# ONYX HUB — Privacy notice

This notice describes data handled by the ONYX HUB website and its account, checkout and support flows. It covers this website, not the behavior of downloaded software or hardware; ask support for product-specific data handling.

## Account information and storage

Creating an account uses a username, email address and password. The server stores the username, email, password hash, account creation time and role in Cloudflare KV storage. The server code stores a hash rather than a plaintext password. Licenses and account functions also use service records associated with the account.



## Sessions, referrals and security checks

The site uses an HttpOnly, Secure session cookie named onyx_sess; session records have a seven-day expiry. Browser local storage is used by existing account and referral flows. Referral attribution can store a referral code, timestamp and referring-page value. The server uses the client IP for rate limits and referral-click deduplication. Cloudflare Turnstile is used for signup and login checks. Password-reset request tokens have a fifteen-minute expiry. These expiries do not mean all account or provider records are deleted on the same schedule.



## Service providers and notifications

Cloudflare hosts the website, KV account storage and security services. Signup notifications can send the username and email to a private Discord webhook when configured; support messages sent through Discord are also handled by Discord. Checkout uses SellAuth and its payment providers. ONYX HUB does not collect payment-card fields directly on its account forms. Remote checkout, challenge widgets, Discord invite information and Cloudflare web analytics, where enabled, make requests to the relevant provider and are subject to that provider's data practices.



## Requests, retention and scope

Account records and support history do not have one published automatic deletion deadline in the current website implementation. Contact official support to ask about access, correction or deletion of account information; ownership checks may be needed. Do not send passwords, complete license keys, session tokens or card details in public messages. This notice makes no claim about a legal business address, a particular compliance certification or the data collected by downloaded products.

- [Contact and privacy requests](https://onyxhub.cc/contact.md)
- [Official Discord support](https://discord.gg/c53CVabEC2)
- [Terms](https://onyxhub.cc/terms)
