Skip to content

PRIVACY / UPDATED 14 SEPTEMBER 2026

Your data.
Your choices.

What OY Labs keeps, why we keep it, and how you stay in control.

Who is responsible.

Orca Labs sp. z o.o., trading as OY Labs, is the controller for website visits, accounts, service administration and support. Registered address: ul. Marcina Kasprzaka 31/119, 01-234 Warsaw, Poland. KRS 0001252745; NIP 5273226616.

Privacy contact: OY Labs privacy team, hello@oylabs.ai. You may also write to our registered address.

When a business instructs us to process personal data in its tasks, that business determines the purposes and we act as its processor under a data processing agreement. Contact us to arrange that agreement before submitting personal data on behalf of your business. This notice covers our website and hosted OY1 service, not the separate practices of your AI client.

What we use and why.

Account & sign-in
Email, account/profile name, optional profile image, password verifier, sign-in provider identifiers, sessions, IP address and browser information, credential verifiers and OAuth permissions. We use these to create your account, authenticate you and connect your chosen AI app. Legal basis: providing the service you request, including steps before a contract (GDPR Article 6(1)(b)). A working email and a sign-in method are needed for an account.
Task memory
The task goals, context, proposed steps, observations, answers and memory that you or your connected client send us. We store these so OY1 can resume tasks and return their history. For personal use, this supports our service contract (Article 6(1)(b)); for business-controlled personal data, we follow the business’s documented instructions. Submit only information needed for your task.
Security & reliability
Usage counters, activity times, short-lived operation receipts, request-rate records, and technical security logs help enforce limits, prevent abuse and recover the service. Legal basis: our legitimate interests in operating a safe, reliable service (Article 6(1)(f)). We limit access and retention. Routine application logs exclude task bodies and credentials.
Optional analytics
With your permission, Google Analytics receives public-page visits, selected signup-link clicks, a referring website’s origin, browser/device information and cookie identifiers. Legal basis: consent (Article 6(1)(a)). We do not send account emails, passwords, API keys or task content to Analytics. Advertising features are disabled.
Support & privacy requests
Your email, correspondence and the information needed to resolve your request. Contract-related support uses Article 6(1)(b); other enquiries use our legitimate interest in answering them (Article 6(1)(f)). Handling GDPR rights uses our legal obligations (Article 6(1)(c)). Limited records needed to establish or defend a legal claim use Article 6(1)(f).

If you choose Google sign-in, Google provides your basic profile and verified email. We do not request Gmail, Drive or other Google content. Google access tokens are encrypted in storage; passwords and previously issued personal keys are stored as verifiers.

OY1 receives tool arguments from your connected AI client and sends results back. We do not run model inference or train a model on your tasks, and do not collect your ChatGPT password or session token. We do not sell personal data or use OY1 data to make solely automated decisions with legal or similarly significant effects on you.

The service is intended for adults. Do not include special-category data, such as health information, or criminal-offence data in tasks without first arranging appropriate terms and safeguards with us. If we learn that a child has provided data, we will assess and remove it where required.

How long we keep it.

Closed tasks
Completed and cancelled tasks, including history, memory and answers: 90 days after closing.
Unfinished tasks
180 days without changes. Reading a task does not extend this period.
Accounts
Until you delete your account or 365 days pass without signing in or using the hosted service. Existing accounts receive a full 365-day period from this policy’s rollout on 14 September 2026.
Usage & access
Daily usage: 30 days. Technical security logs: up to 30 days. Operation receipts and request-rate records: 24 hours. Browser sessions: up to seven days; OAuth access tokens: five minutes; refresh tokens: up to 30 days. Expired authentication records are removed during hourly cleanup. Previously issued personal keys expire within 90 days; expired key metadata is removed after another 30 days.
Backups
Live deletion happens immediately when you delete data, or during hourly expiry checks. Restricted local backups, rollback copies and repair copies expire after seven days. AWS’s separate snapshot rotation means copies may remain for up to 15 days after live deletion. Backups are used for recovery, and deletion instructions must be reapplied before restored data goes live.
Deletion records
Minimal internal identifiers and deletion dates are kept for 30 days to prevent deleted data reappearing after a restore. These contain no email, task text or credentials. Their own backup copies follow the same 15-day limit.
Analytics & cookies
Google Analytics user/event retention is set to two months, without resetting on new activity. Analytics cookies and your device’s consent preference last up to six months. Aggregate reports that no longer identify you may remain. Google’s own deletion and backup cycles can take longer under its processing terms.
Correspondence
Routine support: up to 12 months after closing the request. A minimal record of a privacy request and our response: up to 24 months. We review these records and remove unnecessary content. A specific legal duty, dispute or valid restriction request may require limited records to be preserved longer, with access restricted and the need reviewed.

You can download your live service data, delete any saved task, delete all task data, revoke connected apps or delete your account in Your account. Copies already received by your AI client are governed by that client’s policies. A valid restriction request can pause task processing and automatic expiry while the issue is assessed.

Cookies are your choice.

Essential cookies support sign-in, security and your requested connection. They are needed for those features. We store your analytics choice, its date and policy version on your device for up to six months.

Google Analytics loads only after you accept. Declining leaves it unloaded and does not affect your access to OY1. We do not load Analytics on sign-in, signup, account, password recovery, OAuth or MCP pages. Google processes the optional analytics data on its infrastructure, which may be outside the European Economic Area.

You can withdraw consent at any time using Cookie preferences in the footer. Withdrawal stops collection on this device and removes accessible Analytics cookies; it does not affect the lawfulness of earlier processing or automatically erase data already held by Google. Contact us if you want help with an Analytics access or deletion request.

Change cookie preferences →

Read how Google uses information from partner sites and Google’s privacy policy.

Who receives data.

AWS hosts the service database and backups in Frankfurt, Germany. Its service terms include a Data Processing Addendum and contractual safeguards for applicable international transfers.

Google provides optional Analytics, Google sign-in when you choose it, and our Workspace support email. Analytics processing is covered by Google’s Data Processing Terms; Workspace uses its Cloud Data Processing Addendum. Google acts separately for its own account/sign-in services under its privacy policy.

Your chosen AI client receives the task results and permissions you authorize. It follows its own terms and privacy arrangements. Our authorized personnel access data only as needed for support, security, service operation or legal obligations. We may disclose limited information to professional advisers or public authorities where necessary and lawful.

Providers may process or permit access to data outside the EEA, including in the United States. Depending on the provider and transfer, safeguards include an applicable adequacy decision or the European Commission’s Standard Contractual Clauses with supplementary safeguards. See Google’s transfer information and AWS’s processing safeguards. Contact us to request details or copies of the safeguards applicable to your data.

Your rights.

Subject to the conditions in the GDPR, you may request access and a copy of your data, correction, deletion, restriction of processing, or portability in a reusable format. You may object to processing based on legitimate interests. You may withdraw consent for optional analytics at any time.

Email hello@oylabs.ai or write to our registered address. We normally respond within one month. If a permitted extension is needed because of complexity or the number of requests, we will explain this within that month. Requests are normally free; we will explain any lawful exception. We may ask for proportionate information to confirm your identity, but do not send a password or API key.

You may complain to the President of Poland’s Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, or to the supervisory authority where you live, work or believe an infringement occurred. You do not have to contact us first.

We will keep this notice up to date and draw material changes to your attention through the website or your account, and seek fresh consent where needed.