Privacy Policy
Overview
Ox does not require an Ox account. Ox stores your profiles and credentials using storage you control and sends requests directly to the model providers, websites, and services you choose. OpenOx does not operate an intermediary server that receives your chats.
Data stored by Ox
Profiles can contain chats, memory, character settings, skills, artifacts, attachments, and service configuration. You choose whether a profile is stored on your device, in your iCloud Drive container, or in a folder you select through Files. Temporary chats remain in memory and are discarded when you leave them or Ox exits.
Model-provider keys and service credentials are stored in the iOS Keychain. Website sign-in state is kept in isolated WebKit storage. Ox does not place reusable credentials in chats or diagnostic logs.
Model providers and external services
When you ask Ox to generate a response, the prompt, relevant conversation context, selected attachments, tool results, and service output are sent directly to the model provider you selected. That provider processes the request under its own terms and privacy policy.
When you browse a website, connect an MCP server, install a service repository, or approve an external action, the destination receives the information needed to complete that request. Website traffic is subject to the destination's privacy practices. Ox may download public service metadata and images from Git hosts and openox.ai.
Device permissions
Ox asks for iOS permission before using protected device data. Depending on the services you enable, this may include selected files, approximate or precise location, contacts, calendar events, reminders, notifications, messages prepared for your review, photos, camera input, and Apple Health summaries.
Health access is read-only. Ox moves a persisted chat into temporary mode before reading Health data so the result is not saved by Ox or synced through iCloud. If the result is used in a model request, the selected model provider still processes it.
Diagnostics
Ox keeps diagnostic logs on your device. Logs may contain user content needed to explain what happened, but not reusable credentials. OpenOx receives a log only if you choose to export and share it.
Analytics and tracking
Ox does not include advertising, cross-app tracking, or developer-operated product analytics. Apple may process App Store and platform diagnostics under Apple's own policies.
Website data
When you visit openox.ai, the hosting service records standard access information such as the request time, IP address, requested path, response status, referrer, user agent, country, and network number. These access logs are used for security and reliability and are retained for one month.
Your choices
You can revoke device permissions in iOS Settings, disconnect providers and services, clear website data, delete content in Ox, and delete or move profile folders through Files. See Ox Support for help.
Changes and contact
This policy may change as Ox changes. The effective date above identifies the current version. Questions can be raised in the Ox Discord community.