Skip to content
OpenOnyx
ProductIntelligenceCareersDocs—
Download
ProductIntelligenceCareersDocsGitHub · — starsDownload

OPENONYX / LEGAL

Privacy Policy

Last updated: October 6, 2026

Privacy PolicyTerms of Service

CONTENTS

  1. Introduction
  2. Local-first data
  3. Information the application may process
  4. Google Drive integration
  5. Google API Services User Data Policy
  6. Optional AI features and external APIs
  7. Optional accounts, sharing, and cloud storage
  8. Other third-party services
  9. Website storage, telemetry, and diagnostics
  10. Data storage and security
  11. Data retention and deletion
  12. Your choices and controls
  13. Children’s privacy
  14. Changes to this policy
  15. Contact

01 / Introduction

OpenOnyx is an open-source, local-first knowledge management application. This policy explains how information is handled by the desktop application, the OpenOnyx website, and optional online features and integrations. Available features depend on the version and configuration you use.

Local-first does not mean that every feature is offline. Connecting an integration, enabling external AI, using cloud collaboration, opening remote content, or downloading software can involve requests to third-party services.

02 / Local-first data

Your notes normally remain ordinary Markdown files in the vault folder you choose on your disk. Attachments and other workspace files also reside in local folders. Core local use does not require an OpenOnyx account or uploading your vault to an OpenOnyx server.

OpenOnyx also stores working data locally: settings, indexes, embeddings, AI results, and workspace state may be written into the vault’s .openonyx folder, the application’s user-data directory, browser storage, or local databases. These supporting stores are separate from your Markdown files.

A folder you place in a third-party sync service, share with another person, or back up externally remains subject to those services and your own sharing choices.

03 / Information the application may process

Depending on the features you use, OpenOnyx may process:

  • Notes, document content, attachments, filenames, paths, links, and search queries needed to display, edit, index, or retrieve your knowledge.
  • Preferences, vault history, workspace state, local indexes, embedding vectors, and cached AI responses.
  • Integration configuration, account identifiers, display names, email addresses, resource identifiers, file metadata, and authentication credentials.
  • Selected external-resource descriptions, text excerpts, embedded snapshots, and downloaded preview files.
  • Account and session information for configured cloud features, shared content, collaborator information, and synchronization state.
  • Operational errors and diagnostic logs, and information you choose to send when requesting support.

04 / Google Drive integration

Connecting Google Drive is optional and available only in builds that include and configure the integration. OpenOnyx requests Google Drive read-only access using the scope https://www.googleapis.com/auth/drive.readonly. This permission can read files accessible to your Google account; it is broader than access to only one selected file.

OpenOnyx uses this access to search your Drive, retrieve metadata and content for resources you access through OpenOnyx, and display or embed selected resources in your knowledge workspace. The connector reads account information such as a Google account identifier, email address, and display name, and file information such as IDs, names, types, owners, modification times, sizes, and descriptions. It may retrieve a Google Docs text excerpt, export a Google document for a preview, or download a supported file such as a PDF.

Search terms and authenticated requests are sent directly from the application to Google. Google receives the request and ordinary connection information, such as your IP address. This integration does not use its read-only permission to modify or delete files in Google Drive.

Authorization opens your external browser and uses a Desktop OAuth client with Authorization Code and PKCE. The implementation includes a public client ID, not a bundled Google client secret. Access tokens are held in Electron’s main-process memory. Refresh credentials and connected-account details are saved locally using Electron’s OS-backed encrypted storage when an acceptable secure backend is available. The connector refuses the insecure Linux basic_text fallback and does not connect when secure credential storage is unavailable. This does not mean that all application data or preview files are encrypted.

Disconnecting removes that account’s locally saved refresh credentials and in-memory access tokens and stops further authenticated access through that connection. OpenOnyx also attempts to revoke the grant at Google. Revocation is a best-effort network request and may not succeed while offline or if Google is unavailable. You can independently revoke access in your Google Account settings.

Disconnecting does not delete the original Drive files, saved resource blocks in your notes, recent-resource metadata, or local PDF and document preview caches. Existing snapshots may remain readable until you remove them. See Data retention and Your choices below.

The Drive connector itself does not relay your OAuth credentials to an AI provider or an OpenOnyx cloud server. However, an excerpt saved inside a note becomes part of that note: enabling AI processing or sharing or syncing the note can transfer that excerpt to the configured provider or recipients. Connecting Drive by itself does not enable those features.

  • Manage or revoke third-party access in your Google Account
  • Google’s guidance on managing third-party connections

05 / Google API Services User Data Policy

OpenOnyx’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, to the extent applicable. Google data is used for the user-facing workspace features described here. The Drive connector does not use that data for advertising, sale to data brokers, or training a general-purpose AI model.

Any transfer of Google-derived content through an optional AI, sharing, or cloud feature must remain consistent with the applicable Google policy and the user’s authorization. This statement is not a claim that Google has verified, certified, or endorsed OpenOnyx. Review the data you include before sending a note to an external service; an external provider’s retention and processing practices are separate from the local connector.

  • Google API Services User Data Policy, including Limited Use

06 / Optional AI features and external APIs

External AI features use the provider, model, endpoint, and API credentials configured in the application. Supported configurations include OpenAI, OpenRouter, and custom compatible endpoints. A local endpoint and a hosted provider have different data-handling implications.

AI requests can contain your question, selected text, note titles, excerpts, and retrieved context from your vault or a Space. This can include external-resource text already saved in a note. Summaries, synthesis, writing assistance, and answers are not guaranteed to remain on your device. After you configure AI, some supported workflows can generate annotations automatically, rather than requiring a separate confirmation for every request.

Providers process requests under their own terms and privacy policies; a routing service such as OpenRouter may forward a request to the selected model provider. OpenOnyx cannot guarantee their retention periods, model-training choices, or deletion behavior. Review those settings before enabling AI for confidential or Google-derived material.

Local embedding and indexing features process note content on the device, but may download model files or runtime assets from external hosts, including Hugging Face or jsDelivr. Generated results and settings may be cached locally. AI API keys can be stored in local vault settings; the Google credential protection described above is not a promise that these settings or keys have equivalent encryption.

07 / Optional accounts, sharing, and cloud storage

Local editing does not require a login. Builds configured for Supabase-backed cloud features can support accounts, publishing, collaboration, and synchronization. These features may process email addresses, profile and session information, collaborator identifiers, presence, and shared content through the configured service.

Creating or syncing a cloud Space can upload note content, titles, paths, and related workspace data, including multiple files from the selected vault. Published or shared content may be accessible to others according to the chosen Space and service configuration. Do not assume that enabling a cloud feature preserves purely local storage, or that every shared Space is encrypted.

Signing out or disconnecting locally does not by itself erase copies already stored by a cloud service, collaborators, or backups. Cloud retention and deletion depend on the service and deployment you use; contact its operator about account or server-side deletion.

08 / Other third-party services

The website and downloads use GitHub for repository metadata, releases, source code, issues, and discussions. Visiting these services or downloading a release sends ordinary request information to GitHub and its delivery infrastructure. The website loads typography from Google Fonts.

Optional plugins, remote images, embedded content, API integrations, and MCP servers can contact their own services or process the content and tool arguments you provide. Their permissions and data handling depend on the component you enable. Review a component before trusting it with your files or credentials.

Hosting, email, integration, and AI providers may process connection or support information under their own policies. OpenOnyx’s core local file storage does not automatically upload your vault to all of these services.

09 / Website storage, telemetry, and diagnostics

The checked-in application and website do not include a dedicated product-analytics or automatic remote crash-reporting integration. This is not a promise of zero network activity or zero logging. Hosting and external services may keep access or operational logs, and their production configuration is separate from the application source.

The website uses localStorage for appearance preferences and browser-based demo data, and sessionStorage for cached GitHub star counts. The interactive application demo can use local browser storage for settings and workspace data. These stores are not necessarily cleared when a tab closes. Browser settings can remove them. The checked-in website does not set an advertising or analytics cookie; third-party sites, embeds, or configured account services may use their own storage or cookies.

Application console and integration activity logs may include filenames, paths, tool or resource information, status messages, and errors. Do not assume that every log has been stripped of sensitive information. If you send a bug report, screenshot, or log to maintainers, review it first; a public GitHub issue is visible to other people.

10 / Data storage and security

Local notes and ordinary caches are readable files or local application stores; OpenOnyx does not automatically encrypt all vault files, settings, backups, or Drive previews. Their protection also depends on your device, operating system, filesystem permissions, disk encryption, and any backup or sync service you use.

Google OAuth credentials are handled as described in the Google Drive section. Secure-storage availability varies by operating system and environment. Other integrations and configurable services may use different credential stores. No software or storage mechanism can guarantee absolute security.

11 / Data retention and deletion

Your notes remain in the folders you choose until you remove them. App settings, local databases, browser storage, and derived data can remain after closing or uninstalling the application. Removing a file in the app can move it to the operating system’s trash, where supported, rather than securely erase every copy. Backups and external sync services can retain additional copies.

Drive resource metadata and excerpts saved in notes remain part of those notes. Recent-resource information is retained locally. Downloaded PDF previews and other supported document previews are cached in the application’s user-data directory. General document previews have size-based eviction; the reviewed PDF cache has no automatic age-based expiry or disconnect purge. Removing an embed does not necessarily remove a separate downloaded preview cache.

To remove local Drive copies, remove the saved resource content from the relevant notes, clear associated browser or app storage and recent-resource data, and remove the drive-pdf-cache and drive-preview-cache directories in the application’s user-data location with the app closed. Disconnect first, and back up content you want to retain. Deleting local copies does not delete the source files at Google.

Copies intentionally sent to AI providers, cloud services, collaborators, or support channels have retention rules outside the local application. Requests to remove those copies should be directed to the relevant service or, for information you sent to OpenOnyx, the contact below.

12 / Your choices and controls

You can:

  • Use local vault workflows without connecting Google Drive, configuring external AI, or signing in to cloud features.
  • Disconnect a Drive account in the app and independently revoke OpenOnyx access in Google Account third-party connection settings.
  • Remove AI credentials or change the configured endpoint to control subsequent external AI requests. Already-sent requests are not recalled.
  • Review note content, including embedded resource excerpts, before using AI, publishing, sharing, or synchronizing it.
  • Delete local notes and supporting application data, and clear website browser storage. Closing or uninstalling the app alone may not remove every store.
  • Contact OpenOnyx about information you provided directly to maintainers. OpenOnyx cannot remotely erase your local vault or a third party’s independent copies.

13 / Children’s privacy

OpenOnyx’s website and online integrations are not directed at children under 13. If you believe a child has supplied personal information directly to OpenOnyx without appropriate permission, contact us so we can review and address it. Third-party account and integration services may impose their own age requirements.

14 / Changes to this policy

We may update this policy as features and practices change. The date above identifies the latest revision. Material changes to the use of Google data should be disclosed before that data is used for a new purpose, with additional authorization where required. Review this page when enabling a new online feature.

15 / Contact

For questions about this policy or these terms, contact OpenOnyx.

  • team@openonyx.app
  • OpenOnyx — openonyx.app
OpenOnyx

Open source. Local-first. Your files.

CareersGitHubCommunitySponsorApache-2.0PrivacyTerms
© 2026 OpenOnyxYour knowledge belongs to you.