Technical details
operating entity and rolesdata categories and purposeslegal bases where applicablecookies, local storage and consentpublic traffic, local Inspector and operational data distinctionsbilling, support and abuse recordssubprocessors, transfers and locationsretention and deletionrights and request processsecurity contact and complaintseffective date and changes
How traffic and Inspector data are handled
Oxaa's public edge terminates public HTTPS so it can resolve the exact hostname, identify the current authenticated route and forward the request. The session between the enrolled device and Oxaa is encrypted; the selected local service receives the request through that session.
Oxaa retains bounded account, route, usage, security, billing, support and diagnostic metadata required to operate and protect the service. Inspector body capture is a separate, explicit debugging action: the bounded request or response body copy shown by the local Inspector remains on the developer device and can be redacted, deleted or allowed to expire. Public traffic still has to be processed by the edge, so the accurate claim is local Inspector copies-not “Oxaa cannot see traffic.”
