OneHush Privacy

How OneHush handles information across the public website and applicable OneHush services.

Last updated: August 26, 2026

Operator

OneHush is developed and operated by Shenzhen Guaike Technology Co., Ltd., based in Shenzhen, Guangdong, China.

Scope

This policy applies to the OneHush public website and applicable OneHush services described below. Some product features remain part of a controlled Alpha or under development and may not be generally available.

Website information

Normal technical requests to the public website may result in limited server and network information being processed as needed for site delivery, reliability, abuse prevention, and security. The public website does not use advertising trackers or behavioral advertising analytics. It uses Cloudflare Web Analytics for privacy-oriented website performance and aggregate usage measurement as described below.

Data we handle

The controlled Alpha may process account information, settings, consent records, journal Moments, reflections, Talk messages, Weekly Mosaics, and operational security records.

User-controlled Memory

Long-term Memory is user controlled. A proposed Memory is not active until the user approves it, and users can edit, archive, exclude, or delete Memory records.

AI processing

AI features process only the authorized, bounded context selected for that feature. AI features may remain disabled during Alpha testing, and provider handling will be described before broader availability.

Analytics and diagnostics

The public OneHush website currently uses Cloudflare Web Analytics to measure aggregate website usage and performance, including page-load and Core Web Vitals information. Cloudflare describes Web Analytics as privacy-first real-user monitoring. According to Cloudflare, its Web Analytics usage measurement does not use cookies or localStorage, does not fingerprint individual visitors for usage metrics, and does not collect or use visitors' personal data.

Product analytics and diagnostic telemetry inside the OneHush product remain currently disabled. Product analytics or diagnostics may be enabled later only after disclosure and authorization consistent with existing OneHush governance; both require a separate decision. Consent settings for product analytics and diagnostic telemetry remain available in the app.

Operational security records and error information needed to keep the service running and investigate incidents are separate from disabled product analytics and diagnostic telemetry.

Service providers

OneHush may rely on service providers to process limited data needed to provide the service, including authentication, hosting, database and storage, AI processing when authorized and enabled, operational security, and email or support delivery where applicable. A provider receives only the information needed for the enabled service and subject to the applicable configuration and agreement.

Known categories include Supabase (authentication, database and storage), Cloudflare (hosting, delivery, security, and privacy-oriented Web Analytics and performance measurement for the public website), and an OpenAI-compatible provider integration that remains feature-flag disabled unless separately authorized. GitHub is development infrastructure and is not assumed to be a user-data processor.

Providers do not receive all user content by default, and no provider is authorized to use OneHush user content for training unless separately disclosed and authorized.

Children and age requirements

OneHush is not directed to children. Users must meet the minimum age required by the applicable service terms and local law. OneHush does not knowingly invite children to create Alpha accounts.

Security and limitations

OneHush uses reasonable technical and organizational safeguards appropriate to a controlled Alpha. No system can guarantee absolute security. Users should protect their account credentials and not share passwords or authentication codes.

Security incidents or concerns may be reported through [email protected] or [email protected].

Retention and deletion

Users can delete individual content and Memory records, request a protected data export, and request account deletion after recent authentication. Data may be retained while needed to provide the service, protect security, process deletion requests and meet legitimate legal or operational obligations. Retention details remain under review for the Alpha.

Users may request account deletion through the app or through the Request account deletion page. The public page allows users who cannot access the app to request deletion without signing in.

Contact

Privacy questions may be sent to [email protected] or [email protected].

Operator: Shenzhen Guaike Technology Co., Ltd. · Shenzhen, Guangdong, China