Back to OmnyID

Privacy Policy

Effective date: July 5, 2026

1. What this policy covers

This policy explains how OmnyID handles account information, workspace metadata, billing state, connector configuration, and content processed through the hosted OmnyID service. It applies to the marketing site, hosted homeserver, hosted dashboard, support workflows, and related operational systems.

2. Data we collect

  • Account identity data such as email address, display name, auth provider, and verification state.
  • Workspace and runtime metadata such as agent IDs, thread metadata, plan status, support-access history, and usage counters.
  • Billing data such as Stripe customer/subscription identifiers, plan, status, and billing event history.
  • Connector and integration data needed to operate email, calendar, or model integrations.
  • Operational logs, security events, and limited diagnostic metadata needed to keep the service reliable and secure.

3. How we use data

  • To provide the OmnyID workspace, identity, relay, synchronization, and hosted runtime features.
  • To operate billing, plan enforcement, archive-only mode, support access, and account recovery.
  • To detect abuse, investigate failures, respond to support requests, and improve reliability.
  • To satisfy legal obligations and enforce our Terms of Service.

4. Privacy boundary and hosted operation

OmnyID is designed to minimize unnecessary central access, but hosted operation still involves server-side storage and processing for account, billing, relay, connector, and runtime features. If you choose self-hosted or more local/private deployment paths, your operational boundary changes accordingly. Hosted OmnyID should not be described as a zero-observation service unless the specific deployment and feature path truly support that claim.

5. Third parties and subprocessors

Depending on your enabled features, OmnyID may rely on infrastructure or service providers such as Oracle Cloud, Stripe, email providers, model providers, object storage systems, or authentication providers. We share only the data needed to operate the requested feature.

6. Retention

We retain account, billing, and security records for as long as your account is active and for a limited period afterward where necessary for fraud prevention, dispute handling, backup integrity, or legal compliance. Specific deletion timing is described in the Data Rights & Deletion Policy.

7. Your choices

  • Use the dashboard export flow to download current workspace export data where available.
  • Use the account-deletion flow to request hosted account and hosted runtime deletion.
  • Grant or revoke temporary support access explicitly from the dashboard.
  • Contact [email protected] for privacy or data-rights requests that are not yet self-serve.

8. International users

If you are in the EU, UK, or another jurisdiction with privacy rights, you may request access, correction, deletion, restriction, portability, or objection where applicable. Some rights may be limited by security, fraud-prevention, legal-retention, or technical constraints of the feature you are using.

9. Contact

Privacy and data-rights contact: [email protected]