01Deep dive
Introduction and scope
Who we are, what this policy applies to, and how it relates to our Terms of Service.
Shen Pandi and the o10 team ("o10," "we," "us," or "our") respect your privacy. This Privacy Policy describes how we collect, use, disclose, and protect personal data when you access https://o10.io and related pages (the "Site"), use the o10 inference spend control plane (the "Service"), or interact with us for sales, support, or governance engagements.
Capitalized terms not defined here have the meanings in our Terms of Service. By using the Site or Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Site or Service.
We may update this policy from time to time. Material changes to how we process personal data in the Service will be communicated to registered account holders by email or in-product notice where practicable. The 'Last updated' date at the top reflects the latest revision. Continued use after changes constitutes acceptance.
02Deep dive
Information we collect
Personal data we collect from the Site, the Service, and your communications with us.
Personal data means information that identifies you or could reasonably be linked to you. We collect the categories below depending on how you interact with o10.
- Account and contact data: name, work email, organization, role, billing contact, and credentials you provide when registering for the Service or contacting us.
- Service and routing metadata: model identifiers, venues, token counts, latency, cost, policy decisions, eval scores, shadow-mode deltas, KYI pillar scores, and immutable ledger entries generated when o10 sits in your inference path.
- Configuration data: quality floors, budget envelopes, residency rules, model approval lists, enforce/shadow mode settings, and integration parameters you configure.
- Support and sales data: messages, call notes, audit requests, and documents you voluntarily provide.
- Site usage data: pages viewed, referrers, device type, browser, approximate geography, and similar analytics signals on o10.io.
- Payment data: billing records processed by our payment providers (we do not store full payment card numbers).
03Deep dive
o10.io marketing site
The public Site is largely static; collection is limited.
o10.io publishes educational content, calculators, and demos. You may browse without an account. Interactive demos (for example, the spread calculator and Book widget) run client-side in your browser unless you submit data to us separately.
When PUBLIC_GA_MEASUREMENT_ID is configured, we use Google Analytics 4 via googletagmanager.com for aggregate traffic measurement. GA4 may receive page URL, referrer, device category, and coarse geography. We configure IP anonymization where supported.
We do not operate an advertising network on o10.io and do not use Site analytics for cross-site tracking or sale of visitor lists.
04Deep dive
o10 control plane (Service)
What we process when o10 routes, shadows, or enforces inference spend.
The Service sits above your AI gateways and cloud accounts. It selects models and venues per your policies, records economics on every call, and produces CFO-grade ledgers and KYI governance outputs.
To deliver the Service, o10 must process routing metadata and — depending on your configuration — limited prompt or completion excerpts for eval replay and quality-floor verification. You control what workloads are in scope, which eval suites run, and whether enforce mode is enabled.
Shadow mode mirrors traffic without changing production responses unless you configure otherwise. Enforce mode applies routing in the request path. Both modes write to the immutable ledger you use for audit and board reporting.
You are responsible for ensuring you have lawful basis and any required notices to end users whose inference traffic flows through o10, including when you connect production systems.
05Deep dive
No model training on your content
o10 is a control plane, not a model trainer.
o10 does not use customer prompts, completions, embeddings, or other User Content to train foundation models for o10 or third parties. Our business is spend enforcement and governance — not data harvesting for model improvement.
Upstream model providers (OpenAI, Anthropic, Google, Amazon Bedrock, unified inference gateway, OpenRouter, and others) have their own data practices. You must review and comply with applicable provider terms. o10 routes traffic; it does not override provider retention or training policies except where your configured policies block a route.
06Deep dive
Cookies and similar technologies
How we use cookies on the Site and Service.
We use cookies and similar technologies for strictly necessary functions (security, session integrity), preferences (where offered), and analytics (GA4 on the Site).
You can control cookies through browser settings. Disabling cookies may limit Site functionality. For GA4 opt-out, see Google's tools at https://tools.google.com/dlpage/gaoptout and https://policies.google.com/privacy.
- Strictly necessary: required for security and basic Site operation.
- Functional: remember preferences where a feature offers them.
- Analytics: understand aggregate usage to improve content and performance.
07Deep dive
How we use personal data
Purposes for which o10 processes information.
We use personal data only as described here or as disclosed when you provide it.
- Provide, operate, and secure the Service — including routing, shadow and enforce modes, evals, KYI scoring, and ledger generation.
- Verify savings baselines and calculate gainshare fees tied to proven shadow deltas.
- Communicate about the Service, security alerts, billing, and policy changes.
- Provide support, professional services, and onboarding you request.
- Improve the Service through aggregated, de-identified usage analysis.
- Comply with law, respond to lawful requests, and enforce our Terms.
- Protect o10, our customers, and the public from fraud, abuse, and security risk.
08Deep dive
How we share information
We do not sell personal data. We disclose it only as follows.
Service providers: cloud hosting provider, cloud infrastructure, analytics, payment processors, email delivery, and support tools — bound by contract to use data only for our instructions.
Your gateways and model providers: when you route inference through o10, necessary request metadata flows to the venues you authorize, under your agreements with those providers.
Professional advisors: lawyers, accountants, and auditors under confidentiality obligations.
Corporate transactions: merger, acquisition, financing, or sale of assets — with notice where required by law.
Legal and safety: when required by law or to protect rights, safety, and integrity of the Service.
With your consent or at your direction: for example, board packs or audit exports you explicitly request.
09Deep dive
Data retention
How long we keep information.
Immutable ledger entries and KYI audit trails may be retained for the life of your agreement plus periods required for finance, tax, and regulatory compliance — because customers rely on them for board and regulator assurance.
Shadow-mode baselines used for gainshare verification are retained per your contract and our data schedule.
Site analytics are retained per GA4 configuration and our internal logs policy.
When retention ends, we delete or de-identify data unless law requires longer storage.
10Deep dive
Security
Measures we use to protect information.
We implement administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is 100% secure; you use the Service at your own risk for residual threats.
You are responsible for securing credentials, API keys, and access to your o10 organization. Notify us promptly at security@o10.io if you suspect unauthorized access.
11Deep dive
Your rights and choices
Access, correction, deletion, and regional privacy rights.
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, port data, or withdraw consent. Email privacy@o10.io to exercise rights. We may verify your identity before responding.
Marketing emails include an unsubscribe link. Transactional and security messages may still be sent.
If you are in the EEA, UK, or similar jurisdictions, you may lodge a complaint with your supervisory authority. Our legal bases include contract performance, legitimate interests (security, product improvement), consent where required, and legal obligation.
California residents: we do not sell personal information as defined by the CCPA/CPRA. See our Terms for additional U.S. state disclosures.
12Deep dive
International transfers
Where data is processed.
o10 may process data in the United States and other countries where we or our service providers operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses for transfers from the EEA/UK.
13Deep dive
Children
The Service is not directed to children.
The Site and Service are intended for business and professional users. They are not directed to individuals under 16 (or the age required in your jurisdiction). We do not knowingly collect children's personal data. Contact privacy@o10.io if you believe we have.