← SecureOffline.ai

Data Processing Statement

Last updated July 24, 2026 · OnyxLinc LLC, doing business as SecureOffline.ai (“OnyxLinc,” “we”) · Written for professional, compliance, and procurement review. Questions or an executed copy: [email protected].

1. The two kinds of data — and the one we never touch

Your work content — client documents, prompts, conversations, and AI output — is never received, transmitted, stored, or processed by OnyxLinc. The SecureOffline application performs all AI processing on your own device. There is no server-side component that sees your content, no account, and no telemetry. As a consequence, for your app content OnyxLinc is not a data processor, service provider, or business associate under the CCPA/CPRA, other U.S. state privacy laws, the GDPR, or HIPAA — not by contract, but because no disclosure to us ever occurs. No DPA or Business Associate Agreement is required for data that is never shared. This architectural fact is verifiable: see our Trust & Verification page for the network tests any reviewer can run.

The only personal data we process is the ordinary commerce and support data of our own customers — described below, with the DPA-grade commitments we make for it. For that data we act as an independent controller (we determine the limited purposes: selling, licensing, and supporting the product); we do not process it on your instructions or on behalf of your organization.

2. What we process, and why

DataPurposeRetention
Purchase & license records — name (if provided), email, order reference, license key, editionDeliver and re-issue licenses, honor the 30-day guarantee, prevent abuseLife of the license; billing records up to 7 years (tax/accounting)
Consent records — name, email, timestamp, Terms version, IP, country, user agentLegal evidence of Terms acceptanceRetained as legal proof of agreement
Download requests — name, email, tokenized linkDeliver the installer; verify the addressLinks expire after 7 days
Support & contact correspondence — email address and message content you send usAnswer you; keep a record of what was promisedKept while relevant; unconfirmed contact messages purged after 30 days
Newsletter/guide leads — name (optional), email, sourceSend the requested material and newsletterUntil you unsubscribe or ask us to delete
Server logs — IP, resource requested, user agentSecurity and capacityShort-lived, routinely deleted

We collect no data from inside the application, and the application sends us none. Payment-card details are handled entirely by Stripe (or Apple, for App Store purchases) and never reach us.

3. Subprocessors

The commerce data above is handled by a small set of providers, each receiving only what its function requires. None of them ever receives your app content — there is no pathway by which they could.

ProviderFunctionLocation
Stripe, Inc.Payment processing (direct purchases)United States
Apple Inc.App Store billing (iPad purchases)United States
Resend, Inc.Transactional email delivery (licenses, download links)United States
Zoho CorporationBusiness mailbox (support correspondence)United States
Cloudflare, Inc.DNS, content delivery, license API hosting, bot protectionUnited States (global network)
Railway Corp.Website hosting and databaseUnited States

We will update this page at least ten (10) days before adding or replacing a provider that processes personal data.

4. Security measures

5. Security incident notification

If we confirm a security incident affecting personal data we hold about you, we will notify affected individuals by email without undue delay, and in any event within 72 hours of confirmation, describing the nature of the incident, the data involved, measures taken, and a contact point. Notification is not an acknowledgment of fault or liability.

6. Individual rights & requests

Access, correction, deletion, and portability requests for the commerce data above: [email protected], answered within 30 days. If any individual contacts us about data processed inside your copy of the application, we will explain that we hold no such data and direct them to you — we could not fulfill such a request even if ordered to, because the data does not exist on any system we control. Deletion requests are honored except where law requires retention or a legal hold applies.

7. No AI training on your data

We do not use your content to train, fine-tune, or evaluate any AI model — and unlike cloud AI vendors, this requires no policy promise: we never receive your content at all. The models in the Software are open-weight models (Apache-2.0 licensed) that run and remain on your device. We also do not use commerce data for any AI training purpose.

8. United States processing

OnyxLinc is a U.S. company; the commerce data above is processed in the United States. The Software itself processes your content only on your own device, in whatever jurisdiction you are in — content never crosses any border because it never leaves the machine. We do not offer Standard Contractual Clauses because no cross-border transfer of your content by us can occur.

9. Procurement & audit support

For vendor reviews we will provide, on request: this statement in executed form, completed security questionnaires, our subprocessor list, and reasonable documentation of the architecture claims above (which your own technical staff can also verify directly — see Trust & Verification). Requests: [email protected].

10. Precedence and liability

This statement supplements our Privacy Policy and Terms of Sale & Use; for the processing of personal data, this statement prevails over them to the extent of any conflict. Liability arising out of or related to this statement is subject to the limitations in the Terms and does not increase either party's total aggregate liability beyond the cap stated there.