Fugu Privacy Policy
Last Updated: May 25, 2026
1. Scope of This Privacy Policy
This Fugu Privacy Policy (“Privacy Policy”) explains how Sakana AI Co, Ltd. (“we,” “our,” or “us”) collects, uses, retains, discloses, and otherwise processes your personal data in connection with our AI orchestration service named Fugu (the “Service”).
This Privacy Policy does not apply to our processing of personal data for the purposes of other products or services that we provide. The processing of personal data for such other purposes is governed by other privacy policies in relation to those products or services, which you should review if you interact with those other products or services.
2. How We Collect Your Personal Data and What Personal Data We Collect
We may process your personal data collected directly from you, automatically from your use of the Service, or from third parties depending on how you use the Service.
Such personal data may include:
- Account and profile data, such as name, email address, account identifiers, billing information, and settings;
- Service interaction data, such as prompts, uploaded content, outputs, feedback, feature usage, session data, timestamps, and request identifiers;
- Technical data, such as IP address, browser type, device identifiers, operating system, crash logs, diagnostic logs, and security signals; and
- Support and communications data, such as support tickets, contact forms, survey responses, and correspondence.
Without the personal data described above, we may be unable to provide you all or part of the Services, and any differences in Services are related to your personal data. We may aggregate or de-identify the information described above. Aggregated or de-identified data is not subject to this Privacy Policy.
3. Purposes of Processing Your Personal Data
We may process your personal data for the following purposes:
- To provide, operate, maintain, secure, support, and improve the Service;
- To authenticate users, prevent fraud, maintain security, enforce our Terms of Use and other relevant policies or agreements, comply with legal obligations, and resolve disputes;
- To analyze usage, measure reliability, investigate incidents, and perform debugging and quality assurance;
- To train, fine-tune, evaluate, and improve our models and systems, subject to available opt-out settings and our internal controls; and
- To communicate with users, administer accounts, process billing, and respond to inquiries.
4. Disclosure of Your Personal Data
We may disclose your personal data to the following recipients for the purposes described in Section 3 above and as otherwise permitted or required by applicable laws:
- Authorized vendors and service providers, including large language models (LLMs) and providers of cloud storage and infrastructure, analytics, payment processing, customer support, and others that support us in providing the Services;
- Professional advisers and consultants;
- Buyer(s) or other successor(s) in the event of a corporate business transaction, such as a merger, business transfer, joint venture, the financing or sale of company asset acquisition, company split, insolvency, bankruptcy, or receivership;
- For legal purposes (such as for legal process or in response to a court order or subpoena) or to governmental or other regulatory authorities; and
- Other third parties for purposes disclosed to you at the time we collect your personal data or pursuant to your consent.
5. International Transfer of Your Personal Data
Your personal data may be transferred to third parties located outside your country of residence, including to Japan and the United States. Where we transfer your personal data to third parties located outside the country of your residence, we will comply with applicable data protection laws by implementing appropriate safeguards, such as:
- transferring the data to countries or territories that are recognized as ensuring an adequate level of protection for personal data under applicable data protection laws;
- entering into data transfer agreements with the recipient, as required by applicable data protection laws; or
- obtaining your consent where required under applicable laws.
You may confirm additional details about the protection given if your personal data is transferred outside your resident country by contacting us using the contact details in Section 11 below.
6. Retention Period for Your Personal Data
We retain your personal data only to the extent and for as long as reasonably necessary for the purposes described in Section 3 above. However, this does not apply if we are required by applicable laws or regulations to retain your personal data for a longer period, in which case, we will retain it for the period required by such applicable laws or regulations.
Retention periods may vary by data type, account status, legal obligations, and operational needs. Specific retention schedules may be disclosed in supplemental notices or product documentation.
7. Your Rights and Choices
Depending on where you are located, you may have certain rights in relation to your personal data, including the right to access, correct, and delete, and to request discontinuation of our usage of, your personal data. You may exercise your available rights and obtain detailed information regarding how to exercise them by contacting us, using the information in Section 11 below or the relevant account tools we make available.
If we offer opt-out control for training or fine-tuning use, you may activate that control through the relevant account or product setting. Once effective, we will use commercially reasonable efforts to exclude eligible content from future training or fine-tuning datasets, subject to backup, security, integrity needs, and other requirements under applicable laws. Unless otherwise required by applicable laws, opt-out may not retroactively remove data from models or datasets already trained or derived before the opt-out became effective.
8. Security
We take measures to prevent any leakage or loss of, or damage to, your personal data to be processed and to otherwise maintain the security of personal data, such as establishing rules for the processing of personal data, regular monitoring of the processing of personal data, regular training of employees in the processing of personal data, prevention of theft or loss of equipment used to process personal data, and implementation of access controls. We also exercise appropriate supervision over our service providers and employees who process personal data. If we process personal data in a country outside your resident country, we implement appropriate security control measures in light of that country’s legislation to protect personal data.
9. Children
The Service is intended only for persons eighteen (18) years of age or older. Therefore, we do not knowingly process any personal data of children whose age is under eighteen (18) years. If we discover that we have collected personal data from a child, we will delete that data as soon as possible.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be notified by posting an updated effective date as indicated by the “last updated” date at the beginning of this Privacy Policy, or through other reasonable means. We encourage you to regularly check back on this Privacy Policy to stay apprised of any updates.
11. Contact
If you have any questions, requests, concerns, or complaints about this Privacy Policy and addendum thereto and your personal data, please contact us via the web form linked here.
For Residents of California
1. Scope of This California Addendum
This addendum to our Privacy Policy for residents of California (this “California Addendum”) explains how we process personal information of California residents in connection with the Service under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 and implementing regulations issued thereunder (collectively, the “CCPA”).If you are a “consumer” within the meaning of the CCPA, this California Addendum applies to you.
This California Addendum supplements and forms an integral part of the Privacy Policy, and prevails over any conflicting or inconsistent provisions in the Privacy Policy.
2. CCPA Disclosures
A. Collection of Your Personal Information
Section 2 of the Privacy Policy lists personal information that we may collect, and have collected within the preceding twelve (12) months, from you and the categories of sources from which we may collect, and have collected within the preceding twelve (12) months, your personal information. Such personal information is classified into the following categories of personal information as set forth in the CCPA:
- Identifiers, including name, email address, account identifiers, IP address, and request identifiers;
- Other information, including billing information, settings, and support and communication data, such as support tickets, contact forms, survey responses, and correspondence;
- Commercial information, including service interaction data, such as prompts, uploaded content, outputs, feedback, feature usage, session data, timestamps, and request identifiers; and
- Internet or network activity information, including IP address, browser type, device identifiers, operating system, crash logs, diagnostic logs, and security signals.
- Sensitive personal information, including account data in combination with credential/authentication for user log-in.
Section 3 of the Privacy Policy lists the business or commercial purposes for which we may collect and use, or collected within the preceding twelve (12) months, your personal information.
We retain each category of your personal information as described in Section 6 in the Privacy Policy.
B. Sale, Sharing, and Disclosure of Your Personal Information
We do not sell or share personal information, including the personal information of consumers under sixteen (16) years of age.
The following list describes the categories of personal information that we disclosed to service providers or contractors for our business or commercial purposes within the preceding twelve (12) months:
- Identifiers
- Other information
- Commercial information
- Internet or network activity information
- Sensitive personal information
Section 3 of the Privacy Policy lists the business or commercial purposes for which we disclosed your personal information within the preceding twelve (12) months.
C. Your Rights and Requests
Under the CCPA, you are entitled to the following rights:
- Right to know/access. You have the right to know and request access in a portable format to (i) the categories of personal information that we collected about you within the preceding twelve (12) months, (ii) the categories of sources from which we have collected personal information, (iii) business or commercial purpose for collecting personal information, (iv) the categories of third parties to whom we disclose personal information, and (v) specific pieces of personal information we collected about you. You may only make a request for access twice within a twelve (12)-month period.
- Right to delete. You have the right to request deletion of your personal information that we collect or maintain, subject to certain exceptions.
- Right to correct. You have the right to request correction of inaccurate personal information that we collect or maintain about you.
Please note that we do not use or disclose your sensitive personal information (as defined in the CCPA) for any purposes not expressly permitted by the CCPA that require us to support the right to limit the use or disclosure of your sensitive personal information.
To exercise these rights, where applicable, you may submit a request to us via the web form linked here.
To help protect your privacy and maintain security, we will take steps to verify your identity before granting you access to your personal information or complying with your deletion or correction request. Upon receiving a request from you, we will first verify your identity by requiring you to submit information necessary to verify it, such as your name, email address, and credential/authentication for user log-in, and by matching the information you provide with what we already have on file.
If you use an authorized agent to make a request on your behalf, we may require the authorized agent to provide proof that the consumer gave the agent signed permission to make the request. Also, we may require you to either (i) verify your own identity directly with us (as described above), or (ii) directly confirm with us that you provided the authorized agent permission to submit the request.
Additionally, you have the right not to be retaliated against for exercising privacy rights if and when you exercise your rights under the CCPA.
3. California Do Not Track
Cal. Bus. & Prof. Code § 22575(b) provides that California residents are entitled to know how we respond to “Do Not Track” browser settings. We do not currently take action to respond to Do Not Track signals because a uniform technological standard has not yet been developed.
4. California Shine the Light
Within the meaning of California’s “Shine the Light” law (Cal. Civ. Code § 1798.83), we do not disclose personal information to third parties for their own direct marketing purposes.
For U.S. Residents of Certain States Other Than California
1. Scope of This Other States Addendum
States other than California including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia have a comprehensive consumer data protection law (“Other State’s Data Protection Law”).
If you are a “consumer” within the meaning of any of the Other State’s Data Protection Law, this addendum for U.S. residents in certain states other than California (this “Other States Addendum”) applies to you.
This Other States Addendum supplements the Privacy Policy and prevails over any conflicting or inconsistent provisions in the Privacy Policy.
2. Collection and Disclosure of Your Personal Data
Please see Sections 2, 3, and 4 of the Privacy Policy and Sections 2.A and 2.B. of the California Addendum.
3. Your Rights and Requests
Other State’s Data Protection Law provides consumers with certain privacy rights, which may include those listed below. Ultimately, the particular law of each applicable state will determine how rights apply to individuals within those states.
- Rights to Access and Data Portability. You have the right to request details regarding our processing and access to your personal data and to obtain your personal data in a portable format, and you may have the right to obtain your personal data in a readily usable format, to the extent feasible. You may have the right to request a list of third parties with whom we share personal information here.
- Right to Correct. You have the right to request that we correct inaccurate personal data.
- Right to Delete. You may have the right to request that we delete the personal data we have collected about you.
To exercise such rights, you may submit a request via the web form linked here.
Additionally, you may have the right not to receive discriminatory treatment if and when you exercise your rights conferred by applicable law.