Legal · effective 2026‑07‑17

Privacy Policy

ONYX ("we", "us", "our") operates an AI API gateway at onyxtech.cloud. This policy explains what personal data we collect, why, and how you can control it. We keep this short and plain — no legalese padding.

1. Who we are

ONYX is an independent AI API gateway service. We provide access to large language models through a single OpenAI-compatible endpoint. We are not affiliated with Anthropic or OpenAI.

For privacy matters, contact us at privacy@onyxtech.cloud.

2. What we collect

Account data. When you register, we collect your email address. We do not collect your name, phone number, or postal address unless you provide them voluntarily in a support request.

API usage data. Every API call is logged with: timestamp, model used, token counts (input and output), cost, your API key identifier, and whether the response was served from cache. We do not log the content of your prompts or responses by default.

Payment data. When you top up your balance, we collect the transaction amount, payment method type (e.g. SBP, crypto), and transaction status. Full card numbers and banking credentials are processed exclusively by our payment providers and never reach our servers.

Technical data. We collect IP addresses and standard HTTP request metadata (User-Agent, timestamps) for abuse detection and rate limiting. We do not build profiles from this data.

Communications. If you contact support, we retain the content of that conversation.

3. How we use it

DataPurposeLegal basis
EmailAccount authentication, transactional emailsContract
Usage logsBilling, rate limiting, usage dashboardContract
Payment recordsBalance management, fraud preventionContract / Legal obligation
IP addressAbuse detection, securityLegitimate interest
Support messagesResolving your issueLegitimate interest

We do not sell your data. We do not use your data for advertising. We do not use your prompts or model responses to train AI models.

4. Sharing and processors

We share data with the following categories of third parties only as necessary to operate the service:

  • AI model providers — your API requests are forwarded to upstream model providers to generate responses. Their processing is governed by their own policies.
  • Payment processors — transaction data is shared with Platega and/or CryptoBot to process top-ups. We do not share your email or usage data with payment processors.
  • Infrastructure providers — our servers and database run on third-party hosting providers under data processing agreements.

We do not share data with data brokers, advertisers, or analytics companies. We will disclose data to law enforcement only when required by a valid legal order.

5. Payments and financial data

ONYX uses a prepaid credit model. You top up a balance; we deduct from it per token. We do not store card numbers, bank account details, or any sensitive payment credentials on our servers.

Payment processing is handled by:

  • Platega — for SBP (Fast Payment System) transactions. Platega processes payment data under Russian payment regulations.
  • CryptoBot — for cryptocurrency payments. CryptoBot is operated by Telegram.

Refunds are not issued for tokens already generated. If you were charged for a failed request on our side, contact us and we will credit your account.

6. Data retention

Data typeRetention
Account and emailUntil account deletion + 30 days
API usage logs12 months rolling
Payment records5 years (legal obligation)
IP and request metadata30 days
Support conversations2 years

To delete your account and associated data, email privacy@onyxtech.cloud. Payment records may be retained longer where required by law.

7. Security

API keys are stored as SHA-256 hashes — we cannot recover your raw key, only verify it. Passwords are hashed using scrypt with per-user salts. All connections use TLS 1.2 or higher. We conduct periodic reviews of access controls and data practices.

No system is perfectly secure. If you discover a vulnerability, please report it to security@onyxtech.cloud before disclosing it publicly.

8. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your data (subject to legal retention requirements).
  • Export your data in a portable format.
  • Object to processing based on legitimate interest.
  • Withdraw consent where processing is consent-based.

To exercise any of these rights, email privacy@onyxtech.cloud. We will respond within 30 days.

9. Cookies and local storage

We use a single authentication cookie (onyx_session) to keep you signed in. It is httpOnly, not accessible to JavaScript, and expires after 7 days. We do not use advertising cookies, tracking pixels, or third-party analytics scripts.

We also store your session token in localStorage as a fallback for non-browser API clients. You can clear this at any time by signing out.

10. Children

ONYX is a developer API service not directed at children. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, contact us and we will delete it promptly.

11. Contact and updates

Privacy questions: privacy@onyxtech.cloud
Security reports: security@onyxtech.cloud
General: hello@onyxtech.cloud

We will post changes to this policy at this URL with an updated effective date. Material changes will be emailed to registered accounts at least 14 days in advance.

← Terms of use