Privacy Policy
Last updated: June 2026
OIOXO is operated by Aradsoft Ltd. (Canada), the controller of the limited personal data described here. OIOXO is built so that the data that matters — your code, your prompts, your keys — never touches our servers. This policy lists what we do process, why, and what we deliberately cannot see. The technical walkthrough is at Privacy by design.
1. What never reaches our servers
- Your code and project files. They live in your browser or your local folders. AI generation runs on your device.
- Your prompts and the AI’s output. Processed locally, or sent directly to a provider you configured (see §4).
- Your API keys and GitHub tokens. Stored in your browser’s local storage on your machine only.
2. What we collect, and why
| Data | Why |
|---|---|
| Email and login credentials (or OAuth identity) | Your account. |
| Usage meter counts — numbers of tokens generated/saved, timestamps, plan tier, a device-bound entitlement token | Enforcing the free allowance and Pro entitlements fairly across devices. Counts only — never content. |
| Billing records (handled by Stripe) | Pro subscriptions. We never see or store card numbers. |
| Standard server logs (IP, request path, user agent), short-lived | Keeping the service up and abuse out. |
We never train on your work. We do not use your code, prompts, or AI output to train, fine-tune, or improve any model — not on the free plan, not on any plan. We also do not sell personal data or run third-party advertising trackers.
3. What stays on your device (but is data about you)
Settings, themes, keybindings, recent projects, snapshots, skills, rules, and cached models are stored by your browser on your machine. Clearing site data removes them; we have no copy.
4. Third parties you choose to involve
- BYOK providers (OpenAI, Anthropic, Google, …): your browser calls them directly with your key; their privacy terms govern that traffic.
- GitHub: repository reads/writes and Pages publishing go straight from your browser to GitHub.
- Stripe: payment processing for Pro. We never see or store card numbers.
- Compute Mesh: when you pair your own devices to build together, they connect directly (peer-to-peer) over an encrypted channel; nothing of your project is relayed through our servers.
- Share by code: a project is packaged into the share code itself — the code is the project. Nothing is hosted on, or passes through, our servers.
- Model & runtime delivery: on-device models and tooling are downloaded from public CDNs (Hugging Face, jsDelivr). These see the request, not your code.
5. Cookies and local storage
We use a session cookie to keep you signed in. We do not use third-party advertising or cross-site tracking cookies. Most of what OIOXO remembers — settings, recent projects, your acceptance of the terms, and cached models — is kept in your browser’s local storage on your device, not in cookies on our servers. Clearing site data removes it.
6. Retention and deletion
Account and metering records are kept while your account exists. Email support@oioxo.com to delete your account; we remove your personal data within 30 days, except minimal records we must keep (e.g., tax/billing history). Your local data is already under your control.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict the processing of the personal data we hold about you, and to object to it or withdraw consent. Exercise any of them at the same address above. Since we hold so little, these requests tend to be short conversations. You may also have the right to lodge a complaint with your local data-protection authority.
8. International transfers
We operate the Service from our own infrastructure; where account or billing data is processed in another country, we rely on appropriate safeguards as required by applicable law. Because your code and prompts stay on your device, they are not transferred by us at all.
9. Children
OIOXO is not directed at children under 13 (or the minimum age of digital consent where you live), and we don’t knowingly collect their data. If you believe a child has provided us personal data, contact us and we’ll delete it.
10. Changes
If this policy changes materially, we’ll announce it in the changelog and update the date above. Continued use after a change means you accept the updated policy.
11. Contact
Questions about your privacy or this policy? support@oioxo.com.