Last updated 7 October 2026. This covers the OAICA website, the dashboard and the licence keys sold here. The software you install has its own licence terms; this is about the data.
The short version. We collect what an account, a payment and a licence key need, and nothing else. There is no advertising, no analytics and no third-party tracking script anywhere on this site. You can download everything we hold about you, and you can erase your account, without asking us.
BizTransit Sdn Bhd (Company No. 891234-X), Level 28, Lingkaran Syed Putra, Mid Valley City, 59200 Kuala Lumpur, Malaysia, is the data controller for everything described here. Write to oaica@sprapp.com for anything on this page, including a correction we cannot make for you.
We are established in Malaysia and are subject to Malaysia's Personal Data Protection Act 2010. We handle requests from people in the EU, the UK, Switzerland and Singapore under those laws too, including the rights listed below. We have not appointed a representative in the EU or UK; if Article 27 of the GDPR requires us to name one for you, contact us and we will say so in writing rather than leave the question open.
| Data | Why | Lawful basis |
|---|---|---|
| Your email address, and a record of when your account was created | It is the account identifier. Sign-in is a one-time link sent to that address — there is no password to store | Performance of a contract |
| A session token, held in the page's memory while you are signed in | So you stay signed in for the life of the session | Performance of a contract |
| Data | Why | Lawful basis |
|---|---|---|
| Email, the product bought, the amount, the currency, the country your connection came from, and the payment provider's transaction and customer identifiers | To take the payment, issue the licence or key, and keep the accounting record | Performance of a contract; legal obligation for the accounting record |
| Your card details | We never see them. The payment provider's own checkout collects them, on their domain | — |
The country is derived by Cloudflare from your IP address. It is recorded to answer one question — how much we have sold into each country in the last year — and we tell you plainly that it is unreliable: a VPN moves it, and it is not the same as where you are.
| Data | Why | Lawful basis |
|---|---|---|
| The key itself is never stored: only a SHA-256 hash and the first few characters, so you can tell two keys apart in the dashboard | To validate the key without holding a copy that could be stolen | Performance of a contract |
| A short identifier and name for each machine a licence is activated on | To enforce the seat count you paid for | Performance of a contract |
| Per-request usage: timestamp, model, token counts, cost, latency | To show you your usage, and to alert you about spend | Performance of a contract |
If you use the support chat, we keep the conversation so the next message has context. Those messages are sent to a third-party language model to be answered — see the next section. Do not put anything in a support message that you would not send to a vendor's cloud service; there is no secret to tell us that the dashboard cannot do.
Sign-ins, key changes and administrative actions are recorded with the time, the action, the account and the IP address. This log survives account erasure on purpose: a record of erasure that is itself erased is how a breach goes unnoticed. It is kept for security and for defending legal claims.
We do not sell personal data, and we do not share it for advertising. These are the processors and providers involved, and what each one gets:
| Who | What they receive |
|---|---|
| Cloudflare | Hosting, the database and the network. All traffic, and the IP-derived country. |
| Stripe, and Paddle where it carries a sale | Name, email and payment details, on their own checkout. Paddle is the merchant of record for the sales it handles, and remits tax on them. |
| DeepSeek or MiniMax | The text of a support conversation, when you use the support chat and a model answers it. Nothing else is sent. |
| Telegram | Conversation content and your Telegram username, if you link support to Telegram. |
| Our email provider | The address and the message, when a sign-in link or receipt is sent. |
| GitHub or Google | If you choose to sign in with them: the profile identifier and verified email they return. |
| A webhook you configure | The usage and alert events you asked to be sent to your own endpoint. |
Several of these are outside Malaysia, including in the United States and the European Union. Transfers rest on the providers' standard contractual clauses and, where applicable, an adequacy finding.
| Data | Kept |
|---|---|
| Sign-in links | 15 minutes, or until used |
| Session tokens | 7 days from sign-in |
| A key's plaintext, held only so you can read it once after payment | 24 hours |
| Payment provider events, and support conversations | 30 days |
| Account, keys, usage history, support tickets | Until you erase the account |
| Invoices, licence, payment and refund records | For as long as tax and accounting law requires — at least 7 years after the transaction. We remove your email and the name on the licence; what is left is a transaction with nobody's name on it, and we delete it once the statutory period ends. |
| Security audit log | Kept, with the account it names no longer existing |
Signed in, fetch:
GET https://buy.oaica.com/me/export
The dashboard's export button calls the same route. You get JSON: your account, keys (identifiers and prefixes, never a key value or a hash), usage, licences, entitlements, orders, refunds, support conversations and the audit entries naming you. Credentials are deliberately left out of it, because an export that leaks them is worse than no export.
DELETE https://buy.oaica.com/me x-confirm-erasure: erase
This deletes your account, your keys, your usage history, your support threads and your sign-in credentials straight away, and it cannot be undone. It refuses while a subscription is still live, so cancel first — otherwise the charges would continue against an account that no longer exists. What survives is listed in the table above: the financial record, with you taken out of it.
We answer within 30 days, which is the deadline in all of the laws above.
There is no advertising, no analytics and no third-party script on this site, and no web fonts loaded from anyone else's server. Three things are stored on your device, all first-party:
oaica_rid), set only when you arrive through an affiliate link, so
that a purchase made after that click can be credited to it. It lasts 30 days. It is a random identifier
and nothing else — no browsing history, no cross-site data.That last one is not strictly necessary for the site to work, so in the EEA, the UK and Switzerland — where storing it needs your agreement first — we do not set it at all. There is no consent banner here; there is simply no cookie for those visitors. Everywhere else it is set, and clearing your cookies removes it at any time.
Traffic is encrypted in transit. Keys are stored only as hashes. Payment details never reach our servers. Access to the production database is limited to the operators of the service. If a breach affects your personal data, we will tell you and the relevant authority without undue delay, and in any case within the deadlines the law sets — three days for Singapore's PDPC.
When this notice changes materially, the date at the top changes with it. Because there is no marketing list here and no email we send that is not a receipt, a sign-in link or a support reply, we will tell you about a material change the next time you sign in.