Legal · effective 2026‑07‑17
Privacy Policy
ONYX ("we", "us", "our") operates an AI API gateway at onyxtech.cloud. This policy explains what personal data we collect, why, and how you can control it. We keep this short and plain — no legalese padding.
1. Who we are
ONYX is an independent AI API gateway service. We provide access to large language models through a single OpenAI-compatible endpoint. We are not affiliated with Anthropic or OpenAI.
For privacy matters, contact us at privacy@onyxtech.cloud.
2. What we collect
Account data. When you register, we collect your email address. We do not collect your name, phone number, or postal address unless you provide them voluntarily in a support request.
API usage data. Every API call is logged with: timestamp, model used, token counts (input and output), cost, your API key identifier, and whether the response was served from cache. We do not log the content of your prompts or responses by default.
Payment data. When you top up your balance, we collect the transaction amount, payment method type (e.g. SBP, crypto), and transaction status. Full card numbers and banking credentials are processed exclusively by our payment providers and never reach our servers.
Technical data. We collect IP addresses and standard HTTP request metadata (User-Agent, timestamps) for abuse detection and rate limiting. We do not build profiles from this data.
Communications. If you contact support, we retain the content of that conversation.
3. How we use it
We do not sell your data. We do not use your data for advertising. We do not use your prompts or model responses to train AI models.
5. Payments and financial data
ONYX uses a prepaid credit model. You top up a balance; we deduct from it per token. We do not store card numbers, bank account details, or any sensitive payment credentials on our servers.
Payment processing is handled by:
- Platega — for SBP (Fast Payment System) transactions. Platega processes payment data under Russian payment regulations.
- CryptoBot — for cryptocurrency payments. CryptoBot is operated by Telegram.
Refunds are not issued for tokens already generated. If you were charged for a failed request on our side, contact us and we will credit your account.
6. Data retention
To delete your account and associated data, email privacy@onyxtech.cloud. Payment records may be retained longer where required by law.
7. Security
API keys are stored as SHA-256 hashes — we cannot recover your raw key, only verify it. Passwords are hashed using scrypt with per-user salts. All connections use TLS 1.2 or higher. We conduct periodic reviews of access controls and data practices.
No system is perfectly secure. If you discover a vulnerability, please report it to security@onyxtech.cloud before disclosing it publicly.
8. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data (subject to legal retention requirements).
- Export your data in a portable format.
- Object to processing based on legitimate interest.
- Withdraw consent where processing is consent-based.
To exercise any of these rights, email privacy@onyxtech.cloud. We will respond within 30 days.
10. Children
ONYX is a developer API service not directed at children. We do not knowingly collect data from anyone under 16. If you believe a minor has created an account, contact us and we will delete it promptly.
11. Contact and updates
Privacy questions: privacy@onyxtech.cloud
Security reports: security@onyxtech.cloud
General: hello@onyxtech.cloud
We will post changes to this policy at this URL with an updated effective date. Material changes will be emailed to registered accounts at least 14 days in advance.