Operator: Onbiom operator · Operator address is being configured. Contact: Support contact is being configured.

Privacy

Onbiom stores your verified email, hashed login tokens, monitoring URLs, tool schemas and check history to operate your account. Optional endpoint tokens, refresh tokens and preregistered OAuth client secrets are encrypted and bound to the saved monitor and exact endpoint. Endpoint authentication is separate from tool and model approvals. Google provides sign-in identity and Resend sends transactional email. Billing, when enabled, is handled by Polar.

Inventory checks do not execute tools. An owner can separately configure and acknowledge optional tool calls, which may cause side effects and provider costs. We store the exact fixed tool arguments and bounded redacted execution output for these checks. Optional quality checks store your expected behavior, owner-provided reference fixtures and separate result history. Deterministic comparisons stay local. Only after separate explicit local-model approval, selected bounded evidence and its expectation may be sent to the existing self-hosted Laya model through the internal gateway. Fixed invocation arguments and unnecessary reference fixtures are excluded. We retain model/rubric metadata and an advisory assessment; it never guarantees correctness. Local approval never authorizes external transmission. Only separate explicit Cloudflare approval sends the same selected evidence and expectation to Cloudflare-hosted cf-qwen3-30b, without the Laya verdict. Both judgments stay advisory. A minimal credit ledger retains hashed attempt identities, counters and token usage for up to 400 days after monitor history expires; it contains no tool arguments or selected evidence. Public tool inventories may contain information from the remote server; add endpoints you are authorized to monitor. Do not put credentials or personal data in monitor names or URLs.

Detailed history follows your plan retention. Separately stored numeric connection observations retain timestamps, success/failure and response times for up to 366 days when collected on Starter, including after paid access ends; Free observations last up to 8 days. A separately published public link exposes only these numeric observations. You can revoke that link; paid lapse hides the page. Deleting a monitor removes its observations, public link, checks and pending notifications. To request account deletion, contact the published support address; billing records required for tax compliance remain with the merchant of record.