Skip to main content
Privacy

Privacy notes

EONAPP is local-first where practical. Optional paid access uses Dodo Payments hosted checkout and server-verified entitlements. The separate, optional MyLead Reward Center uses trusted server postbacks for bounded non-cash EONKEY software unlocks; EONAPP does not operate a cash referral payout, wallet payment rail, or Cloudflare AI-generation backend.

Last updated: 17 August 2026

Public trust policy

This page follows the public trust policy: verified payment activation, public-proof-only support, local-first privacy, no wallet or chain action, refund exceptions, no investment advice, and no profit or result promises.

  • Safe evidence: invoice ID, public transaction hash, quote ID, plan, amount, timestamp, URL, and device context only.
  • Never share secrets: seed phrase, private key, full API key, wallet backup file, password, or full card data.
  • Manual review: refunds, unsupported crypto transfers, abuse reports, and policy exceptions require human review and may need third-party processor evidence.

Local-first storage

EONAPP stores many preferences, badges, plan status, renewal reminders, result history, generated assets, optional vault profile data, and feature state in your browser. Clearing browser storage may erase local state unless you exported a vault backup or kept independent receipt proof.

Optional Google Login and account metadata

Guest use remains available. When optional Google Login is enabled, EONAPP requests only identity scopes: openid, email, and profile. It does not request Gmail, Drive, Calendar, Contacts, YouTube, or other Google-service access.

Cloudflare may hold a random EON account ID, a protected reference to the Google identity, verified-email and session metadata, plus minimal Dodo customer/subscription references and tier/status fields required for entitlement and billing support. EONAPP does not keep raw Chat, prompts, AI outputs, Vault data, provider keys, files, projects, Realm layouts, City progress, browser storage exports, Google access/refresh tokens, or card data in this identity account service.

Important: Google Login is not a backup and does not create automatic cloud sync. Create and keep your own encrypted backup for local work you cannot lose. You can delete the minimal cloud account/session metadata from Profile; local data remains on your device because it was never uploaded.

Payments and processors

Paid subscriptions use Dodo Payments hosted checkout. Dodo processes payment details under its own terms; EONAPP receives server-side lifecycle events and stores minimal customer/subscription references, plan, status and timestamps needed for entitlement, cancellation, expiry, refund/dispute handling and support. EONAPP does not store full card data.

Wallet and public transaction data

No direct wallet-payment rail is active in this release. Never send a wallet payment because of a message, link, or assumed future feature. Public transaction data should be shared with support only when a separately published payment flow explicitly requests it.

Vault and backups

Your exported vault file is controlled by you. If you encrypt it with a passphrase, remember the passphrase. EONAPP does not keep a server-side recovery copy unless a future account product explicitly says so in its own terms.

AI provider keys

If you enter your own AI API keys, keep them secret. BYOK flows should keep keys in your device vault and send them only to the relevant provider when you initiate a request. Support should only receive masked provider names or test results, not full key values.

Sponsored AI EONBOT route: signed-in free accounts in configured economic-pilot countries may use EON Sponsored AI · Vexrail, and an eligible anonymous visitor may receive one guarded Sponsored AI try before sign-in when the guest-one-shot policy is enabled. The visible conversation messages selected for the request are then sent through EONAPP's same-origin server route to Vexrail for model completion, contextual analytics and, when relevant, contextual sponsored recommendations. For upstream conversation continuity, EONAPP derives a salted pseudonymous identifier from the signed-in account and the browser conversation identifier; the raw EON account ID is not placed in that Vexrail conversation header. The Sponsored AI prompt builder does not expose the full local memory ledger, Vault data, private files or arbitrary device activity. When the user has separately enabled the relevant context controls, EONAPP may include only a small bounded set of redacted EONBOT memory cards, intent-gated recent-work labels, and an explicitly queued one-turn cited research packet after Sponsored-specific filtering. Those values are supplied as untrusted context only and do not grant the model browser, tool, account or action authority. For abuse control, EONAPP derives short-lived salted rate-limit buckets from the signed-in account and Cloudflare-provided network address; raw network addresses are not stored in the rate-limit ledger. Coarse Cloudflare country/ASN and available bot-risk signals may be used only to decide Sponsored AI eligibility and abuse controls. Vexrail publisher credentials remain server-side. EONAPP also applies a conservative server-side detector that rejects some obvious secrets and sensitive identifiers before Vexrail contact; this is a safety layer, not a guarantee that all sensitive information can be recognized. Because Vexrail processes conversation context, do not use this route for secrets, API keys, sensitive personal data or material that must remain device-local. When EONAPP recognizes a paid, trial or grace account session, the route remains off by default. The user may explicitly select Sponsored AI when the same configured pilot-country policy permits it; that opt-in is limited to the Vexrail chat route and does not turn ordinary display advertising on. Paid Sponsored AI uses separate hourly/daily fair-use limits, while request-count and token-weighted account/country/global safety budgets, network controls and human verification also apply. After the guarded guest one-shot is used or unavailable, a browser with no valid account session must sign in to continue hosted Sponsored AI and may otherwise use Guide Mode, Local AI or BYOK. Local AI stays on the selected local runtime, and BYOK provider credentials are never forwarded to Vexrail. Vexrail's OpenAI-compatible API can return contextual recommendations within ordinary assistant content rather than as a separate ad object. EONAPP therefore identifies the route itself as EON Sponsored AI · Vexrail; a particular answer may or may not contain a contextual recommendation. The upstream model is selected dynamically from Vexrail's currently available catalogue subject to EONAPP's verified economics and quality policy, so model availability can change without requiring a different user-facing route.

Aggregate measurement and local diagnostics

EONAPP can use Google Analytics for aggregate traffic and approved product-route measurement only after you enable it in Profile. The setting is off until you choose it and applies only to the production EONAPP site.

When enabled, EONAPP sends approved logical route IDs only. It does not send chat messages, files, Vault contents, credentials, account identifiers, Google OAuth information, signed Realm shares, referral codes, local model names, raw URLs, URL queries, fragments, or user-entered values to Analytics. Advertising audiences, Google Signals, remarketing, cross-domain linking, and ad personalization are disabled in the bridge.

Redacted local diagnostics are separate, off by default, and stay only in this browser profile. When you explicitly enable them in Profile, limited local route and event summaries exclude chat content, credentials, URL queries, and fragments. You can switch them off or clear them at any time.

This page does not make a legal determination for your jurisdiction. The product default is no aggregate measurement until you actively enable it.

Advertising, Sponsored Missions and EONKEYS

Subscriptions remain EONAPP's primary monetization. Signed-in free accounts in configured economic-pilot countries may use the separately labelled Sponsored AI Vexrail route; when the guarded guest-one-shot policy is enabled, an eligible anonymous visitor may receive one clearly labelled zero-history Sponsored AI answer before sign-in; paid/trial/grace accounts may use it only by explicit selection. Separately, a proven logged-out guest or signed-in Free account on one of the four approved public acquisition tools may, after an explicit browser choice, load the isolated ExoClick Native sponsored placement. Paid/trial/grace and identity/billing-unknown states do not receive that ordinary placement. The ExoClick provider script executes on the dedicated ad origin rather than the EONAPP application origin. EONAPP does not intentionally pass Local AI prompts, BYOK credentials, Vault contents or private project content into that ordinary display request. The advertising provider may still process technical information such as device, network, cookie/consent and advertising-event data under its own notice and the deployed consent configuration.

Sponsored Missions are different from ordinary advertising. A guest or signed-in user may voluntarily open the external MyLead OfferWall from the EON Reward Center. EONAPP uses opaque server-generated player and correlation identifiers for reward attribution and does not mint EONKEYS from clicks, redirects, browser timers, iframe closes, ordinary ad playback or other client-only events. For guests, a trusted MyLead postback creates only a pending server-side reward tied to an opaque guest reward identity; it becomes spendable only after a one-time sign-in claim. Signed-in rewards and guest pending rewards are authoritative only after a trusted MyLead server postback confirms an eligible conversion. Duplicate transactions are idempotent, and a later provider rejection or reversal can reverse previously credited EONKEYS, including creating a reward debt when credited EONKEYS were already spent.

Sponsored Missions are optional and separate from normal Free, paid, Local AI, BYOK and EON City access. The Reward Center exposes only bounded, temporary software unlocks; EONKEYS have no cash value, are not transferable, and cannot create subscription discounts, renewal credits, provider credits or unlimited hosted AI. EONAPP does not forward private chats, Local AI prompts, BYOK keys or user files to MyLead as part of the reward attribution flow. Ordinary display/editorial advertising, where separately enabled on reviewed public pages, remains governed by its own placement, consent and provider policies.

You can allow or disable the public-tool display choice in Profile; the same browser preference is consumed by the approved acquisition tools. Signed-in Free and paid/trial/grace accounts receive no ordinary ExoClick landing placement and are not automatically routed to sponsored Vexrail. Paid users may explicitly select Sponsored AI when the configured pilot-country policy permits it without changing ordinary-ad eligibility. Voluntary MyLead Sponsored Missions are a separate opt-in system and can remain available to eligible guests as pending rewards and to free or paid signed-in accounts when the provider and EONAPP reward authority are configured.

Signed referral and Realm links

Public eon2 referral and eon3 Realm links carry signed public metadata and a fresh cryptographic share ID. They contain no wallet secrets, password, payment request, payout claim or browser-granted reward value. A signed referral identifier may be used for later server-side attribution, but clicks or shares alone never grant EONKEYS. Do not put real names, private notes, secrets, or sensitive details into a public label or handle.

Operator, supplier and data-controller record

Checking the deployed operator configuration…

Legal operator/supplier
Trading name
Business address
Country
Support contact
Privacy contact
Security contact
Governing law
Venue

Paid launch remains blocked if this deployment does not expose a complete, owner- and counsel-approved record.

Purposes and legal bases

EONAPP processes only the data required for the selected function: identity/session security, subscription and transaction administration, referral/Sponsor-EONKEY integrity, optional advertising and consent controls, private support cases, security/abuse prevention and legal compliance. Depending on the deployed operator jurisdiction and the request, the legal basis may be contract performance, steps requested before contract, consent, legitimate interests in security and service integrity, or compliance with a legal obligation. The deployed operator record and reviewed policy determine the applicable basis.

Data inventory, retention and deletion

  • Device-owned work: Chat, Projects, Library, Vault, local AI settings, Creator media and City progress normally remain in browser storage until the user exports or deletes them.
  • Identity/session: minimal account and session records are retained only for account access and security, then deleted or expired according to the identity schema.
  • Billing/referral: provider references, lifecycle events, commands, entitlements and required accounting/anti-fraud records follow their declared retention and legal obligations.
  • Support/security: redacted case facts, status, owner role and public response are retained only for case handling, audit, defence and required security/legal follow-up.

“Delete account” cannot truthfully promise immediate deletion of records that must be retained by law or a payment provider. The response must identify what was deleted, what remains locally, and what is retained with its reason.

International transfers and subprocessors

Google may process identity authentication; Dodo Payments processes hosted checkout, payment and customer-portal activity; Vexrail processes the current request when an eligible user explicitly selects Sponsored AI or when Auto selects the clearly disclosed Sponsored route for an eligible guest/FREE no-file chat; the guest one-shot carries no prior chat history. Paid/trial/grace accounts remain off Sponsored AI by default and require explicit selection. Zyntent receives only the bounded Sponsored Discovery fields described above when an eligible public-tool guest uses that feature, ExoClick may process the isolated public-tool ad request only after the explicit display choice, MyLead receives only the bounded reward-attribution data required for Sponsored Missions, and a user-selected BYOK AI provider processes only requests the user explicitly sends to it. Cloudflare provides hosting, security and D1 infrastructure where configured. Local AI and other browser-local work are not sent to Vexrail merely because they exist on the device. Transfer safeguards and the current subprocessor register require owner/counsel verification before paid launch.

Your privacy rights

Subject to applicable law, a person may request access, export, correction, restriction, objection or deletion through a private privacy-rights case. A real case ID is issued; the request is reviewed rather than decided by browser state. Identity verification must be proportionate and must not require provider keys, recovery phrases, full card data or private workspace content.

Children

EONAPP is not directed to children who cannot lawfully consent to the relevant digital service or data processing in their jurisdiction. Paid access and account use must follow the age and parental-authorisation rules that apply to the deployed operator. The operator must publish a counsel-reviewed minimum-age rule before public paid launch.