Ontic Entia · onticentia.ai · Last updated September 12, 2026
Ontic Entia is the umbrella for the software projects of an independent developer, Phanes,
doing business as OnticEntia (the "Operator"). This policy explains what onticentia.ai
(the "Site") collects, why, and who it is shared with. It also applies to every Ontic Entia
sub-project, app, or site that links to it; where a sub-project collects something not
listed here, its own pages say so. Contact:
[email protected].
1. What is collected
Every visitor (no account needed):
Request metadata: IP address, the page or path requested, HTTP method and status, time, browser user-agent string, and preferred language.
Approximate location (country, region, city, and coordinates) as reported by Cloudflare, the network in front of the Site. This is derived from your IP address; the Site does not ask your device for GPS location.
A theme preference cookie if you change the colour theme.
Members (if you create an account):
Username, a salted hash of your password (the password itself is never stored), and an email address if one is required for verification.
Optional profile details you choose to add (bio, avatar, theme).
Everything you post in chat: messages, reactions, threads, and uploaded attachments. Text is extracted from uploaded documents so the AI features can read them when asked.
Web-push subscription endpoints if you enable notifications.
A session cookie that keeps you logged in.
Donors (on this site or any Ontic Entia sub-project site): payments are handled entirely by Stripe under the OnticEntia account. Neither the Site nor any sub-project ever sees or stores your card number. Stripe shares the donation amount, date, and the name and email you entered so the Operator can acknowledge the donation and handle any dispute.
2. How it is used
Running the Site: serving pages, keeping you logged in, delivering chat and notifications.
The visitor globe: the Site shows approximate visitor locations on a public map. Locations are anonymous (no username, IP, or identifier is shown) and are randomly offset at city level before display.
Security and abuse prevention: the Site is also a honeypot. Requests that look like scanning or exploitation attempts (for example requests for common malware paths, or bursts of 404s from one address) are recorded with their IP address and metadata. Addresses that meet the abuse thresholds are blocked at Cloudflare. Because the block is applied at the account level it also prevents access to other sites run by the Operator. Blocks expire on a rolling schedule. Summaries of abusive traffic, including IP addresses, are sent to the Operator via Discord.
AI features: when you invoke the AI (with a command, a trigger word, or by asking it a question) the relevant messages and attachments are sent to the configured model provider. That may be a model hosted on the Operator's own hardware or Google's Gemini API, depending on the current configuration. AI activity is logged for moderation.
Email: verification and account emails are sent via an SMTP provider (currently Google Workspace/Gmail).
3. Cookies
Cookie
Purpose
Lifetime
session
Keeps a member logged in (signed; contains no password).
Until logout or expiry
oe_theme
Remembers the colour theme you picked.
1 year
release access
Remembers that you entered the password for a protected download.
12 hours
The Site does not use advertising or cross-site tracking cookies. Cloudflare may set its own cookies for bot protection; see Cloudflare's privacy policy.
4. Who receives data
Cloudflare (United States): all traffic passes through Cloudflare's network; chat attachments are stored in Cloudflare R2; abusive addresses are blocked via Cloudflare's firewall.
Stripe: donation processing.
Google: Gemini API when it is the selected AI provider; Gmail for outgoing email.
GitHub: public repository data is fetched for project channels. Nothing about you is sent to GitHub.
Other members: your username, profile, and anything you post in a channel are visible to the other members who can see that channel. Your public profile at /u/<username> is visible to anyone.
Data is not sold and is not shared with advertisers. It may be disclosed if required by law or to protect the Site and its users.
5. Retention
Request and probe logs are kept for security analysis and are periodically trimmed; blocked-address records expire on a rolling schedule.
Account data and chat content are kept until you delete them or your account is deleted.
Uploaded attachments that are never posted are removed automatically; posted attachments are kept until deleted.
Stripe retains payment records per its own policy and applicable law.
6. Your choices and rights
You can edit or delete your own messages and profile details from the Site.
You can request a copy of your data, correction, or deletion of your account by emailing [email protected] from the address on your account. Requests are answered within 30 days.
If you believe your address was blocked in error, email the same address with the approximate time and your IP address.
Residents of the EU/UK, California, and other jurisdictions with privacy laws have the rights those laws provide; the contact above is the way to exercise them.
7. Children
The Site is not directed at children under 13 and does not knowingly collect their data. If you believe a child has created an account, contact the Operator and it will be removed.
8. Security
Passwords are hashed with scrypt, sessions are signed, all traffic is served over HTTPS, and login attempts are rate-limited. No system is perfectly secure; use a unique password.
9. Changes
This policy may be updated from time to time. The "last updated" date above shows the current version.