Orihai
PRIVACY POLICY IN EFFECT 27 AUGUST 2026

Orihai's server does not store story content. It stores an account and one metered row for each generation.

This policy applies to orihai.com, to account.orihai.com and to the Orihai desktop application. It describes the personal data Orihai actually holds, not the data it might one day hold.

01Three ways to run it

Orihai can be run in three ways: with your own provider key, with a model running on your own machine, or with managed AI.

With your own key, the application communicates with your provider directly. With a local model, no data leaves the computer. Neither of these two ways sends anything to an Orihai server, and neither requires an account.

Managed AI is optional, is free while it is being tested, and requires an account. It is the only way of running Orihai in which Orihai's own servers process any data. The rest of this policy describes managed AI.

02Who holds it

Orihai is not incorporated. The controller is the individual developing it: [CONTROLLER — LEGAL NAME], [POSTAL ADDRESS].

You can write to hello@orihai.com.

03Story content

Your stories, scenarios, characters, personas, lore and notes are held in one file on your own disk. There is no cloud synchronisation. The server has nowhere to put a prompt or a reply, and neither is written to a log.

Managed AI does send your prompt out. It is sent to the model provider so that it can be answered, and the text is sent to the classifier so that it can be moderated. Both are named in clause 06, and both process the text inside the EU. The prompt and the reply pass through Orihai's server in memory for the duration of one generation and are not stored.

Orihai's server processes the text but does not keep it. Each processor applies its own retention, and clause 06 states what is known about it.

04What is stored

The server stores one row per record, and the list below is the whole of what those rows contain.

ACCOUNT
Your email address; the date it was verified; the date on which you affirmed that you are 18 or over, if you have done so; your plan, the number of tokens it has used in the current period and the date that period started; and the date the account was created.
SESSIONS
An irreversible fingerprint of the sign-in token, stored in place of the token itself, so that a copy of Orihai's records cannot be used to sign in as you; a coarse description of the browser or application, so that the devices list can name one; an identifier for the installation; and the dates on which the session began, was last used and expires.
SIGN-IN CODES
An irreversible fingerprint of the six-digit code rather than the code itself, together with the number of attempts made against it. A code expires ten minutes after it is issued, and only one code at a time can be outstanding for an address.
INSTALLATIONS
An id generated by the application, with the dates it was first seen and last seen. The id is a rate-limiting signal and is not a credential. After erasure, it carries no account.
GENERATIONS
One row for each generation, containing metadata only: the operation, the provider, the model, token counts, the cost in micro-dollars, the status, the block rule that fired if one did, and timestamps. These rows hold no prompt, no reply, no title and no text written by you.
RATE COUNTERS
A count held against a keyed digest of the subject being limited. No email address and no IP address is stored in plaintext.
CLEARED BLOCKS
A keyed digest of each block of text that the classifier has already passed, so that a world sheet is not classified twice. The text itself is not stored, and only blocks that passed are recorded.

05How long

A sign-in code expires ten minutes after it is issued. A session expires on the date held in its own row, and signing out deletes it.

Generation rows and cleared-block digests have no automatic expiry at present. Deleting your account deletes the digests with it and removes the account from the generation rows; clause 08 describes what that leaves. A retention window for the metered rows is [RETENTION — NOT YET ENFORCED IN CODE], and until one is in force this paragraph describes what happens.

06Who else processes it

Four processors are used, and no others.

HETZNER
Hosting for the servers and the database, in Germany and Finland.
ALIBABA CLOUD MODEL STUDIO
Provides the model that writes, Qwen, in a Frankfurt workspace whose deployment scope is the EU. It receives the prompt and the text written back.
AWS BEDROCK GUARDRAILS
Content moderation, in eu-central-1. It receives the text submitted for classification, and no model is invoked there. AWS states that this call is zero-retention.
RESEND
Delivers the sign-in emails. It is reached through a mail service that Orihai operates, which makes Resend a subprocessor of that service. It receives the email address and the code.

Model Studio stores prompts and outputs at rest in the workspace's own region. Its retention period, who may access the data and whether inputs are used for training are [PROCESSOR TERMS — TO BE CONFIRMED IN WRITING UNDER THE DPA].

Processing takes place in the EEA. Two of these processors have a parent company outside the EEA, and the standard contractual clauses in their data processing agreements cover the transfers that result.

07This website

This site uses no analytics, no tracking pixel and no cookie, and it writes nothing to your browser's storage. This page loads no script. The landing page loads one script, which turns the folds and changes the theme.

The site makes one external request, for the four typefaces, which are served by Google Fonts. Google receives your IP address in order to serve them.

The desktop application has no telemetry and no crash reporter.

08Access and erasure

You can do both at account.orihai.com/account. That page shows what is held on the account. To request a copy of it, write to hello@orihai.com.

Deleting the account takes effect immediately and is not recorded as a flag on a retained row. Every session is signed out at once, the outstanding sign-in code is deleted, the cleared-block digests are deleted, the installation loses its link to you, and the account row is deleted.

The generation rows are kept, with the account removed from them. They are the record of cost and capacity, and they hold no prompt, no reply and no email address.

You can also ask for a correction, object to the processing, and complain to a supervisory authority: [SUPERVISORY AUTHORITY — THE ONE FOR THE CONTROLLER'S COUNTRY].

09Why it is held

The account, the sessions and the sign-in codes exist so that you can hold an account and sign in to it. The generation rows meter a free allowance and record what it costs. The rate counters, the installation ids and the cleared-block digests protect the service against abuse and against the cost of running it.

Moderation runs on every managed request, and clause 03 of the content policy describes what it looks for.

10Changes

The date at the top of this page is the date on which this policy took effect. A change that alters what is stored or who processes it will be announced to the email address on your account before it takes effect.