Mystery Coding Model 'Ox Alpha' Retains All User Prompts via Anonymous Provider
The stealth AI model, available on platforms like OpenRouter, explicitly stores user data through an unnamed third party.
A newly released coding model known as Ox Alpha is drawing scrutiny after it was revealed that the system retains every prompt submitted by its users. The model, which operates under a veil of anonymity, stores this data through an unnamed third-party provider.
Released around August 20, 2026, Ox Alpha (also referred to as 'stealth/ox-alpha') is accessible through AI aggregators such as OpenRouter and platforms like OpenCode. Documentation from OpenRouter confirms that prompts and completions generated by the model are retained by a provider whose identity remains undisclosed. This data retention policy is a core characteristic of the model's current implementation, though the laboratory or company responsible for the model's development has not been named.
The Rise of Stealth Models
The emergence of Ox Alpha reflects a growing trend of "stealth" releases in the AI industry, where high-performance models are deployed to the public without an associated brand or corporate entity. By utilizing platforms like OpenRouter, developers can distribute their weights and gather performance data without the immediate overhead of corporate branding or public relations. However, this lack of transparency becomes a critical issue when data handling policies are involved, as users are left without a clear entity to hold accountable for their privacy.
Security Implications for Developers
The retention of all prompts in a tool specifically designed for coding poses a severe security risk to the software engineering community. Developers frequently use AI assistants to debug complex logic, which often involves inputting proprietary source code, internal architectural diagrams, and occasionally sensitive API keys or environment variables. When a model retains this information via an anonymous third party, the risk of intellectual property theft or credential leakage increases significantly, as there is no verifiable security audit or legal agreement governing how that data is stored or who has access to it.
The Accountability Gap
What remains most concerning is the total anonymity of the operating entity. In standard enterprise AI agreements, data retention is governed by strict Service Level Agreements (SLAs) and privacy policies that specify data deletion timelines and encryption standards. With Ox Alpha, the absence of a named company means there is no legal recourse for users whose data may be compromised. Industry observers are now watching to see if OpenRouter or other hosting platforms will implement stricter disclosure requirements for anonymous models to protect end-users from invisible data harvesting.