Legal & privacy
Privacy Policy
Your conversations and workspace are stored locally. Learn what account and license information Onevium receives and what happens when you connect a service.
1. Who we are and what this policy covers
Onevium does not automatically upload your conversations, prompts, project content, attachments, generated files, or model API keys to our account and license services. Your work is stored in a local database and files on your device. Signing in or activating a license does not upload your workspace or turn on cloud backup.
This policy covers the Onevium website, desktop application, account and license services, and support. Account information is separate from your local work content. Contact [email protected] with privacy questions or requests.
When you use an AI model or explicitly connect another service, the information needed for that task is sent to the service you choose, as explained below. Onevium is an independent product; those providers have their own privacy policies.
2. Account and license information
Your Onevium account is used to sign in, associate licenses and any organization membership, show subscription status, manage authorized devices, and provide support. It is not a cloud account for storing your conversations or project files.
For email sign-in, we process your email address, verification-code validation, login session information, and account status. License services process activation and license records, validity dates, and device associations so the app can verify your entitlement and device limit.
At sign-in, the app sends device identifiers, device name, operating system and version, processor architecture, hardware and CPU model, memory capacity, screen resolution, app and runtime versions, language, and time zone. We use device information for device recognition and management, license binding, and troubleshooting. Authentication and security records also include request IP address, user-agent information, login time, and approximate country or city when supplied by the network service.
Periodic license checks send device identifiers, app version, and elapsed app running time; the service records connection time and IP address. These checks do not send chat text, conversation titles or history, project content, files, model API keys, or actual conversation counts. They check license and device status, independently of your work content.
If you contact support, we receive only the message, contact details, and attachments you choose to provide in addition to the relevant account records. Send only what is needed for your request, and remove customer content, passwords, API keys, and other confidential information from attachments.
3. Local work content and services you enable
Conversation history, tool results, saved memories, and workspace records are stored in your local database. Attachments, generated media, project files, and local diagnostics are stored on your device as database records or files, depending on the feature. We do not collect this work content through account sign-in, license checks, or background product analytics, or use it to train our models.
When you ask an AI model to work on a task, the desktop app sends the necessary prompt, context, and selected content to your configured model provider or endpoint. Credentials needed to authenticate that request go to that provider or endpoint. These requests do not pass through our account or license service. The provider's own policy governs its processing.
When you enable browser automation, a channel bot, a plugin, an MCP server, or external access, task information may be sent to the service or recipient you configure. If you choose a remote relay, the relay receives and can retain the requests, responses, and delivery records needed for that connection. External access is off by default on a new installation. These are user-enabled task connections, not automatic uploads of your local workspace for product analytics. Review each connection before enabling it.
Diagnostic logs are written locally and are not automatically sent to Onevium support. If you decide to share a log or screenshot, review and redact it first. Sharing a support attachment is a separate action from using the app.
4. Google sign-in
This section applies where Google sign-in is available. If you choose to sign in with Google, Onevium requests only openid, email, and profile. Google may provide your account identifier, email address, email-verification status, display name, and profile image. We use these fields to create or link your Onevium account, authenticate you, display your profile, protect your account, and provide support.
We do not receive your Google password. Google sign-in does not request access to Gmail, Google Drive, contacts, calendars, or other Google content. Website analytics and any separately configured browser, plugin, or MCP connection are distinct from Google sign-in.
The Google identifier and profile fields needed for login are stored with your Onevium account while it is active and for any additional period required for security, disputes, or legal obligations. They are shared only as needed with providers operating our authentication, hosting, security, and support. We do not send Google sign-in data to AI model providers as part of authentication. Information you separately include in an AI task is handled as described in the local workspace section.
We follow the Google API Services User Data Policy, including Limited Use, when using or transferring information received from Google APIs. We do not sell Google user data, use it for advertising or credit decisions, or use it to develop, improve, or train generalized AI models. Human access is limited to your specific agreement, necessary security investigation, applicable legal requirements, or other uses allowed by that policy.
You can revoke Onevium's access in your Google Account and request deletion of your Onevium account and associated Google sign-in information at [email protected]. Revoking access does not by itself delete an existing Onevium account, local files, or records we must retain for security or legal obligations. We may verify your identity before processing a deletion request.
5. Website analytics, cookies, and preferences
The public website uses Google Analytics to measure page visits, referrals, campaign attribution, and actions such as release-link and contact-link clicks. Google Analytics can use cookies and device or browser information. Website hosting and security providers also process connection information, such as IP address, browser details, request time, and the requested page. This website measurement does not read your desktop conversations, projects, files, or model API keys.
The desktop app does not send website analytics reports about your chat activity. Opening an official website link may include a fixed label identifying the entry point, but not an account, device, project, or conversation identifier. A website click measurement does not establish that you installed the app or completed a purchase.
We use browser storage for referral information and preferences such as language selection and dismissed language suggestions. Browser settings can limit cookies and clear stored preferences. Google provides a browser add-on to opt out of Google Analytics.
7. Retention and deletion
You control the work content stored on your device. Desktop privacy settings include an action to clear the local database and stored media. It does not erase project files, separately exported files, diagnostics, backups, server-side account records, or copies already received by another service. Because account and license services do not hold a copy of your workspace, deleting an account does not remotely erase your local files.
We retain account, license, login-security, device-check, and support records as needed to provide the service and meet security, dispute, and legal obligations. You can request deletion of the information we hold at [email protected]. Some records may need to be retained for those obligations. Information held by an AI provider or another connected service must also be managed through that service.
8. Security
We use technical and organizational measures appropriate to the data and service, including encrypted network connections and access controls. Your device, credentials, configured endpoints, plugins, and backups also affect security. No system can guarantee absolute security. Contact support if you suspect unauthorized access; do not include secrets in your report.
9. Your choices and rights
You can manage local information, change configured providers, disconnect integrations, and request help with account information. Depending on applicable law, you may have rights to access, correct, delete, obtain a copy of, restrict, or object to processing of your personal information, withdraw consent, or complain to a competent authority.
Send requests to [email protected]. We may ask for proportionate information to verify the request and will respond as required by applicable law. We will not ask for your password or full API key. Where processing depends on consent, withdrawing it does not affect processing that was lawful before withdrawal.
10. Children and changes to this policy
Onevium is a general productivity tool and is not directed at children. If you believe a child has provided personal information to us without appropriate authorization, contact us so we can investigate.
We will update this page when our practices change and provide additional notice or request consent when required. The date above identifies the latest revision. Questions about this policy can be sent to [email protected].