Chapter I — Foundational Principles
§ 01 Data Protection as an Engineering Standard
QXONI treats data protection as an engineering and governance objective. Where personal data is processed, QXONI seeks to apply privacy by design and privacy-friendly defaults in accordance with applicable law, including Article 25 GDPR where the GDPR applies and Article 7 FADP. The controls actually implemented depend on the service, hosting environment, and feature concerned and are reviewed when material changes are introduced.
§ 02 Scope and Geographic Application
This policy applies to digital services operated by QXONI int., including OMINO, account services, websites, APIs, beta environments, and related subdomains. A service-specific notice may provide additional or more precise information for a particular feature. If a service-specific notice conflicts with this general policy, the more specific notice applies to that processing activity, subject to mandatory law.
§ 03 Responsibility and Accountability
QXONI int. is responsible for deciding the purposes and means of processing for its own services unless a service-specific notice identifies another controller. Access to production systems should be limited to authorised persons with a legitimate operational need. Administrative and security access may be logged where technically implemented. QXONI does not sell personal data to data brokers.
§ 04 Data Minimisation
QXONI aims to collect only data reasonably necessary for an identified purpose. Retention periods are determined by operational need, contractual obligations, legal requirements, security needs, and the availability of deletion mechanisms. Data is deleted, anonymised, or reviewed when it is no longer reasonably required, subject to backups, legal holds, and other lawful exceptions.
§ 05 IP Addresses and Network-Level Data
IP addresses and related network metadata may be processed by QXONI, its hosting providers, and security services to deliver requests, apply rate limits, investigate abuse, and protect systems. These data may appear in short-term server, proxy, or security logs. QXONI does not use IP addresses for advertising profiles. Retention depends on the relevant service and security purpose and should be kept no longer than reasonably necessary.
§ 06 Transport Encryption — QXONI Shield
Security Protocol
QXONI uses HTTPS and transport-layer encryption for supported public services. Protocol versions, cipher suites, certificate management, and HSTS behaviour may be controlled partly by hosting and content-delivery providers. QXONI seeks to disable obsolete protocols where configuration control is available, but does not represent that every third-party connection uses an identical protocol or cipher.
§ 07 AI Services — Data Flow and Processing
AI Services
OMINO and other QXONI AI features may send prompts, conversation context, uploaded images, and tool requests to external service providers in order to generate a response. As of 10 July 2026, relevant integrations may include Groq for model inference, Pollinations for image generation, PythonAnywhere or other hosting providers, DuckDuckGo or Google News for search and news retrieval, and Open-Meteo for weather data. The precise provider used depends on the requested feature. Search terms, image prompts, location names, uploaded media, and technical request metadata may therefore be disclosed to those providers. Users should not submit secrets or sensitive personal data unless necessary and authorised.
ℹ️QXONI does not use OMINO prompts to train a QXONI model by default. Third-party providers process data under their own contractual terms, privacy notices, and configured data-control settings. QXONI uses contractual and transfer safeguards where legally required and available.
§ 08 Advertising-Free Environment
As of the effective date, OMINO does not intentionally deploy advertising cookies, behavioural advertising pixels, or third-party session-replay tools. Functional providers may still receive request data that is necessary to deliver AI, image, search, weather, hosting, font, or account services. Such functional disclosures are not described as advertising, but they remain data processing and are disclosed in this policy.
§ 09 Local Storage — Device-Side Preference Data
OMINO stores interface preferences, projects, chat history, a browser client identifier, and—depending on the account flow—authentication information in browser storage. These items remain on the device until they expire, are removed by the application, or are cleared by the user. Sending a message transmits the selected prompt, recent chat context, attachments, and relevant configuration to the QXONI backend. The “Delete all chats” control removes locally stored chat history only; it does not automatically delete server logs, provider records, account data, or server-side agent memories. Separate deletion requests may be required for those records.
§ 10 Account Credentials and Password Security
QXONI does not intentionally store account passwords in plain text. Credential handling is performed by the account service using one-way password hashing and related security controls appropriate to the implementation. Password-reset and verification links should be time-limited and single-use where supported. Users are responsible for keeping credentials confidential and for using a trusted device.
Chapter II — Job Centre
§ 11 Integrity of the QXONI Job Centre
The QXONI Job Centre operates under dedicated data security controls, maintained in an isolated environment segregated from the primary platform infrastructure. Application documents are processed under strict access restrictions. Note: QXONI Jobs is presently available exclusively within the canton of Appenzell Ausserrhoden, Switzerland. Geographic expansion will be communicated through updated policy documentation.
§ 12 Applicant Data Collection
QXONI int. collects only data strictly necessary for candidate evaluation: full name, contact details (email address and telephone number), employment history, technical competencies, and prior project references. All submission occurs through encrypted forms. Uploading a curriculum vitae or portfolio material does not constitute consent for any use beyond the active recruitment review process.
§ 13 Retention Periods for Applicant Records
Applicant data is retained only for as long as reasonably necessary for the recruitment purpose, legal obligations, and dispute handling. Unless a vacancy notice states a different period, QXONI targets the following schedule: active applications up to six months after the last relevant activity; an optional talent pool up to twelve months with separate consent; and prompt restriction or deletion after a valid withdrawal request. Deletion may be delayed by backups, legal holds, or records needed to document the process.
| Situation | Target period | Typical action |
|---|
| Active application | Up to 6 months after last relevant activity | Delete, anonymise, or retain only where lawfully required |
| Talent pool | Up to 12 months with separate consent | Renew consent or remove the record |
| Withdrawal request | Without undue delay | Stop active processing and delete or restrict subject to lawful exceptions |
| Hiring decision | As required for onboarding, legal obligations, and disputes | Transfer necessary data to employment records or delete it |
§ 14 Right to Supplement or Replace Application Materials
Submitted application documents may be supplemented, replaced, or updated at any time during the active application period. A written request directed to qxoniint@gmail.com is sufficient to initiate any modification to the applicant record on file.
§ 15 Right of Withdrawal
✓ GDPR Art. 17
Applicants may withdraw an application at any time. QXONI will stop active recruitment processing and delete or restrict the relevant application data within a reasonable operational period, subject to legal retention obligations, dispute preservation, backups, and records needed to document the withdrawal. QXONI will confirm the action where practicable.
§ 16 Optional Talent Pool Participation
With separate, documented written consent, applicant data may be retained in the QXONI Talent Pool for a period not exceeding twelve months. This authorises QXONI int. to contact the applicant proactively for suitable future vacancies. Talent Pool participation is entirely voluntary, may be revoked by written request at any time, and carries no obligation of any kind on either party.
§ 17 Access Controls for Applicant Records
Access to applicant data is limited to persons who need it for recruitment or legal administration. Access events may be logged where the relevant system supports audit logging. QXONI applies organisational and technical controls proportionate to the sensitivity of application materials.
§ 18 Communication During the Application Process
Application correspondence may be conducted by ordinary email or other designated channels. Standard email is generally encrypted in transit between supporting providers but is not necessarily end-to-end encrypted. Applicants should avoid sending unnecessary sensitive information and may request an alternative channel where available.
§ 19 Work Samples, References, and Intellectual Property
All submitted portfolio materials, work samples, and creative content remain the exclusive intellectual property of the applicant. QXONI asserts no ownership rights over submitted materials. Reference verification and credential checks are conducted only following documented explicit written consent. Following conclusion of the application process, all submitted files are handled under the standard deletion schedule defined in § 13.
§ 20 Application Process Feedback Data
Feedback collected regarding the application experience — including usability assessments and process satisfaction data — is maintained in a system entirely separate from the application record. This data is used exclusively for technical and UX improvement of the Job Centre. It is technically isolated from hiring processes and cannot influence recruitment decisions under any circumstances.
Chapter III — Community
§ 21 Community Participation
👥 Community
When publishing content on the QXONI platform, a timestamp and anonymised account reference are stored alongside the content. The user's chosen display name is visible to registered members. Underlying account data — including legal name, email address, and contact information — remains strictly protected and is not accessible to other platform users.
§ 22 Content Moderation and Platform Integrity
QXONI may moderate community content for spam, unlawful material, threats, harassment, exploitation, impersonation, and technical abuse. Moderation may involve automated signals and human review. Notice, reasons, and appeal options are provided where required by law and where doing so would not undermine safety, fraud prevention, or an investigation.
§ 23 Profile Information Visibility
Display names, avatars, and brief biographical descriptions are visible to registered members by default. Users have granular control over which profile elements are publicly visible, restricted to logged-in members, or fully private. Visibility settings are configurable at any time through Account Settings → Privacy.
⚠️Content shared publicly may be indexed by external search engines. Users should review their privacy settings periodically and disclose only information they are comfortable with being publicly discoverable.
§ 24 Reactions, Likes, and Engagement Signals
Interaction events such as reactions and likes are recorded to compute accurate aggregate counts. The link between a user account and a specific reaction is retained solely to enable withdrawal of that reaction. Upon removal, the corresponding record is immediately updated or deleted from the system.
§ 25 Notification Preferences
QXONI operates an internal notification system for platform-related events including replies, mentions, and content updates for followed topics. Each notification category — including type, frequency, and delivery channel — is independently configurable through the Settings panel. Unsolicited promotional notifications are not sent.
§ 26 Technical Error Logging
Technical and security logs may contain timestamps, IP addresses, request paths, browser or device information, error messages, rate-limit events, and diagnostic identifiers. Logs are used to operate the service, detect abuse, and investigate faults. Retention varies by system and incident and should be limited to what is reasonably necessary for security, troubleshooting, legal obligations, and audit purposes.
§ 27 Private Messaging and Encryption
🔒 E2E Roadmap
Private or account-linked communications may be stored in encrypted databases or protected storage, but they are not end-to-end encrypted unless the relevant interface explicitly states that they are. QXONI and its authorised service providers may technically be able to access stored content for operation, security, support, or legal compliance. Any future end-to-end encryption feature will be described separately when it is actually available.
§ 28 Protection Against Automated Scraping
QXONI may use rate limits, authentication controls, request validation, abuse monitoring, and other proportionate measures to reduce automated scraping and misuse. The exact controls differ by service. Circumventing technical safeguards or systematically extracting protected user data without authorisation is prohibited.
§ 29 Metadata Handling in Media Uploads
Uploaded files may contain EXIF data, geolocation, device identifiers, document properties, or other embedded metadata. QXONI may process or remove some metadata depending on the feature, but users should not assume that all metadata is stripped. Users should review and remove sensitive metadata before uploading where disclosure would be harmful.
§ 30 Archival of Community Content
Where community features are offered, QXONI may retain public contributions to preserve conversation context, legal records, or platform integrity. Account deletion may result in deletion, anonymisation, or retention of particular content depending on the user’s request, the nature of the content, third-party rights, and legal obligations. Users should delete content before closing an account where immediate removal is important.
Chapter IV — Data Subject Rights (GDPR)
§ 31 Right of Access
✓ GDPR Art. 15
Every user has the right to receive comprehensive information about which personal data is stored, for what purpose, for what duration, and to whom it has been disclosed. Upon written request, a complete data summary is provided in clear, accessible language within the statutory timeframe.
§ 32 Right to Rectification
✓ GDPR Art. 16
Inaccurate, incomplete, or outdated personal data may be corrected upon request. The majority of profile and preference data can be modified directly through Account Settings. For backend data not accessible through the platform interface, rectification requests should be directed to the privacy contact listed in § 95.
§ 33 Right to Erasure
✓ GDPR Art. 17
Users may request deletion of personal data where the applicable legal requirements are met. QXONI will delete, anonymise, or restrict relevant data unless retention is necessary for legal obligations, security, fraud prevention, dispute resolution, or another lawful ground. Deleted data may remain temporarily in protected backups until normal backup rotation, provided it is not restored for ordinary use.
§ 34 Right to Restriction of Processing
✓ GDPR Art. 18
Under defined circumstances — including where the accuracy of data is disputed or where an objection to processing has been submitted — the user may request restriction rather than erasure. During the restriction period, the relevant data is secured in a quarantine state and excluded from all active processing operations. Restriction remains in effect until the underlying matter is resolved.
§ 35 Right to Data Portability
✓ GDPR Art. 20
Where the right to data portability applies, QXONI will provide eligible data in a structured, commonly used, machine-readable format. The available format and delivery method depend on the service. Requests are handled within the applicable statutory period, subject to identity verification and lawful extensions.
§ 36 Right to Object
✓ GDPR Art. 21
Users have the right to object to data processing at any time, particularly where processing is based on legitimate interest grounds. Upon receipt of a valid objection, all processing is suspended immediately unless QXONI can demonstrate compelling legitimate grounds overriding the data subject's interests, rights, and freedoms, or where processing is necessary for the establishment or defence of legal claims.
§ 37 Rights Regarding Automated Decision-Making
✓ GDPR Art. 22
QXONI does not subject any user to decisions based solely on automated processing that produce legal or similarly significant effects. Content recommendation algorithms serve relevance purposes only and carry no contractual or legal consequence. All account-affecting decisions generated by automated systems are subject to mandatory human review prior to execution.
§ 38 Right to Lodge a Supervisory Authority Complaint
Users may complain to the competent supervisory authority. For Swiss matters, the Federal Data Protection and Information Commissioner (FDPIC) is the national supervisory authority; EU residents may also contact the competent authority in their Member State where the GDPR applies. QXONI’s current privacy contact is wernerfrehner22@gmail.com. QXONI aims to acknowledge substantive requests promptly, but does not guarantee a fixed three-business-day resolution.
§ 39 Transparency in Rights Communication
QXONI aims to communicate privacy rights in clear language. Under the GDPR, requests are generally answered without undue delay and within one month, subject to permitted extensions. Under Swiss law, access information is generally provided within 30 days; if that is not possible, the requester should be informed of the delay. Other rights may require a different period depending on the request and applicable law.
§ 40 Exercise of Rights at No Cost
Privacy requests are generally handled without charge. Applicable law may allow a reasonable fee or refusal where a request is manifestly unfounded, excessive, repetitive, or requires disproportionate effort. Where Swiss law permits a cost contribution, QXONI will inform the requester before processing the request.
Chapter V — Security Architecture
§ 41 TLS 1.3 and Encryption Standards
🔒 Security
QXONI uses HTTPS and other security measures intended to protect data in transit and at rest. Specific protocols, ciphers, storage encryption, and key-management controls depend on the system and provider. Security reduces risk but cannot eliminate it, and no internet service can promise absolute protection against every attack or failure.
§ 42 Infrastructure Partners and Server Locations
QXONI relies on service providers to operate OMINO and related services. The current categories and integrations may include:
| Provider or category | Purpose | Data potentially processed |
| PythonAnywhere or current hosting provider | Web and API hosting | IP address, request metadata, account or API data required for the service |
| GroqCloud | AI model inference | Prompts, conversation context, uploaded images, outputs, and technical metadata |
| Pollinations | Image generation | Image prompts and, for direct browser requests, IP address and browser metadata |
| DuckDuckGo / Google News | Search and news retrieval | Search or news query terms and technical request metadata |
| Open-Meteo | Weather and geocoding | Place names, coordinates generated from the query, and technical request metadata |
| QXONI content and font services | Static assets and fonts | IP address, user agent, requested asset, and timing data |
Provider use may change. Material changes should be reflected in this policy or a service-specific subprocessor notice.
§ 43 International Data Transfers
Personal data may be processed in Switzerland, the European Economic Area, the United States, or another country in which a service provider operates. Where applicable law requires safeguards for a cross-border transfer, QXONI uses an available lawful mechanism such as an adequacy decision, recognised standard contractual clauses, contractual guarantees, or another permitted basis. Transfer safeguards and destination countries depend on the provider and service concerned.
§ 44 Security Reviews and Vulnerability Management
QXONI aims to review security risks, prioritise credible vulnerability reports, and remediate confirmed issues according to severity, exploitability, user impact, and available resources. Urgent defects are escalated promptly, but this policy does not guarantee a fixed 48-hour resolution period. Security measures and review frequency should be proportionate to the service and risk.
§ 45 Incident Response and Breach Notification
QXONI assesses security incidents under the laws that apply to the affected processing. Under Article 33 GDPR, a notifiable personal-data breach is reported to the competent supervisory authority without undue delay and, where feasible, within 72 hours after awareness; affected individuals are informed without undue delay where the breach is likely to create a high risk. Under Article 24 FADP, a breach likely to create a high risk is reported to the FDPIC as soon as possible, and affected persons are informed where necessary for their protection or when required by the FDPIC.
Chapter VI — Extended Privacy Commitments
§ 46 Analytics and Aggregate Statistics
QXONI may create aggregate service metrics and security statistics. OMINO does not intentionally use third-party behavioural advertising analytics as of the effective date. Operational logs and hosting-provider metrics may still be processed for reliability, fraud prevention, capacity planning, and troubleshooting. Aggregation is not treated as anonymous unless re-identification is not reasonably possible.
§ 47 Third-Party Data Sharing Policy
QXONI does not sell personal data to advertisers or data brokers. Personal data may be disclosed to hosting, AI, image-generation, search, weather, communication, security, and account-service providers where necessary to deliver the service. Data may also be disclosed where required by law, to protect users or systems, in connection with an organisational restructuring, or with the user’s valid consent. Providers receive only the data reasonably required for their role, subject to applicable contracts and law.
§ 48 Special Categories of Personal Data
QXONI does not intentionally request special-category or highly sensitive personal data for ordinary OMINO use. Users may nevertheless include such information in prompts, files, messages, applications, or community content. When that occurs, the data may be processed by QXONI and relevant providers. Users should avoid submitting health, biometric, political, religious, sexual, financial, authentication, or other highly sensitive information unless the feature requires it and they are authorised to disclose it.
§ 49 Child and Youth Data Protection
QXONI services are intended for users aged 13 or older unless a service-specific rule sets a higher threshold. Where the law of the user’s country requires parental authorisation or a higher digital-consent age, that requirement applies. In the EU, the age for a child’s own consent to certain information-society services may vary by Member State between 13 and 16. QXONI may request age information and take reasonable steps to address underage accounts, but does not claim universal identity or age verification unless explicitly offered.
§ 50 Anonymisation and Pseudonymisation
QXONI applies pseudonymisation and technical anonymisation throughout its data processing pipelines to reduce re-identification risk. Pseudonymised records enable system diagnostics without exposing user identity. True anonymisation — where re-identification is technically infeasible — is applied before any data is incorporated into aggregate reporting or statistical analysis outputs.
Chapter VII — AI & Automation Ethics
§ 51 AI-Assisted Content Moderation
🤖 AI Services
QXONI may use automated filters or model-based signals to identify potentially unlawful, unsafe, or abusive content. Such systems can make mistakes. Human review is used where appropriate, feasible, or legally required, particularly before significant account action. QXONI may take temporary protective measures while a matter is reviewed.
§ 52 AI Model Training and User Data
🤖 AI Services
QXONI does not use OMINO prompts, private messages, or uploaded files to train a QXONI-owned general-purpose model by default. External AI providers may retain or process inputs and outputs for security, reliability, or service improvement according to their agreements and configured controls. As of 10 July 2026, Groq documentation describes standard retention of customer data for up to 30 days unless Zero Data Retention is enabled for the relevant organisation or feature. Users should assume provider processing occurs unless a service-specific notice confirms a zero-retention configuration.
§ 53 Transparency in AI-Generated Content
OMINO is presented as an AI system, and content generated inside the OMINO interface should be understood as AI-generated. QXONI may label generated text, images, summaries, or agent actions where appropriate. Users who publish or redistribute synthetic media are responsible for any disclosure, attribution, watermarking, or transparency duties imposed by law, platform rules, or professional standards.
§ 54 Prohibition of AI Deepfake Content
⛔ Prohibited
Users must not use QXONI to create or distribute non-consensual intimate imagery, sexual content involving minors, fraudulent impersonation, deceptive synthetic media intended to cause harm, or unlawful defamatory material. QXONI may restrict access, preserve evidence, and report conduct to competent authorities where required or permitted by law. Enforcement depends on the facts, applicable law, and available evidence.
§ 55 Spam and Coordinated Inauthentic Behaviour Detection
QXONI may analyse request patterns, account activity, prompts, and technical metadata to detect spam, phishing, malware, fraud, coordinated abuse, or attempts to evade safeguards. Automated signals may be used to prioritise review or temporarily limit access. Data used for abuse detection may be identifiable where necessary to investigate the incident.
§ 56 Feed Personalisation
Where personalisation is offered, QXONI may use recent interactions, selected preferences, or locally stored context to tailor the experience. The controls and data used depend on the feature. Users may disable available personalisation controls or clear locally stored history. Disabling personalisation may reduce relevance but should not remove core access unless the feature inherently depends on context.
§ 57 Mandatory Human Review of Automated Decisions
QXONI does not intend to make decisions producing legal or similarly significant effects solely through OMINO outputs. Where an automated decision of that kind is used, QXONI will provide the information, opportunity to express a view, and human review required by applicable law. Routine rate limits, spam filters, and temporary security controls may operate automatically, subject to later review where appropriate.
§ 58 Ethics Review for AI Features
QXONI aims to conduct proportionate privacy, safety, and misuse assessments before launching materially new AI features. The depth of review depends on the risk, scale, and legal classification of the feature. This statement describes a governance objective and does not represent that every feature has completed a formal external audit or certification.
§ 59 Disclosure of AI Systems on Request
QXONI will provide meaningful information about material AI-supported processing where required by law and reasonably possible. Disclosure may be limited to protect security, intellectual property, confidential provider information, or the rights of others. Requests are handled within applicable statutory or contractual periods rather than a guaranteed ten-business-day deadline.
§ 60 Preference for Open-Source AI Frameworks
QXONI may use both open-source and proprietary AI frameworks. Open-source components can improve auditability, while proprietary services may be selected for capability, security, availability, or cost. Provider selection is based on the needs and risks of the feature and does not imply that every model, training dataset, or safety system is publicly inspectable.
Chapter VIII — Child Safety & CSAM
§ 61 Zero Tolerance Policy — CSAM
⚖ Legal Obligation
Content involving the sexual exploitation or abuse of minors is prohibited. QXONI may immediately restrict access, preserve relevant records where lawful, and report suspected illegal material to competent national or international authorities or reporting bodies when legally required or reasonably necessary for child protection. Reporting routes depend on jurisdiction and the nature of the incident.
§ 62 Age Verification at Registration
Users must meet the applicable minimum age and provide accurate age information when requested. QXONI may use age declarations and other proportionate measures appropriate to the service. QXONI does not claim that every date of birth is independently verified. Accounts believed to be underage may be restricted while the matter is assessed.
§ 63 Community Reporting System
Where a reporting mechanism is available, users may report suspected abuse or child-safety concerns. Reports are prioritised according to severity and available evidence. QXONI aims to escalate urgent child-safety matters promptly, but does not guarantee a fixed review time for every report.
§ 64 Hash-Based CSAM Detection
QXONI may use hash matching, provider safety tools, content classifiers, or manual review where those controls are available and lawful. These tools do not detect every harmful file and may produce false positives or false negatives. QXONI does not represent that known illegal material can never reach or be stored by its systems.
§ 65 Moderation Team Support and Training
Moderation personnel who may encounter potentially illegal or psychologically harmful content in the course of their duties have access to mandatory psychological support resources, regular clinical debriefing sessions, and ongoing training in detection standards, mandatory reporting obligations, and trauma-informed review protocols. Team member wellbeing is a documented organisational responsibility.
Chapter IX — Legal & Regulatory Compliance
§ 66 Governing Law and Jurisdiction
⚖ Legal
This policy is interpreted under Swiss law, including the Federal Act on Data Protection, to the extent Swiss law applies. The GDPR and other mandatory laws may apply based on the user, service, establishment, or targeting activity. Nothing in this policy removes mandatory rights or a consumer’s right to bring a claim before a competent court under applicable law.
§ 67 Swiss Data Protection Act (revFADP) Compliance
QXONI aims to comply with the Swiss Federal Act on Data Protection, in force since 1 September 2023, and with the GDPR where it applies. Compliance depends on actual operational practice, contracts, security controls, and ongoing implementation. This policy is not a certification or guarantee of compliance and should be reviewed when services or laws change.
§ 68 Intellectual Property
All content, interface designs, logos, codebases, and documentation created by or for QXONI are the exclusive intellectual property of QXONI int. User-generated content remains the sole property of its creator. QXONI holds only a limited, non-exclusive, revocable licence to display content on the platform, which expires automatically upon content deletion.
§ 69 Disclaimer for External Links
QXONI accepts no liability for the content, privacy practices, or security of externally linked websites. The inclusion of an external link does not constitute an endorsement. Operators of external sites bear full responsibility for their own content and data processing. Users are advised to review the privacy policies of any external services they access.
§ 70 Policy Amendments
QXONI may update this policy to reflect changes in services, providers, organisational structure, or law. The effective date and version will be updated. Material changes will be communicated through a reasonable channel, such as an in-product notice, website notice, or email, where appropriate and practicable. If law requires renewed consent, QXONI will request it before the relevant processing begins.
Chapter X — Platform Features & User Controls
§ 71 Two-Factor Authentication
🔒 Security
Where two-factor authentication is offered, QXONI recommends enabling it. Supported methods and recovery options depend on the account service. Users should store recovery information securely and should not assume that hardware security keys or a particular authenticator standard are available unless shown in Account Settings.
§ 72 Session Management and Token Lifecycle
Authentication tokens may be stored in cookies or browser storage depending on the service. The current OMINO web client may store an account token in Local Storage, which means scripts running on the same origin could potentially access it. Users should use trusted devices, log out on shared devices, and keep browsers updated. Token expiry, revocation, and active-session controls depend on the account backend and are described in the relevant account interface.
§ 73 Developer API Access Keys
Where developer API access is offered, keys must be kept confidential and used within published scopes and rate limits. Keys may be suspended or revoked for abuse, compromise, unlawful access, or attempts to evade limits. Availability of rotation, scoping, dashboards, and developer programmes depends on the current API service.
§ 74 Offline Mode and Local Caching
Some QXONI features store data locally to support continuity or offline-like behaviour. Browser Local Storage is not inherently encrypted by QXONI and may be accessible to anyone with access to the device or browser profile. Users should protect their devices and clear site data when using a shared or untrusted device.
§ 75 Full Data Export
OMINO provides a local chat export function where available. This export covers data stored by the browser interface and may not include server logs, account records, provider records, or server-side memories. Requests for other personal data may be sent to the privacy contact and will be handled under applicable access and portability rights.
§ 76 Push Notifications and Device Tokens
Where push notifications are enabled, a device or browser subscription token may be stored by QXONI and the relevant platform notification provider. Such tokens can be linked to an account or browser session for delivery. Users can revoke notification permission through browser, device, or account settings.
§ 77 Search History and Autocomplete
The current OMINO interface searches locally stored chat titles and content in the browser. Search or news tools invoked through OMINO may send the query to external search providers. QXONI does not use those queries for advertising, but providers may process them under their own notices.
§ 78 Accessibility Settings
Accessibility preferences such as reduced motion, font size, theme, and layout may be stored locally in the browser and, where synchronisation is offered, in an account profile. The location and retention of each preference depend on the relevant service.
§ 79 Language and Regional Settings
Language, timezone, and regional preferences may be stored locally or in an account profile to present the service correctly. Location names entered for weather or search features may be transmitted to relevant providers. QXONI does not treat a language preference alone as proof of nationality or precise location.
§ 80 Third-Party OAuth Sign-In
Where third-party sign-in is offered, the identity provider may disclose an account identifier, email address, display name, avatar, or other authorised fields. The exact data is shown by the provider during authorisation. Provider tokens and linkage identifiers are handled according to the account implementation and may be revoked through QXONI or the provider.
Chapter XI — Roadmap & Commitments
§ 81 Privacy Technology Roadmap 2026–2027
QXONI may research stronger privacy and security features, including end-to-end encryption, hardware-backed authentication, improved key management, and privacy-preserving verification. Roadmap items are plans rather than binding commitments and may change for technical, legal, security, or resource reasons. A feature should be treated as available only when it appears in the relevant product interface and documentation.
§ 82 Privacy Inquiry Channels
Privacy requests may be sent to wernerfrehner22@gmail.com; general enquiries may be sent to qxoniint@gmail.com. QXONI aims to acknowledge requests promptly. GDPR requests are generally handled within one month, subject to lawful extensions. Swiss access requests are generally handled within 30 days; if more time is needed, the requester will be informed where required.
§ 83 Responsible Disclosure Programme
QXONI welcomes good-faith reports of security vulnerabilities. Researchers should avoid accessing unnecessary personal data, disrupting services, or publicly disclosing an unremediated vulnerability. Reports may be sent to the general contact until a dedicated security channel is published. Safe-harbour treatment depends on good-faith compliance with these conditions and applicable law.
§ 84 Decentralised Architecture Research
QXONI may research decentralised or user-controlled storage approaches. Research, prototypes, and roadmap discussions do not mean that self-custody, decentralised storage, or protocol-based operation is currently available. Any future implementation will receive a separate privacy and security assessment before release.
§ 85 Sustainable Infrastructure Selection
QXONI may consider energy use, location, security, reliability, cost, and legal compliance when selecting infrastructure. Environmental claims are made only where supported by provider information or other reasonable evidence. This section is an objective rather than a guarantee that every provider uses renewable energy.
§ 86 Engagement with the Privacy Research Community
QXONI may engage with open-source, security, or privacy communities and may publish technical lessons that do not expose personal or confidential information. Participation levels vary over time. QXONI does not claim formal membership in, or endorsement by, a research organisation unless separately documented.
§ 87 Privacy Training Requirements
Persons with access to personal data should receive privacy and security guidance appropriate to their role. Training frequency and content depend on responsibilities, risk, and organisational capacity. QXONI does not claim external certification of every team member unless separately stated.
§ 88 Deceased User Accounts
If QXONI receives a credible request concerning a deceased user, it may request evidence of identity, authority, and death before taking action. Available outcomes depend on the service, the user’s instructions, applicable law, third-party rights, and technical capability. A memorial profile or transfer option is not guaranteed unless expressly offered.
§ 89 Account Transfers and Organisational Accounts
Personal accounts are not transferable unless QXONI expressly supports a transfer mechanism. Where organisational accounts are offered, administrator changes may require identity and authority verification. QXONI may restrict or refuse a transfer to protect the account, organisation, or affected individuals.
§ 90 Privacy in Beta Programmes
Beta features may be incomplete, unstable, or subject to different providers and retention behaviour. QXONI will identify material differences where reasonably possible. Users should avoid placing irreplaceable or highly sensitive data into beta features and should maintain their own copies of important information.
Chapter XII — Definitions & Glossary
§ 91 Definition: Personal Data
For the purposes of this policy, "personal data" means any information relating to an identified or identifiable natural person, including: full name, email address, IP address (under applicable conditions), account username, profile information, usage data, device identifiers, and any other data that can directly or indirectly identify an individual.
§ 92 Definition: Processing
"Processing" designates any operation or set of operations performed on personal data — encompassing collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure by transmission, dissemination, combination, restriction, erasure, or destruction. Each form of processing is subject to the principles set out in this document.
§ 93 Legal Bases for Processing
Where the GDPR applies, QXONI relies on one or more legal bases depending on the activity: performance of a contract, legitimate interests subject to balancing, consent, compliance with a legal obligation, protection of vital interests, or another applicable basis. Under Swiss law, processing must comply with the FADP principles and may require consent or another justification in specific circumstances. Service-specific notices may identify the relevant basis more precisely.
§ 94 Glossary of Technical Terms
Transport Layer Security (TLS): protocol family used to encrypt network connections.
Password hashing: one-way processing intended to prevent storage of a recoverable plain-text password.
End-to-end encryption: a design in which only the communicating endpoints hold the content-decryption keys.
OAuth: a standard for delegated authorisation and sign-in.
EXIF: metadata that may be embedded in image files.
HSTS: a browser instruction encouraging HTTPS-only connections.
DPA: a data-processing agreement used where one party processes personal data on behalf of another.
FADP: the Swiss Federal Act on Data Protection, in force since 1 September 2023.
§ 95 Privacy Contact Information
For data-protection enquiries, rights requests, and regulatory matters:
📬 Privacy contact: wernerfrehner22@gmail.com
General contact: qxoniint@gmail.com
Supported languages: German and English
Target acknowledgement: as soon as reasonably practicable
Statutory handling period: the period required by the applicable law, including generally one month under the GDPR and generally 30 days for Swiss access requests, subject to permitted extensions.
§ 96 Severability
Should any provision of this policy be determined invalid, unenforceable, or contrary to applicable law, such determination shall not affect the validity or enforceability of the remaining provisions. The invalid provision shall be replaced by interpretation with a valid clause that most closely reflects the original protective intent.
§ 97 Authoritative Language
This policy is drafted in English and is intended to be the authoritative QXONI version. Translations may be provided for accessibility. Mandatory local law, consumer-protection rules, and statutory interpretation requirements remain unaffected; an English-language priority clause does not remove rights granted by applicable law.
§ 98 Relationship to Terms of Service
This Privacy Policy explains data processing and should be read together with the Terms of Service, Cookie Policy, AI Use Policy, and any service-specific notice. Privacy rights are governed by applicable law and are not reduced by a conflicting contractual term.
§ 99 Policy Version History
| Version | Date | Numbered sections | Key changes |
| v4.01 | 10/07/2026 | 110 | Corrected breach timelines, AI/provider disclosures, browser-storage wording, cookie claims, age wording, jurisdiction clauses, and added the separate AI Use Policy. |
| v4.0 | 23/06/2026 | 110 | Consolidated policy release. |
| v3.0 | 01/06/2026 | 110 | Full rewrite and mobile-first design. |
| v2.3 | 20/05/2026 | 110 | Transition to QXONI int. structure. |
| v2.2 | 14/05/2026 | 110 | Expanded AI and data-protection chapters. |
§ U Updates
v4.01 — 10/07/2026: corrected absolute or unverified claims; clarified OMINO local storage, server-side processing, current providers, AI retention, cross-border transfers, incident notification, child-consent rules, and user deletion controls; added a dedicated AI Use Policy.
v4.0 — 23/06/2026: consolidated policy release and design update. Earlier versions are summarised in the version-history table.
§ 100 Our Commitment to You
Privacy at QXONI is an organisational objective that must be reflected in actual technical and operational practice. QXONI reviews this policy when material services, providers, or processing activities change. This policy contains 110 numbered sections plus an update notice. Last updated and effective: 10 July 2026. Policy version: 4.01.
Chapter XIII — Supplementary Provisions
§ 101 Email Verification Data
Verification and reset tokens are intended to be single-use and time-limited. Exact expiry and deletion periods depend on the account service. Tokens may be retained temporarily in security logs or backups where necessary to investigate abuse or comply with law.
§ 102 Newsletter and Mailing List Data
Where newsletters are offered, subscription requires an affirmative opt-in and each marketing message will include an unsubscribe method. Unsubscription is processed without undue delay, although a suppression record may be retained to ensure the address is not added again. Service and security messages may still be sent where necessary.
§ 103 Survey and Feedback Data
Where surveys or feedback forms are offered, QXONI processes the information provided for product research, support, or service improvement. Responses may be linked to an account where the form or context makes that clear. Retention depends on the purpose and sensitivity of the data; identifiable responses are deleted or anonymised when no longer reasonably needed.
§ 104 Profile Verification
🔒 Verification
Where profile or organisational verification is offered, QXONI may request supporting evidence. The evidence, review notes, and result are retained only for as long as reasonably necessary for verification, fraud prevention, appeals, and legal obligations. QXONI does not represent that only a boolean result is retained in every implementation.
§ 105 Dormant Account Policy
QXONI may introduce inactivity or dormant-account rules. If such a rule is applied, users will receive reasonable notice where contact details are available, and the relevant service will explain the inactivity period, consequences, and available export or recovery options. This section does not itself create an automatic 24-month deletion schedule.
§ 106 Online Events and Webinar Data
Where QXONI hosts events or webinars, registration data is used for administration, communications, and security. Recording occurs only with appropriate notice and, where required, consent. Retention depends on the event purpose, legal obligations, and whether participants reasonably expect continued access to the recording.
§ 107 Whistleblower Protection
✓ Protected Right
QXONI does not retaliate against persons who report concerns in good faith. Reports are handled as confidentially as reasonably possible, subject to investigation, legal obligations, and the rights of affected persons. Until a dedicated reporting channel is published, reports may be sent to the general or privacy contact.
§ 108 Commercial Partnerships and Data Processing
Before appointing a processor for personal data covered by the GDPR, QXONI uses the contractual terms required by Article 28 GDPR where applicable. Not every external recipient is legally a processor, and safeguards differ by relationship and jurisdiction. QXONI reviews provider terms and risk proportionate to the processing, but does not claim that every provider has undergone a formal audit by QXONI.
§ 109 Competitions and Prize Events
Where QXONI runs a competition or prize event, the event notice will explain the data collected, eligibility rules, recipients, retention period, and any sponsor involvement. Data is kept only as long as reasonably necessary for administration, fraud prevention, tax or accounting obligations, and disputes. Sponsor disclosure requires an appropriate legal basis.
§ 110 Final Declaration
QXONI treats these provisions as a living policy that must be kept aligned with real services. Users should review material updates and use the privacy contact where a description appears inconsistent with actual behaviour. © QXONI int. · Bühler (AR), Appenzell Ausserrhoden, Switzerland · Policy v4.01 · Effective 10 July 2026.