Email or provider data stays outside world storage.
Privacy by design
Your imagination should not become your identity.
Onlix is built to reduce what the platform can connect, expose or infer about you—not merely to promise discretion in a policy.
The design boundary
Separate what does not need to be connected.
Story, characters, lore and memory use per-world boundaries.
Choose your privacy level
Convenience when you want it. Pseudonymity when you need it.
Google and email sign-in are private, but they are not anonymous. Pseudonymous accounts require no email or external identity provider and use a generated login ID plus recovery material.
The identity service uses the provider subject for sign-in. Profile claims are not copied into worlds.
The normalized address is encrypted inside the separate identity vault.
No email, social profile or identity-provider account is required.
Technical controls
Privacy is a system property.
Server-side, not browser-bound
Inference, retrieval and durable world storage run in Onlix’s cloud. The browser receives only what the current interface needs.
Encrypted world boundaries
Creative records are encrypted by world and kept apart from the identity vault’s keys and lookup material.
Minimized request traces
The application edge strips client-origin identity headers before forwarding requests, and application access logging is disabled.
No discovery layer
No public character marketplace, user profile, follower graph or recommendation feed is required for the product to work.
Short-lived browser authority
Access and CSRF material stay in memory. Refresh authority remains in Secure, HttpOnly, SameSite cookies.
Explicit history
World changes produce versioned records. Branching does not silently destroy alternate timelines.
Plain-language boundary
What this does—and does not—mean.
Encryption and separation reduce linkability and blast radius. They do not make a Google or email account anonymous to its provider, and an operating cloud service still processes the scene context needed to generate a response.
The strongest identity-minimizing path is pseudonymous sign-in. The long-term architecture aims to make operator access to creative plaintext technically exceptional and tightly bounded, not a routine product capability.
Choose pseudonymous sign-inBuild privately