Legal
Privacy Policy
What we collect, why we collect it, and the control you have over it.
Last updated 29 September 2026
Who we are
This policy explains what personal information Odyssey (“we”, “us”) collects when you use our website, dashboard, playground and API (the “Service”), why, and what control you have over it. It forms part of our Terms of Service.
What we collect
- Account information. Your email address, name and profile picture if you add them, and sign-in details such as connected accounts and two-factor settings. Authentication is handled by our provider Clerk.
- API keys. The name you give each key, its first characters and last four characters, its limits, and when it was created and last used. We store only a one-way hash of the key itself, so we cannot read or recover it.
- Usage records. For each request: when it was made, the model called, the endpoint, the key used, token counts, cost, latency, the status and any error message, and a request id.
- Billing records. Credit purchases, grants, balances, plan months and how much of each plan's allowance was used, and notes about how a purchase was arranged. If you ask us to review a withheld sign-up bonus, we keep the note you send with the request.
- Security information. IP address, browser and device information for your sessions and for sensitive account events, used to protect your account. We also keep the networks your signed-in browser visits come from, and the network, approximate country and browser identifier your sign-up check was completed from, and we check your email domain's public mail and registration records. We use these to stop automated sign-ups and to stop the same person claiming free credit, such as the sign-up bonus, with more than one account. For the same reason we compare email addresses by inbox, so spellings that reach one mailbox (Gmail dots, "+tags", @googlemail.com) count as one address.
- Support conversations. What you tell us when you contact us on Discord, together with the Discord account you use.
Prompts and responses
We do not store the content of your prompts, messages, images or model responses. Content passes through our systems only while a request is being served, and is sent to the model that serves it. The playground works the same way: a conversation lives in your browser tab, not on our servers.
The companies that operate the models receive your request content in order to generate a response, and handle it under their own terms. Avoid sending sensitive personal data, such as health or financial information about other people, unless you have a lawful basis to do so.
How we use it
- to provide the Service: authenticate you, run your requests and show you your usage and activity;
- to bill you correctly, enforce rate and spend limits, and keep financial records;
- to keep the Service and your account secure, and to detect and prevent fraud and abuse;
- to monitor, debug and improve performance and reliability;
- to answer support requests and tell you about important changes to the Service or these policies;
- to meet legal obligations and enforce our Terms.
Where the law requires a legal basis, we rely on performing our contract with you, our legitimate interests in running a secure and reliable service, and compliance with legal obligations. We do not sell your personal information, we do not use it for advertising, and we do not use your content to train models.
Who we share it with
- AI model operators, who receive request content to generate responses, as described above. They do not receive your account details.
- Service providers that run parts of the Service for us: Clerk for authentication, Cloudflare for network delivery and protection, our server hosting provider, and Discord for support.
- Legal and safety. Authorities or other parties where we believe in good faith that the law requires it, or that it is needed to protect the rights, property or safety of our users, the public or Odyssey.
- Business transfers. A successor organisation if Odyssey is involved in a merger, acquisition or sale of assets, subject to this policy.
Cookies and local storage
We use only the cookies needed to keep you signed in and secure. Clerk sets the sign-in cookies. We set a first-party security cookie when you complete the sign-up check, holding a random identifier for your browser, so we can detect automated and duplicate sign-ups and stop abuse of free credit. Your browser's local storage remembers interface preferences such as theme, density and sidebar state; these never leave your device. We do not use advertising or cross-site tracking cookies.
How long we keep it
We keep account information for as long as your account is open. Usage and billing records are kept for as long as we need them for billing, tax, accounting, fraud prevention and legal obligations, which can continue after your account is closed; when an account is deleted, its usage history is retained in this way rather than erased. Security information is kept for a limited period. Support conversations remain on Discord under Discord's own retention.
Security
Traffic to the Service is encrypted in transit. API keys are stored only as hashes, and credentials we hold for the infrastructure behind the Service are encrypted at rest. Access to production systems is restricted. No system is perfectly secure, so we cannot guarantee absolute security, and you are responsible for keeping your own keys and sign-in details safe.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent where we rely on it. You can update most account details yourself in Settings. For anything else, contact us on Discord. We may need to verify that the request comes from the account holder, and some information may be kept where the law requires it. You also have the right to complain to your local data protection authority.
International transfers
Our servers and service providers may be located in countries other than yours, whose data protection laws may differ. Where required, we take appropriate steps to protect your information when it is transferred.
Children
The Service is not directed at children and may only be used by people aged 18 or over. We do not knowingly collect information from children; if you believe a child has given us personal information, contact us and we will delete it.
Changes to this policy
We may update this policy as the Service changes. We will change the date at the top of this page, and for material changes we will give notice through the Service or on Discord before they take effect.
Contact
For privacy questions and requests, reach our team on Discord. See the Contact page for details.