On this page 12 sections
At a glance
- Accounts connect to the Ocacity API. AI generation, payments, and deployment remain unconnected.
- Projects and bounded conversation history are saved to your account. Landing prompts can also appear in the URL.
- Account forms send credentials to the API. Sessions use HttpOnly cookies; passwords and session tokens are not stored in browser local storage.
This overview helps you navigate. The full document follows.
01Who is responsible for your information
AURTIZ LTD operates Ocacity and is the organisation responsible for deciding why and how personal information is used in connection with the service described here. This notice covers the Ocacity landing page, demonstration workspace, and preview authentication screens.
- Operator
- AURTIZ LTD
- Company number
- 17307727
- Registered office
- Office 19819, 182–184 High Street North, East Ham, London, E6 2JA, United Kingdom
- Legal & privacy contact
- Write to our registered office, marked Legal or Data Protection
This is a review draft describing the present preview. This notice is scoped to the preview described below. Production hosting, logging, and any new providers will require an updated notice before public launch.
This notice does not cover a separate website that someone builds from a Ocacity export. Its operator must provide their own privacy information.
02Information used by the preview
Information comes from what you type or select, records created by the workspace, and the technical requests your browser makes to load pages. The application currently handles these categories:
| Information | What happens to it |
|---|---|
| Landing-page draft | Text stays in the text field until you submit it. On submission, the prompt is included in the workspace URL along with the selected mode and, if attached, a reference filename. |
| Workspace projects | Project identifiers, names, prompts, template types, revisions and up to 40 recent messages within a size limit are stored in the API database under your account. The project list shows the latest 100 records. |
| Reference attachments | The browser provides the selected filename, type, and size for validation. The application retains the filename only; it does not read or upload the file contents. |
| Sign-in and sign-up fields | Name, email and password are submitted to the API for registration or sign-in. Passwords are hashed by the API. Verification and reset emails use the configured email service. Passwords are not written to browser storage. |
| Technical requests | The server receives requests needed to deliver the site, including the requested path and query parameters. Ordinary connection data can include an IP address and browser headers. Production logging and retention have not been finalised. |
| Exports and copied links | An export creates a file on your device. A copy action writes the selected code or link to your clipboard. Your device, browser, and any recipient control their own copies. |
Your browser may separately offer autofill, history synchronisation, password-manager, or download features. Those features are controlled by your browser or device provider, not by this application.
03Why information is used
Inputs provide the requested account, saved workspace and example-building workflow. The API handles authentication, profiles, project storage, security checks and transactional email. Generation still selects curated examples; no AI model receives these inputs.
For processing necessary to provide the account and saved workspace you request, the intended UK GDPR basis is contract. Security and abuse prevention rely on legitimate interests, subject to a documented necessity and balancing assessment. Statutory privacy requests are handled under legal obligations. These choices and the actual deployment must be reviewed before public launch.
You can view the landing examples without an account. Access to the saved workspace requires sign-in. Browser storage used for requested account features is described in section 5.
There is no current purpose involving targeted advertising, paid account management, model training, or selling personal information. We will explain any new purpose and establish the appropriate basis before starting it. Accepting terms is not blanket consent to unrelated processing.
04Prompts in URLs and shared information
When you start a build from the landing page, the workspace address includes your prompt and selected options. Query parameters are part of the requested address; they can be received by the site server, retained in browser history, copied with the address, or captured in infrastructure logs where logging is enabled.
For this reason, a landing prompt is not guaranteed to stay solely on your device. Do not use it for passwords, tokens, private customer data, or confidential business information. A filename can itself reveal personal information even though the file is not uploaded.
The workspace’s “Share preview” action creates a starter-template link without including the saved chat history. Copying the full address from your browser is different and may include the original prompt. Anyone receiving a file or link can keep or forward it.
05Cookies and browser storage
The application does not set advertising or analytics cookies. It uses HttpOnly session cookies for authentication and short-lived cookies to bind provider sign-in to your browser. In production these cookies are Secure. The default session lasts seven days (deployment configuration permits one to 30 days); OAuth binding cookies last ten minutes by default. Sign-out revokes the corresponding server session.
| Storage | Purpose and duration |
|---|---|
| forma-demo-projects-v1 | Legacy browser-only demo records. The connected workspace does not read, import, overwrite or delete these records. You can remove them using browser site-data controls. |
| Session and action records | Expired sessions and action tokens are removed by scheduled maintenance. Verification links expire after 24 hours, password-reset links after 30 minutes. Email payloads are erased after successful sending; maintenance removes successful email metadata after seven days and all outbox records after 30 days. |
| Temporary page state | Form entries and interface state remain in page memory. The ocacity:return-to session-storage entry keeps a same-site workspace destination through sign-in and is removed on return or when the tab session ends. |
Project edits are saved automatically through the API when account services are available. A failed or pending save remains indicated in the workspace. The signed-in interface uses a session-bound CSRF value held in memory for changes. Rejecting the required session cookie prevents account access.
Use the project-list delete control to remove a project from the API database. Clearing browser site data only removes cookies and browser records; it does not delete API records, backups, exports, browser history or recipients’ copies.
06AI providers, integrations, and training
No external AI model receives prompts, repository contents, files, or chat history through the current preview. “Auto”, “Fast”, and “Thoughtful” are demonstration choices, not active model routes. The application does not train models on your content.
Enabled Google, Apple and Microsoft buttons redirect to the chosen provider for sign-in. The API validates the provider identity and stores its issuer and subject identifier, a display name, and a verified email where supplied. Microsoft sign-in does not assume its email claim proves contact ownership. Provider access and refresh tokens are not retained. Passwords are entered with the provider rather than shared with Ocacity in these flows.
Before connecting live AI or other providers, we must identify what each receives, why it is needed, where it is processed, retention and training settings, and any available choices. This notice makes no guarantee about the practices of a future provider.
08How long information remains
- Unsaved inputs: held temporarily in the page. Leaving or reloading normally clears application state, although a browser may restore form entries independently.
- Account and project records: retained in the API database until deletion; no automatic account-retention schedule is configured. Each project keeps up to 40 recent messages, within a 40 KB state limit. Older history can be displaced. Deployments must define retention and backup rules.
- URL history, clipboard content, and downloads: retained under your browser and device settings until you remove them. The application cannot remotely erase copies you have shared.
- Server request logs: the application does not define a production log-retention schedule. The final hosting configuration and deletion periods must be documented before publication.
- Privacy or legal correspondence, if received: retain only as needed to handle the request and any applicable legal obligations or dispute. The appropriate period depends on the nature of the request, whether it is resolved, and whether a legal record is still needed; information should not be retained merely because storage is available.
Deleting browser data does not delete your API account. Project deletion is available in the workspace; account deletion and data-rights requests should be sent to the operator. Backup deletion periods and account-retention schedules remain deployment decisions that must be documented before public launch.
09Security and your device
The API checks project ownership and authenticates requests with revocable sessions. Credentials use password hashing; session tokens and email action tokens are stored as hashes. This does not protect against every risk, compromised devices or browser extensions. Use your own account and sign out on shared devices.
Keep your browser and device updated and avoid entering confidential or sensitive material in projects. Email accounts support verification and password recovery when email delivery is configured. Backups and operational recovery arrangements have not been established by this local implementation.
The current preview is not a secure repository for sensitive data. No system is completely secure, and this notice does not give a security certification or service-level guarantee.
10Your privacy rights
Where UK GDPR or another applicable data-protection law gives you rights, those rights continue to apply. Depending on the processing and its legal basis, you may request access, correction, deletion, restriction, or a portable copy of personal information.
If processing is based on consent, you can withdraw that consent without affecting the lawfulness of processing before withdrawal. Not every right applies in every situation; any refusal or limitation should be explained under the applicable law.
Write to the registered office in section 1, marked “Ocacity — Data Protection”, and include a way for us to reply. We may need proportionate information to verify a request. Do not send passwords or unnecessary identity documents. We will respond within the applicable legal deadline and explain any permitted extension.
For data stored only in your browser, we may not have a server copy or the ability to identify or remove it remotely. You can use the browser controls described above. That limitation does not remove duties relating to information the operator actually holds.
You may complain to the UK Information Commissioner’s Office through ico.org.uk/make-a-complaint, or to the relevant supervisory authority where you live. You do not have to exhaust a complaint with us first.
11Children and automated decisions
Ocacity’s preview is intended for adults aged 18 or over. It does not perform age verification. Please do not enter children’s personal information into demonstration prompts or forms. Any service later offered to children would need a separate assessment and appropriate safeguards.
The preview selects example designs and simulates build steps. It does not use your information to make solely automated decisions that produce legal or similarly significant effects on you.
12Updates and questions
The version and preparation date appear at the top of this document. Before introducing analytics, payments, AI providers, additional processors, or a new purpose for information, we must update this notice to describe the actual processing and provide any notice or choice the law requires.
Changes will not retrospectively authorise uses that were not lawfully permitted. We will make the applicable version available and explain material changes in a way suited to the service.
Privacy questions and requests should be directed to AURTIZ LTD. You can write to the postal contact in section 1. Please describe the information or processing involved and the action you are requesting.