Privacy Policy
Last Updated: February 24, 2026
This Privacy Policy explains how Lation Labs LLC ("Lation Labs," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use Onyx and related services (the "Service").
1. Company Information
Lation Labs LLC
971 US Highway 202N Ste R
Branchburg, NJ 08876
support@onyxbot.io
2. Scope
This Privacy Policy applies to information processed through:
- The Onyx web application and website
- Discord bot features and related integrations
- Support, operations, security, and billing workflows related to the Service
3. Information We Collect
3.1 Account and Identity Information
When you create or use an account, we may collect:
- Email address
- Account identifiers (for example, user ID and customer ID)
- Profile information provided by your authentication provider (for example, name)
3.2 Billing and Transaction Information
If you purchase a paid plan, payments are processed by Paddle (our payment processor and merchant of record). We receive transaction and subscription metadata needed to provision and manage your subscription, such as customer ID, subscription status, plan identifiers, billing events, and related records.
We do not store full payment card numbers in our systems.
3.3 Service Content and Configuration Data
To provide Service features, we may process and store:
- Discord-related identifiers and configuration data
- User-submitted prompts, questions, and support interactions
- Bot responses and related metadata (for example, model, token usage, and service diagnostics)
- Uploaded files and extracted text
- Generated chunks, embeddings, and connection metadata used for retrieval and search
- URLs and related crawl/indexing data submitted through the Service
3.4 Technical and Usage Information
We may collect technical and usage information such as:
- IP address and approximate geolocation inferred from IP
- Device/browser information
- Request, error, performance, and operational logs
- Event and diagnostic telemetry for reliability and abuse prevention
3.5 Cookies and Similar Technologies
We use cookies and similar technologies for essential product functions and service improvement. Current examples include session/state preferences and interface settings.
If we enable non-essential analytics cookies (such as Google Analytics), we provide required notice/consent mechanisms where required by law.
4. How We Use Information
We use personal information to:
- Provide, maintain, and improve the Service
- Authenticate users and secure accounts
- Process billing and manage subscriptions
- Deliver AI-assisted responses and retrieval features
- Monitor performance, troubleshoot errors, and detect abuse/fraud
- Enforce our Terms and legal obligations
- Communicate important product, billing, security, and policy notices
- Provide customer support
5. Legal Bases for Processing (EEA/UK)
If GDPR or UK GDPR applies, we generally process personal data under one or more of these legal bases:
- Performance of a contract (providing the Service you requested)
- Legitimate interests (security, reliability, fraud prevention, product improvement)
- Legal obligations (tax, accounting, compliance, law enforcement requests)
- Consent (where required, including certain analytics/cookie use)
6. How We Share Information
We do not sell personal information for monetary consideration.
We may share personal information with trusted providers and partners only as needed to operate the Service, including:
- Paddle (billing and subscription processing)
- Supabase (database, authentication, and storage infrastructure)
- Vercel (hosting and deployment infrastructure)
- Discord (platform APIs and bot interactions)
- Sentry (error monitoring, diagnostics, and operational logging)
- AI model and inference providers used by Service features (for example, OpenAI, Google, Anthropic), depending on configured models and workflows
We may also disclose information:
- If required by law, legal process, or government request
- To enforce our Terms or protect rights, users, and systems
- In connection with a merger, financing, acquisition, reorganization, or asset sale
7. AI and Automated Processing Disclosure
The Service uses AI systems to generate responses, summarize content, classify intent, and create/search embeddings.
As part of these features, user content (including uploaded text/documents and Discord support interactions) may be processed by third-party AI providers acting on our behalf.
You are responsible for ensuring that content you submit is lawful and that you have rights to provide it for processing.
8. International Data Transfers
Your information may be processed in countries other than where you reside, including the United States. Where required, we use appropriate safeguards for cross-border transfers.
9. Data Retention
We retain personal information for as long as reasonably necessary to provide the Service and meet legal, security, tax, accounting, and dispute-resolution obligations.
In practice, retention depends on data type and purpose, such as:
- Account and subscription records for account management and compliance
- Service content and embeddings while needed for active Service functionality
- Logs and diagnostics for security, debugging, and abuse prevention
When data is no longer needed, we delete, de-identify, or aggregate it, subject to legal/operational constraints (including backup and archival processes).
10. Security
We implement technical and organizational safeguards designed to protect personal information. No system is 100% secure, but we take reasonable measures to reduce risk and respond to incidents.
11. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information, contact us at support@onyxbot.io and we will take appropriate steps.
12. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, or restrict certain processing of your personal information, and to request portability where applicable.
To exercise rights, contact: support@onyxbot.io. We may verify your identity before fulfilling requests.
12.1 California Privacy Rights
If you are a California resident, you may have rights under the CCPA/CPRA, including rights to know, delete, and correct personal information, and rights related to sharing/selling concepts defined by California law.
We do not sell personal information for monetary consideration. We do not discriminate against you for exercising applicable privacy rights.
12.2 EEA/UK Rights
If you are in the EEA or UK, you may have rights to access, rectify, erase, restrict, object, and request data portability, and to lodge a complaint with a supervisory authority.
13. Third-Party Links and Services
The Service may contain links to third-party websites or services. Their privacy practices are governed by their own policies, and we are not responsible for those third-party practices.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date and may provide additional notice through the Service or by email.
15. Contact
If you have questions or privacy requests, contact:
Lation Labs LLC
971 US Highway 202N Ste R
Branchburg, NJ 08876
support@onyxbot.io