Workflows
HOME/LEGAL
Privacy Policy
This policy covers Oxaide — the per-job research desk (no account, pay per brief). Uploads wiped from our storage in 24h, packs kept 90 days. Default runs use a US-hosted frontier model — see §4.
Privacy at a glance
Oxaide — email desk
Briefs and attachments sent to brief@oxaide.com are processed only to deliver your pack. Each job runs on its own isolated computer; uploads wiped from our storage within 24h, packs kept 90 days. Default runs use a US-hosted frontier model on the provider's contributor tier — fixed S$49/390/1500 per job, no retainer. For a brief you consider sensitive, email privacy@oxaide.com before you send. Card and PayNow payments run via Stripe.
Private portfolio data
Portfolio data, generated baskets, transmit history, and notes are private to the workspace unless an authorised user chooses to share them.
No data sale
We do not sell or rent personal data, and we do not use private portfolio data for third-party advertising.
Service providers
Data is processed by the infrastructure, payment, model, communications, and data providers needed to operate the Service.
No trading secrets
Do not submit passwords, seed phrases, private keys, or write-enabled exchange, broker, wallet, or trading credentials.
Information We Collect
We collect what you send us — briefs, files, emails — plus billing references via Stripe (never card numbers) and basic technical data like IP, device, and cookies. Never send passwords or crypto keys.
Read the full wording
1.1 Information you provide
1.2 Information collected through use
1.3 Information you should not submit
Oxaide never needs your passwords, seed phrases, wallet private keys, or write-enabled credentials for an exchange, broker, wallet, bank, or trading system. Do not place those secrets in messages, files, notes, or support messages. If you submit them accidentally, contact us promptly and rotate or revoke them with the relevant provider.
How We Use Information
Your data is used only to quote, bill, build, and deliver your pack, keep the service secure and reliable, and meet legal duties. No marketing list — you get transactional email only (quotes, receipts, packs).
Read the full wording
2.1 Provide Oxaide
- Quote, bill (via Stripe), generate, and deliver per-job research packs to your email thread
- Run each paid brief on its own isolated computer and wipe uploads on completion
- Track per-job status, 3-pack credits, referrals, and resend budgets to prevent double-charging and abuse
- Send transactional mail only (quotes, receipts, packs, renewals) — no marketing list
- Measure funnel and latency in aggregate to keep the 2-hour SLA and fixed pricing
2.2 Operate and protect the Service
- Process subscriptions, payments, invoices, cancellations, and account administration
- Provide support and send transactional, security, billing, and usage communications
- Detect abuse, investigate incidents, debug failures, maintain reliability, and enforce our Terms
- Understand feature use and improve product quality using feedback, service telemetry, and aggregated or deidentified information where reasonably possible
- Comply with law, respond to lawful requests, and establish, exercise, or defend legal claims
Legal Bases
Under Singapore PDPA and GDPR we process your data to fulfil your order, keep the service secure, with your consent where we ask for it, or where the law requires. Withdrawing consent may limit features that need that data.
Read the full wording
The legal basis depends on the information, purpose, and jurisdiction. Where laws such as the GDPR or Singapore PDPA apply, we rely on the following bases as appropriate:
- Basis
- Contract
- Typical purpose
- Creating accounts, providing research features, enforcing limits, billing, and support.
- Basis
- Legitimate interests
- Typical purpose
- Security, fraud prevention, reliability, product improvement, and business administration, balanced against your rights.
- Basis
- Consent
- Typical purpose
- Optional marketing, optional sharing, and other processing where consent is requested. Consent may be withdrawn.
- Basis
- Legal obligation
- Typical purpose
- Tax, accounting, regulatory, court, and lawful government requirements.
| Basis | Typical purpose |
|---|---|
| Contract | Creating accounts, providing research features, enforcing limits, billing, and support. |
| Legitimate interests | Security, fraud prevention, reliability, product improvement, and business administration, balanced against your rights. |
| Consent | Optional marketing, optional sharing, and other processing where consent is requested. Consent may be withdrawn. |
| Legal obligation | Tax, accounting, regulatory, court, and lawful government requirements. |
Under the Singapore PDPA, we collect, use, and disclose personal data with consent or another basis permitted by law. Withdrawing consent may limit features that require the affected data.
Providers and Sharing
Vendors (hosting, Stripe, model, email) see only what they need to do their job. Your work stays private unless you explicitly share it. Default model runs process in the US; sensitive briefs can use the paid contract path — ask first.
Read the full wording
4.1 Service providers
We disclose information to vendors acting for us when needed to operate the Service. Their role, location, and data access depend on the feature you use. Core provider categories currently include:
- Provider or category
- Supabase
- Purpose
- Account authentication, workspace records, databases, and storage.
- Provider or category
- Cloudflare
- Purpose
- Website delivery, network protection, edge services, and parts of application hosting.
- Provider or category
- Muse Spark 1.3 (US-hosted frontier model)
- Purpose
- Default Brief engine — runs your brief on its own isolated computer. Uploads wiped from our storage in 24h, packs kept 90 days, never mixed across clients. Provider data terms apply; for sensitive briefs email privacy@oxaide.com before you send.
- Provider or category
- Muse Spark 1.2 paid API + DeepSeek fallback (private path)
- Purpose
- Automatic fallback when the free tier rate-limits or fails, verifier second-pass, and sensitive-job option (email privacy@oxaide.com to force paid-only before you brief). Paid-path processing follows provider contract, no training use.
- Provider or category
- Stripe
- Purpose
- Subscription checkout, payment processing, invoices, and billing administration.
- Provider or category
- Communications and operations providers
- Purpose
- Transactional email, support, error reporting, and service monitoring.
- Provider or category
- Telegram (founder ops alerts)
- Purpose
- Job-status pings to the founder only (from-address + subject line, never brief contents or files) so failures get human eyes within minutes.
- Provider or category
- Data and tool providers
- Purpose
- Retrieving public market data and running tools requested through the Service.
| Provider or category | Purpose |
|---|---|
| Supabase | Account authentication, workspace records, databases, and storage. |
| Cloudflare | Website delivery, network protection, edge services, and parts of application hosting. |
| Muse Spark 1.3 (US-hosted frontier model) | Default Brief engine — runs your brief on its own isolated computer. Uploads wiped from our storage in 24h, packs kept 90 days, never mixed across clients. Provider data terms apply; for sensitive briefs email privacy@oxaide.com before you send. |
| Muse Spark 1.2 paid API + DeepSeek fallback (private path) | Automatic fallback when the free tier rate-limits or fails, verifier second-pass, and sensitive-job option (email privacy@oxaide.com to force paid-only before you brief). Paid-path processing follows provider contract, no training use. |
| Stripe | Subscription checkout, payment processing, invoices, and billing administration. |
| Communications and operations providers | Transactional email, support, error reporting, and service monitoring. |
| Telegram (founder ops alerts) | Job-status pings to the founder only (from-address + subject line, never brief contents or files) so failures get human eyes within minutes. |
| Data and tool providers | Retrieving public market data and running tools requested through the Service. |
Providers and subprocessors may change as the Service changes. We require providers to handle data for the relevant service purpose and subject to their applicable contractual and legal obligations.
Model and provider selection can vary by request based on task needs, availability, reliability, safety, and product changes. Default Brief runs use a US-hosted frontier model — same pack, same source-linked standard. Oxaide does not promise a fixed model or provider.
Free-tier Contributor processing happens in the US and the offer is time-limited by the provider; if it rate-limits, your job auto-falls-back to the paid path so the 2h SLA holds. We process Customer Content to provide, secure, support, and maintain the Service; product improvement uses feedback, service telemetry, and aggregated or deidentified information where reasonably possible — except the Contributor free tier, which per its terms may learn from prompts/completions.
Your files never train our models. What compounds is our method — checklists, source coverage, verification — so each job runs a sharper harness on your private, isolated copy. Your brief stays yours.
4.2 Other disclosures
- With workspace owners, members, or administrators according to their permissions
- With recipients you choose through an explicit share action or share link
- With professional advisers, auditors, insurers, and authorities where reasonably necessary or legally required
- To protect users, Oxaide, providers, or the public from fraud, abuse, security threats, or unlawful conduct
- In connection with a financing, merger, acquisition, restructuring, or sale, subject to appropriate confidentiality and notice where required
4.3 Private by default and opt-in sharing
We do not make private portfolio data public by default. An authorised user must take an affirmative sharing action before a basket, note, or other supported item is shared outside the workspace. Users control what they share and are responsible for recipient access. Revoking a link cannot remove copies already downloaded, forwarded, indexed, or retained by a recipient.
Service and Broker Connection Boundaries
The AI explains and analyses your portfolio — it never moves money, trades, or takes custody. It never receives payment secrets, price settings, or your credentials.
Read the full wording
- Oxaide manages accounts, workspaces, subscriptions, plan entitlements, usage measurement, and the authority to generate paid baskets.
- The AI assistant and its model providers process authorised requests to explain drift and analyse the portfolio. The assistant never transmits orders.
- Payment credentials, Stripe secrets, price configuration, and subscription mutation authority are not provided to assistant processing.
- The Service does not require and must not receive passwords, seed phrases, private keys, or write-enabled trading credentials.
- Oxaide does not use Customer Content to execute trades, take custody of assets, or manage an investment account.
Security
We protect data with encryption, access controls, logging, backups, and monitoring — but no online service is perfectly secure, so guard your inbox links, devices, and share links too.
Read the full wording
We use administrative, technical, and organisational measures designed to protect information in light of its nature and the risks involved. Measures may include:
- Encrypted network transport and storage protections supplied by our infrastructure providers
- Authentication, workspace permissions, access restrictions, and separation of billing authority from order handling
- Logging, monitoring, backups, updates, incident handling, and provider security controls where appropriate
- Access limitation for personnel and service providers based on operational need
No online service is completely secure. You are responsible for protecting your sign-in methods, devices, workspace invitations, exported files, and share links, and for notifying us promptly of suspected unauthorised access.
Retention and Deletion
Brief uploads are wiped within 24 hours of completion; packs auto-delete after 90 days. Records needed for history, billing, and legal duties stay longer — ask privacy@oxaide.com for deletion, subject to lawful exceptions.
Read the full wording
We retain information for as long as reasonably necessary to provide the Service, maintain workspace and basket history, administer an active account, meet legal and accounting obligations, resolve disputes, enforce agreements, protect security, and support legitimate business operations.
- Retention varies by data type, account status, workspace settings, provider systems, and legal requirements.
- When information is no longer required, we delete it or anonymise it according to our operational processes, subject to lawful exceptions.
- Deleted information may remain temporarily in backups, security logs, fraud-prevention records, or provider systems until ordinary deletion cycles complete.
- Aggregated or deidentified information may be retained where it no longer reasonably identifies an individual.
- You may request account or personal-data deletion at privacy@oxaide.com. We may verify identity and retain limited records where required or permitted by law.
Oxaide specifics (no account)
- Uploads are wiped within 24 hours of the job completing (delivered or failed). Jobs still awaiting payment or human review keep their inputs until resolved, then the same 24-hour wipe applies.
- Delivered packs (files + download links) auto-delete after 90 days; links stop working then.
- Quote records, answer text and job metadata stay in our database to provide history, prevent abuse and double-charging, and meet accounting and legal duties. Ask for deletion at privacy@oxaide.com — we honour it subject to lawful exceptions.
- Delivery and download links are bearer links: anyone holding the link can download until expiry. Do not forward them.
Your Rights and Choices
You can ask to see, fix, or delete your data, withdraw consent, or complain to your privacy authority. Email privacy@oxaide.com — we reply within the period the law requires.
Read the full wording
Depending on where you live, you may have rights concerning your personal data. These can include:
- Accessing personal data and information about how it is used
- Correcting inaccurate or incomplete personal data
- Requesting deletion, restriction, or objection to certain processing
- Receiving portable data where the right applies and the format is technically available
- Withdrawing consent without affecting earlier lawful processing
- Opting out of marketing communications through the message link or by contacting us
- Complaining to the relevant privacy or data protection authority
Send requests to privacy@oxaide.com. We may ask for information needed to verify your identity, authority, workspace relationship, and jurisdiction. We will respond within the period required by applicable law. Certain rights are subject to legal exceptions.
International Transfers
We're based in Singapore; providers may process data elsewhere — default model runs process in the US. Where the law requires, contractual safeguards apply.
Read the full wording
Oxaide is based in Singapore, and our providers may process information in Singapore and other countries. Default Brief runs are processed in the US (Contributor Free tier) to keep fixed per-job pricing — your isolated job computer still wipes uploads in 24h and packs auto-delete after 90 days. Paid-fallback and sensitive-job runs use the paid contract path. Those countries may have different privacy laws. Where required, we use contractual or other recognised safeguards and take steps intended to provide a standard of protection comparable to applicable requirements.
Children
Adults only — the service isn't for under-18s and we don't knowingly collect children's data. Tell us if you think a child sent us data.
Read the full wording
The Service is for adults and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so we can review and take appropriate action.
Data Breaches
If personal data leaks, we investigate, contain it, and notify the authorities and affected people within the legally required time.
Read the full wording
We investigate suspected personal-data breaches and take containment and remediation steps appropriate to the circumstances. When applicable law requires notification to an authority or affected person, we will provide it within the legally required period and include the information required by that law.
Changes to This Policy
This policy can change as the service or law changes. Updates post here with a new date — big changes affecting your rights get extra notice.
Read the full wording
We may update this policy as the Service, providers, or law changes. We will post the updated policy with a new effective date and provide additional notice when required by law or when a change materially affects your rights. Your continued use after the effective date is subject to the updated policy.
Contact
Data controller: Hillmere Private Limited (UEN 201806463W), 21 Collyer Quay, Singapore 049320. Privacy: privacy@oxaide.com — support: support@oxaide.com. Unresolved? Contact Singapore's PDPC.
Read the full wording
Data controller
Hillmere Private Limited
UEN 201806463W, trading as Oxaide
Registered address
21 Collyer Quay
Singapore 049320
Privacy and data protection
privacy@oxaide.comGeneral support
support@oxaide.comIf we do not resolve your concern, you may contact the Personal Data Protection Commission of Singapore or the competent privacy authority in your jurisdiction.
Privacy contact
Questions or data requests?
Contact us about access, correction, deletion, portability, consent, or any concern about how your data is handled.
Privacy contact
privacy@oxaide.comData controller
Hillmere Private Limited, UEN 201806463W, trading as Oxaide
By using Oxaide, you acknowledge that you have read and understood this Privacy Policy.
