for personal details. Sending it is entirely optional — nothing on the site requires it, and browsing collects none of this. When you do submit the form, we receive what you type into it:

  • Your name (first and last)
  • Company
  • Email address
  • How you'd use mureo (the option you pick)
  • Your message

These details are sent to HubSpot, the form and CRM processor we use, and stored there on our behalf. We use them only to reply to your enquiry and, where relevant, to discuss mureo with you. We do not use them for advertising and do not sell or share them. HubSpot processes the data as our provider under its own terms; see HubSpot's privacy policy. If you would prefer not to use the form, you can email us instead at mureo@logly.co.jp.

What this site does not do today

  • Set any cookies unless you accept analytics on the banner (Cloudflare's layer stays cookieless either way)
  • Fingerprint your device across sites
  • Collect personal information from you unless you choose to send it through the contact form (see When you contact us above)
  • Run an advertising or remarketing pixel (no Meta Pixel, no Google Ads tag, no LinkedIn Insight Tag); ad storage and personalization stay denied even if you accept analytics
  • Sell or share data with third parties

Managing your choice

When analytics is enabled on the site you see a banner at the bottom of the page with two options:

  • Accept analytics turns on Google Analytics 4 for your browser.
  • Essential only leaves it off; only the cookieless Cloudflare layer runs.

Your choice is stored locally in your browser (in localStorage, not a cookie we send anywhere) so we do not ask again on every visit. To change it later, use the Cookie settings link in the page footer: it clears the stored choice and shows the banner again. Clearing your browser storage has the same effect.

Third-party resources loaded by the page

The page loads a small number of externally-hosted resources. Each has its own privacy policy:

  • Cloudflare — serves the entire site and provides the cookieless analytics beacon. See Cloudflare's privacy policy.
  • Google Fonts — serves the Inter typeface from fonts.googleapis.com and fonts.gstatic.com. See Google's privacy policy.
  • Google Tag Manager and Google Analytics 4 — loaded only after you accept analytics on the banner (see above). Google Tag Manager loads the analytics tag; Google Analytics 4 receives the usage data. Both are operated by Google. See Google's privacy policy.
  • HubSpot — receives your contact-form submission when (and only when) you send the form. No HubSpot script or cookie is loaded while you browse. See HubSpot's privacy policy.
  • Outbound links — links to github.com, pypi.org, or other services send you to those destinations. Each has its own privacy policy; we do not receive data from those clicks.

Future changes

We may add additional analytics, conversion tracking, or advertising tools in the future. If we do:

  • This page will be updated with a new "Last updated" date
  • Where required, a cookie-consent banner will be added before any non-cookieless tool loads
  • Material changes will be noted in the blog so returning visitors have a chance to notice

Related: the mureo OSS framework

The mureo framework is a separate product. It runs on the operator's machine, loads credentials from local disk, and makes API calls directly to the platforms the operator has authenticated — with no routing through any infrastructure we operate. Its data posture, including the threat model and the commitments it makes, is documented at /security/ (mirrored from logly/mureo/SECURITY.md).

Contact

Security reports (for the framework or this site): GitHub private vulnerability reporting .

Other privacy questions: open an issue at github.com/logly/mureo.