Skip to content

Onimi Pages

Privacy policy

Last updated: October 6, 2026

This policy explains how Onimi Pages handles information for its website, accounts, publishing and payment-related services. Send privacy enquiries and data rights requests to oceanailab@gmail.com. Published pages may include content or scripts chosen by their authors; processing by those pages also depends on the publisher and relevant third parties.

1. Information we handle

Account information: user identifiers, email, display name and avatar supplied by sign-in services, preferences and authorisation records. Your work: uploaded HTML and assets, project names, versions, visibility settings and sharing permissions. Payment information: customer and subscription identifiers, plan, amount, currency, payment status and billing records. Payment providers handle full card details; our website does not receive or store full card numbers or security codes. Operational and support information: request times, network and device information, security and error logs, page traffic statistics, and emails or feedback you send us.

2. Why we use information

Necessary information supports account creation and security, publishing and delivery, sharing permissions, usage limits, subscriptions, troubleshooting and support. Processing serves our contract with you, security and operational interests, or legal obligations. Where applicable law requires a specific lawful basis, these correspond to contractual necessity, legitimate security and operational interests, legal obligations or consent. Google Analytics and signed-in product activity measurement require your consent. Microsoft Clarity runs without cookies: it may load by default in reviewed regions where this processing is permitted, and requires analytics and replay consent in regions that require prior consent. You can reject or turn off this optional measurement.

3. Cookies and optional measurement

Necessary cookies or similar storage support sign-in, security, language, theme and privacy preferences. Rejecting optional measurement does not disable these basic functions. Google Analytics loads only with an active privacy policy and your analytics consent. Microsoft Clarity always runs in cookieless mode with its analytics and advertising storage denied. It may load by default only in reviewed and configured regions. In mainland China, the EEA, the UK, Switzerland and unknown regions, it first requires your analytics and replay consent. An unavailable policy or regional configuration prevents default loading. An explicit rejection or withdrawal of analytics or replay keeps Clarity off. Cookieless does not mean no information is processed. Clarity may receive page content and interactions, device and browser information, network information and inferred approximate location, and provide single-page behaviour recordings. We do not send it account identifiers or enable cross-page cookie recognition. These reports can show page views, but do not accurately measure unique visitors, returning visitors or cross-page sessions. We respect Do Not Track; Global Privacy Control blocks Clarity. Turning it off stops subsequent collection, but does not automatically delete data already sent or flushed when stopping. This third-party measurement covers only selected public product pages. It excludes dashboards, sign-in, authorisation, payment, administrator pages, the gallery and user-published work. When you sign in to the dashboard and grant the analytics purpose, we record one server-side product activity fact per day and link it to a server-verified consent receipt. That record contains no raw IP address, access token, email address or consent proof supplied by the browser. Do Not Track blocks this record. Once separately reviewed and enabled, and only with your website analytics consent, we may also record fixed categories for starting a work, confirming publication, and authorised recipient access to shared work, plus artifact type and bounded durations. These first-party experience events contain no work content, prompts, full URLs, access codes or tokens, and are not sent to PostHog. Records older than 30 days are excluded from analytics and removed by scheduled cleanup. Agent stage analytics requires separate consent for that Agent. Change your website analytics decision at any time using Privacy choices in the footer; withdrawal stops new optional records. We also respect supported browser Do Not Track and Global Privacy Control signals.

4. Services involved

Clerk provides user sign-in; Supabase provides the database and administrator identity service; Cloudflare stores files and delivers pages; Vercel hosts the website; Stripe handles payments and subscriptions. Google Analytics provides analytics with your consent. Microsoft Clarity provides cookieless analysis and single-page recordings under the regional and privacy-choice rules above. Onimi and Microsoft act as independent controllers for Clarity data. Microsoft may use data for its own purposes, including product improvement and advertising, under its terms and Privacy Statement; this is not anonymous measurement used only by Onimi. Email services help deliver service notices and respond to support requests. Providers process information needed for their roles; payment services and third-party services you choose also have their own privacy policies. Public work is shown to visitors according to your settings. We may disclose necessary information to meet valid legal requests, address fraud or protect the service. We do not sell your personal information.

5. Retention and deletion

Account and work information is kept while you use the relevant services, until you delete content, close your account or it is no longer needed. Your plan limits the number of versions and the time range of available statistics. Some records may remain after you leave for accounting, disputes, legal obligations or security; backups may remain until their rotation cycle ends. Retention depends on those purposes and applicable requirements. A plan's statistics retention period is not a single deletion deadline for all information.

6. Security and international processing

We use measures including access controls, encryption in transit and environment isolation. No internet service can guarantee absolute security. Do not put passwords, keys or sensitive personal information in public work. Providers may process information outside your country or region; we use applicable data protection arrangements as required.

7. Your choices and rights

Manage work visibility, sharing permissions and available account settings in the product. Reject or withdraw optional measurement through Privacy choices. Contact oceanailab@gmail.com to request access, correction, export, deletion or account closure. Depending on applicable law, you may also have rights to restrict or object to processing and to complain to a local regulator. We may need to verify your identity to protect your information and will request only what is needed. Withdrawal does not affect lawful processing that occurred before it.

8. Updates and contact

We date updates on this page. For material changes to processing purposes or optional measurement, we provide appropriate notice and seek renewed consent where needed. Contact oceanailab@gmail.com about privacy, children's information or personal information in published content.

For account, payment, privacy or content enquiries, contact:

oceanailab@gmail.com