Privacy notes
EONAPP is local-first where practical. Optional paid access uses Dodo Payments hosted checkout and server-verified entitlements. EONAPP does not operate an offerwall, cash referral payout, wallet payment rail, or Cloudflare AI-generation backend.
Last updated: 17 August 2026
Public trust policy
This page follows the public trust policy: verified payment activation, public-proof-only support, local-first privacy, no wallet or chain action, refund exceptions, no investment advice, and no profit or result promises.
- Safe evidence: invoice ID, public transaction hash, quote ID, plan, amount, timestamp, URL, and device context only.
- Never share secrets: seed phrase, private key, full API key, wallet backup file, password, or full card data.
- Manual review: refunds, unsupported crypto transfers, abuse reports, and policy exceptions require human review and may need third-party processor evidence.
Local-first storage
EONAPP stores many preferences, badges, plan status, renewal reminders, result history, generated assets, optional vault profile data, and feature state in your browser. Clearing browser storage may erase local state unless you exported a vault backup or kept independent receipt proof.
Optional Google Login and account metadata
Guest use remains available. When optional Google Login is enabled, EONAPP requests only identity scopes: openid, email, and profile. It does not request Gmail, Drive, Calendar, Contacts, YouTube, or other Google-service access.
Cloudflare may hold a random EON account ID, a protected reference to the Google identity, verified-email and session metadata, plus minimal Dodo customer/subscription references and tier/status fields required for entitlement and billing support. EONAPP does not keep raw Chat, prompts, AI outputs, Vault data, provider keys, files, projects, Realm layouts, City progress, browser storage exports, Google access/refresh tokens, or card data in this identity account service.
Important: Google Login is not a backup and does not create automatic cloud sync. Create and keep your own encrypted backup for local work you cannot lose. You can delete the minimal cloud account/session metadata from Profile; local data remains on your device because it was never uploaded.
Payments and processors
Paid subscriptions use Dodo Payments hosted checkout. Dodo processes payment details under its own terms; EONAPP receives server-side lifecycle events and stores minimal customer/subscription references, plan, status and timestamps needed for entitlement, cancellation, expiry, refund/dispute handling and support. EONAPP does not store full card data.
Wallet and public transaction data
No direct wallet-payment rail is active in this release. Never send a wallet payment because of a message, link, or assumed future feature. Public transaction data should be shared with support only when a separately published payment flow explicitly requests it.
Vault and backups
Your exported vault file is controlled by you. If you encrypt it with a passphrase, remember the passphrase. EONAPP does not keep a server-side recovery copy unless a future account product explicitly says so in its own terms.
AI provider keys
If you enter your own AI API keys, keep them secret. BYOK flows should keep keys in your device vault and send them only to the relevant provider when you initiate a request. Support should only receive masked provider names or test results, not full key values.
Sponsored AI EONBOT route: signed-in free accounts in configured economic-pilot countries may explicitly select EON Sponsored AI · Vexrail. Anonymous visitors cannot use this Vexrail route. The visible conversation messages selected for the request are then sent through EONAPP's same-origin server route to Vexrail for model completion, contextual analytics and, when relevant, contextual sponsored recommendations. For upstream conversation continuity, EONAPP derives a salted pseudonymous identifier from the signed-in account and the browser conversation identifier; the raw EON account ID is not placed in that Vexrail conversation header. The Sponsored AI prompt builder does not inject EONAPP's local memory ledger, recent local activity projection or queued client-only research packet into Vexrail. For abuse control, EONAPP derives short-lived salted rate-limit buckets from the signed-in account and Cloudflare-provided network address; raw network addresses are not stored in the rate-limit ledger. Coarse Cloudflare country/ASN and available bot-risk signals may be used only to decide Sponsored AI eligibility and abuse controls. Vexrail publisher credentials remain server-side. EONAPP also applies a conservative server-side detector that rejects some obvious secrets and sensitive identifiers before Vexrail contact; this is a safety layer, not a guarantee that all sensitive information can be recognized. Because Vexrail processes conversation context, do not use this route for secrets, API keys, sensitive personal data or material that must remain device-local. When EONAPP recognizes a paid, trial or grace account session, the route remains off by default. The user may explicitly select Sponsored AI when the same configured pilot-country policy permits it; that opt-in is limited to the Vexrail chat route and does not turn ordinary display advertising on. Paid Sponsored AI uses separate hourly/daily fair-use limits, while request-count and token-weighted account/country/global safety budgets, network controls and human verification also apply. A browser with no valid account session is denied Sponsored AI and may instead use Guide Mode, Local AI, BYOK or sign in. Local AI stays on the selected local runtime, and BYOK provider credentials are never forwarded to Vexrail. Vexrail's OpenAI-compatible API can return contextual recommendations within ordinary assistant content rather than as a separate ad object. EONAPP therefore identifies the route itself as EON Sponsored AI · Vexrail; a particular answer may or may not contain a contextual recommendation. The upstream model is selected dynamically from Vexrail's currently available catalogue subject to EONAPP's verified economics and quality policy, so model availability can change without requiring a different user-facing route.
Aggregate measurement and local diagnostics
EONAPP can use Google Analytics for aggregate traffic and approved product-route measurement only after you enable it in Profile. The setting is off until you choose it and applies only to the production EONAPP site.
When enabled, EONAPP sends approved logical route IDs only. It does not send chat messages, files, Vault contents, credentials, account identifiers, Google OAuth information, signed Realm shares, referral codes, local model names, raw URLs, URL queries, fragments, or user-entered values to Analytics. Advertising audiences, Google Signals, remarketing, cross-domain linking, and ad personalization are disabled in the bridge.
Redacted local diagnostics are separate, off by default, and stay only in this browser profile. When you explicitly enable them in Profile, limited local route and event summaries exclude chat content, credentials, URL queries, and fragments. You can switch them off or clear them at any time.
This page does not make a legal determination for your jurisdiction. The product default is no aggregate measurement until you actively enable it.
Advertising, Sponsor Transmissions and EONKEYS
Subscriptions remain EONAPP's primary monetization. Signed-in free accounts in configured economic-pilot countries may use the separately labelled Sponsored AI Vexrail route; anonymous visitors may not; paid/trial/grace accounts may use it only by explicit selection. Separately, signed-in free accounts may, after an explicit browser choice, see restrained third-party sponsored cards on selected non-chat surfaces. Standard display advertising is kept separate from private EONBOT conversation content: EONAPP does not intentionally pass Local AI prompts, BYOK credentials, Vault contents or private project content into a standard display-ad request. Third-party advertising providers may still process technical information such as device, network, cookie/consent and advertising-event data under their own notices and the deployed consent configuration.
Sponsor Transmissions are different from banner ads. A voluntary rewarded offer can grant one non-transferable Sponsor EONKEY only after EONAPP creates a signed server session and validates the required ordered VAST playback events, minimum timing, expiry, caps and replay protections for the qualifying completion. This is EONAPP server validation of the rewarded VAST flow, not a claim that ExoClick cryptographically signs each completed view. The exact offered reward, limits and expiry are shown before the user chooses the offer. Ordinary impressions, banner clicks, shares, browser timers and unsanctioned client-only callbacks never mint Sponsor EONKEYS. Sponsor offers are optional, may have no fill, and are never required for normal EON City/world progression.
ExoClick is the approved ordinary-display provider for selected EONAPP content surfaces when enabled. EONAPP requests SFW inventory and keeps adult/explicit, popunder, SmartLink, Social Bar, push-notification and forced-interstitial formats disabled. Google AdSense remains verification-only until site approval, policy-safe placements and the required consent/CMP controls are certified. Sponsor Terminal video is a separate voluntary rewarded flow. When its rewarded runtime is configured, EONAPP can grant exactly one consumable Sponsor EONKEY after the signed server session validates the required VAST completion sequence; unavailable, skipped, early, duplicate or replayed sessions grant nothing.
You can allow or disable standard sponsored cards in Profile. Paid subscription accounts receive no ordinary display advertising and are not automatically routed to sponsored Vexrail. They may explicitly select Sponsored AI when the same configured pilot-country policy permits it without changing ordinary-ad eligibility. Voluntary rewarded Sponsor Transmissions are a separate opt-in system and can remain available to free and paid signed-in accounts when a verified provider has inventory.
Cookies, consent and advertising storage
EONAPP keeps essential session/security storage separate from optional measurement and advertising choices. Standard third-party display scripts are not intentionally mounted by EONAPP on the selected free-account surfaces until this browser records an explicit sponsored-card choice. You can change that choice in Profile. Disabling optional sponsored cards does not remove ordinary Free access, Local AI or BYOK access.
Advertising providers can use cookies, local storage, device/network identifiers or similar technologies where their approved configuration and applicable law permit. Provider availability, geography and consent requirements can differ. Google display advertising remains disabled until EONAPP has a policy-safe placement and the required certified consent/CMP configuration for the relevant region. The deployed consent authority must take precedence over a provider's fill opportunity.
Rewarded Sponsor Transmissions are separately opt-in per offer. Starting one does not constitute consent to unrelated standard display placements. A declined, skipped or unavailable Sponsor Transmission does not reduce normal product or world progression.
Signed referral and Realm links
Public eon2 referral and eon3 Realm links carry signed public metadata and a fresh cryptographic share ID. They contain no wallet secrets, password, payment request, payout claim or browser-granted reward value. A signed referral identifier may be used for later server-side attribution, but clicks or shares alone never grant EONKEYS. Do not put real names, private notes, secrets, or sensitive details into a public label or handle.
Operator, supplier and data-controller record
Checking the deployed operator configuration…
- Legal operator/supplier
- Trading name
- Business address
- Country
- Support contact
- Privacy contact
- Security contact
- Governing law
- Venue
Paid launch remains blocked if this deployment does not expose a complete, owner- and counsel-approved record.
Purposes and legal bases
EONAPP processes only the data required for the selected function: identity/session security, subscription and transaction administration, referral/Sponsor-EONKEY integrity, optional advertising and consent controls, private support cases, security/abuse prevention and legal compliance. Depending on the deployed operator jurisdiction and the request, the legal basis may be contract performance, steps requested before contract, consent, legitimate interests in security and service integrity, or compliance with a legal obligation. The deployed operator record and reviewed policy determine the applicable basis.
Data inventory, retention and deletion
- Device-owned work: Chat, Projects, Library, Vault, local AI settings, Creator media and City progress normally remain in browser storage until the user exports or deletes them.
- Identity/session: minimal account and session records are retained only for account access and security, then deleted or expired according to the identity schema.
- Billing/referral: provider references, lifecycle events, commands, entitlements and required accounting/anti-fraud records follow their declared retention and legal obligations.
- Support/security: redacted case facts, status, owner role and public response are retained only for case handling, audit, defence and required security/legal follow-up.
“Delete account” cannot truthfully promise immediate deletion of records that must be retained by law or a payment provider. The response must identify what was deleted, what remains locally, and what is retained with its reason.
International transfers and subprocessors
Google may process identity authentication; Dodo Payments processes hosted checkout, payment and customer-portal activity; Vexrail processes conversation context only when an eligible user explicitly selects EON Sponsored AI · Vexrail; paid/trial/grace accounts are off by default and require explicit selection; enabled display/rewarded advertising providers process only the data involved in their approved advertising flow and consent state; and a user-selected BYOK AI provider processes only requests the user explicitly sends to it. Cloudflare provides hosting, security and D1 infrastructure where configured. Local AI and other browser-local work are not sent to Vexrail merely because they exist on the device. Transfer safeguards and the current subprocessor register require owner/counsel verification before paid launch.
Your privacy rights
Subject to applicable law, a person may request access, export, correction, restriction, objection or deletion through a private privacy-rights case. A real case ID is issued; the request is reviewed rather than decided by browser state. Identity verification must be proportionate and must not require provider keys, recovery phrases, full card data or private workspace content.
Children
EONAPP is not directed to children who cannot lawfully consent to the relevant digital service or data processing in their jurisdiction. Paid access and account use must follow the age and parental-authorisation rules that apply to the deployed operator. The operator must publish a counsel-reviewed minimum-age rule before public paid launch.