QXONI Policies v4.01
Version 4.01 is a focused legal and transparency update for QXONI and OMINO. It introduces a dedicated AI Use Policy, explains external service data flows, clarifies browser-stored data, and replaces overly absolute statements with wording that better reflects the actual service and applicable law.
Dedicated AI Use Policy
A new standalone AI Use Policy now explains how users may use OMINO and other QXONI AI features, what limitations apply, and how generated output should be handled.
- 12 dedicated AI sections covering acceptable use, safety, generated content, and enforcement.
- Clear notice that AI output may be incomplete, inaccurate, outdated, or unsuitable for high-stakes decisions.
- Professional legal, medical, financial, and safety-critical decisions require independent qualified review.
- Prohibited use now includes malware, fraud, abusive automation, unlawful impersonation, exploitation, and harmful content.
OMINO data flows and external services
The Privacy Policy now describes which information may leave the browser when a user sends a prompt, uploads an image, requests search results, or creates an image.
- Model inference may involve Groq.
- Image prompts may be sent to Pollinations.
- Search, news, and weather requests may involve DuckDuckGo, Google News, and Open-Meteo.
- Hosting providers may process network, request, and security metadata.
- The exact provider depends on the requested feature and may change with an updated notice.
Local storage and chat deletion clarified
The policies now distinguish between information stored in the browser and information transmitted to QXONI or a service provider.
- OMINO may store chats, projects, preferences, a browser identifier, and account-related information locally.
- Browser Local Storage is not presented as encrypted storage.
- Delete all chats removes locally saved chat history only.
- Local deletion does not automatically erase backend logs, provider records, or persistent agent memory.
- Users are advised to log out and clear site data on shared or untrusted devices.
Provider retention wording corrected
Previous absolute statements about third-party storage and model training have been replaced with provider-specific, configuration-dependent explanations.
- QXONI does not claim that every external AI request is automatically zero-retention.
- Provider processing may occur for security, reliability, abuse prevention, or service operation.
- Groq retention is described according to the controls and documentation applicable as of the release date.
- Users should avoid entering highly sensitive information unless the feature and provider controls are appropriate.
Privacy rights and breach timelines refined
The rights and incident-response sections now separate statutory duties instead of promising the same response or notification in every situation.
- GDPR requests are generally handled within one month, subject to lawful extensions.
- Swiss access requests are generally handled within 30 days, with delay notices where required.
- The GDPR 72-hour period is correctly tied to qualifying supervisory-authority notifications.
- Affected individuals are informed when the legal risk threshold is met.
- Swiss breach notification wording now reflects the applicable high-risk standard.
Cookie and browser-storage transparency
The Cookie Policy no longer assumes a fixed number of cookies across every QXONI service and now explains the difference between cookies and Local Storage.
- Technically necessary authentication, security, and preference storage is described by purpose.
- No advertising or behavioural-tracking cookies are intentionally deployed by OMINO as of 10 July 2026.
- Authentication may use cookies or browser storage depending on the relevant service.
- Users can remove browser-side information through application controls or browser settings.
International transfers and infrastructure wording
Infrastructure statements are now designed to remain accurate when providers or regions change, while still explaining that external processing may occur.
- Specific certifications are no longer attributed to every provider without verification.
- International transfers are described as depending on the provider, region, and available legal mechanism.
- Applicable safeguards may include contractual measures and recognised transfer frameworks.
- Service-specific notices can supplement the main Privacy Policy.
Age, child safety, and AI governance language
Child-safety commitments remain strong, while age-consent and AI-law statements now avoid presenting a single rule as universally applicable in every jurisdiction.
- Digital-consent requirements are described as jurisdiction-dependent.
- Child sexual abuse material remains strictly prohibited and subject to reporting obligations.
- AI Act language reflects phased application rather than claiming blanket certification.
- Human review and appeals remain central where automated systems affect users materially.
Safer and more precise legal wording
Statements framed as universal guarantees have been replaced with language that reflects statutory requirements, operational targets, and mandatory consumer rights.
- Response times are expressed as legal periods or service targets rather than unconditional guarantees.
- Jurisdiction clauses preserve mandatory consumer and data-protection rights.
- Security measures are described without claiming controls that have not been independently verified.
- Missing organisational details are not invented and must be completed from official records before final publication.
Policy set in version 4.01
The legal hub now contains five coordinated policy documents. The section figures below reflect the navigation structure of the v4.01 release.
| Document | Sections | Main purpose |
|---|---|---|
| Privacy Policy | 110 | Personal data, rights, providers, security, and retention |
| AI Use Policy | 12 | AI limitations, acceptable use, safety, and enforcement |
| Terms of Service | 20 | Service rules, user responsibilities, and limitations |
| Cookie Policy | 12 | Cookies, Local Storage, authentication, and preferences |
| Legal Notice | 4 | Operator, contacts, legal information, and disclosures |