Zero content retention
Standard synchronous API prompts and responses are not persisted by the Ofox gateway.
OFOXAI2608, ends Aug 31Learn moreOfoxAI, operated by NICE TALK PTE. LTD., brings our current security, privacy, data-handling and reliability information together in one place.
Last reviewed:
Zero content retention
Standard synchronous API prompts and responses are not persisted by the Ofox gateway.
Encrypted transport
TLS protects customer-to-Ofox and Ofox-to-provider connections.
Protected API keys
Keys are shown once, verified by hash, and support rotation, revocation and IP allowlists.
99.99% availability
Live platform and model-route health is published on the Ofox status page.
Data handling
Retention follows the feature. Standard API traffic is transient; features that must resume a job or return a result keep the minimum information needed to do that.
Customer content
Prompts and responses are processed to complete the request and are not persisted by the Ofox gateway.
Operational records
Account and key identifiers, model/provider, tokens, cost, latency, status and errors may be retained to operate and protect the service.
Customer content
Text turns stay in the active page. The latest image or video turn may be saved in the signed-in user's browser for up to 24 hours so a result or running job can be recovered.
Temporary results
Generated media, task IDs and result links may use temporary storage while the result remains available for recovery or download.
Customer content
Prompts, request parameters and result references are retained while an asynchronous job is processed and made available to the account.
Job records
Task state, provider, usage, cost, errors and result metadata support processing, retrieval and billing.
Controls
Standard API prompt and response content is processed transiently and excluded from gateway message logs and persistent prompt storage. Error handling redacts message content.
API keys are verified by hash and can be rotated, revoked and restricted by source IP.
TLS protects API traffic from the customer to Ofox and from Ofox to the selected provider.
Rate limits, bot protection and identity-aware controls protect public and administrative surfaces.
Requests follow the active model route; supported paths also accept an explicit fallback-model list.
Platform and individual model-route health is available at status.ofox.ai.
Compliance
OfoxAI follows the GDPR requirements that apply to the personal data we process, including data minimization, purpose limitation, security safeguards and support for data-subject rights.
Singapore data protection
OfoxAI is operated by Singapore-incorporated NICE TALK PTE. LTD. Individuals can submit access, correction, deletion or consent-withdrawal requests through hi@ofox.ai.
Payment security
Card details are collected and processed through hosted checkout services operated by Stripe or Airwallex. Ofox does not store full card numbers or security codes, retaining only order records and limited payment metadata.
OfoxAI publishes 99.99% availability for its platform. Current platform and model-route health is available on the public status page.
Talk to us about security reviews, data handling or a privacy-rights request.