Onixus / legal

Privacy policy

How Onixus handles information across the public site, workspaces, and Signal social workflows.

Last updated: October 3, 2026

Information you provide

Onixus may receive information you submit when you create an account, contact us, request a service, or use an Onixus workspace. This can include your name, email address, business details, messages, brand information, and content you choose to provide.

Accounts and authentication

We use account and authentication information to sign you in, maintain your session, provide workspace access, and protect the service. We may also receive basic account information from an authentication provider when you choose a supported sign-in method.

Signal and connected social accounts

If you use Signal or connect a social account, Onixus may process the provider account and asset information needed for the connection you authorize. This may include identifiers and display metadata for Facebook Pages, eligible Instagram professional accounts, LinkedIn organizations, TikTok creator accounts, or other supported assets, along with connection status, granted permissions, and token expiry information. OAuth authorization information and provider access or refresh tokens are handled server-side in protected credential storage and are not shown in the browser. We do not use a connection to access accounts or assets beyond the permissions and actions you authorize.

Content and publishing

Signal may process content, media, approval choices, schedules, publishing results, publishing IDs, status information, errors, and provider links that you choose to create, review, schedule, manage, or publish. Existing Signal workflows may use third-party publishing services configured for your workspace. Native provider connections are introduced separately and do not change those existing workflows unless enabled for your account.

How we use information

We use information to provide and secure Onixus services, operate workspaces, respond to requests, manage connected accounts at your direction, deliver content workflows, diagnose errors, and improve the service. We do not sell personal information. We do not use connected social credentials for unrelated advertising or messaging activity.

Service providers

Onixus uses service providers and platform APIs needed to operate the product. Depending on the feature you use, this can include Supabase for application infrastructure, Stripe for payments, and social or publishing providers you choose to connect. Those providers process information under their own terms and policies. Onixus does not control the privacy practices of third-party services.

Storage, security, and retention

We use access controls and server-side protections appropriate to the information handled by the service. Connected-account credentials are kept out of browser-facing responses and are protected by the application’s server-side credential storage. We retain information for as long as it is needed to provide the requested service, meet operational needs, resolve disputes, or comply with applicable obligations. Retention can vary by account, feature, and record; we do not promise a single fixed retention period for every type of data.

Your choices

You can stop using a connected social account by disconnecting it where the relevant Onixus feature provides that control. Disconnecting stops Onixus from using that connection through the application, but it does not by itself change permissions or data held by the social provider. You may also ask us to access, correct, or delete information associated with your Onixus account. See the data deletion instructions for the request details we need.

Policy updates

We may update this policy as Onixus and its services change. We will update the date on this page when the policy changes. The current version is the version that applies to information handled after its publication.

Contact

For privacy questions, access requests, correction requests, or deletion requests, email hello@onixus.xyz.