We do not collect, transmit, or store your dataset content — not a single cell value, column name, or row count. Section 2 below describes, in full, every network contact the Software makes with servers we operate, and none of it includes the data you process with the Software. Separately, if you point the Software at a database or a cloud storage location you specify, it connects directly to that source to read your data — never through us, and never through any server we operate, as explained at the end of Section 2.
The Software makes network contact with servers we operate only for the following purposes:
Because each of the contacts above is an ordinary network request, it necessarily carries your device's source IP address. We use the IP address only to secure your licence and detect abuse — for example, one licence appearing from many different locations at once — and it is never combined with, and never reveals, anything about the data you process.
Database and cloud sources you specify. If you configure the Software, from the Database or Cloud tabs, to read from a database or a cloud storage bucket you specify, the Software connects directly to that source — using the connection details and credentials you provide — to load your data. That traffic runs only between your computer and the source you chose; it is not one of the contacts listed above, it never passes through us or any server we operate, and we never see it, its credentials, or its contents.
We never collect, transmit, or store the content of any dataset you process with OreML — no cell values, no column names, no row counts, no file contents, and no file names. This is a structural property of how the Software is built, not a configurable setting.
Separately from the network contacts above — and never transmitted anywhere — the Software embeds a persistent, one-way identifier in the file metadata of every Parquet, Feather and Excel file you export (in Excel, as a document property, never as a cell). It is not written into CSV, JSON, or any other format without a file-metadata layer, which are left unmarked.
This identifier identifies your licence, not you as an individual; it cannot be reversed to recover your licence key or any personal data; it touches no cell, column, or row of your actual data; and it survives table-level rewrites of the file, so it persists into files you build from your export and forward to someone else — though not through a dataframe library, which discards file metadata when it writes a new file. We disclose it here because, even though it never travels over a network and is never received by us, it is information about your licence that rides along inside output files you control and may choose to share.
Where the UK/EU GDPR applies, we rely on the following legal bases:
Purchases are processed by Paddle.com Market Ltd ("Paddle"), which acts as the Merchant of Record and an independent data controller for your payment information (name, email address, billing address, and card details). OreML does not receive, process, or store your payment card details, and we do not receive your Paddle account email or name unless you separately provide it to us (for example, by emailing support). Paddle's own privacy practices are described at paddle.com/legal/privacy.
Licence and machine-fingerprint records are retained for as long as needed to administer your licence, prevent abuse of the free trial, and comply with legal obligations. Opt-in telemetry, if enabled, is retained only as long as necessary for diagnostic purposes and is never linked to your dataset content, which we do not receive in the first place. Usage events are retained for 90 days.
Depending on your location, you may have the right to request access to, correction of, or deletion of personal data we hold about you (such as your licence ID, machine fingerprint, or the usage events recorded for your account), to object to or restrict certain processing, and to lodge a complaint with your local data-protection authority. To exercise any of these rights, contact support@oreml.com. If you are in the United Kingdom you may also use our UK representative — see Section 14. You may lodge a complaint with your local supervisory authority; in the United Kingdom that is the Information Commissioner's Office (ico.org.uk). For requests concerning your payment or billing data, please contact Paddle directly, as they are the controller for that information.
Licence-related data is encrypted in transit, stored on access-restricted infrastructure in the European Union, and backed up nightly to encrypted storage. Because we never receive your dataset content, the security of your underlying data is governed by your own device's security, not by us.
This website (oreml.com) does not itself set any cookies. It uses your browser's session storage only — cleared automatically when you close the tab — to remember standard advertising campaign parameters (source, medium, campaign) if you arrived here via a marketing link, so a signup completed later in the same visit can be attributed to that campaign. This is not a cookie, is not combined with any other identifier, is never sent to any third party, and disappears on its own. It is used only to tell us which marketing channel a signup came from — never to identify you individually or to track you across other websites.
We do not use advertising or cross-site tracking cookies of our own, and we run no analytics on this website today.
Our licence server and machine ledger are hosted in the European Union. Requests reach them through a global content-delivery network, which may process the request in transit outside the EU/UK under its own safeguards. Paddle, as the Merchant of Record and an independent controller for your payment data, may process and transfer that data outside the EU/UK under its own safeguards — see Paddle's privacy policy for how it handles international transfers of your payment data.
The Service is not directed at, and is not intended for use by, children. We do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above.
The data controller for the personal data described in this policy is OBSITH, trading as OBSITH / OreML — a sole proprietorship (Ατομική Επιχείρηση) established and registered in Greece, identified by the registration numbers below.
Questions about this Privacy Policy, about the Software, about your licence or subscription, and any request concerning your personal data can all be sent to support@oreml.com. That is the fastest route and the correct one for every country.
We are established in Greece and have no establishment in the United Kingdom. Under Article 27 of the UK GDPR we have appointed DataRep as our Data Protection Representative in the United Kingdom. If you are an individual in the United Kingdom, or a UK authority, you may reach us about the processing of your personal data through DataRep, in any of these ways:
When writing by post, address your letter to "DataRep" and not to OBSITH / OreML — mail addressed to us rather than to DataRep may not reach them. Please also name OBSITH / OreML clearly in your correspondence so that it can be routed to us. We may ask you to evidence your identity before acting on a request, so that your personal data is never disclosed to anyone but you.
This representative route is for individuals and authorities in the United Kingdom only, and only for matters concerning the processing of personal data. For every other country, and for anything else — support, billing, or the Software itself — please write to support@oreml.com instead. DataRep handles the personal data it needs in order to act for us in line with its own privacy notice at www.datarep.uk/privacy-policy.