Plain-language privacy information — v9

How account, passport and payment information are separated

Your private passport

The readable passport, voice notes and vault passphrase remain encrypted on the participant’s device. The operator cannot reset the vault passphrase or read the local passport.

Your central account

PostgreSQL stores the account email, participant/coordinator role, enabled sign-in methods, trial dates, subscription status, Stripe customer/subscription identifiers and protected session records. Password accounts store a salt and one-way scrypt password hash. Google-linked accounts store a one-way hash of Google’s stable account identifier and the email address supplied by Google; Onexa does not retain the Google ID token or receive the Google password. It also keeps a one-way email fingerprint so the same email cannot repeatedly claim trials. This fingerprint remains after account deletion.

When Google sign-in is used, Google learns that the person is signing in to Onexa and processes the authentication request under Google’s terms. No Recovery Passport content, vault passphrase, consent access code or coordinator note is sent to Google by Onexa.

For reliable subscription confirmations, the email outbox stores the recipient address, account role, monthly price, creation and delivery times, attempt count and a non-sensitive error category. It does not store passport content, vault passphrases or access codes.

Payments

Stripe processes card details, Checkout, invoices and cancellation. Onexa receives subscription status and Stripe identifiers but not complete card numbers. Review Stripe’s privacy information before subscribing.

After a plan ends

A participant’s local passport is not deleted. It remains available for viewing, encrypted export, coordinator-access revocation and local deletion. Editing and new sharing pause. An inactive coordinator cannot open client shares. Payment never overrides consent.

Encrypted sharing

The relay stores an opaque lookup, expiry, owner-token hash and encrypted approved report or proposal. It does not receive the client access code or readable report. Revocation deletes the encrypted share and waiting proposal, but cannot remove screenshots or information already retyped by a recipient.

Email and operational records

A client email is processed transiently when a neutral proposal notification is sent. Subscription confirmations are queued centrally for reliable delivery. The SMTP provider processes each recipient address and message. Hosting, reverse-proxy and payment services may also process IP addresses, timestamps and browser or transaction metadata. Production retention must be documented and minimised.

Translation and copying

Automatic translation is attempted only using a supported on-device browser feature and is not certified. Copying is deterred only in the coordinator view; participants retain control of their information. Screenshots cannot be prevented.

Account deletion

Billing must first be cancelled and ended. Account deletion removes the central account and sessions, but does not delete the local passport from every device. Revoke active shares and delete local vaults separately. The non-reversible trial-history fingerprint remains to prevent repeated trial abuse.

Safety

This app is not an emergency service, diagnosis, clinical assessment or replacement for qualified care. For immediate danger in Australia call 000. Lifeline: 13 11 14.

Contact and help

For account, subscription or technical help, email support@onexa.com.au. Do not include passwords, access codes or sensitive health information in email. Support cannot recover a forgotten private vault passphrase.

Account and plans · Participant app