Privacy Policy

Privacy Policy

Last updated: February 18, 2025

1. Information We Collect

We collect information you provide directly when creating an account, including your name, email address, and profile information through our OAuth authentication provider. We also collect usage data such as conversation history, messages sent to AI models, Knowledge Vault contents, and service interaction patterns. Technical data including IP addresses, browser type, device information, and access timestamps is collected automatically.

2. How We Use Your Information

Your information is used to: (a) provide and maintain the Service, including processing your messages through AI models; (b) manage your account, subscription, and credit balance; (c) store and organize your Knowledge Vault content; (d) improve the Service through usage analytics and performance monitoring; (e) communicate with you about your account, updates, and service changes; and (f) detect and prevent fraud, abuse, or security incidents.

3. Conversation Data

Your conversations with AI models are stored on our servers to provide conversation history, enable the Knowledge Vault feature, and maintain continuity across sessions. Conversations are associated with your account and are not shared with other users unless you explicitly use the share feature. When you share a conversation, only the content of that specific conversation is made accessible via the shared link. You may delete individual conversations or your entire conversation history at any time through the Service.

4. Third-Party AI Providers

When you send messages through the Service, your prompts are transmitted to third-party AI model providers (such as OpenAI, Anthropic, Google, and others) for processing. These providers may process your data according to their own privacy policies. We select providers that maintain appropriate data handling practices, but we encourage you to review the privacy policies of the AI providers whose models you use. We do not sell your conversation data to third parties.

5. Data Storage & Security

Your data is stored on secure servers with encryption in transit and at rest. We implement industry-standard security measures including secure authentication, encrypted connections (HTTPS/TLS), access controls, and regular security reviews. Files uploaded through the Service are stored in secure cloud storage (S3-compatible) with access controls. While we take reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure.

6. Data Retention

We retain your account data and conversation history for as long as your account is active. When you delete a conversation, it is removed from our active databases. When you delete your account, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (such as fraud prevention). Aggregated, anonymized usage statistics may be retained indefinitely.

7. Your Rights

Depending on your jurisdiction, you may have the right to: (a) access the personal data we hold about you; (b) request correction of inaccurate data; (c) request deletion of your data; (d) object to or restrict processing of your data; (e) request portability of your data; and (f) withdraw consent where processing is based on consent. To exercise these rights, please contact us through the Service or at the contact information provided on our website.

8. Cookies & Analytics

We use essential cookies for authentication and session management. We may use analytics tools to understand how the Service is used, including page views, feature usage, and performance metrics. We do not use third-party advertising cookies or trackers. You can control cookie settings through your browser preferences, though disabling essential cookies may prevent the Service from functioning properly.

9. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly.

10. International Data Transfers

Your data may be processed and stored in countries other than your country of residence. By using the Service, you consent to the transfer of your data to these countries. We ensure that appropriate safeguards are in place for international data transfers in compliance with applicable data protection laws.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service with a new "Last updated" date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us through the Service or at the contact information provided on our website.

© 2026 Onello. All rights reserved.