Privacy Policy
Last updated: 5 September 2026
This policy explains what OrigoZero collects when you use origozero.ai, the Zero engine in your browser or on your desktop, and the ZeroMind service behind them, why we collect it, who else sees it, how long we keep it, and what you can do about it. It is written to describe what the software does today. When the software changes in a way that matters to you, this page changes with it.
Who is responsible
The service is run by OrigoZero Oy, Espoo, Finland ("OrigoZero", "we"). We are the controller of the personal data described here. For anything in this policy, including requests about your data, write to admin@origozero.com from the email address on your account.
What we collect
Account details. A username and a password (stored only as a hash). Optionally an email address (and the time you verified it), a display name, a short bio, pronouns, an avatar image, a 3D avatar description, and a profile colour. If you register a bot, its account carries a bot flag and a link to your account.
Sign-in providers. If you sign in with Google or another provider listed on the sign-in page, the provider tells us your identifier with them and the email address it holds for you, and we store those two things. The provider also offers us your profile name and picture; we do not store them or use them as your display name. What a provider itself records about that sign-in is governed by its own policy.
Content. Worlds, assets, packages, commits, comments, votes and ratings, and anything else you put on the platform. A world has one of three visibilities:
- Public. Anyone can view it, play it, fork it and pull parts of it, under the licence you chose when you published. Search engines and AI systems can read it.
- Unlisted. Anyone who has the link can open and play it. It is left out of listings, search and the sitemap, but it is not private: a link that is shared or guessed opens it.
- Private. Only you, the people you invite, and our administrators can open it. We access private worlds only to run the service, to fix a problem you reported, or where the law requires.
Agents, bots and connected AI clients. If you register a bot or connect an AI agent to your account, its actions are recorded under your account together with the keys and tokens that let it act. If you connect a third-party AI client (for example Claude or ChatGPT) to your account through our sign-in flow, that client's operator receives whatever the client reads and writes on your behalf, including content from your private worlds, for as long as it stays connected. A client stays connected for as long as it keeps using its access: each access token lasts one hour and each refresh token 30 days, and a client that refreshes in time receives new ones. Its access ends when it has gone 30 days without refreshing, when the client itself gives its tokens back, or when you delete your account. Settings has no control yet for listing or disconnecting a client; until it does, write to admin@origozero.com and we will disconnect it for you.
Chat with the built-in agent. Messages you send to the built-in agent, images and files you attach, the agent's replies, its working notes, and the inputs and outputs of the tools it runs on your world are stored by the chat host so that a conversation can continue where it left off. They are kept until you delete the conversation or delete your account, at which point the chat host deletes every conversation the account owns, with its messages, attachments and replies. That deletion does not yet reach what the host keeps beside a conversation: the recorded inputs and outputs of the tools the agent ran, the notes kept with it, and the files the agent wrote in your working area on the host. We intend to delete those too and will update this page when we do.
Bug reports and feedback. When you send a bug report or feedback from the site, the engine or an editor plugin, we store what you wrote together with your account, the world it concerns, the network address the report came from and your browser or engine version. A report may be copied into a public issue on GitHub; the copy carries the text and the world, never your network address or email. The stored report is deleted when you delete your account. A copy already published on GitHub stays there, because it is a public record of a defect and no longer carries your account or address.
Usage data. Three kinds:
- Request logs. Every request to the service is logged with the route called, the result, timing, the size of the request and response, which account and which installed engine made it, the network address it came from, and the browser or engine version. The front door logs the same for every page, including the full address requested (so a search you typed into the site's search box is in that log). Kept 30 days.
- Engagement measurements. How long a world stayed open, whether the engine finished loading, which pages were visited, and how many chat turns and credits a session used. These carry a random identifier that lives only for one page view and is not stored in your browser. They contain no content you typed. Kept 90 days.
- Play history. When you open a world while signed in, we record that you opened it and when, so your profile and recommendations can use it. Deleted with your account.
Play state in worlds. While you play, the world's live state, your position and per-world saved data are held by the multiplayer services (SpacetimeDB and the relay) under your account, so the world can keep them between sessions and share them with other players in the same world. Our presence counts, which show how many people are in a world, are kept as numbers without names.
Email. If you give us an email address we use it to verify the account and to send password reset links. We do not send marketing email.
The desktop engine. The installed Zero engine checks for updates each time it starts by sending its version and a random per-installation identifier to origozero.ai. It keeps your session token, an installation identifier and its own signing key in a file on your computer, along with logs, caches and the worlds you open, under your user profile. Nothing in those local files is uploaded by the engine itself, and they stay on your computer after you remove the engine until you delete them (the Terms say where they are). When you use an in-engine AI agent that is a separate program on your computer, that program's own settings on your machine may be changed to let the engine talk to it.
Device permissions in the browser. A world can ask your browser for the microphone, Bluetooth, the clipboard and pointer lock. Sound and device data stay inside the engine on your device unless a world's own script sends them somewhere (see "Worlds are programs").
Worlds are programs. A world's scripts can contact other servers on the internet chosen by the world's author, and on the desktop can open network and serial connections. What a world sends there is decided by its author, not by us, and this policy does not cover it. Play worlds from authors you trust.
We do not collect payment details on the site. A paid plan is arranged by email and invoiced outside the site, so no card number passes through the service; we keep the email you write to us from and the invoice details you give us (see "How long we keep it"), and the plan itself is recorded on your account.
Why we use it, and on what basis
Under EU data protection law each use rests on one of three bases: the contract with you (the service you signed up for), our legitimate interest, or your consent.
| Use | Data | Basis |
|---|---|---|
| Signing you in and keeping your account | Account details, sessions, sign-in provider identifiers | Contract |
| Storing and showing your content, at the visibility you chose | Content, play state | Contract |
| Answering your chat with the built-in agent | Chat messages, attachments, the world it works on | Contract |
| Letting agents, bots and connected clients act for you | Their keys, tokens and actions | Contract, at your request |
| Making public content findable: descriptions and search indexes | Text of public worlds and the assets in them (see Gemini below) | Legitimate interest in a working catalogue |
| Keeping the service working and safe: finding abuse, limiting misuse, debugging | Request logs, engagement measurements, bug reports | Legitimate interest in security and reliability |
| Understanding which parts of the product are used | Engagement measurements | Legitimate interest in improving the service |
| Contacting you about your account | Contract | |
| Sending email verification and password resets | Contract |
We do not ask for consent for anything today, so nothing here rests on it. If we ever add something that does, we will ask first, and you can withdraw that consent at any time.
Who else sees your data
We use a small number of providers to run the service. Each one receives only what its job needs.
- Hosting and file storage. Hetzner, in the European Union: the servers that run the service are in Finland, and the object storage that holds files is in Germany. Files you download, such as covers and world content, are served from that object storage, which sees the network address of the downloader.
- Domain name service. Cloudflare provides DNS only. It does not sit in front of the site and does not see your traffic.
- Sign-in providers. Google, and any other provider listed on the sign-in page, only when you choose to sign in with them.
- Transactional email. Resend, for verification and password reset messages, in the United States.
- The chat model. Messages you send to the built-in agent are answered by a large language model reached through OpenRouter (United States). Each turn sends the whole conversation so far, your attachments, the agent's instructions, and the inputs and outputs of the tools it ran, which can include files from the world it is working on. The model behind OpenRouter is chosen by us and can change; at the time of writing it is operated by OpenAI. We use these providers' business interfaces, under their business terms.
- Descriptions and search indexes. Google's Gemini models (United States) generate descriptions and search indexes from the text of public worlds and the assets in them. Text from a private or an unlisted world is not sent. Publishing a world is what puts its text in scope, and making a public world private or unlisted, or moving it to Trash, takes it back out.
- Search engines. When you publish, change or unpublish a public world, we notify search engines of the address so their index stays current.
- Connected AI clients. Any third-party client you connect to your account, as described above, for as long as it stays connected.
Providers in the United States process data outside the European Economic Area. Where we rely on a provider there, we rely on its standard data protection terms for that transfer.
We do not sell your data and we do not share it with advertisers. We do not use your data, and to our knowledge our providers do not use it under the terms we use them on, to train AI models.
Cookies and browser storage
We do not use tracking cookies, and no cookie from anyone else is set by our pages. Our own pages load their scripts, styles, fonts and images only from us and from the Hetzner object storage described above, and embed no frames from other companies. Content written by other users is the exception: a world's description or an asset's README can include an image hosted anywhere on the web, and your browser fetches it from that host, which then sees your network address. That is the same kind of outside contact a world's own scripts can make (see "Worlds are programs").
The only cookies we set appear during sign-in with a provider, and both are there to keep that sign-in safe:
cb_oauth_state, set when you start a provider sign-in, holds a signed token that ties the provider's reply to your browser. It lasts ten minutes and is removed when the sign-in finishes.cb_oauth_pending, set only when a provider sign-in creates a new account, carries the provider's identity for you into the registration step. It lasts ten minutes and is removed when registration finishes.
Everything else lives in your browser's storage, which you can clear at any time from your browser:
- your session and refresh tokens, which keep you signed in;
- your choice of opening worlds in the browser or in the desktop engine;
- whether you dismissed the desktop engine card;
- which chat conversation you last had open in each world;
- the text of an unsent idea from the Create page while you sign in (removed as soon as it is restored);
- the engine's caches of world content, models and compiled shaders, so a world you have opened loads faster next time.
None of these identify you to anyone but us, and none are used for advertising or for measuring you across other sites.
How long we keep it
| Data | Kept |
|---|---|
| Account details | Until you delete the account |
| Session tokens | 7 days since last use; refresh tokens 30 days |
| Email verification and password reset links | 24 hours and 1 hour |
| Worlds you delete | In your Trash for 30 days, where you can restore them, then purged (see below) |
| File contents of a purged world | Deleted within about two weeks of the purge, once nothing else on the service still points at those bytes |
| Comments you delete | Blanked at once; a placeholder marked as removed stays in the thread |
| Request logs and the front door's access logs | 30 days |
| Engagement measurements | 90 days |
| Play history | Until you delete the account |
| Bug reports and feedback | Until you delete the account, or until we delete them; there is no automatic expiry otherwise |
| Chat with the built-in agent | The conversation and its messages: until you delete the conversation or the account. The tool records, notes and working files kept beside it: until we delete them; there is no automatic expiry today |
| API keys and bot credentials | Until you remove them or delete the account |
| Sign-in provider connections | Until you delete the account; Settings has no way to unlink one yet |
| Connected AI client grants | Access tokens 1 hour, refresh tokens 30 days, renewed for as long as the client keeps refreshing; removed once it stops for 30 days, gives its tokens back, or you delete the account |
| Paid-plan email and invoice details | As long as the plan is active, then for the period bookkeeping law requires (in Finland, six years from the end of the financial year) |
What "purged" means. When the 30 days are over, the world, its memberships, comments, references and the assets only it used are deleted from the service. A hidden record that the world existed stays behind. Votes and ratings given by accounts that have since been deleted are kept as counts with no voter attached.
The file contents go too, on a short delay. Files are stored by their fingerprint, so two worlds that publish the same bytes share one copy, and a file can only be deleted once nothing at all still points at it: no world, no commit, no cover image, no avatar. A background job checks this and deletes the bytes it finds unused, normally within about two weeks of the purge. The delay is a safety margin: a file is held for a while after it looks unused, so that a world which turns out to still need it gets it back instead of losing it. A file that another world does still use is kept, because deleting it would break that world.
Your rights
You can see and change your account details in Settings at any time, and you can delete your own worlds and content.
You can delete your account yourself in Settings, under Danger zone. Deleting it removes your username, display name, email, avatar, bio, sessions, keys, bots, follows, bookmarks, play history and memberships, moves your worlds to the Trash (purged after 30 days), erases your conversations with the built-in agent and the bug reports and feedback you sent, and leaves only an anonymous record where your comments used to point at you. Your votes and ratings are deleted outright, and the scores they contributed to keep their totals, so nothing you voted on changes and nothing says how you voted. Deleting an account cannot be undone.
If you are in the EU, the EEA or the UK you also have the right to ask for a copy of your data, to have it corrected, to have it erased, to receive the data you gave us in a machine-readable form, to restrict or object to how we process it, and to complain to your data protection authority. In Finland that is the Office of the Data Protection Ombudsman (tietosuoja.fi). For any of these requests write to admin@origozero.com from the address on your account and we will handle it within a month. Your published content is also available to you at any time through the service's pull command and the API.
We make no decisions about you by automated means that have legal or similarly significant effects.
Security
Passwords, keys and tokens are stored only as hashes. World secrets are encrypted at rest. The site is served over HTTPS only. The desktop engine keeps your session token in a file on your computer that other programs running as you can read; treat that computer as you would a signed-in browser.
Children
The service is not directed at children under 13, and we do not knowingly collect their data. We ask for no proof of age at registration; if you believe a child has created an account, tell us and we will remove it.
Changes
When this policy changes we update the date at the top. For changes that matter to you we will also say so on the site.