Orihai's servers do not store story content. They store account details and usage metadata.
This policy applies to orihai.com, to account.orihai.com and to the Orihai desktop application. It describes the personal data Orihai holds and how it is processed.
01Scope
Orihai can be used with your own provider key, with a model running on your own computer, or with managed AI.
With your own key, the application communicates directly with your provider. With a local model, no data leaves your computer. Neither sends data to an Orihai server, and neither requires an account.
Managed AI is optional and requires an account. It is the only mode in which Orihai's servers process data. The remainder of this policy concerns managed AI and the account area.
02Controller
Orihai is not incorporated. The data controller is Manuel Raya Coello (49064506D), an individual resident in Spain.
Contact hello@orihai.com with any question about this policy or to exercise the rights described in clause 08.
03Story content
Your stories, scenarios, characters, personas, lore and notes are stored in a file on your own computer. There is no cloud synchronisation, and Orihai's servers do not store or log prompts or replies.
When managed AI is used, the prompt is sent to the model provider for generation and to the moderation service for classification. Both are named in clause 06, and both process the text within the EU. The prompt and the reply pass through Orihai's server in memory for the duration of the generation and are not stored.
Each processor applies its own retention policy, described in clause 06.
04Data stored
Orihai's server stores the following records and nothing else.
- ACCOUNT
- Email address; the date it was verified; the date of the 18+ affirmation, if made; plan; tokens used in the current period and the date the period started; and the date the account was created.
- SESSIONS
- A one-way hash of the session token (the token itself is not stored); a coarse description of the browser or application; an installation identifier; and the dates on which the session started, was last used and expires.
- SIGN-IN CODES
- A one-way hash of the six-digit code and the number of attempts made against it. Codes expire ten minutes after issue, and only one code per address may be outstanding at a time.
- INSTALLATIONS
- An identifier generated by the application, with the dates it was first and last seen. Used for rate limiting; not a credential.
- GENERATIONS
- One record per generation, containing metadata only: the operation, provider, model, token counts, cost, status, the block rule applied if any, and timestamps. No prompt, reply, title or other text is stored.
- RATE COUNTERS
- A count held against a keyed hash of the subject being limited. Email addresses and IP addresses are not stored in plaintext.
- One record per message sent: a one-way hash of the address, the template sent, whether the message bounced or was reported as spam, and the date. Used to avoid sending further mail to an address that has rejected it.
- CLEARED BLOCKS
- A keyed hash of each block of text that has passed moderation, so that unchanged text is not classified again. The text itself is not stored.
05Retention
Sign-in codes expire ten minutes after issue. Sessions expire on their stored expiry date, or when signed out.
A nightly process deletes expired sign-in codes, rate counters older than one day, cleared-block hashes older than thirty days, and mail records older than ninety days. Records of messages reported as spam are retained, so that no further mail is sent to that address.
Generation records are retained for the life of the account, as the record of service cost and allowance use. They contain no text you wrote. When an account is deleted, they are retained with the link to the account removed.
06Processors
Four processors are used.
- HETZNER
- Hosting for servers and database, in Germany and Finland.
- ALIBABA CLOUD MODEL STUDIO
- Provides the language model (Qwen), in a Frankfurt workspace with EU deployment scope. Receives the prompt and the generated text.
- AWS BEDROCK GUARDRAILS
- Content moderation, in eu-central-1. Receives the text submitted for classification; no model is invoked. AWS states that this call is zero-retention.
- RESEND
- Delivers sign-in emails, as a subprocessor of a mail service operated by Orihai. Receives the email address and the code.
Model Studio stores prompts and outputs at rest in the Frankfurt region. Alibaba's privacy notice for the service states that customer data is not used to train its models. Audit logs, which cannot be disabled, record the request id, time, model, token counts, latency and status, but not the prompt or response, and are retained for thirty days. Inference logs, which would contain the prompt and response, are disabled and are not available in this region. Alibaba's data processing addendum requires deletion or return of data at the end of the agreement.
All processing takes place in the EEA. The Model Studio contract is with Alibaba (Netherlands) B.V. Two of the processors have parent companies outside the EEA; the resulting transfers are covered by the European Commission's standard contractual clauses, published as Implementing Decision (EU) 2021/914 and incorporated in their data processing agreements. Copies are available on request from hello@orihai.com.
07Cookies and analytics
orihai.com
The website sets no cookies. It stores one value in browser local storage: the theme you last selected, if any. Clearing browsing data removes it.
Page views are counted using Umami, self-hosted at analytics.facilitra.com. It sets no cookies and stores nothing in your browser. It receives the page address, page title, referrer, screen size and browser language. Your IP address is received with the request, as with any request, and is used together with the browser string to distinguish new from returning visits; it is not stored. No identifier is assigned to you.
Fonts are served from orihai.com. No other third-party requests are made.
account.orihai.com
The account area sets four cookies, all strictly necessary for its operation. No consent is required for them.
- SESSION
- Keeps you signed in. Contains the session token. Thirty days; removed on sign-out.
- FORM TOKEN
- A random value used to prevent cross-site request forgery. Removed when the browser is closed.
- SIGN-IN STEP
- The current sign-in step and the address entered, for the duration of sign-in. Ten minutes.
- ADDRESS CHANGE
- The new address entered, for the duration of an address change. Ten minutes.
All four are marked HttpOnly, Secure and SameSite=Strict and carry the __Host- prefix. They cannot be read by scripts and are not sent to any other site.
Page views in the account area are counted by the same Umami instance on the same terms. Page addresses on this host contain no identifiers, email addresses or tokens.
The desktop application
The desktop application has no telemetry and no crash reporting. Your stories, characters and settings are stored on your own computer. Its network use is described in clause 01. If measurement is ever added, clause 10 applies.
08Your rights
You can view the data held on your account, export it and delete the account at account.orihai.com/account.
Deletion is immediate. All sessions are ended, any outstanding sign-in code and all cleared-block hashes are deleted, the installation record is unlinked from the account, and the account record is deleted. Generation records are retained with the links to the account and to the installation removed; they contain no prompt, reply or email address.
You can change the email address on your account at account.orihai.com/account/email.
You also have the right to object to processing, to request that it be restricted, and to lodge a complaint with the supervisory authority: the Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid.
09Legal basis
Account, session and sign-in code records are necessary to provide the account, and are processed on the basis of the contract between you and Orihai. Generation records meter the allowance and record its cost, on the same basis.
Rate counters, installation identifiers, cleared-block hashes and mail records are processed on the basis of legitimate interest: keeping the service available, affordable and deliverable. Moderation is processed on the same basis and as a requirement of the model provider.
No processing is based on consent. The 18+ affirmation is a statement made under the terms of service, not a consent to processing.
Moderation is applied to every managed AI request. Clause 03 of the content policy describes what it checks.
10Changes
This policy took effect on the date shown at the top of this page. Changes affecting what is stored or who processes it will be notified to the email address on your account before they take effect.