Privacy Policy
Effective date: 24 August 2026
Last updated: 24 August 2026
ONYX ("ONYX", "we", "us") operates the website at https://onyx-crypto.com and the automated trading service available through it (the "Service"). This Privacy Policy explains what information we collect, why we collect it, and what choices you have.
If you do not agree with this policy, please do not use the Service.
1. The most important thing first: we are non-custodial
ONYX never holds, receives, or controls your funds. Your assets remain in your own account at a third-party exchange (currently Toobit and BingX) at all times.
We connect to your exchange account only through an API key with withdrawal permission disabled. A key of this type allows reading balances and placing trades. It does not allow moving assets off the exchange. Our system rejects keys that have withdrawal permission enabled.
We do not collect payment card details, bank account details, or wallet private keys, and we will never ask you for them.
2. Information we collect
2.1 Information you give us
- Email address — collected when you create an account or sign in with Google, so we can identify your account and contact you about the Service.
- Password — if you register with email and password. It is stored only as a salted cryptographic hash, so we cannot read it.
- Google account information — your email address, basic profile information, and your Google account identifier, if you choose "Continue with Google". We request only the
openid,email, andprofilescopes. We do not request access to Gmail, Drive, Contacts, or any other Google data. - Exchange API key and API secret — when you connect an exchange account, and when you register a sub-account key. Used to read your balances and place trades on your instruction. See Section 3.
- Exchange account identifier (UID) — returned by the exchange when you connect a key. Used to link your ONYX account to your exchange account and to verify eligibility.
- Your consent choices — recorded during onboarding, so there is a record of which terms and risk disclosures you agreed to, and when.
2.2 Information we receive from the exchange
When you connect an exchange account, we receive from that exchange:
- your exchange UID;
- the permissions attached to your API key, including whether withdrawal is enabled;
- your referral status — whether your exchange account was created through ONYX;
- your KYC status — whether the exchange has verified your identity. We receive a status only. We do not receive or store your identity documents, government ID numbers, photographs, or address.
2.3 Information generated by using the Service
- Strategies you follow, and when you start or stop them
- Sub-accounts you register
- Orders, fills, positions, margin, and realised and unrealised profit and loss
- Parameters you configure, such as allocation, leverage, stop-loss and take-profit
2.4 Technical information
- IP address, browser type and version, device type, operating system, and referring page
- Pages viewed and general usage patterns, collected through Google Analytics (see Section 6)
- Error and diagnostic logs generated when something fails
3. Exchange API keys — how we handle them
This is the most sensitive information we handle, so we describe it separately.
What we require. We accept only API keys with withdrawal permission disabled. If you submit a key that has withdrawal enabled, we reject it and ask you to create a new one. This is a structural limit: even in the worst case, a key of this type cannot move assets out of your exchange account.
How the key reaches us. Your key and secret are sent from your browser directly to our server over an encrypted connection (HTTPS). Our web application clears them from the browser's memory immediately after transmission and does not write them to browser storage.
Where the key is stored. Keys are stored on our servers in encrypted form and are used only to carry out the trading actions you have instructed.
What you can do. You can revoke an API key at any time from your exchange account. Revoking the key immediately ends our ability to act on that account, without needing our involvement.
4. How we use your information
We use the information described above to:
- create, authenticate, and maintain your account;
- connect your exchange account and confirm that your API key meets our security requirements;
- run the strategies you choose to follow, and place the resulting orders in your account;
- show you your positions, fills, and performance;
- verify eligibility, including referral status and exchange KYC status;
- keep a record of the terms and risk disclosures you agreed to;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- diagnose faults and improve the reliability and usability of the Service;
- comply with legal obligations that apply to us.
We do not sell your personal information. We do not share it with advertisers, and we do not use it for behavioural advertising.
5. Who we share information with
- Toobit, BingX, and any exchange you connect receive API requests carrying your instructions, so that trades can be placed and managed in your own account. Their handling of your data is governed by their own privacy policies.
- Google LLC receives your Google account identifier and email if you use Google sign-in, usage data through Google Analytics, and your IP address when certain fonts are loaded.
- Netlify, Inc. receives technical request data, including your IP address, in order to host and deliver the website.
- Service providers acting on our instructions receive only what is necessary for the task they perform — infrastructure, monitoring, and support.
- Authorities receive only what we are legally required to disclose.
We may also disclose information where necessary to establish, exercise, or defend legal claims, or to protect the rights and safety of our users or the public.
If our business is transferred to another entity, your information may transfer with it. We will notify you before your information becomes subject to a different privacy policy.
6. Cookies and analytics
We use Google Analytics 4 on onyx-crypto.com to understand how the site is used — for example which pages are visited and how visitors arrive. Google Analytics sets cookies in your browser and processes your IP address for this purpose.
Analytics is loaded only on the live domain. It is not loaded on local or preview environments.
Aside from analytics, our web application does not write your data to browser storage — it does not use localStorage, sessionStorage, or its own tracking cookies. Session values exist only in the page's memory and are gone when you close the tab.
You can block or delete cookies through your browser settings, or install the Google Analytics opt-out add-on published by Google at https://tools.google.com/dlpage/gaoptout. Blocking analytics cookies does not affect your ability to use the Service.
We also load certain fonts from Google's font servers for languages that require them. When this happens, your IP address is visible to Google.
7. How long we keep information
We keep information only for as long as we need it for the purposes described in this policy.
- Account information is kept while your account is open, and deleted after you close it, except where we are required to keep records for longer.
- Exchange API keys are deleted when you disconnect the exchange account or close your account. You can also revoke a key yourself at the exchange at any time, which takes effect immediately.
- Trading records — orders, fills, and positions — are kept while your account is open, so that you and we have an accurate history of activity carried out on your instruction.
- Consent records are kept as evidence of the terms you agreed to, for as long as they may be relevant to a legal claim.
- Technical and error logs are kept only as long as needed to diagnose and fix problems, and are then deleted.
- Analytics data is retained according to the settings configured in Google Analytics.
If you want your information deleted, contact us at the address in Section 13.
8. Security
We protect your information with encryption in transit (HTTPS), encryption at rest for sensitive credentials, access controls limiting who can reach production systems, and the structural safeguard described in Section 3 — we only ever hold keys that cannot withdraw funds.
No system is perfectly secure, and we cannot guarantee absolute security. You also play a part: use a strong, unique password, enable two-factor authentication on your exchange account, and never share your API secret with anyone, including anyone claiming to be from ONYX. We will never ask you for your password, your API secret, or a key with withdrawal permission enabled.
9. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct information that is inaccurate or incomplete;
- delete your information, subject to records we are required to keep;
- object to or restrict certain processing;
- receive a copy of information you gave us, in a portable format;
- withdraw consent at any time, where we rely on consent;
- complain to your local data protection authority.
To exercise any of these, contact us at contact@onyx-crypto.com. We will respond within 30 days. We may need to verify your identity before acting on a request.
You can disconnect your exchange account at any time by revoking the API key at the exchange. This takes effect immediately and does not require us to act.
10. International transfers
We operate an internet service. Our servers, and the service providers we rely on, may be located in countries other than the one you live in, and your information may be processed there. Where that happens, we take steps to ensure your information continues to be protected to a standard comparable to that of your home country, and we require our service providers to handle it only on our instructions.
11. Children
The Service is not intended for anyone under 18 years of age, and we do not knowingly collect information from them. If you believe someone under 18 has provided us with personal information, contact us and we will delete it.
12. Changes to this policy
We may update this policy. If a change materially affects how we handle your information, we will notify you before it takes effect — by email, or by a notice on the site. The "Last updated" date at the top always reflects the current version.
13. Contact
ONYX
Email: contact@onyx-crypto.com
If you have a question about this policy, or want to exercise any of the rights in Section 9, that address is the fastest way to reach us.