Privacy
This page describes how mureo.io — the website you are reading — handles visitor data today. It is not a perpetual promise. If our practices change, this page is updated with a new "Last updated" date. For the data posture of the mureo OSS framework (separate product, runs on your machine), see /security/.
Who runs this site
This website is operated by Logly, Inc. (ログリー株式会社) — the same company that operates mureo.jp and the commercial editions of mureo. Where this page says "we", it means Logly, Inc.
What this site collects today
There are two layers. The first is always on and uses no cookies. The second only runs if you choose to accept it.
Always on: Cloudflare cookieless analytics
We use Cloudflare Web Analytics in its cookieless mode. It sets no cookies and runs whether or not you accept the analytics banner. For each page view, it records:
- The URL visited
- The HTTP
Refererheader (if your browser sends one) - Screen and viewport dimensions
- A coarse geography derived from IP; the IP itself is not stored
- A browser / OS user-agent category
Data is aggregated at the edge and retained by Cloudflare for up to 6 months. We do not export it, join it with other sources, or attempt to de-anonymize it.
Only if you accept: Google Analytics 4
We load Google Analytics 4 through Google Tag Manager. This is off by default. It loads under Google Consent Mode v2, which we set to deny analytics storage until you press Accept analytics on the cookie banner. If you never accept, Google Analytics does not store anything and sets no cookies.
If you do accept, Google Analytics sets its own cookies (for
example _ga and _ga_*) to tell repeat
visits apart, and sends usage data to Google. We
use it for traffic analysis and to measure which pages lead to a
conversion. We keep advertising signals (ad storage,
personalization) denied even after you accept, so this is analytics
only, not ad targeting.
When you contact us
The contact form on the commercial page is the one place where we ask for personal details. Sending it is entirely optional — nothing on the site requires it, and browsing collects none of this. When you do submit the form, we receive what you type into it:
- Your name (first and last)
- Company
- Email address
- How you'd use mureo (the option you pick)
- Your message
These details are sent to HubSpot, the form and CRM processor we use, and stored there on our behalf. We use them only to reply to your enquiry and, where relevant, to discuss mureo with you. We do not use them for advertising and do not sell or share them. HubSpot processes the data as our provider under its own terms; see HubSpot's privacy policy. If you would prefer not to use the form, you can email us instead at mureo@logly.co.jp.
What this site does not do today
- Set any cookies unless you accept analytics on the banner (Cloudflare's layer stays cookieless either way)
- Fingerprint your device across sites
- Collect personal information from you unless you choose to send it through the contact form (see When you contact us above)
- Run an advertising or remarketing pixel (no Meta Pixel, no Google Ads tag, no LinkedIn Insight Tag); ad storage and personalization stay denied even if you accept analytics
- Sell or share data with third parties
Managing your choice
When analytics is enabled on the site you see a banner at the bottom of the page with two options:
- Accept analytics turns on Google Analytics 4 for your browser.
- Essential only leaves it off; only the cookieless Cloudflare layer runs.
Your choice is stored locally in your browser (in
localStorage, not a cookie we send anywhere) so we do
not ask again on every visit. To change it later, use the
Cookie settings link in the page footer: it clears
the stored choice and shows the banner again. Clearing your
browser storage has the same effect.
Third-party resources loaded by the page
The page loads a small number of externally-hosted resources. Each has its own privacy policy:
- Cloudflare — serves the entire site and provides the cookieless analytics beacon. See Cloudflare's privacy policy.
- Google Fonts — serves the Inter typeface from
fonts.googleapis.comandfonts.gstatic.com. See Google's privacy policy. - Google Tag Manager and Google Analytics 4 — loaded only after you accept analytics on the banner (see above). Google Tag Manager loads the analytics tag; Google Analytics 4 receives the usage data. Both are operated by Google. See Google's privacy policy.
- HubSpot — receives your contact-form submission when (and only when) you send the form. No HubSpot script or cookie is loaded while you browse. See HubSpot's privacy policy.
- Outbound links — links to
github.com,pypi.org, or other services send you to those destinations. Each has its own privacy policy; we do not receive data from those clicks.
Future changes
We may add additional analytics, conversion tracking, or advertising tools in the future. If we do:
- This page will be updated with a new "Last updated" date
- Where required, a cookie-consent banner will be added before any non-cookieless tool loads
- Material changes will be noted in the blog so returning visitors have a chance to notice
Related: the mureo OSS framework
The mureo framework is a separate product. It runs
on the operator's machine, loads credentials from local disk,
and makes API calls directly to the platforms the operator has
authenticated — with no routing through any infrastructure we
operate. Its data posture, including the threat model and the
commitments it makes, is documented at
/security/ (mirrored from
logly/mureo/SECURITY.md).
Contact
Security reports (for the framework or this site): GitHub private vulnerability reporting .
Other privacy questions: open an issue at github.com/logly/mureo.