OmxusPrivacy & Terms
Contents

Omxus Technologies

Signing in takes a few pieces of web technology. Here's each one Omxus uses, what it's for, and what it isn't for.

None of them is used for advertising, and none follows you from site to site. For everything we store, read What Omxus stores about you.

Last updated 17 September 2026

Cookies

A cookie is a small piece of data a website asks your browser to keep and send back on later visits.

Omxus uses one cookie, on the Omxus sign-in page at auth.omxus.com. It remembers a recent sign-in, so the next site you visit can offer Choose an account instead of asking you to type everything again.

CookieWhat it doesHow long
Omxus sign-in, on auth.omxus.comRemembers a recent sign-in. Only auth.omxus.com can read it, scripts on the page can't, and it's only sent over secure connections.Up to 30 days. It ends when you sign out, change your password, or sign out everywhere.

Help, Privacy and Terms set no cookies of their own. Omxus uses no advertising or analytics cookies, and no cookies from other companies.

Browser storage

Browser storage is space a website can use in your browser. Each website's storage belongs to that website's address, and other sites can't read it.

When a site shows the Omxus sign-in on its own page, it keeps your sign-in in its own browser storage. Help does the same when you sign in to the Community.

What's keptWhat it's forHow long
A sign-in keyShows the site you're signed in, each time it asks Omxus for something.15 minutes, then it's renewed
A renewal keyGets a fresh sign-in key without asking you to sign in again. Each renewal replaces it.Up to 30 days of use, 90 days at most from when you signed in
When the sign-in key expiresTells the page when to renew.As long as the keys

Signing out removes all three. If an old renewal key is ever used a second time, which can mean it was copied, Omxus ends that sign-in on every device that shared it.

Passkeys

A passkey lets you sign in with the fingerprint, face or PIN you use to unlock your device.

Passkeys follow Web Authentication, an open standard from the W3C. When you save one, your device makes a pair of keys for that one website:

  • The private key stays on your device, or in your password manager if it syncs passkeys. It's unlocked with your fingerprint, face or PIN, and Omxus never sees it.
  • The public key is sent to Omxus. It can check a sign-in, but it can't be used to sign in.

With the public key, Omxus keeps which site the passkey is for, when you saved it and last used it, and whether it's backed up. Omxus asks your device to confirm it's you each time, not just that the device is present.

Important

A passkey only works on the website it was made for. A fake sign-in page gets nothing from it, which is why passkeys are the strongest way to sign in. Learn how to add one.

The per-site key

An optional way in with nothing to reset: your name, your date of birth and your secret words.

When you sign in this way, your device mixes the three things together into a private key. The key never leaves your device, and neither do your name, date of birth or words.

  1. Your device makes a different key for each site, from the same three things.
  2. It signs a one-time challenge from Omxus with that site's key.
  3. Omxus receives only the signed proof and the public address for that site's key.

Because every site gets a different key, two sites can't match you up by it. Nobody can reset the three things for you, and that includes Omxus. Learn more.

Private IDs for sites

Whichever way you sign in, a site that uses the Omxus sign-in page gets an ID for you made only for that site. Omxus makes it from your account, the site's web address and a secret only Omxus holds. Learn how private IDs work.

Security checks

A few checks keep accounts safe without learning more about you.

Limits on attempts

Omxus counts recent attempts from a network address, an account or a network, to slow down and stop guessing. Network addresses are shortened before they're stored. The Help contact form, Community and assistant count requests the same way, using a one-way fingerprint of your network address instead of the address itself. Learn more.

The breached password check

When you choose a new password, your browser sends Have I Been Pwned a small part of a scrambled fingerprint of it, and checks the answer itself. Your password never leaves your device. Learn more.

The person check on the contact form

The Help contact form uses Cloudflare Turnstile to check that a person, not an automated script, is sending the message. To do that, Cloudflare processes technical details about your browser and connection. Turnstile isn't used anywhere else on Help, Privacy or Terms.

Ask Omxus Help

The Help assistant answers from Help articles, using Cloudflare Workers AI.

When you ask a question, Help finds the articles that match it and sends your question and those articles to an AI model that runs on Cloudflare Workers AI. The answer links the articles it used.

  • Help doesn't store your questions.
  • The assistant can't see or change your account, and it never asks for passwords, codes or secret words.
  • Don't type personal details into it. Use the contact form for anything about your own account.

What Omxus doesn't use

  • No advertising. No ads, no advertising cookies, and no advertising profiles.
  • No analytics or tracking. No analytics scripts, tracking pixels or cross-site identifiers on Help, Privacy, Terms or the sign-in page.
  • No selling. We don't sell personal information.

Things that load from other companies

  • Fonts. These pages and the sign-in screen can load their typeface from Google Fonts, which receives your browser's network address when it does.
  • Cloudflare. Omxus runs on Cloudflare, which delivers every page. Turnstile and Workers AI are Cloudflare services too.
  • Have I Been Pwned. Only for the breached password check, as described above.

Your controls

Questions about these technologies? Read the FAQ, or send a privacy request.