Data Protection & Privacy Architecture

Privacy Policy

Last Updated: August 27, 2026•GDPR & CCPA Compliant•View Terms of Service ➜
Our Privacy Commitment to Creators

At OneBio.lol ("OneBio", "we", "us", "our"), we believe privacy is a fundamental human right. We do not sell your personal data to data brokers or advertisers, we do not track you across unrelated websites, and we enforce strong cryptographic safeguards across our edge database and Cloudflare network.

01.Privacy Policy

This Privacy Policy explains how OneBio collects, processes, stores, and protects personal information when you use our website at onebio.lol, creator dashboards, APIs, edge rendering services, and mobile-optimized link pages.

By accessing or using our Service, you acknowledge the data handling practices described in this policy. If you do not agree with our practices, please do not use our Service.

02.Changes To Privacy Policy

We may update this Privacy Policy from time to time to reflect operational, legal, technical, or regulatory changes. When updates are published, we will revise the "Last Updated" date at the top of this page.

For significant modifications affecting your rights, we will provide additional notice through dashboard announcements or email broadcasts to registered account holders.

03.Information We Collect

We collect the minimum information required to deliver high-performance creator services:

A. Account Credentials & Profile Data

When you register, we collect your username handle, email address, salted password hashes (PBKDF2 Web Crypto), display name, bio biography, avatar images, badges, custom links, and background audio files.

B. Connected Social & OAuth Accounts

If you sign in or connect with Google or Discord, we receive your provider user ID, email address, display name, and avatar URL in accordance with the permissions granted.

C. Aggregated Edge Analytics & Telemetry

When visitors view your profile, our edge network records privacy-preserving aggregate metrics: total view counts, link clicks, coarse country/region location (derived via Cloudflare edge headers without storing raw visitor IPs), referrer sources, and browser device type.

04.Cookies

OneBio uses strictly necessary session cookies and cryptographic tokens to maintain your authenticated dashboard login session (onebio_session) and protect against Cross-Site Request Forgery (CSRF).

We do not use third-party tracking cookies or cross-site advertising trackers. Public visitor views on creator bio pages do not require or place tracking cookies on visitors' devices.

05.Cloudflare Turnstile

We use Cloudflare Turnstile bot verification technology to protect our sign-up, login, ticket submission, and password reset forms from automated credential stuffing, spam bots, and distributed brute-force attacks.

Cloudflare Turnstile evaluates non-intrusive browser environment telemetry and telemetry signals to confirm human interaction without requiring interactive CAPTCHA puzzles or selling behavioral data.

06.How We Use Your Information

We process your data for the following essential operational purposes:

  • To host, render, and distribute your creator bio profile at ultra-low latency via Cloudflare edge nodes.
  • To authenticate your login sessions and secure your account settings.
  • To provide you with privacy-first real-time view and click traffic analytics.
  • To manage paid memberships, vanity aliases, and badge activations.
  • To send critical transactional security alerts, verification links, and password resets.
  • To detect and prevent fraudulent activities, illegal content, and abusive behavior.

07.Marketing and Communications

If you opt in to receive news and promotional updates during sign-up or through the Newsletter hub, we may periodically send product announcements, feature upgrades, or community promotions.

You can unsubscribe from non-essential promotional emails at any time by clicking the "Unsubscribe" link in the email footer or adjusting your preferences in Account Settings. Essential transactional notices (such as security alerts and password resets) cannot be opted out of while maintaining an active account.

09.Data Retention and Deletion

We retain personal data only for as long as your account remains active or as needed to provide our services, maintain security audits, or resolve disputes.

When you delete your account via the Settings dashboard, your profile data, uploaded assets (in Cloudflare R2), and links are immediately unrendered and queued for permanent database purging within thirty (30) days.

10.Disclosure of Your Information

We do not sell, rent, monetize, or trade your personal data. We only share information with trusted third parties under strict confidentiality and security terms:

  • Infrastructure Providers: Cloudflare (Edge compute, D1 database, R2 object storage, Turnstile, and CDN caching).
  • Payment Processors: Secure PCI-DSS compliant payment gateways for processing VIP memberships.
  • Legal Authorities: When required by valid subpoenas, court orders, or applicable law enforcement directives.

11.Third-Party Links and Services

Your public OneBio profile may link to external websites, social networks, and streaming services. We are not responsible for the privacy practices, content, or data collection policies of external third-party sites. We encourage you to review their respective privacy policies.

12.Payments and Billing

When you make a purchase on OneBio, your financial credentials (such as credit card numbers or banking information) are collected directly by our payment processor. OneBio does not store or process raw credit card numbers on our servers.

We only retain transaction reference identifiers, billing timestamps, and plan tier statuses to manage your account privileges.

13.International Transfers

Because OneBio operates on a globally distributed edge network (Cloudflare), your data may be transferred to and processed on edge servers located outside of your country or jurisdiction of residence.

We ensure appropriate safeguards (including Standard Contractual Clauses and encrypted edge transmission protocols) are maintained to protect your personal data in accordance with international standards.

14.Security

We implement industry-grade technical and organizational security measures:

  • Transport Layer Security (TLS 1.3 / HTTPS) on all endpoints and edge nodes.
  • PBKDF2 cryptographic password hashing with unique per-user salts.
  • Two-Factor Authentication (TOTP / 2FA) support with cryptographically encrypted secrets.
  • Automated DDoS protection, Web Application Firewalls (WAF), and Bot Challenge verification.
  • Strictly scoped role-based access control (RBAC) protecting internal administrative operations.

15.Data Protection Rights (GDPR & CCPA)

Depending on your location, you hold specific statutory privacy rights:

  • Right to Access: You can request a copy of your personal data stored on our servers.
  • Right to Rectification: You can edit and correct your profile information directly in your Account Settings.
  • Right to Erasure (Right to be Forgotten): You can permanently delete your account and all associated data.
  • Right to Data Portability: You can request an export of your profile links and analytics in machine-readable format.
  • Right to Opt-Out (CCPA): We do not sell personal data.

To exercise any of these rights, contact us at privacy@onebio.lol.

16.Children's Information

MINIMUM AGE REQUIREMENT: 13 YEARS OLD

OneBio is strictly not intended for or directed toward children under the age of thirteen (13). We do not knowingly collect, solicit, or maintain personal information from children under 13. If we discover that an account has been registered by a child under 13 without verified parental consent, we will promptly delete the account and purge all associated records.

17.Contact

If you have any questions, privacy concerns, or requests regarding this Privacy Policy or our data architecture, please contact our Data Protection Officer:

Data Controller: OneBio.lol

Privacy Officer: privacy@onebio.lol

Support Desk: https://onebio.lol/help