What this policy covers
This policy describes the current Onyxian website, its website APIs, and support requests made to the Onyxian team. It explains what the website processes when you browse, request a download, use release information, or use the email-reading endpoint.
This policy does not describe the internal behavior of the downloadable desktop application or independently operated third-party services. Their own notices and terms apply to those services.
Information processed
Website requests. Hosting and file-delivery infrastructure may process your IP address, browser or device information, requested URL, request time, response status, and related technical information needed to deliver and protect the site.
Website analytics. We use Vercel Web Analytics on the homepage, Terms, Privacy, and Status pages to understand page views and visitor counts. Vercel processes page URLs, referrers, timestamps, approximate location, and browser, operating system, and device details for aggregated statistics. We do not send custom events, account IDs, email addresses, or other user identifiers through this integration. We remove query strings and fragments from the page URL before sending it. Analytics does not receive the requested addresses or message contents returned by the email API.
Email-reading API. If you use this endpoint, the server processes the mailbox alias or email address you request and queries a connected Google mailbox. A response can contain matching messages’ sender, recipient, subject, dates, snippets, plain-text or HTML content, and a link extracted from a message. Only request mail you are authorized to access.
Support. If you contact us through Discord, the information you choose to share, such as your Discord identity, messages, and relevant troubleshooting details, is available to the people handling your request. Discord also processes information under its own policy.
How information is used
Information is processed to deliver pages and downloads, understand aggregate website traffic, return requested API results, provide release and support information, respond to questions, investigate errors or misuse, and meet applicable legal obligations.
The email endpoint uses server-side Google authorization to retrieve the requested messages. Its authorization tokens are used for that connection; the homepage does not ask for your Google password.
Providers and external links
Hosting and file-delivery providers process requests needed to serve the website and downloads. Vercel processes website analytics. Google processes requests from the email integration. Visiting Discord or contacting us there involves Discord’s services.
The current frontend does not include advertising integrations or code for cross-site advertising tracking. This does not prevent necessary technical processing by hosting providers or the separate processing performed by services you choose to visit.
You can read the relevant provider notices here: Google Privacy Policy, Discord Privacy Policy, Vercel Privacy Notice, and Vercel Web Analytics privacy documentation. Providers may process information in countries other than your own.
Storage and retention
The website frontend does not maintain its own persistent visitor database. Aggregated analytics are stored by Vercel under its service settings and policies. The email API does not implement persistent storage of returned messages; it temporarily caches a Google access token in server memory until it expires.
The email endpoint’s processing does not delete or change messages in the connected mailbox. Mailbox retention remains separate from the website. Infrastructure logs, support conversations, and provider records may be retained under the relevant provider’s settings and policies; this site does not configure a single retention period for all of those records.
Do not post passwords, authorization tokens, or sensitive message contents in a public support channel.
Your choices and requests
You can browse the website without using the email API or joining Discord. You can control browser caching and external-service permissions through your browser and those services’ settings.
Depending on the law that applies to you, you may be able to request access, correction, deletion, restriction, or another action concerning personal information. Contact the Onyxian team through the official Discord and ask for a private way to discuss your request. We may need enough information to establish which records concern you and verify that you are entitled to them.
Requests concerning information controlled by an independent provider should also be directed to that provider. You may have the right to complain to the relevant privacy authority.
Children and age requirements
The website does not provide an account-registration form for children. Do not submit personal information or contact us through a third-party service if you do not meet that service’s minimum age requirements.
If you believe a child’s personal information has been shared with Onyxian inappropriately, contact the team through the official Discord so the issue can be addressed.
Changes and contact
We may update this policy when the website’s features or data handling change. The date at the top identifies the latest revision. If a change requires additional notice or consent, that requirement still applies.
For privacy questions or requests, contact the Onyxian team through the official Onyxian Discord. You can also read our Terms of Use.