OMA collects the minimum data needed to run the service: the email address or wallet address you choose for sign-in, a SHA-256 hash of API keys, per-call usage records, and on-chain deposit or settlement identifiers.
We do not sell personal information. OMA does not persist prompt or completion content. Request content is forwarded transiently to the selected inference provider so it can generate a response; provider handling is described below. You can export or delete the account data OMA stores from the dashboard.
What we collect
The data we keep and the data we never touch
What we store
Email address: Stored when you choose magic-link sign-in and used for authentication and account messages.
Wallet address: Used for authentication via SIWE (EVM) signatures.
API usage: Token counts and timestamps for billing.
Transaction hashes: For on-chain deposit verification.
API keys: Hashed for authentication, prefixed for identification.
What OMA does not persist
Prompt text: Inference runs in memory; content is not persisted.
Completion text: Model output is streamed to you and discarded.
Wallet activity: We do not read balances, NFTs, or transaction history.
Profile enrichment: No legal name or demographic profile is required beyond the email or wallet identifier you choose for authentication.
Authentication
Passwordless email or SIWE wallet
You can authenticate with a passwordless email magic link or Sign-In With Ethereum (SIWE). OMA stores only the identifier needed for the method you choose.
Email sign-in: Stores your email address so we can deliver magic links and account messages.
Wallet sign-in: Stores your public wallet address after you prove control with a SIWE signature.
Usage attribution: Associates token spend, keys, and credits with your account for billing.
If you use wallet sign-in, OMA does not crawl your wallet history or build a profile from unrelated on-chain activity.
Logs and billing
What we meter, what we never see
For billing
Model id: e.g. "kimi-k3"
Token counts: Prompt and completion tokens per request.
Cost in cents: Computed at settlement time.
Request timestamp: UTC, to the second.
We do not log
Prompt text: The body of your request is never stored.
Completion text: The model's response is never stored.
Tool payloads: Function-call arguments and outputs are not retained.
File contents: Uploaded files are processed transiently and dropped.
Retention
How long we keep things
API logs90 daysfor usage reporting
Account datauntil deletionemail or wallet identifier and account settings
CreditsUntil account deletionnon-redeemable, do not expire
API keyson revokedeletion revokes immediately
Third parties
Who sees what
Inference cannot happen without sending request content to the service that runs the selected model. OMA forwards that content transiently for inference and does not persist it. Provider retention and privacy guarantees depend on the selected provider and model; review the provider terms for sensitive workloads.
Venice AIInferencereceives request content to run the selected model; Venice privacy mode and provider policies apply
OMA-AI / OpenBrokerInferencerequest content is processed by the Gonka/OpenBroker-backed model that serves the call
Surplus Intelligence (if enabled)Fallback inferencemapped models may be retried through this optional fallback after a primary-provider failure
BaseSettlementon-chain transaction verification
~ We do not sell, rent, or share any personal data with advertisers or analytics services.
Sub-processors
DPA list
Operational vendors that process account, billing, rate-limit, or email data on our behalf. These are separate from the inference providers listed above and do not receive prompt or completion content as part of their operational role. Contact support@nosytlabs.com for a signed DPA.
Base / on-chain RPCSettlementtx hashes for deposits
ResendEmail deliverytransactional magic link emails
PolarPayment processingcard checkout; no prompt content
Your rights
What you control
Request deletion (Art. 17 GDPR)
Under Article 17 of the GDPR, you have the right to erasure ('right to be forgotten'). Delete your account and all associated profile, sessions, and API keys immediately and permanently from the Danger Zone under Settings.
Revoke API keys (Art. 16/18 GDPR)
Under Article 16/18 of the GDPR, you have the right to restrict processing. You can disable or permanently revoke any of your API keys from the dashboard at any time, instantly halting further request metering on those keys.
Export your data (Art. 15/20 GDPR)
Under Articles 15 & 20 of the GDPR, you have the right to access and data portability. Download your full data-portability bundle (JSON profile, api keys list, active sessions, deposits, credit balances, and audit history) from the Privacy panel under Settings.
Contact our DPO (Art. 13 GDPR)
Under Article 13 of the GDPR, you have the right to contact us regarding your data. Email support@nosytlabs.com for any privacy, rectification, processing restriction, or data control inquiry. We reply within five business days.