OraLoyBack to site
Updated 10 Sept 2026

Privacy Policy

What OraLoy collects, why it needs it, how long it keeps it, and what you can ask us to do about it.

OraLoy is built to sit between you and your editor while knowing as little about you as the job allows. This policy sets out exactly what that means in practice. It covers oraloy.dev, the dashboard, and the MCP server.

1. What we collect

There are four categories, and no others:

  • Account data. Your name, your email address, and the timestamp your account was created. You give us these when you sign up.
  • Authentication data. A hashed credential or the identifier from the provider you signed in with, plus session cookies that keep you signed in.
  • Usage data. A count of compiles per billing cycle, the timestamp of each call, and which key made it. This is what draws your usage meter and enforces your plan limit.
  • Billing data. Your plan, your interval, your subscription status, renewal dates and invoice records.

2. What we do not collect

OraLoy never touches your files. It is a remote server, so it only ever receives the text of the request you deliberately send to a tool. It does not read your repository, your open buffers, your environment, or anything else on your machine.

We do not store your card number. Payment details go straight to our payment processor and never reach our servers.

We do not use your requests or the prompts we compile from them to train models, our own or anyone else's.

There is no advertising network, no third-party tracker and no cross-site profiling anywhere on the site.

3. How your prompts are handled

A request travels to the server over TLS, gets compiled, and the result goes back to your editor. Compiling calls a third-party model provider, so the text of your request is processed by that provider under a business agreement that forbids using it for training.

If prompt history sync is on for your plan, the request and the compiled prompt are stored against your account so you can see them in the dashboard. You can clear history at any time, and deleting your account deletes it outright. With sync off, the request is held only for as long as the call takes and is not written to disk.

4. Why we are allowed to hold it

Under the UK GDPR and the EU GDPR we rely on three bases. Performing our contract with you covers your account, your keys, your compiles and your billing, because without them there is no service to give you. Legitimate interests covers keeping the service secure, preventing abuse and understanding aggregate load, balanced against your rights. Legal obligation covers keeping invoice and tax records for as long as the law requires.

We do not rely on consent for anything except optional product email, which you can decline without losing any part of the service.

5. Who else sees it

We do not sell your data, and we never will. It is shared only with the processors that make the product work:

  • Supabase, for the database and authentication that hold your account.
  • Polar, our Merchant of Record, for payment processing, tax handling and invoices.
  • Our model provider, for the compiling call itself, under terms that forbid training on your text.
  • Our hosting and error-monitoring providers, which see request metadata in the ordinary course of serving traffic.

Each of these is bound by a data processing agreement. We would also disclose data where a valid legal order requires it, and where we are allowed to tell you about it, we will.

6. International transfers

Some of these providers operate outside the UK and the EEA, principally in the United States. Where data moves there it is covered by Standard Contractual Clauses or the UK addendum to them, together with the technical measures described below.

7. How long we keep it

Account data lives for as long as the account does. Usage counters are kept for 12 months so your history and your invoices agree with each other, then aggregated. Prompt history lives until you clear it or delete the account.

Deleting your account removes the account record, its keys and its history within 30 days, including from backups as those roll over. Invoice records outlive it, because tax law requires us to keep them for six years.

8. Security

Everything travels over TLS. Secret keys are stored hashed, which is why the dashboard can show you a key exactly once and never again. Database access is restricted by row-level policies so one account cannot read another's rows, and administrative access is limited to the people who need it to run the service.

No system is perfectly safe. If a breach affects your personal data and puts you at risk, we will tell you and the relevant regulator within 72 hours of becoming aware of it.

9. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it to another provider in a portable format, or object to processing we base on legitimate interests. Most of this is a button in the dashboard already, and for anything that is not, email us and we will act within 30 days at no charge.

Write to support@oraloy.com to exercise any of these. If you think we have handled your data badly, you are entitled to complain to your data protection authority, which in the UK is the Information Commissioner's Office.

10. Cookies

We set the cookies that keep you signed in and the ones that keep the checkout working. That is the whole list. There are no analytics cookies, no advertising cookies, and consequently no consent banner to click through.

11. Children

OraLoy is not for anyone under 16. We do not knowingly hold data about a child, and if we learn we have, we delete it.

12. Changes and contact

When this policy changes, the date at the top changes with it, and anything material is emailed to the address on your account before it takes effect.

The data controller for the processing described here is OraLoy. Reach us at support@oraloy.com.