Privacy Policy
Last updated 2026-08-13.
1. What this covers
This policy describes how OneHux ("we", "us") collects, uses, and protects personal data when you use OneHux Accounts — either directly, or because an Organization that uses OneHux Accounts as its identity provider has an account for you.
2. Data we collect
Account data
Email address, name, and — if you choose to set one — a username, avatar, phone number, date of birth, gender, or country. Most of these fields are optional.
Authentication data
A hashed password (if you set one — never plaintext), passkey public keys (never the private key, which stays on your device), TOTP/backup-code MFA secrets, and metadata about each sign-in: IP address, user-agent, an approximate geographic location derived from IP, and a device fingerprint used only to recognize a previously-trusted device so we can ask for extra verification from an unrecognized one.
Session & usage data
Active session records (which device/application, when, until when), and a full audit log of security-relevant events on your account — sign-ins, permission changes, session revocations, MFA changes, and similar — retained so your Organization's admins (and you, for your own account) can review real account history.
Billing data
If your Organization is on a paid plan, payment processing itself is handled entirely by Paystack — we store a Paystack customer/subscription reference, never your raw card details.
3. How we use it
- To authenticate you and maintain your session across connected applications;
- To detect and respond to suspicious sign-in activity (an unrecognized device or location triggers a step-up verification, not a silent allow);
- To operate the audit log your Organization's admins can review;
- To process billing for paid plans, via Paystack;
- To send transactional email — sign-in links, one-time codes, security notices; and
- To comply with legal obligations where applicable.
We do not sell personal data, and we do not use your account data for advertising.
4. Who we share it with
Data is shared only with the real, specific processors needed to run the Service:
- Paystack — payment processing, for paid Organizations only;
- Cloudflare Turnstile — bot/abuse protection on sign-in and sign-up forms;
- Our transactional email provider — delivering sign-in links, one-time codes, and security notices; and
- The Organization that owns your account — its admins can see your name, email, Role assignments, and your own audit log entries within that Organization, as part of normal account administration.
We do not share personal data with any other third party except where required by law, or with your explicit consent.
5. Data retention & deletion
Most records (Organizations, Applications, Roles, Memberships) use recoverable soft-deletion — deleting one clears it from active use immediately but retains the underlying record briefly for operational recovery before permanent removal. Deleting your Organization is a genuine, deliberate action gated behind typing its exact name, and immediately revokes every active session and cancels any active subscription. Audit log entries are retained as an append-only record and are not deleted when the event they describe is later reversed — this is what makes the audit log trustworthy as a real history, not a mutable one.
6. Your rights
You can review and update most of your own account data directly from your Profile and Security settings pages — including revoking individual sessions, changing your email, and managing MFA/passkeys. You can request a copy of your personal data, or ask us to delete it (subject to the retention needs described above and any legal obligations), by contacting us at the address below.
7. Cookies
We use one essential, httpOnly session cookie to keep you signed in across requests. It is not readable by client-side JavaScript and is not used for advertising or cross-site tracking. We do not use third-party advertising cookies.
8. Security
Passwords are hashed, never stored in plaintext. Access tokens are short-lived (15 minutes by default) and every session can be revoked in real time, with that revocation checked on the very next request across every connected application. See the homepage's Security & trust section for more on how this works in practice.
9. International data transfer
Our infrastructure and processors may process data outside your own country. Where this happens, we rely on the safeguards our processors (Paystack, Cloudflare, our email provider) themselves provide for cross-border transfer.
10. Children's privacy
The Service is not directed at children under 13, and we do not knowingly collect personal data from them.
11. Changes
We may update this policy as the Service changes. Material changes will update the date at the top of this page.
12. Contact
Questions about this policy, or a request about your own data: [email protected].