privacy

Zero data retention

Your API calls leave nothing behind. Each one is handled in memory, answered, and dropped. What we do keep, and which services a request has to reach, is all on this page.

Zero data retention, in practice

Your prompts and the model's answers are held in memory only while the request is being answered, then discarded. Nothing from a model call is written to a database or a log. Two exceptions: an image you ask for is kept 7 days so you can download it, and an agent run you start from the console or a schedule keeps its question and answer for 30 days so you can read it again. What visitors ask an agent's page is not kept.

What this means for you

  • What you send through the API is not saved, sensitive or otherwise
  • Nothing you send is used to train anything — we don't train models at all
  • A breach of our systems can't leak API conversations we never stored
  • Nothing to request a copy of or ask us to delete, beyond your account and billing rows

What we don't do

  • Keep prompts to "improve the service"
  • Store your API conversations or query history
  • Sell your data, or hand it to anyone for their own use
  • Keep logs that contain your prompt content
architecture

How a request moves through our servers

When you send a request to the API, this is what happens to it:

1

In memory only

The request is handled in memory, forwarded to the model, and, for a plain API call, never written to disk.

2

Gone after the answer

Once the response has streamed back to you, the request and the reply are dropped.

3

Billing rows only

We keep what the bill needs: timestamp, token counts, the model and oracle used, and which account to charge. Not the content.

4

No prompt cache

No cache holds your API messages. Agent runs can finish on our servers while you are away, and are kept 30 days; a generated image, 7 days.

Why we work this way

We make money when you top up a wallet and spend it on tokens and lookups. There is no second business in your data, so there is no reason to keep it.

what has to leave our servers

Who sees a request, and for how long

To answer you, a request has to reach the service that does the work. Each one receives only what it needs for that call — never your account details.

1

The model

Your messages go to the provider that serves the open model you picked, and come straight back as the answer.

2

Live data, only when you switch it on

A lookup goes to the source for that oracle: Brave Search (web), newsdata.io (news), WeatherAPI (weather), Yahoo Finance (stocks), LiveCoinWatch (crypto), Geoapify (maps & places). It sees the query, not who asked.

3

Generated images

Images are made by Cloudflare Workers AI and kept for 7 days under an unguessable link so you can download them — then deleted automatically.

4

Billing metadata

We keep the timestamp, token counts, model and oracle used per call so we can charge the right amount — never the content.

why oraicle

Built for privacy-critical work

Kept only when you ask

A plain API call leaves nothing on our side to leak, subpoena or lose. An agent run you start from the console or a schedule is kept 30 days, and an image you ask for 7 days. What visitors ask an agent's page is not kept.

Named, not vague

The services a request reaches, and for how long, are listed above by name. If that list changes, this page changes.

Less to account for

When a customer or a regulator asks what is kept about a conversation, the answer for our part is the billing rows above. Your own obligations stay yours.

Who you are dealing with

Oraicle is run by ML Global Limited, registered in Hong Kong under business registration number 60643987, with its registered office at Room 803B, 8/F., West Coast International Building, 290-296 Un Chau Street, Cheung Sha Wan, Kowloon, Hong Kong. The same company is named on every invoice.