OIXCreate account
LEGAL

Privacy Policy

Effective August 3, 2026

This Policy explains the information OIX processes to provide accounts, scoped operating-system capabilities, proof records, and rights transfers. Each independently operated asset and its owner remain responsible for their own customer, commerce, and privacy obligations.

Information we collect

  • Account data such as name, email, password hash, recovery-code hash, and session records.
  • Asset manifests, operating specifications, runtime records, package-authenticated proofs, policy decisions, cost evidence, and rights-transfer records.
  • Security and service data such as IP-derived rate-limit keys, user-agent hashes, error logs, and device session activity.
  • For buyer-validation research, keyed digests and the minimum structured evidence needed to evaluate demand; raw identifiers are excluded when a digest is sufficient.
  • External settlement references and provider status only when an owner attaches an asset-scoped evidence connector. OIX does not store complete card details.

How we use information

We use information to authenticate users, isolate account and asset data, enforce scoped runtime policy, meter resources, verify evidence, recover execution, support rights transfers, prevent abuse, maintain security, and improve the service. OIX does not use this information to become the asset's seller or operate its customer business.

Sharing

Information may be shared with infrastructure, model, verification, hosting, and analytics providers only as needed for owner-authorized platform capabilities. OIX does not share asset commercial credentials or customer data to advertise, sell, fulfill, support, or refund an asset's output. We may disclose information when legally required or necessary to protect users and the service.

Storage and security

OIX uses durable platform storage, salted password hashing, hashed session tokens, HttpOnly cookies, access controls, and rate limits. No system is perfectly secure, so protect your password and recovery code and disconnect credentials you no longer use.

Retention

Account and asset records are retained while needed to provide the service, preserve financial and proof ledgers, resolve disputes, and meet legal obligations. Security attempts and expired sessions may be deleted on a rolling basis. Public research signals expire after 180 days unless a shorter period is required.

Your choices

You can update your profile and password in Settings, disconnect external services, pause assets, and request account-data actions through the support channel when available. Essential authentication cookies are required for signed-in use.

Changes

Material updates will be presented through OIX. The effective date above identifies the current version.