← SecureOffline.ai

Privacy Policy

Effective September 1, 2026 · OnyxLinc LLC, doing business as SecureOffline.ai (“we”)

By downloading or using SecureOffline, or using this website, you agree to this Privacy Policy and our Terms of Sale & Use.

The application

The SecureOffline app runs entirely on your device. We do not receive your conversations, documents, voice audio, or usage data — the app contains no analytics or telemetry and requires no account. The app connects to the internet only when you initiate a download of an AI model, voice pack, or app update from our content servers; those requests are ordinary file downloads and are not associated with any identity.

What we collect, and why

Service providers

We use a small number of processors, each receiving only what its job requires: Stripe (payments), Resend (transactional email delivery), Zoho (our mailbox), Cloudflare (content delivery, license API, and DNS), Railway (website hosting), and — for iPad purchases — Apple (App Store billing). We do not sell or share your personal information for advertising, and we do not buy data about you from anyone. A full description of what we process, our subprocessors, security measures, and retention — written for professional and procurement review — is in our Data Processing Statement.

Security

The most important safeguard is architectural: the content you create in the app never reaches us, so the most sensitive data has no server-side copy to protect. For the limited commerce data we do hold: all connections use TLS encryption; database connections are encrypted; admin access is password-hashed (scrypt), rate-limited, and session-protected; public forms are protected by Cloudflare Turnstile and rate limits; and we collect the minimum needed for each purpose. No method of storage is 100% secure, and we cannot guarantee absolute security — but we can keep the attack surface small, and we do.

If a breach occurs. If we confirm a security incident affecting your personal information, we will notify affected people by email without undue delay, describe what happened and what data was involved, and take reasonable steps to contain and remediate it — in addition to any notification required by law.

This website

secureoffline.ai uses one third-party tag: Google’s ads-measurement tag (gtag.js), which sets cookies solely so we can measure whether visits and trial signups came from our own advertising. We do not use it to build remarketing or advertising audiences, your app content is never involved, and the tag is not loaded at all when your browser sends the Global Privacy Control signal (or when you block third-party cookies). Beyond that single tag there are no analytics profiles and no fingerprinting trackers. Our web and download servers keep standard, short-lived technical logs (IP address, resource requested, user agent) for security and capacity purposes; these are routinely deleted and are not used to build profiles.

Retention

Order and license records are retained while your license is active and for the period required for tax and accounting law (billing records up to 7 years). Consent records are retained as legal evidence of agreement. Download links expire after 7 days; unconfirmed contact-form messages are purged after 30 days. Newsletter emails are kept until you unsubscribe. Technical logs are short-lived. When you ask us to delete your data, we delete what the law does not require us to keep. Legal hold: if a dispute or legal proceeding is pending or reasonably anticipated, we suspend deletion timelines for the affected records until the matter is resolved, as permitted or required by law.

Your rights

Wherever you live, we extend the same rights: you may ask what we hold about you, ask us to correct it, delete it, or export it, by writing to [email protected]. We respond to verified requests within 30 days. We do not discriminate against you for exercising these rights.

State privacy rights (California and others)

If you are a resident of California (CCPA/CPRA) or another U.S. state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Texas, and others), the rights above are how we honor your statutory rights of access, correction, deletion, and portability. We do not sell personal information. Our only advertising-related processing is the Google ads-measurement tag described above, used to measure our own campaigns — never to build advertising audiences. To the extent that measurement counts as “sharing” under California law, you can opt out: we honor the Global Privacy Control signal automatically (the tag is not loaded), and blocking third-party cookies has the same effect. We do not use personal information for automated decisions that produce legal or similarly significant effects. To exercise any right, email [email protected]; authorized agents may submit requests the same way.

Where your data is processed

We are a United States company and our service providers process the commerce data described above in the United States. The Software itself processes your content only on your own device, wherever you are. If you access this website from outside the U.S., the information you submit will be transferred to and processed in the U.S.

Children

Our products and website are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.

Changes

If this policy changes, we will update this page and its effective date. We will never weaken the core commitment above — the application does not transmit your content — without discontinuing the product name it’s attached to.