ODEI
DOCUMENTATION Public surfaces evolve in real time.
Runtime World Model Live Knowledge Graph Session

Privacy Notice

Effective date: February 25, 2026  |  Last updated: July 26, 2026

1. Scope of This Notice

This Privacy Notice applies to all ODEI hosted surfaces: app.odei.ai (including the Talk workspace, wallet sign-in, waitlist, agent builder, and public agent share cards), api.odei.ai (public documentation, intake and contact forms, and API endpoints), community.odei.ai (the $ODAI holder verification funnel, including wallet-to-Telegram binding), daorg.odei.ai (the community forum), same-origin launch artifacts, and any hosted onboarding or launch workflow we operate. It explains what personal data we process, why we process it, and how we handle it.

ODEI is local-first by design. That means your browser state, local runtime state, and any execution that stays on your machine remain under your control unless you explicitly submit information to an ODEI-hosted surface or choose a third-party provider that processes your data.

2. Controller and Contact Channels

The controller for personal data processed through ODEI hosted surfaces is Anton Illarionov, sole proprietor, registered in Budapest, Hungary (registration No. 61955583; tax No. 91815600-1-42) and holder of the registered EU trade mark ODEI®, No. 019341655 (EUIPO), operating with the ODEI founding team. Formation of an incorporated operating company is in progress; this notice will be updated to name that entity when it exists.

3. What Stays Local and What Reaches ODEI

  • Local by default: browser session state, launch progress stored in local state, local runtime files, local world-model state, and local execution receipts generated on your machine.
  • Hosted by ODEI when you submit it: intake details, launch preferences, contact data, Talk workspace conversations, waitlist submissions, hosted launch artifacts, API request metadata, support communications, and form submissions.
  • Processed by third parties when you choose them: model providers, wallet software, browser extensions, external APIs, or other connected services you authorize. Those providers operate under their own terms and privacy notices.

4. Categories of Data We Process

Data you provide directly: name, email address, wallet address, Telegram handle, organization details, endpoint URLs, launch choices, connected-surface selections, and any free-text details you submit through intake, waitlist, or support flows.

Sign-in and account data (app.odei.ai): your wallet address and a verified email where you provide one. If you sign in through Privy, Privy processes your chosen login identity (email, Google, Apple, or X account, and any embedded wallet it manages); our own systems store the verified email and derived identifiers, not your third-party account credentials.

Talk workspace content: messages you exchange in a hosted Talk session are stored server-side with the session record, together with the verified email, wallet address, tier, and billing references tied to that session. Treat Talk like any hosted messaging surface: what you type is stored until deleted (see Retention and Your Rights).

Community verification (community.odei.ai): if you verify holder access, we bind your wallet address to your Telegram account for tier verification. Binding records are created server-side from your signed-in session, are time-limited, and related telemetry uses hashed identifiers rather than raw ones.

Forum data (daorg.odei.ai): username, password hash, session cookie, your posts, and IP addresses in server logs. By design, no email address is required to register there.

Hosted usage data: request timestamps, route or artifact requested, response status, IP address, user agent, and security or abuse-monitoring metadata.

Public-source data: publicly available blockchain data associated with wallet or contract addresses you ask us to inspect or display.

5. Cookies and Local Storage

We set no advertising or analytics cookies and load no third-party tracking scripts. No consent banner is shown because none is required: every cookie we set is strictly necessary for a service you explicitly request (ePrivacy Art. 5(3) exemption). The cookies are:

  • odei_operator_session (app.odei.ai) — your sign-in session; HttpOnly; lifetime 7 days; strictly necessary.
  • odei_talk_preview_access (app.odei.ai) — Talk preview access gate; HttpOnly; time-limited; strictly necessary.
  • Forum session cookie (daorg.odei.ai, NodeBB) — forum login session; strictly necessary.

First-party browser storage (localStorage) on app.odei.ai holds functional state only: intake and profile form drafts (cleared on successful submit; drafts you abandon stay on that device until cleared — be mindful on shared machines), continuity identifiers for your own submissions, and interface flags. Privy sets its own cookies and storage during sign-in under its own privacy notice. If a future feature ever needs a non-essential cookie, we will ask for consent before setting it.

6. Public Pages You Create

If you mint an agent and it gets a public share card, that card page shows the agent name together with the associated wallet address and is reachable by anyone with the link. Mint and share deliberately; you can ask us to take a card down at any time via ai@odei.ai.

7. Why We Process Personal Data

  • Operate launch, intake, Talk, and hosted runtime support surfaces
  • Process onboarding, waitlist, and contact requests
  • Verify holder tiers and wallet-linked entitlements
  • Secure, monitor, and troubleshoot hosted endpoints
  • Provide support, follow-up, and service communications
  • Improve reliability, integrity, and abuse resistance

8. Legal Bases (GDPR)

  • Contract performance (Art. 6(1)(b)) for delivering requested hosted services, sign-in, Talk sessions, holder verification, launch artifacts, onboarding, and API access.
  • Consent (Art. 6(1)(a)) where you explicitly submit intake or waitlist forms, request follow-up, publish an agent share card, or authorize a specific hosted workflow.
  • Legitimate interests (Art. 6(1)(f)) for security monitoring, abuse prevention, and service hardening — including fraud- and abuse-prevention logs (IP address, user agent) kept for a limited window as described under Retention.

9. Sharing and Processors

We do not sell personal information. We share personal data only with the service providers below, only as needed to operate hosted services or comply with law:

  • Cloudflare (US) — edge network, Workers compute, and KV storage for app.odei.ai and DNS/proxy for our zones. Holds sign-in sessions, operator profiles, Talk session records, waitlist records, and agent cards.
  • Privy (US) — wallet and social sign-in. Processes your login identity (email, Google, Apple, or X account, and embedded Base wallets it manages) and sets its own storage during sign-in.
  • Resend (US) — transactional email delivery (for example waitlist confirmations). Receives the recipient email address and message content.
  • Stripe (US/EU) — payment and billing where paid plans apply. Receives billing email and holds customer and subscription identifiers; card details go to Stripe directly and never touch our systems.
  • Google Cloud Platform (US/EU) — virtual machines and infrastructure hosting api.odei.ai, community.odei.ai, and daorg.odei.ai, including server logs, intake records, and the forum database.
  • Neo4j — graph database infrastructure where hosted graph or launch surfaces require it.
  • Telegram — the community bot and the holder-verification flow process your Telegram account identifiers when you choose to interact with them. Operational intake notifications to our private operator channel are minimized to non-contact fields (intake ID, name, role); full contact details stay in the access-guarded intake store.
  • Base network RPC (Coinbase) (US) — wallet-balance and entitlement lookups transmit your wallet address when you connect a wallet.

Waitlist submissions may additionally be mirrored to a second ODEI-operated store for redundancy; both copies are covered by this notice and by deletion requests.

If you intentionally connect a third-party model provider, wallet, extension, external API, or other service, your interaction with that provider is governed by its own privacy and security terms. We do not control those external providers.

10. International Transfers

Several of the providers above are established in the United States or process data outside the European Economic Area. For Cloudflare, Google Cloud, Stripe, Resend, and Privy, transfers rely on those providers' standard data-processing terms incorporating the EU Standard Contractual Clauses (and, where the provider is certified, the EU–US Data Privacy Framework). Telegram offers no equivalent safeguard, which is why we minimize what reaches it (see Section 9). We do not claim any certification or safeguard we do not actually hold.

11. Retention

We state retention honestly, including where automatic deletion is not yet implemented:

  • Intake and onboarding submissions: currently retained until you request deletion. An automatic purge (target: 12 months after last activity) is under consideration; until it ships, we do not claim it.
  • Waitlist records: retained until your deletion request.
  • Talk session records (chat history, verified email, wallet, billing references): currently retained until you request deletion; automatic expiry is planned but not yet shipped.
  • Operator profiles, agent records, and public agent cards: retained while active, and afterwards until you request deletion.
  • Community binding records (wallet ↔ Telegram): stored with server-side expiry; related telemetry uses hashed identifiers.
  • Hosted request and security logs, including fraud- and abuse-prevention logs (IP address, user agent): target window of up to 90 days; where log rotation on a given store is still being confirmed, entries may persist longer until purged.
  • Backups of hosted systems: short rolling windows; we do not currently publish a fixed backup retention figure and will not state one until it is enforced.
  • Public blockchain data: public by nature; referenced as long as it remains public and relevant to the requested proof surface.

Any record above can be deleted on request at any time — see Your Rights.

12. Your Rights

If the GDPR or a similar privacy law applies to you, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where consent is the legal basis. You may also lodge a complaint with your local supervisory authority — for Hungary, the National Authority for Data Protection and Freedom of Information (NAIH, naih.hu).

To exercise privacy rights, contact ai@odei.ai from the email address associated with your records, or include proof of control of the relevant wallet address. Fulfillment is currently a documented manual procedure across our stores (hosted key-value records, intake records, and logs); self-service deletion in the product is planned. We respond within 30 days.

13. Automated Systems and Human Review

We use automated systems for rate limiting, abuse detection, security filtering, and service integrity. These systems are designed to protect the hosted service and do not intentionally produce decisions with legal or similarly significant effects without human review. If you believe an automated control has impacted you incorrectly, contact us for review.

14. Security

We apply technical and organizational safeguards appropriate to the hosted service, including TLS in transit, restricted operational access, and controlled infrastructure exposure. We hold no third-party security certification (such as SOC 2 or ISO 27001) and claim none. No hosted or local system is absolutely secure, so you should also secure your own devices, wallets, model accounts, and connected services.

15. Children

ODEI is not directed to children under 16, and we do not knowingly collect personal data from children. If we learn that such data was submitted, we will take reasonable steps to delete it.

16. Changes and Contact

We may update this Privacy Notice as the product evolves. Material changes will be reflected by updating the date above and, where appropriate, by a visible notice on an ODEI-hosted surface.

For privacy questions, rights requests, or incident reports, contact ai@odei.ai. For due diligence, contracting, or legal notices, contact ai@odei.ai.