MÖBIUS
Terms

Privacy Policy

Last updated — July 2026

Möbius Oracle ("Möbius", "the Platform", "we", "us") is built around a simple principle: we collect as little as possible to operate, and we don't keep what we don't need. This policy explains exactly what data we handle, what we don't, and why.

1. What We Collect

We collect the minimum data required to authenticate your access, process payments, and maintain billing records. Here's the full picture:

Data Point Purpose Status
API Key (hashed) Authentication & account identification Collected
Deposit TXIDs Payment verification & billing records Collected
Sender wallet address Associating deposits with your account Collected
Query metadata Credit deduction, usage tracking, error detection Collected
Timestamp & mode selection Billing accuracy & system diagnostics Collected
Your name, email, or identity — Not collected
Conversation content — Not collected
IP address logging — Not collected
Browser fingerprints — Not collected

"Query metadata" means: timestamp, execution mode selected, MC cost, and success/failure status. It does not include the content of your query or the response generated.

2. What We Don't Collect

Your conversations are not permanently stored. Query content and response content are processed in-memory during execution and are not written to persistent storage. Once your session ends, that data is gone. We have no archive of your prompts or outputs.

We do not require or collect:

  • Personal identification — No name, email, phone number, government ID, or physical address. Your API key is your only identifier.
  • Behavioral analytics — No tracking pixels, no session replay, no heatmaps, no engagement metrics.
  • Conversation logs — Prompt content and generated responses are ephemeral. They exist only during active processing.

3. Cryptocurrency Payments

Payments are processed exclusively in USDT (TRC-20). When you make a deposit, we observe and record:

  • The transaction ID (TXID) on the TRON blockchain.
  • The sender wallet address.
  • The deposit amount and confirmation status.

This information is inherently public on the blockchain. We use it solely to verify your deposit and credit your account. We do not perform chain analysis, attempt to link wallet addresses to real-world identities, or share transaction data with third parties.

4. Cookies & Local Storage

Möbius does not use tracking cookies. The Platform uses your browser's localStorage to persist the following on your device:

  • API key — So you don't have to re-enter it every session.
  • UI preferences — Selected execution mode, interface settings, and display preferences.
  • Session state — Temporary conversation context for your active session (cleared on session end).

This data is stored locally on your device only. It is never transmitted to our servers except for the API key when authenticating requests. You can clear this data at any time through your browser's developer tools or storage settings.

5. Third-Party AI Processing

Möbius routes queries through third-party AI inference providers to generate responses. Here's what you should know:

  • We do not disclose which AI models or providers are used in our routing pipeline. This is proprietary operational infrastructure.
  • No user identity is shared with third-party providers. Queries are submitted to inference APIs without any information that could identify you — no API key, no wallet address, no account metadata.
  • Third-party providers receive only the query content necessary to generate a response. They operate under their own data processing policies, but they have no knowledge of who submitted the query.
  • We may change, add, or remove providers from our routing pipeline at any time without notice.

The architectural separation between your identity and the query content submitted to providers is by design. You are a key to us. To them, you don't exist.

6. Data Retention

6.1 Ephemeral Data

Session data — including query content, response content, and active conversation context — is ephemeral. It exists in-memory during processing and is not persisted to long-term storage. When your session ends or the processing pipeline completes, this data is discarded.

6.2 Retained Data

The following data is retained for operational and billing purposes:

  • Billing records — Deposit TXIDs, credit transactions, MC balance history, and query cost logs. These are retained indefinitely for accounting integrity.
  • API key records — Hashed API keys and their associated account status. Retained for the lifetime of the account.
  • System logs — Anonymized error logs and performance metrics for infrastructure monitoring. These contain no user-identifiable information or query content.

7. Security

We implement the following security measures to protect the data we do handle:

  • Encryption in transit — All communication between your device and the Platform is encrypted via TLS. API requests and responses never travel in plaintext.
  • No plaintext storage of sensitive data — API keys are stored in hashed form. We do not store raw keys in our database.
  • Minimal attack surface — By not collecting personal information, we minimize the value and risk of any potential data breach. You can't leak what you don't have.
  • Infrastructure isolation — Query processing pipelines are isolated from billing and account management systems.

No system is invulnerable. While we employ strong security practices, we cannot guarantee absolute security. If you discover a vulnerability, contact us at sovereign@mobiusoracle.io.

8. Your Rights

Given our minimal data collection, traditional data subject rights (access, rectification, portability) are largely moot — we don't hold meaningful personal data to act upon. However:

  • You may request deletion of your account and all associated billing records by contacting us. Upon verification, we will purge your data within a reasonable timeframe.
  • You can clear all locally stored data (API key, preferences) at any time through your browser.
  • You may request a summary of the billing data we hold associated with your API key.

9. Children

The Platform is not directed at individuals under the age of 18. We do not knowingly collect data from minors. Given our invite-only access model and absence of personal data collection, we have no practical mechanism to verify age — but this Platform is not intended for children.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. Changes will be posted on this page with an updated revision date.

Your continued use of the Platform after any changes are published constitutes your acceptance of the revised Privacy Policy. If we make material changes that significantly affect how we handle your data, we will make reasonable efforts to notify active users.

11. Contact

For questions, concerns, or data requests related to this Privacy Policy, reach us at:

sovereign@mobiusoracle.io

© 2026 Möbius Oracle. All rights reserved.

Terms  ·  Privacy