Onyx Media CenterTerms of Service

Privacy Policy

One policy across Onyx.

This policy covers the Onyx website, the Windows and Linux desktop app, the Android app, the downloadable server, and the account services a server operator chooses to connect. It explains what each part processes and who is responsible.

Effective and last updated: 2 September 2026.

The short version

  • The website has no account, advertising, analytics, tracking, cookies or browser storage.
  • The Onyx project does not receive your library, account, watch history or radio history.
  • Your server operator controls server accounts and viewing data. Their identity must be shown before sign-up.
  • Local media stays on your device. It is read only after you enable the feature and grant the device permission.
  • You can export your server data, clear viewing history, sign out, and delete your account inside the apps.

1. Scope and responsibility

"Onyx" in this policy means the website, desktop app, Android app and server software together. The website and software publisher is Victor GumiƄski, operating the Onyx Media Center project from Norway. For website or publisher requests, use the contact method on theproject maintainer's public profile.

Each Onyx server is operated independently. The person or organization running the server is the controller for accounts, access lists, viewing data and server logs connected with that server. Their name, postal address and electronic contact must appear in the privacy notice shown by the app before account creation. Do not create an account if those details are missing.

A server used only for a purely personal or household activity may fall outside GDPR under Article 2(2)(c). An operator serving anyone beyond that setting must meet the controller duties described here and any other duties that apply to their operation.

2. What is processed

Website delivery

The website host may receive the IP address, request time, requested page, browser information and security events needed to deliver and protect the site. Onyx does not add an identifier or build a visitor profile.

Downloads

When you press a download button, the download host receives the connection data needed to deliver the file. The website sends no account or profile data with that request and uses a no-referrer policy.

Desktop and Android devices

The apps store the settings you choose, sign-in tokens, the profiles used on that device, saved radio stations and an update package only when you request an update. Windows protects the session for the operating-system user. Linux restricts it to that user. Android uses secure, Keystore-backed storage and disables app backups.

If you enable local media, the app reads the device media index after the operating system permission prompt. File names, library contents and local playback stay on the device and are not sent to an Onyx server.

Accounts and server use

A server may process your display name, email address, Supabase account identifier, playback positions, watched marks and favorites. Invite-only servers also compare your email with an operator-managed allow list. Passwords travel directly to Supabase over an encrypted connection. The Onyx server does not receive the password and Supabase stores a password hash.

Requests and reports

If you contact the publisher or a server operator, they process the contact details and message needed to answer a privacy request, security report or illegal-content report. A Digital Services Act notice may also include the reported item's exact location, an explanation of alleged illegality and a good-faith statement. Do not include unrelated personal or sensitive information.

Onyx has no advertising identifiers, telemetry, crash reporting, profiling or automated decisions with legal or similarly significant effects.

3. Purposes and legal bases

  • Service and account features, GDPR Article 6(1)(b): authentication, password recovery, playback progress, favorites, data export, updates and the functions you request.
  • Device-media consent, Article 6(1)(a): local media access is off by default and can be withdrawn in Onyx settings and the operating-system settings.
  • Security, Article 6(1)(f): website security logs, fraud and abuse prevention, an invite-only email allow list, and protection of accounts and media. The relevant controller must balance this interest against your rights.
  • Legal duties, Article 6(1)(c): responding where law requires it, including data-protection requests, security incidents and valid illegal-content notices or authority orders.

A name and email are required only when you choose to create a server account. Local media and radio can be used without giving the Onyx project an account.

4. Recipients and external connections

  • Cloudflare: hosts the static website and may process ordinary connection and security data for the website controller.
  • GitHub: hosts downloadable packages. It receives a direct request only when you choose a download.
  • Supabase: provides authentication and, when selected by the server operator, the profile database. It acts under the server operator's instructions for that processing.
  • The server host: carries server traffic when the operator uses a cloud host. A server running only on a home machine has no cloud server host.
  • Radio Browser and radio stations: opening the Radio screen makes a direct request from your device to the community catalogue. Playing a station connects directly to that station. These services receive your IP address and ordinary connection data, but no Onyx account token, email or profile name. The app reports a station play using its public station identifier. Radio can be disabled in settings.

Onyx does not sell personal data and does not share it for advertising. External providers may process data outside the EEA. The responsible controller must use an EEA region where available and put an Article 28 processing agreement and a valid Chapter V transfer mechanism in place where required.

5. Retention

  • Website and download connection records follow the security and retention settings of the relevant host.
  • Device settings and saved stations remain until you change them or remove the app data.
  • Device sessions remain until sign-out, profile removal, account deletion or token expiry.
  • Playback progress and favorites remain until you clear them or delete the account.
  • Account name and email remain until account deletion, subject to any legal retention duty.
  • After account deletion, a random account identifier with no name or email may remain for up to seven days to reject old tokens, then it is removed.
  • The Android data-export file in the Onyx cache is removed after the save or share sheet closes. A copy you save is under your control.
  • Requests and reports are kept only as long as needed to answer, document and defend the decision, then deleted or anonymized.

6. Cookies and device storage

The website sets no cookies and uses no local storage, session storage or IndexedDB. It therefore needs no tracking-consent banner. App files are limited to storage that is necessary for a feature you explicitly request, such as staying signed in, remembering settings, saving a radio station or installing an update. This reflects the strictly necessary exception in section 3-15 of the Norwegian Electronic Communications Act.

7. Your rights

Where GDPR applies, you may request access, correction, deletion, restriction, portability and, where relevant, object to processing or withdraw consent. You also have the right to complain to a supervisory authority.

  • Access and portability: use "export my data" in the desktop tasks screen or Android Profile tab to receive the server data as JSON.
  • Correction: ask the server operator to correct your name or email in Supabase.
  • Erasure: clear watch history, remove favorites or delete the account inside either app. Ask the operator to remove your email from an invite-only allow list.
  • Restriction or objection: contact the controller identified for the server or processing concerned.
  • Withdraw local-media consent: switch local media off and revoke the operating-system permission at any time.

The controller normally answers a verified request within one month. In Norway you may complain to Datatilsynet, P.O. Box 458 Sentrum, NO-0105 Oslo.

8. Children

Onyx is designed for household use and has no age-verification system. In Norway, a child aged 13 or older may give their own consent where an information-society service relies on consent. A parent or guardian must act for a younger child. A server operator serving people outside their household must not create an account for a child under 13 without valid parental authorization.

9. Security and incidents

Onyx uses authenticated profiles, validated access tokens, per-profile authorization, short-lived single-item stream tickets, secure mobile token storage and data minimization. Internet-facing servers must use HTTPS. Plain HTTP on a trusted home network is not encrypted between the device and server.

No system is completely secure. Where GDPR applies, the responsible controller must assess a personal-data breach, notify the supervisory authority within 72 hours when required by Article 33, and inform affected people when Article 34 requires it.

10. Changes and contact

Material changes receive a new effective date and should be presented before they take effect for an account. The version shown by an independently operated server may add its controller details, providers, retention periods and local choices. It may not remove rights given by mandatory law.

Contact the server operator for account, library and server requests. Contact the Onyx project maintainer for the website or published app itself. Include enough information to identify the relevant server or request, but never send your password or access token.

This policy is intended to provide the information required by GDPR Articles 12 to 14 and to describe the product's privacy controls. Compliance also depends on each server operator completing the controller details, processor agreements, regional settings, access controls, retention choices and security duties that cannot be completed by the software publisher.