Privacy Policy
onomeo issues language-model credits (meo) to signed-in accounts and spends them on model calls. This page lists everything the service stores about you, what stays in your browser, what third parties receive, and how to export or delete your data.
What is stored on our server
- Account.A random account id, the time it was created, and the network address it was created from. The address is used to cap how many accounts one network can open per day, to refuse invite rewards between accounts from the same network, and to help us investigate abuse.
- Sign-in identity.The email address you verified with a code, and, if you sign in with Google, the account identifier and email address Google reports. Nothing else is taken from Google.
- Sign-in codes.Each code is stored as a salted hash, expires after 10 minutes, and is deleted once used. We also count how many codes were requested and how many sign-ins failed for an address on a given day, and discard those counts when the day ends.
- Signed-in devices.For every browser you sign in from: a hashed session token, when it signed in and was last seen, a shortened browser identifier and the network address. A session lasts 30 days. The account page lists these devices and lets you sign the others out.
- Keys.Only an irreversible hash of each key, so a copy of our database cannot be used to spend anyone's balance. Alongside it, the name, spending cap and expiry date you set for the key, if any.
- Balance and counters.Current balance, meo collected and spent in total, surveys completed, check-in record (last check-in day, current streak, total days, and the dates of your recent check-ins), spending per day for the last few days, and the number of wrong redeem codes entered today.
- Activity log.The last 40 events on the account: check-ins, survey credits and reversals, sign-ins (with the browser identifier), shares created and viewed, invite rewards, redeem codes, adjustments made by the operator, and model calls. A model-call entry holds the time and the amount spent, never the content.
- Preferences.Interface language and which email alerts you have switched on.
- Invites.Your invite code, the account that invited you, and the accounts you invited, with the time and whether the reward was paid.
- Survey transactions.For each survey the partner reports: its transaction id, your account id, the amount, and whether it was reversed. Kept for 30 days so that repeated notices are ignored and reversals can be matched to the original credit.
- Conversations.Every conversation you have on the chat page is saved to your account: the messages you sent, the replies, the model used and the time. Up to 50 conversations are kept per account. You can rename or delete any of them, or delete all of them, on the chat page; deletion takes effect immediately. They are not used to train models and are not shown to anyone else. What the provider that produced a reply retains is described under “Your prompts”.
- Shared conversations.When you press Share on the chat page, the messages you chose are copied to our server under a random link and can be read by anyone who has that link. A share is deleted after 90 days, or earlier if you delete it from the console. To count distinct visitors for the share reward, each share keeps for the current day a hash of every visitor's network address and browser identifier; the hashes are discarded when the day ends.
- Suspension.If the operator suspends an account, the reason is recorded with the account.
Accounts created before 2026-08-31, when signing in became mandatory, may hold no email address at all; such an account is identified only by its key.
Who can see it
The operator can view the records above, including email addresses, in an administration panel, can adjust balances, suspend accounts and download a backup of the data. The data lives on our hosting provider's persistent storage. The hosting provider (Railway) and the network provider in front of the site (Cloudflare) keep ordinary request logs, including network addresses, under their own retention rules.
What is stored in your browser
- Your key,in this browser's local storage. It leaves your device only inside the requests you make to the API.
- Which conversation is openon the chat page, and any message you have typed but not sent. The conversations themselves are stored on our server with your account, as described above.
- Display settings:interface language, colour scheme, and whether the opening animation has already played.
- Cookies.A sign-in cookie valid for 30 days; a short-lived anti-forgery cookie during Google sign-in; when you arrive through an invite link, a cookie holding the invite code until you sign in; and, in some sign-in flows, a cookie remembering which page to return to.
Clearing this site’s data removes all of the above from the device. Your balance is not affected: sign in again and the console issues a new key on the same account.
Your prompts
Requests you send to the API, and messages you send on the chat page, are forwarded to the model provider that answers them, and the reply is returned to you. When you use the arena on the chat page, the same message is sent to each model you selected, so each of those providers receives it. We do not store the content of prompts or replies; we record only the token count, because that is what is deducted. The model provider has its own retention policy, which we do not control.
Emails we send
Sign-in codes, and, if you leave the alert switched on, one notice per day when your balance drops below 1000 meo. Emails are delivered through a third-party email service (Resend), which processes the recipient address and message for that purpose.
Surveys
Surveys are provided by CPX Research, operated by Make Opinion GmbH, Berlin, Germany. When you open the survey wall, the only thing we send to the partner is your account id. Inside the wall, the partner asks its own profiling questions, sets its own cookies and sees your network address and device details; all of that is governed by the partner’s own privacy policy, not by this one. What the partner sends back to us is a transaction id, an amount, and whether the survey was completed or reversed, tied to your account id. We never receive your answers.
Advertising
Google’s advertising script is loaded on our pages. It is required for Google to verify the site and, if display advertising is switched on, to serve ads. Rewarded ads are not offered. Third-party vendors, including Google, may use cookies to serve ads based on your prior visits to this and other websites. You can opt out of personalised advertising at google.com/settings/ads, opt out of a wider list of vendors at aboutads.info/choices, and read how Google handles data from sites that use its services at policies.google.com/technologies/partner-sites.
What we do not do
We run no analytics scripts and do no cross-site tracking of our own. We do not sell or rent any of the data above. We do not receive your survey answers, and we do not store what you say to the models.
Exporting and deleting your data
The Data tab of the account page downloads everything the server holds about your account as a JSON file. To delete the account, write to the address below from the email address the account is signed in with; the account, its keys, activity log, conversations and shared conversations are then removed. Survey transaction records, which contain only the account id and an amount, expire on their own after 30 days.
Contact
the address on the contact page