Oktrai

Privacy policy

Last updated 10 October 2026

Who this covers

This policy explains what Oktrai collects when you use the website, create an account, or use Oktrai SMM. It sits alongside the terms of service.

Information you give us

  • Name, email address, and an optional phone number
  • A password, which we store only as a hash
  • Order details: the service, the link, the quantity, and any comments you type
  • Deposit details: the amount, the method, a payment reference, a bank-transfer note, or a crypto transaction id
  • Support messages, and the order a ticket is about
  • A name you give an API key. The secret itself is stored only as a hash

If you continue with Google, we receive your Google account id, name, and email address. We do not receive your Google password. Google only returns an address that Google has verified.

Information collected automatically

When you sign in we store the IP address and browser type for that session, and the IP address of the latest sign-in. We use that to keep the session valid and to investigate abuse. The session token in your browser is random. The database stores a hash of it, so a copy of the database cannot be used to sign in as you.

Cookies

Oktrai uses only cookies that run the site. We do not use them for advertising.

  • oktrai_session keeps you signed in. It lasts 30 days and is renewed while you keep using the site.
  • oktrai_theme remembers light or dark mode for a year.
  • oktrai_google_oauth lasts about 10 minutes and only exists while a Google sign-in is in progress.
  • sidebar_state remembers whether the dashboard sidebar is open.

Who else receives information

We share what is needed to take payment and to deliver an order.

  • Paystack receives the deposit you start there. Card details stay with Paystack. We store the payment reference and status.
  • A crypto deposit is checked against the transfer that arrives at an Oktrai USDT address.
  • The provider that fulfills an order receives the link, the quantity, and any comments required by that service.
  • Google receives the sign-in request when you choose Google.

We do not sell personal information.

How long we keep it

Account, order, wallet, and payment records stay while the account is open and for as long as we need them for support, disputes, and our own records. Session records expire. Password-reset links expire after one hour. You can revoke an API key at any time.

To ask about the information on your account, email support@oktrai.com.