Privacy Notice
Effective date: February 25, 2026 | Last updated: March 29, 2026
1. Scope of This Notice
This Privacy Notice applies to ODEI hosted surfaces, including app.odei.ai, api.odei.ai, public documentation, intake and contact forms, same-origin launch artifacts, and any hosted onboarding or launch workflow we operate. It explains what personal data we process, why we process it, and how we handle it.
ODEI is local-first by design. That means your browser state, local runtime state, and any execution that stays on your machine remain under your control unless you explicitly submit information to an ODEI-hosted surface or choose a third-party provider that processes your data.
2. Controller and Contact Channels
The controller contact channels for personal data processed through ODEI hosted services are:
- Privacy: [email protected]
- Legal and diligence: [email protected]
3. What Stays Local and What Reaches ODEI
- Local by default: browser session state, launch progress stored in local state, local runtime files, local world-model state, and local execution receipts generated on your machine.
- Hosted by ODEI when you submit it: intake details, launch preferences, contact data, hosted launch artifacts, API request metadata, support communications, and form submissions.
- Processed by third parties when you choose them: model providers, wallet software, browser extensions, external APIs, or other connected services you authorize. Those providers operate under their own terms and privacy notices.
4. Categories of Data We Process
Data you provide directly: name, email address, wallet address, Telegram handle, organization details, endpoint URLs, launch choices, connected-surface selections, and any free-text details you submit through intake or support flows.
Hosted usage data: request timestamps, route or artifact requested, response status, IP address, user agent, and security or abuse-monitoring metadata.
Public-source data: publicly available blockchain data associated with wallet or contract addresses you ask us to inspect or display.
We do not use cookies for advertising or cross-site tracking. Where a hosted session needs continuity, we prefer browser-local state or explicit same-origin artifacts over opaque tracking layers.
5. Why We Process Personal Data
- Operate launch, intake, and hosted runtime support surfaces
- Process onboarding and contact requests
- Secure, monitor, and troubleshoot hosted endpoints
- Provide support, follow-up, and service communications
- Improve reliability, integrity, and abuse resistance
6. Legal Bases (GDPR)
- Contract performance (Art. 6(1)(b)) for delivering requested hosted services, launch artifacts, onboarding, and API access.
- Consent (Art. 6(1)(a)) where you explicitly submit intake forms, request follow-up, or authorize a specific hosted workflow.
- Legitimate interests (Art. 6(1)(f)) for security monitoring, abuse prevention, service hardening, and operational analytics that do not override your rights.
7. Sharing and Processors
We do not sell personal information. We share personal data only where needed to operate hosted services or comply with law.
- Google Cloud Platform for hosting, compute, and infrastructure operations
- Neo4j for database infrastructure where hosted graph or launch surfaces require it
If you intentionally connect a third-party model provider, wallet, extension, external API, or other service, your interaction with that provider is governed by its own privacy and security terms. We do not control those external processors.
8. Retention
- Intake and onboarding submissions: up to 12 months after last activity, unless a longer retention period is required for an active commercial or legal relationship
- Hosted request and security logs: up to 90 days
- Backups of hosted systems: rolling 7-day retention
- Public blockchain data: retained as long as it remains public and relevant to the requested proof surface
9. International Transfers
Hosted data may be processed on infrastructure operated outside the European Economic Area. Where required, we rely on Standard Contractual Clauses or comparable safeguards to protect personal data transferred across borders.
10. Your Rights
If the GDPR or a similar privacy law applies to you, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where consent is the legal basis. You may also lodge a complaint with your local supervisory authority.
To exercise privacy rights, contact [email protected]. We aim to respond within 30 days.
11. Automated Systems and Human Review
We use automated systems for rate limiting, abuse detection, security filtering, and service integrity. These systems are designed to protect the hosted service and do not intentionally produce decisions with legal or similarly significant effects without human review. If you believe an automated control has impacted you incorrectly, contact us for review.
12. Security
We apply technical and organizational safeguards appropriate to the hosted service, including TLS in transit, restricted operational access, and controlled infrastructure exposure. No hosted or local system is absolutely secure, so you should also secure your own devices, wallets, model accounts, and connected services.
13. Children
ODEI is not directed to children under 16, and we do not knowingly collect personal data from children. If we learn that such data was submitted, we will take reasonable steps to delete it.
14. Changes and Contact
We may update this Privacy Notice as the product evolves. Material changes will be reflected by updating the date above and, where appropriate, by a visible notice on an ODEI-hosted surface.
For privacy questions, rights requests, or incident reports, contact [email protected]. For diligence, contracting, or legal notices, contact [email protected].