Privacy Policy
Effective August 3, 2026
This Policy explains the information OIX processes to provide accounts, scoped operating-system capabilities, proof records, and rights transfers. Each independently operated asset and its owner remain responsible for their own customer, commerce, and privacy obligations.
Information we collect
- Account data such as name, email, password hash, recovery-code hash, and session records.
- Asset manifests, operating specifications, runtime records, package-authenticated proofs, policy decisions, cost evidence, and rights-transfer records.
- Security and service data such as IP-derived rate-limit keys, user-agent hashes, error logs, and device session activity.
- For buyer-validation research, keyed digests and the minimum structured evidence needed to evaluate demand; raw identifiers are excluded when a digest is sufficient.
- External settlement references and provider status only when an owner attaches an asset-scoped evidence connector. OIX does not store complete card details.
How we use information
We use information to authenticate users, isolate account and asset data, enforce scoped runtime policy, meter resources, verify evidence, recover execution, support rights transfers, prevent abuse, maintain security, and improve the service. OIX does not use this information to become the asset's seller or operate its customer business.
Sharing
Information may be shared with infrastructure, model, verification, hosting, and analytics providers only as needed for owner-authorized platform capabilities. OIX does not share asset commercial credentials or customer data to advertise, sell, fulfill, support, or refund an asset's output. We may disclose information when legally required or necessary to protect users and the service.
Storage and security
OIX uses durable platform storage, salted password hashing, hashed session tokens, HttpOnly cookies, access controls, and rate limits. No system is perfectly secure, so protect your password and recovery code and disconnect credentials you no longer use.
Retention
Account and asset records are retained while needed to provide the service, preserve financial and proof ledgers, resolve disputes, and meet legal obligations. Security attempts and expired sessions may be deleted on a rolling basis. Public research signals expire after 180 days unless a shorter period is required.
Your choices
You can update your profile and password in Settings, disconnect external services, pause assets, and request account-data actions through the support channel when available. Essential authentication cookies are required for signed-in use.
Changes
Material updates will be presented through OIX. The effective date above identifies the current version.