Save 15% on top-ups — use OFOXAI2608Learn more
OfoxAI Trust Center

Security you can build on.

OfoxAI, operated by NICE TALK PTE. LTD., brings our current security, privacy, data-handling and reliability information together in one place.

Last reviewed:

Zero content retention

Standard synchronous API prompts and responses are not persisted by the Ofox gateway.

Encrypted transport

TLS protects customer-to-Ofox and Ofox-to-provider connections.

Protected API keys

Keys are shown once, verified by hash, and support rotation, revocation and IP allowlists.

99.99% availability

Live platform and model-route health is published on the Ofox status page.

Data handling

What Ofox stores

Retention follows the feature. Standard API traffic is transient; features that must resume a job or return a result keep the minimum information needed to do that.

01

Standard model API

Zero content retention

Customer content

Prompts and responses are processed to complete the request and are not persisted by the Ofox gateway.

Operational records

Account and key identifiers, model/provider, tokens, cost, latency, status and errors may be retained to operate and protect the service.

02

Playground

Browser-first history

Customer content

Text turns stay in the active page. The latest image or video turn may be saved in the signed-in user's browser for up to 24 hours so a result or running job can be recovered.

Temporary results

Generated media, task IDs and result links may use temporary storage while the result remains available for recovery or download.

03

Video and async jobs

Feature-required retention

Customer content

Prompts, request parameters and result references are retained while an asynchronous job is processed and made available to the account.

Job records

Task state, provider, usage, cost, errors and result metadata support processing, retrieval and billing.

Controls

Current technical controls

Zero Data Retention (ZDR)

Standard API prompt and response content is processed transiently and excluded from gateway message logs and persistent prompt storage. Error handling redacts message content.

Key protection

API keys are verified by hash and can be rotated, revoked and restricted by source IP.

Encrypted request path

TLS protects API traffic from the customer to Ofox and from Ofox to the selected provider.

Access protection

Rate limits, bot protection and identity-aware controls protect public and administrative surfaces.

Provider-aware routing

Requests follow the active model route; supported paths also accept an explicit fallback-model list.

Public service status

Platform and individual model-route health is available at status.ofox.ai.

GDPR Compliance

Compliance

GDPR compliant

OfoxAI follows the GDPR requirements that apply to the personal data we process, including data minimization, purpose limitation, security safeguards and support for data-subject rights.

  • Access, correction and deletion requests
  • Documented provider and processing disclosures
  • Privacy contact: hi@ofox.ai

Singapore data protection

Singapore PDPA

OfoxAI is operated by Singapore-incorporated NICE TALK PTE. LTD. Individuals can submit access, correction, deletion or consent-withdrawal requests through hi@ofox.ai.

Payment security

Handled by PCI DSS Level 1 providers

Card details are collected and processed through hosted checkout services operated by Stripe or Airwallex. Ofox does not store full card numbers or security codes, retaining only order records and limited payment metadata.

Reliable by design, visible in public

OfoxAI publishes 99.99% availability for its platform. Current platform and model-route health is available on the public status page.

System Status

Trust resources

Need a security or privacy answer?

Talk to us about security reviews, data handling or a privacy-rights request.

Email hi@ofox.ai