This page is under legal review. It describes how Omniscio works today and we intend to stand behind it, but the wording is not final and may change. If anything here matters to a decision you are making, please email legal@omniscio.com and we will confirm it in writing.
Omniscio — Cookie Notice
Effective date: 2026-08-20 Last updated: 2026-08-20
Key terms at a glance
Plain-English summary — not a substitute for the full Cookie Notice. This box is a quick, friendly overview of the points people ask about most. It is not legal language and does not replace the numbered sections below, which are the Notice that actually applies. If anything here seems to differ from those sections, the full sections control.
- The app itself barely uses cookies. It sets two strictly-necessary cookies for the optional web-access feature —
amc_web_tokento keep your paired phone or browser signed in, andamc_device_id, a long-lived random id so the App can recognise that device. No tracking, analytics, or advertising cookies. (§3) - The marketing website uses Google Analytics.
omniscio.comloads Google Analytics (via Google Tag Manager) to understand site traffic, and Google sets its own cookies there. (§4) - That analytics counts as a "share." Google Analytics ad-personalization is on, which California law treats as a "share" — opt out with the "Do Not Sell or Share My Personal Information" link in the site footer, or with Global Privacy Control. (§4, §7)
- Nothing is set on these pages until you accept. These legal pages are part of
docs.omniscio.comand carry the same analytics tag as the rest of it — but Google Consent Mode holds analytics and advertising storage at denied on every page load, so no analytics cookie is set until you press Accept, and Decline or Global Privacy Control keeps it that way.shares.omniscio.comloads no analytics at all. These pages also load two web fonts from outside providers, which — like any image or font a page loads — lets those providers see your IP address. (§4, §5) - Marketing emails have a tracking pixel. Our onboarding and marketing emails include a standard open- and click-tracking pixel (via Resend); block it by turning off remote images, and every one has an unsubscribe link. (§6)
- No creepy tech. We don't use Flash cookies, ad SDKs, or session-replay/screen-recording tools. (§6)
- How to stay in control. Manage or clear cookies in your browser, install Google's analytics opt-out, or use the Do-Not-Sell-or-Share link and GPC — we honor GPC. (§7)
1. About this notice
This Cookie Notice explains how Omniscio LLC ("Omniscio," "the Company," "we," "us," or "our"), a North Carolina limited liability company, uses cookies and similar technologies. It covers:
- our marketing website (
omniscio.com) and our documentation site (docs.omniscio.com); - our web-Shares surface at
shares.omniscio.com, where you can view artifacts shared from the App; - the mobile-web access surface for pairing a phone or browser to the App; and
- the Omniscio desktop application (the "App")
— together, the "Services." It supplements, and should be read with, our Privacy Policy. Where this notice and the Privacy Policy describe the same cookie, the descriptions are meant to be consistent.
2. What cookies and local storage are
Cookies are small text files placed on your computer or mobile device when you visit a website or use a connected app. They serve different purposes — for example, keeping you signed in, remembering your preferences, letting you move between pages efficiently, and helping the operator understand how a site is used.
Local storage and session storage are related browser technologies that let a site store data in your browser, similar to cookies but typically holding more data.
Session vs. persistent. A session cookie expires when you close your browser; a persistent cookie stays on your device until it expires or you delete it.
First-party vs. third-party. A first-party cookie is set by us (or by the App running on your own machine) and read only by us. A third-party cookie is set by an outside service loaded into a page — for example an analytics or advertising provider — and can be read by that outside party. As described below, the App itself sets only first-party, strictly-necessary cookies, while our marketing website loads Google Analytics (a third-party analytics tool).
3. The cookies the App sets (strictly necessary)
When you use the optional web-access feature — pairing a phone or browser to the App over your local network (the same surface as the mobile-web access above) — the App's local server sets two strictly-necessary functional cookies. Both are first-party and set only by that local server.
a) Sign-in cookie
- Name:
amc_web_token - Type: first-party; strictly necessary / essential; persistent
- Attributes:
HttpOnly,SameSite=Lax,Max-Ageof 30 days - Duration: persistent — up to 30 days, and each visit slides that window forward; cleared when you sign out (or any time from your browser's cookie settings)
- Purpose: keeps your paired browser signed in across page loads
- What it holds: your session access token — not a tracking, analytics, advertising, or cross-site identifier
b) Device-recognition cookie
- Name:
amc_device_id - Type: first-party; strictly necessary / essential; persistent
- Attributes:
HttpOnly,SameSite=Lax,Max-Ageof 400 days (the browser-enforced maximum) - Duration: up to 400 days, so a device stays recognised across sign-ins and idle gaps — you can clear it at any time (Section 7)
- Purpose: lets the App tell your paired devices apart, so it can show you which devices are paired and let you sign one out. It is server-assigned: the App mints a random identifier when the cookie is absent, so a device that has never paired with your App reads as a new device
- What it holds: a random identifier with no meaning outside your own App — not a tracking, analytics, advertising, or cross-site identifier, and it is never shared with a third party
Because both are strictly necessary to deliver a feature you have chosen to use, they are set as soon as you sign in to that feature, and they are exempt from cookie-consent requirements. The App itself sets no advertising or third-party tracking cookies.
4. Cookie categories
| Category | Used? | Description | Details / who serves them |
|---|---|---|---|
| Strictly necessary / essential | Yes | Required to operate a feature you use; cannot be switched off. | amc_web_token (persistent, up to 30 days) and amc_device_id (persistent, up to 400 days) — both first-party, set by the App's web-access feature (Section 3). |
| Analytics | Yes — on our websites, only after you accept | Help us understand how our websites are used (page views, traffic sources, aggregate feature interest). | Google Analytics, loaded via Google Tag Manager (container GTM-TFQCQH9S) on every page of omniscio.com and docs.omniscio.com, these legal pages included. Google sets its own third-party cookies (for example _ga, _ga_*) — but only once you Accept on the consent banner; until then Google Consent Mode holds analytics and ad storage at denied, and Global Privacy Control keeps them denied. Not present on shares.omniscio.com or in the App. (These pages also load Google Fonts, a different Google service that sets no cookie and does no analytics; see the web-fonts row below.) |
| Advertising / remarketing | Yes — via Google Analytics ("Google signals") | Used to build interest profiles or to show/measure ads across sites. | Google Analytics ads-personalization ("Google signals") is enabled, so GA4 sets advertising/remarketing cookies via doubleclick.net and can use your activity for remarketing. Under California law this is a "share." Opt out with the "Do Not Sell or Share My Personal Information" link in our website footer, Global Privacy Control, or the controls in Section 7. |
| Functional (preferences) | Not separately | Remember preferences such as theme or language. | None confirmed beyond essential session state. |
| Social media | No | Social login / sharing widgets. | We do not embed social-media widgets that set third-party cookies. |
| Web fonts (no cookies) | Yes — on our website and these legal pages | Load the typefaces the pages are set in. | Fontshare (Indian Type Foundry, api.fontshare.com) for our brand typeface and Google Fonts (fonts.googleapis.com / fonts.gstatic.com) for the body typeface. Neither sets a cookie or tracks you, but because your browser fetches the files directly, each provider receives your IP address, browser user-agent, and the page you were on. See Section 5. |
5. Third-party recipients and international transfers
Our marketing website loads Google Tag Manager and Google Analytics, so Google receives the information those tools collect (such as your IP address, the pages you view, and a randomly-generated analytics identifier) and processes it under Google's own terms as an independent third party. Google is a US-based provider that may process this data in the United States or other countries.
The App's amc_web_token and amc_device_id cookies are first-party and are shared with no third party. shares.omniscio.com loads no third-party cookie technology. These legal pages carry the same consent-gated analytics as the rest of our websites, so Google receives nothing from them unless you have accepted.
Web fonts. Every page on this site — including this notice, the Privacy Policy, and the Subprocessors page — loads two typefaces from outside providers: Fontshare (Indian Type Foundry, api.fontshare.com) and Google Fonts (fonts.googleapis.com, fonts.gstatic.com). Your browser requests those files directly, so each provider receives your IP address, your browser's user-agent, and the page you were viewing, and processes it under its own terms. Neither sets a cookie, stores anything on your device, or tracks you across sites. Fontshare is operated from India and Google Fonts is a global Google service, so these requests leave the United States. Blocking third-party requests in your browser stops both; the pages remain fully readable in a fallback typeface.
6. Other technologies
- Local / session storage (browser web storage). Our web surfaces and the paired web-access UI may use browser local or session storage to hold interface state (for example, the signed-in session or view preferences) for the strictly-necessary purposes described above. You can clear browser web storage through your browser's settings.
- Web beacons / pixel tags. We do not use web beacons or tracking pixels in our own web pages for cross-site tracking. Our marketing and onboarding emails do include a standard open- and click-tracking pixel, served by our email provider Resend (resend.com), so we can measure whether an activation email was opened and whether its links were clicked. This is first-party email analytics (not cross-site advertising); you can block it by turning off remote-image loading in your email client, and every marketing email includes an unsubscribe link.
- Flash LSOs, mobile-ad SDKs, and session-replay tools. We do not use Flash local shared objects, interest-based-advertising SDKs, or session-replay/DVR technologies.
7. How you can control cookies
Strictly-necessary cookies. The amc_web_token cookie is required to keep you signed in to the web-access feature; if you block it, that feature will not work. You can end the session by signing out and clear the cookie through your browser's settings. The amc_device_id cookie is persistent (up to 400 days) — clearing it through your browser's settings simply makes that browser look like a new device to the App the next time you pair it, and the App mints a fresh random id.
Browser settings. Most browsers let you see, manage, block, and delete cookies and clear local storage (usually under Settings → Privacy). Blocking cookies may mean you need to sign in to the web-access feature again.
Google Analytics opt-out. You can opt out of Google Analytics across all websites by installing Google's opt-out browser add-on at https://tools.google.com/dlpage/gaoptout, or by blocking analytics/third-party cookies in your browser.
"Do Not Sell or Share My Personal Information." Because we enable Google Analytics ads-personalization (a "share" under California law), we provide a "Do Not Sell or Share My Personal Information" link in our website footer. Clicking it opts your browser out of the analytics/advertising sharing — we disable Google Analytics' advertising features for that browser (stored locally in your browser).
Opt-out preference signals (Global Privacy Control). We honor recognized browser opt-out signals such as Global Privacy Control (GPC) as a valid request to opt out of the sale or sharing of information collected through cookies — when we detect a GPC signal on our website, we disable the Google Analytics advertising features for that browser. We do not sell your personal information for money.
Consent gate. Non-essential cookies (Google Analytics and any advertising or remarketing tags) are gated behind your prior consent using Google Consent Mode: analytics and ad storage default to denied on every page load and are only granted after you press Accept on the banner. Press Decline, turn on Global Privacy Control, or use the "Do Not Sell or Share My Personal Information" link and they stay denied. Your choice is remembered in your browser and applies until you clear it.
8. Relationship to our Privacy Policy
For more about how we collect, use, and share information — including your privacy rights and how to exercise them — see our Privacy Policy, which is the controlling description of our data practices; this notice adds cookie-specific detail. (Note: the Privacy Policy's statement that the App sets no tracking cookies remains accurate; this notice discloses the separate use of Google Analytics on the marketing website.)
9. Changes to this notice
We may update this Cookie Notice from time to time — for example, if we add or remove a cookie or a web-surface technology. Material changes are indicated by the "Last updated" date above and, where appropriate, additional notice.
10. Contact
Questions about this Cookie Notice? Contact us at legal@omniscio.com, Omniscio LLC, 5301 Terminal St, Charlotte, NC 28208.