Onyx

Privacy

Last updated July 30, 2026.

Onyx uses PostHog Cloud US for website and product analytics. We use this information to understand acquisition, onboarding, reliability, and which product surfaces are useful.

What analytics collects

PostHog begins collecting when an Onyx page loads. It uses its standard persistent cookies and browser storage, processes IP addresses for approximate geolocation, and records full page URLs and referrers. PostHog automatically measures page navigation, clicks and other DOM interactions, performance, heatmaps, and product errors. After sign-in, Onyx identifies you with an internal account ID and sends your email address, display name, account creation time, signup method, and internal-user status. Team and project profiles include their internal IDs, display names, creation times, and selected operational attributes such as license, membership count, and repository access mode.

Official Onyx CLI releases collect one structured outcome event for each eligible user command, starting from the first command. The first eligible interactive command prints a one-time telemetry notice describing collection and how to opt out. The event can include an allowlisted command name, outcome, rounded duration, version, authentication state, stable failure classification, and internal team or project context. Before login the CLI uses a random installation identifier; it does not merge that anonymous history into a later user identity.

Research and operational exclusions

Onyx does not add analytics events to research settlement, reporting, polling, presence, heartbeat, leasing, worker, or webhook hot paths. Structured custom events do not include API keys, credentials, command arguments, environment variables, request or response bodies, source code, diffs, prompts, model output, research descriptions, or raw research metric values. Separately from events, PostHog’s data warehouse periodically syncs selected product database records — including research project, campaign, and experiment records with their descriptions and metric results — for aggregate product analysis. Credentials, API keys, and invitation records are never synced. Supabase remains authoritative for research outcomes. Because PostHog’s standard browser autocapture and replay can observe the rendered page, ordinary visible page text may be present in PostHog even when it is not part of a custom event; the sensitive surfaces described under Session replay are excluded.

Session replay

Session replay for the landing site and authenticated app follows the active PostHog project settings. The initial configuration records all eligible sessions, uses PostHog’s default input masking, and records network timing without request bodies, response bodies, or headers. Console recording is disabled. In the authenticated app, content surfaces are excluded from replay and autocapture before data leaves the browser: source code, diffs, file trees and paths, commit identifiers, and research text such as hypothesis plans, experiment descriptions, and worker progress are never recorded. Ordinary page text, names, and navigation remain visible. Mintlify documentation replay remains disabled by its native integration default.

Error tracking

Browser and eligible server errors may be sent to PostHog with the native error, stack information, route, stable error code, environment, and release metadata. Onyx does not enable PostHog error tracking for CLI or worker stacks.

Choices and retention

Browser collection uses the current PostHog project defaults and does not have an Onyx consent preference. You can restrict or clear cookies and site storage through your browser. CLI analytics can be inspected or changed withonyx telemetry status,onyx telemetry disable, andonyx telemetry enable. The CLI also honorsONYX_TELEMETRY_DISABLED=1 andDO_NOT_TRACK=1. Data retention follows the active PostHog account and project settings.

For access, deletion, or other privacy requests, contact support@onyxresearch.ai.