This page is under legal review. It describes how Omniscio works today and we intend to stand behind it, but the wording is not final and may change. If anything here matters to a decision you are making, please email legal@omniscio.com and we will confirm it in writing.
Omniscio — Privacy Policy
Effective date: 2026-08-20 Last updated: 2026-09-23
Key terms at a glance
Plain-English summary — not a substitute for the full Privacy Policy. This box is a quick, friendly overview of the points people ask about most. It is not legal language and does not replace the numbered sections below, which are the Policy that actually applies. If anything here seems to differ from those sections, the full sections control.
- Local-first by design. Most of your data — your projects, agent sessions, the full text of your conversations, your settings, and any API keys you provide — stays on your own device and is never uploaded to us. (§1, §2)
- Your keys stay yours. API keys and sign-in tokens are encrypted on your device and are never sent to our servers — they're used only to make the requests you ask for. (§3)
- What we do handle in the cloud. A limited set: your account, billing and AI-credit metering, daily usage/spend aggregates, support messages, and — only if you turn them on — team and Shares features. Using the App normally, we do not upload your session history or your project code. (The one exception is a developer tool that is not part of the App you install — see §4.) (§4)
- Diagnostics are always on. Basic reliability and usage telemetry (app version, device info, crash reports, feature counts, and the text of your Settings searches and "Ask Omniscio" help questions) runs with no off switch — this policy is how we keep it honest. (§6)
- We don't sell your data or train on your code. We don't sell your personal information for money, and we never use your prompts, code, or conversations to train our own models. (The one "share": our public websites use Google Analytics, which you can opt out of.) (§7, §8)
- Voice is off by default. No microphone audio leaves your device unless you turn voice on yourself. (§5)
- Personal-development features are sensitive and stay local. If you use AI-coaching, journal, or Life Inventory, those notes and insights live on your device; coaching and journal reflections run on your own Anthropic key, so we never receive that content. (§2, §8)
- Your privacy rights. Depending on your state, you can access, correct, delete, or get a copy of your data and opt out of sharing — email legal@omniscio.com to exercise them. (§8)
- US-only for now; we store your data in the US. The Services are offered only in the United States, and the cloud data above is stored here. A few AI and voice vendors we route content to are outside the US — §4 names them. (§1, §4)
- How long we keep things. Local data stays until you delete it; cloud records like billing, diagnostics, and support have set retention windows. (§9)
- Google data you connect. If you connect your Google account, Omniscio uses that data only for features you can see, keeps it on your device, never uses it to train AI models, and follows Google's Limited Use rules. (§15)
1. Overview
Omniscio (the "App") is a desktop application published by Omniscio LLC ("the Company," "we," "us"), a North Carolina limited liability company. Omniscio helps you run and manage AI coding agents on your own computer.
Omniscio is local-first by design. Most of your data — your projects, agent sessions, the full text of your conversations, local cost tracking, settings, and any API keys you provide — is stored on your own device and is not uploaded to us. A limited, purpose-specific set of data is handled in the cloud to run accounts, billing, support, opt-in-or-default diagnostics, and the optional team features. This policy explains both.
Where you are. The Services are currently offered only in the United States. This policy is written for US users; if we expand to other regions we will provide region-specific terms.
2. Data stored locally on your device
Stored in a local database (mission-control.db, in your OS application-data folder) and an encrypted local config file, and not sent to the Company except as described in Sections 4–6:
- Sessions and conversations — your agent sessions and full message history (prompts, agent responses, system messages, attachments).
- Projects — names and local folder paths.
- Costs and usage (local) — per-session AI cost/token estimates and a local cost log (see Section 6 for what leaves the device).
- Automations, schedules, saved prompts.
- Channels/integrations you connect (e.g., SMS, Slack, Telegram, RSS, webhooks, email) — their message history and config.
- Notes/knowledge, settings, and credentials (Section 3).
- Personal-development data (only if you use those features) — the optional AI-coaching, journal/reflection, and self-assessment ("Life Inventory") features store the notes, ratings, and generated insight/profile text you create. This can include psychological, emotional, and health-adjacent information about you, and is kept locally on your device. The AI-coaching and journal-reflection features additionally send the relevant text to Anthropic to generate insights — on your own Anthropic API key (the same key your coding agent uses; if you have no API key set, those AI features don't run). Life Inventory is computed on your device with no AI call. (See Sections 5 and 8.)
- Dictation (only if you turn on FlowVoice) — your recent dictation history (the transcript and the app or window you dictated into) and the audio of each dictation, kept only until its text is saved. If a dictation could not be transcribed, or had to be recovered from its saved audio, the audio stays on your device so you can transcribe it again — until you delete it, it ages out with your data-retention setting, you sign out, or you erase all local data.
- Local logs — diagnostic logs for troubleshooting; not sent to us unless diagnostics are on (Section 6) or you send a report.
Some operational data also lives outside that folder. If you use the App's built-in developer
tooling (the dev pipeline / cloud test offload — see §4), it writes to a folder called .amc in
your user home directory: branch names, run history, job ledgers, and the App's local access
token. That folder is not inside the application-data folder, so removing one does not remove the
other.
To delete your local data: delete it in the App, remove the App's data folder, and remove the
.amc folder in your home directory if it exists.
3. Credentials and API keys (verified)
- API keys and OAuth tokens you provide are stored locally and encrypted at rest using your OS secure storage (Windows DPAPI / macOS Keychain / Linux libsecret), with an encryption marker on the stored value.
- They are decrypted only in the App's main process to make the requests you direct; they are stripped before reaching the App's interface layer and are not uploaded to the Company's servers.
- BYOK keys are used solely to authenticate the requests you initiate to that provider, and (when you ask the App to validate a key) are sent directly to that provider, never to a Company server.
4. Data we handle in the cloud
When you use features that need our backend (Google Firebase / Google Cloud), we process a limited set of data:
- Account and identity — user ID, email, display name, profile photo URL (the photo is stored as a link, not as image bytes), plan/tier, and (for team features) organization and role. Your display name and photo usually come from the Google or GitHub sign-in you used, and you can change both in Settings.
- Billing and AI-credit metering — a billing/credit record (balance and holds), an append-only usage/metering ledger of AI requests routed through our gateway, a hashed key identifying your gateway access, and a Stripe customer identifier. Card/payment details are handled by Stripe, not stored by us.
- Identified usage and spend aggregates — for signed-in users, we upload daily aggregates of AI spend and usage (e.g., daily spend in USD, sessions started, active minutes, top features), keyed to your account. These are identified, not anonymous. (This corrects any impression that nothing derived from your local cost data leaves the device — the raw local cost log stays local, but these daily aggregates are uploaded.)
- Support and feedback — if you contact support or submit a bug report/feedback, we receive the content plus limited diagnostics; a single bug report may be copied to several processors listed in Section 5.
- Team/collaboration features (enabled by you) — Team Chat messages, reactions, and shared-artifact ("Shares") content and comments are stored in the cloud for real-time collaboration. Comment threads may be readable by other signed-in users of the Service. A shared artifact's visibility can be private, unlisted, or public, and it is worth knowing exactly what each one means:
- We publish what you share as-is. There is no automatic redaction step. Whatever is in the artifact — names, email addresses, file paths — is published exactly as written, so please check it before you share it.
- "Unlisted" means unlisted, not secret. It is not indexed or listed anywhere, but anyone with the link can open it, links get forwarded, and the short link we can generate is short enough that a determined person could find it by guessing. Treat unlisted as "anyone I give this to, and anyone they give it to".
- Public shares can be indexed. A public (or link-previewed) share can be picked up by search engines and cached outside our systems, and a cached copy can outlive the share itself.
- Retention for Shares is in Section 9. If something is sensitive, keep it private or do not share it.
- Inbound email and support storage — if you use agent-email or support chat, inbound email bodies and support/helpdesk conversations are stored server-side (see retention in Section 9).
We do not upload your local session history or project code as part of using the App.
One exception, and it is not part of the App you install. The Company's own repository ships a developer tool ("cloud test offload") that our engineers can run to execute a build or test suite on Company machines instead of their own. When a developer explicitly turns it on, it uploads a bundle of the code in their working folder — including files they have not committed — plus the name and email recorded on each commit, to a Company-owned Google Cloud Storage bucket in the United States, where Company-owned worker machines unpack and run it. Bundles are deleted on a 7-day schedule and run logs on a 14-day one.
This is called out here for completeness and honesty, not because it affects you: the tool lives only in the Company's source repository and is not included in the application you download and install, so no customer installation can reach it. The people whose code and identity it handles are the Company's own contributors, working on the Company's own code.
Where your data is processed (data residency). The cloud data described above is processed and stored in the United States. Our backend — Google Firebase / Firestore / Cloud Storage / Cloud Functions — runs in a US region (us-central1, Iowa), and crash/error reports go to Sentry's US region. Mobile push notifications are delivered through Google Firebase Cloud Messaging (FCM), a global Google service, so notification content (such as a session name or message subject) transfers to Google's infrastructure. If you access the App from outside the US, you understand your data is transferred to and processed in the US. The internal developer tool described in Section 4 is US-only too: its storage bucket and worker machines run in us-central1 (Iowa), so a contributor's code snapshot and the name/email recorded on their commits are processed in the United States.
Some AI vendors are outside the US. Being offered only in the US bounds where our customers are; it does not bound where a vendor is. A small number of the helper-AI and voice vendors in Section 5 process content outside the United States on Company-held keys — most notably CrofAI (China; the automatic backup for our DeepSeek lane), DeepSeek (China), Fish Audio (China-founded; the default read-aloud relay), and the Alibaba-operated model upstream some OpenRouter requests are served by. The published Subprocessors page lists each one under "Where processing happens" with what it receives and when. We do not currently operate EU/UK regions or rely on Standard Contractual Clauses (SCCs) for those transfers.
Cookies (functional only). If you use the optional web-access feature (pairing a phone or browser to the App over your local network), the App's local server sets two strictly-necessary functional cookies. amc_web_token (HttpOnly, SameSite=Lax) keeps your paired browser signed in across page loads — its value is your session access token. amc_device_id (HttpOnly, SameSite=Lax, Max-Age of 400 days) is a persistent, server-assigned random device identifier: the App mints one for a browser that has not paired before, so it can tell your paired devices apart, show you which ones are paired, and let you sign an individual device out. Neither cookie is a tracking, analytics, advertising, or cross-site identifier, so both are exempt from cookie-consent requirements as strictly-necessary cookies (each is set as soon as you sign in to that feature, before any banner), and both are first-party — shared with no third party. Clearing amc_device_id through your browser's settings simply makes that browser look like a new device the next time you pair it. The App sets no advertising or third-party tracking cookies. Our public websites (omniscio.com and docs.omniscio.com) separately use Google Analytics to understand site traffic, behind a consent banner that keeps it off until you accept — including these legal pages, which are served from docs.omniscio.com. No analytics cookie is set on any of them until you accept. See our Cookie Notice for details and opt-out options.
5. Third parties and subprocessors
We use the following. Core services run the Services; optional ones receive data only if you enable the relevant feature.
Core subprocessors
| Provider | Purpose | Data involved |
|---|---|---|
| Anthropic (Claude) | Default AI provider powering agent sessions. The optional personal-development features (AI-coaching, journal reflection) also call Anthropic to generate insights — on your own Anthropic API key (the same key the agent uses), and only if you have one set. | Your prompts, code, file contents, conversation context, and attachments — sent when you run an agent (directly or via our gateway) — plus, for the personal-development features, the coaching/journal text those insight calls process (on your own key). |
| Google — Firebase / Google Cloud | Authentication, database (Firestore), cloud functions, hosting, our AI gateway (Cloud Run), secret storage | Account/identity, billing/metering, aggregates, support, diagnostics, and team data described above. |
| Stripe, Inc. | Payment processing and US sales-tax calculation | Payment method and billing details (held by Stripe); the Company receives a customer identifier and subscription status. |
| Sentry | Application crash/error reporting | Crash/error reports with scrubbed messages (see Section 6). |
| Resend | Transactional email delivery (bug reports, digests, notifications) and product activation / marketing email (the onboarding drip) | The email content the App sends (e.g., your bug report and diagnostics); for activation/marketing messages, your email address and the message content. |
| Cloudflare | Agent-email relay (inbound/outbound) | Email routed through the agent-email feature. |
| AgentMail | Feedback/bug-report intake | Bug-report/feedback content sent to our intake. |
| Groq | Cost-efficient "helper" AI model, routed via our AI gateway — inbound agent-email pre-screening/classification and other built-in helper features (e.g., reply suggestions, short spoken summaries) | Content those helper features process (e.g., inbound email; the message text a suggestion or summary is generated from). |
| OpenRouter, OpenAI, DeepSeek (via our AI gateway) | Cost-efficient "helper" AI models for built-in features — session-title generation, summaries and daily digests, Plain Speak rewrites, contact-name inference, Supermail AI email filtering + "Catch me up" thread summaries, and Inbox Pilot (which reads the recent turns of an agent session to decide whether it needs your attention, and — when you have it drafting replies — writes the suggested reply) | The prompt/message content those helper features process, routed through our gateway on Company-held keys. (OpenRouter is the primary helper provider today; OpenAI and DeepSeek are provisioned in the same gateway.) |
| RunInfra and CrofAI (upstreams serving our DeepSeek lane) | The "DeepSeek" models above are served by RunInfra on a Company-held key. If RunInfra errors, our gateway automatically retries the same request against CrofAI, also on a Company-held key — so a request sent to the DeepSeek lane may be served by either. CrofAI is China-hosted, so a request that fails over to it leaves the United States. | The same prompt/message content the DeepSeek helper lane processes. |
| FlowVoice (Company-hosted dictation server) | OS-wide voice dictation (speech-to-text) on a Company-operated hosted backend — engaged only when you turn on dictation. | Live microphone audio of whatever you dictate into any app, plus the foreground app name and window title (which can itself carry a document or person name, an email subject, or a URL). |
Supermail backend (mailback.jls.dev) |
Company self-hosted backend (US) for the Supermail inbound-email feature and its server-side contact enrichment — engaged only when you use Supermail. | Inbound email content routed to the feature — sender, subject, and body — plus the contact-enrichment lookups performed on the Company backend. |
| LiveKit (real-time call media) — not yet active | In development; not enabled in the current build, so no data reaches LiveKit today. When Team Chat voice/video calls ship, LiveKit will act as the real-time audio/video relay (SFU), engaged only when you start or join a call, with the Company minting a scoped access token on its own LiveKit account (Company-operated, lane-2). LiveKit will be added to the Subprocessors list before that path is ever enabled. | Once enabled: live audio and video of the call participants (including other members on the call) plus call room/token metadata. |
Optional / secondary (only when you enable them)
AI sign-in / OAuth provider — authenticates your Claude/Anthropic account.
Other AI providers you configure (e.g., OpenAI/Codex, Google Gemini, DeepSeek, Moonshot/Kimi, Zhipu/GLM, MiniMax, xAI, OpenRouter, and other coding-agent engines you select) — receive your prompts/context when you use them, on your own API key, under their terms.
Channel integrations you connect — receive data only for the integrations you enable, each a direct connection to your own account. These include Pushbullet (SMS gateway — receives SMS/MMS content and synced contact info), messaging platforms (Slack, Telegram), and meeting, content & automation tools (Granola, Fathom, Canva, Zapier), plus the email/calendar accounts you link.
Board / project-management integrations you connect (e.g., Trello, Jira, Notion, Linear, ClickUp, Airtable, Asana, Monday.com) — when you sync a board, member names/emails and card content are exchanged with that service on your own account/key, under their terms. Monday.com data (including OAuth tokens, board items, and people-column names/emails) is additionally proxied through a Company-operated backend (
amcback.jls.dev).GitHub — if you sign in with GitHub, or connect a repository so the App can push a branch, open a pull request, or read PR/issue activity, that happens on your own GitHub account under GitHub's terms. Pushing a branch or opening a pull request transmits every commit's author and committer name and email address along with the code changes themselves, and GitHub sign-in shares your account identity with us.
Cloud backup you connect (Dropbox, Microsoft OneDrive) — the backup archive is encrypted on your device before upload, so the provider sees ciphertext only; connecting the account separately transmits your account email address and display name to that provider in the clear.
Bank sync (the Coffer feature, via a SimpleFIN bridge) — if you connect a bank, a credentialed request plus your bank account balances and transaction history are exchanged with the SimpleFIN bridge you configure (self-hosted or a third-party-hosted bridge), on your own bridge subscription under its terms.
Contact/company enrichment (only when a contact or company card is enriched) — an email address is sent to Gravatar to resolve a profile image, and a company domain to Clearbit to fetch a logo.
Location search (OpenStreetMap / Nominatim) — if you use the card-location picker (in the project-management feature), your typed place-search queries are sent to the OpenStreetMap Nominatim geocoder (
nominatim.openstreetmap.org), a keyless public endpoint operated by the OpenStreetMap Foundation (EU-hosted). No API key or account identifier is sent.SMS GIF search (Klipy) — if you insert a GIF in the SMS composer, your typed GIF search terms are sent to Klipy; it uses a Company-held default key unless you set your own.
Web-access and data tools (Firecrawl, Apify, X/Twitter) — when you use a built-in web-scraping, data-extraction, or read-only tweet/user-search feature, the URLs, queries, or page content you request are routed through our gateway on Company-held keys.
Decision-model calls (TypeSafe, via our gateway) — the "Jev" decision feature lets an agent ask a typed question and receive a typed answer with a confidence score rather than generated prose. The situation text and the questions submitted are routed through our gateway to TypeSafe on Company-held keys; this is the primary route and the one an ordinary call takes. A second route through OpenRouter, on the same gateway, is used only as a backup when the first is unavailable. Both are Company subprocessors for this content.
Bundled AI providers (OpenAI, Google Gemini, Perplexity) — an off-by-default "bundled API keys" feature lets your agent call these providers through our gateway on Company-held keys. OpenAI is available today; Gemini and Perplexity are pre-integrated but not yet active, and will be moved to the Core list before that path is enabled.
Team-chat voice/video calls (LiveKit) — an in-development feature not yet reachable in shipped builds; when it ships, realtime call audio/video will route through LiveKit Cloud on a Company-minted access token, and LiveKit will be added to the Core list before that path is enabled.
Screen capture & "Snip to Text" — if you use the on-demand snip/OCR feature, the screen region you capture is sent as an image to Anthropic (Claude Vision, for text extraction) and, for an AI-generated snip title, to OpenRouter — only when you explicitly trigger it. An image cannot be automatically redacted, so anything visible in the region you capture (including other people's data) is sent as-is; avoid capturing sensitive on-screen content.
Meeting transcription — if you turn on meeting transcription, audio of the meeting — which can include other participants — is streamed to a speech-to-text provider (e.g., Deepgram) on your own provider key to produce a transcript (in shipped builds; otherwise the feature stays notes-only), and attendee names may be stored in your local notes. You are responsible for any notice or consent your jurisdiction requires from other participants on the call.
Voice features (off by default) — if you turn on voice, speech-to-text streams your microphone audio to the provider you select (Deepgram, ElevenLabs, Groq, or Meta — whose "Muse Voice Transcribe" engine is also reachable through OpenRouter) on your own key; text-to-speech sends the response text to Fish Audio by default through a Company-funded relay, and to Soniox the same way if you select it (both are Company subprocessors for this path), or to xAI Grok / ElevenLabs / Speechify / Pika on your own key.
Voice is OFF by default. Speech-to-text and text-to-speech are turned off out of the box; unless you turn them on in Settings, no microphone audio or voice data leaves your device. If you enable voice, audio and voice data are sent to the providers listed above — which can be sensitive personal information (see Section 8).
Other sites and services. The App, our websites, our emails, and content you view through the Services may contain links to third-party websites, tools, or services we do not operate. This Policy does not apply to those third parties, and we are not responsible for their content, practices, or privacy policies. Review the privacy policy of any third-party site or service before you provide it your information.
6. Diagnostics and product telemetry (always on)
Omniscio collects diagnostic and product-usage data to keep the App reliable. This collection is always on — there is no setting that turns it off. The disclosure here is how we keep it honest, not a promise you can disable it. The one related control is "Auto-Email Crash Reports," which gates only whether a crash report is additionally emailed to us; it does not stop crash capture (Sentry) or usage telemetry.
When it starts. This diagnostic collection begins when the App first launches — before, and independent of, any sign-in or Terms-acceptance step. Some fleet-health signals (for example, an install/first-run event, aggregate error/crash reports, and the diagnostic digests) can be sent before you sign in or accept these terms. Because the collection is mandatory, not consent-based, accepting the Terms and this Policy is how you are informed of it — it is not an on/off choice.
- What we collect: app version, operating system/platform, OS version, CPU architecture and core count, a coarse total-memory figure (rounded to whole gigabytes, never an exact size), feature-usage counts, crash/error reports, and the identified daily spend/usage aggregates described in Section 4. This also includes two typed-text streams — the text you type into Settings search and the questions you ask the in-app help / Ask-Omniscio assistant. Both are scrubbed of credentials and file paths and keyed only to a per-install identifier (never your name, account, or a session). About that identifier: when you are signed in, AI requests routed through our gateway also carry a device identifier so we can spot one machine abusing a free trial. It is a one-way hash and it is not your name, email, or account — but it is generated once per installation and stored on your device, and deleting your account does not by itself delete it. Removing the App's local data (§2) resets it. The Settings-search term is reduced to a short scrubbed snippet. The full text of your Ask-Omniscio help question is collected (scrubbed of credentials and file paths, bounded to about 2,000 characters), so we can understand and fix the problems people are actually having — a help question can therefore include personal details you type into it, so treat it like a support message.
- Reduction and encryption: reports are automatically processed to reduce personal identifiers — we attempt to remove usernames, file paths, and message content, and error messages are truncated. This reduction is best-effort, not a guarantee that every identifier is removed (identifiers embedded in free-text error strings may remain). Our fleet-diagnostic payloads (sent to our diagnostics endpoint) are encrypted on your device before they leave it. Our crash-report and weekly-digest emails are sent over TLS (encrypted in transit) but their bodies are not additionally encrypted; in those emails the subject line carries only a shortened, hashed hostname token, while the full device hostname remains in the email body (so reports from different machines can be told apart).
- What we don't do: we do not read your code or the content of your agent conversations for telemetry, and we do not sell this data.
7. How we use data
To provide, operate, and secure the Services; authenticate you; process payments and operate the AI-credit allowance; prevent abuse/fraud of credits; provide support; diagnose and improve reliability and features; and comply with legal obligations. We do not sell personal information and do not use your prompts, code, or conversations to train the Company's own models.
De-identified and aggregated data. Where we use aggregated or de-identified information, we maintain and use it only in de-identified form and do not attempt to re-identify it, except as permitted by law to test that the de-identification is effective. This paragraph does not describe the identified usage and spend aggregates covered in Section 4: those are uploaded keyed to your account and are personal information, not de-identified data, and they are handled as described in Sections 4, 6 and 9.
Disclosures for legal reasons and business transfers. We may disclose personal information when we reasonably believe it is necessary to: (a) comply with applicable law, regulation, legal process, or an enforceable governmental request; (b) enforce our terms and policies; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of the Company, our users, or the public as required or permitted by law. If the Company is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, personal information may be transferred as part of that transaction; we will require the recipient to honor this Policy or will notify you of any material change to how your information is handled.
8. Your US state privacy rights
Depending on your state of residence, you may have privacy rights under a comprehensive state privacy law — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA), and other states as their laws take effect. Subject to the exceptions in each law, these rights generally include the right to know and access the personal information we hold about you, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the "sale" of personal information, or certain profiling. We do not sell your personal information for money. However, our public websites use Google Analytics with advertising features ("Google signals"), which discloses online identifiers to Google for cross-context behavioral advertising and is therefore treated as a "share" (and, in some states, a "sale") under the CPRA and similar laws. You can opt out at any time using the "Do Not Sell or Share My Personal Information" link in our website footer, by turning on Global Privacy Control (which we honor), or via the controls in our Cookie Notice. No other category of personal information is sold or shared, and none of the data inside the App is shared for advertising.
The California-specific disclosures below (the Notice at Collection and the sensitive-personal-information right to limit) are provided for California residents; the mechanics for exercising your rights, honoring opt-out preference signals, and appeals apply to residents of every state whose law provides them.
Sources of personal information. We collect the categories below from: you (what you type, upload, or connect); your use of the Services (automatically — feature usage, diagnostics, and device and network information); service providers acting on our behalf (for example, our payment processor); and third parties you connect or who contact you through an integration you enable (for example, the senders of messages you receive in a connected channel).
Categories of personal information (Notice at Collection):
| Category | What we collect | Purpose | Disclosed to service providers? | Sold or shared? |
|---|---|---|---|---|
| Identifiers | account ID, email, display name, profile photo URL, IP address, device/install ID | account, login, security, support | Yes | No |
| Commercial information | plan/tier, billing and purchase records | billing, subscription | Yes (Stripe) | No |
| Internet/network activity | feature usage, diagnostics, crash reports | reliability, product improvement | Yes (e.g., Sentry) | No |
| Geolocation (coarse) | region inferred from IP address | sales tax, availability | Yes (Stripe Tax) | No |
| Payment/financial | payment-card details (handled by Stripe; not stored by us). Plus, if you use the Coffer personal-finance feature: structured financial data stored in your local encrypted database — bank balances, credit limits, a dated transaction ledger, and payee names (a SimpleFIN bank sync you connect is user-direct). | payment; personal budgeting | Card details: Stripe. Coffer data: local to your device; SimpleFIN sync user-direct | No |
| Sensitive personal information | Only if you enable voice (off by default): microphone audio / voice recordings sent to your chosen speech provider, and response text sent to the text-to-speech provider. No SSN; your credentials stay on your device. | Provide the voice features you turn on | Yes — to the voice provider you select (and Fish Audio or Soniox, which read aloud through Company-funded relays) | No |
| Sensitive personal information (personal-development features) | If you use the optional AI-coaching, journal/reflection, or self-assessment ("Life Inventory") features: psychological, emotional, and health-adjacent notes, ratings, and generated profile/insight text you create. Stored locally on your device. AI-coaching and journal reflection also send the relevant text to Anthropic on your own API key to generate insights; Life Inventory is computed locally with no AI call. | Provide the personal-development features you use | Anthropic (on your own key), for coaching/journal insight generation only | No |
Sharing for cross-context behavioral advertising. The online identifiers collected by our public websites (such as your IP address and a Google Analytics identifier) are shared with Google for cross-context behavioral advertising through Google Analytics' advertising features — the only "sharing" we do. You can opt out (see the "Do Not Sell or Share My Personal Information" link and Global Privacy Control described below, and our Cookie Notice). No other category in the table above is sold or shared, and nothing inside the App is shared for advertising.
- Sensitive personal information: we collect voice/biometric data only if you turn on voice features (off by default). If you do, you have the CPRA right to limit the use of sensitive personal information — exercise it by turning voice off in Settings (which stops any further voice data) or by emailing legal@omniscio.com. We use voice data solely to provide the voice features you enabled — never to infer characteristics about you, and never sold or shared.
- Personal-development features (AI-coaching, journal, Life Inventory): if you use these optional features, they can hold psychological, emotional, and health-adjacent information you record about yourself. This data is stored locally on your device. The AI-coaching and journal-reflection features additionally send the relevant text to Anthropic on your own Anthropic API key to generate insights (if you have no API key set, those AI features don't run); Life Inventory is computed on your device with no AI call. You can delete this data in each feature's own screen, and the App's "erase all local data" function now removes these personal-development stores as well — including the on-disk AI-coaching files the feature writes under your
~/Claudefolder. Because these features use your own API key, the Company does not receive this data, and we do not use it to train the Company's own models (Anthropic processes it under your own Anthropic account's terms). You have the CPRA right to limit its use — turn the feature off, delete the data, or email legal@omniscio.com. - Screen captures and meeting audio: the optional Snip-to-Text and meeting-transcription features can capture sensitive on-screen content or the voices of other people on a call. They run only when you enable or trigger them, and captured images are sent to an AI provider unredacted (an image cannot be scrubbed).
- How to exercise your rights: email legal@omniscio.com (or use any in-App request tool we provide). We will confirm receipt and verify your request by matching it to the information associated with your account; we may ask for additional information to confirm your identity, which we use only to process the request. We will respond within the time your state's law requires — for California, within 45 days, extendable once by another 45 days when reasonably necessary, with notice. We will not discriminate against you for exercising these rights.
- Authorized agents: you may use an authorized agent to submit a request on your behalf. We will require written proof of the agent's authorization and may still verify your identity directly before acting.
- Right to appeal: if we decline your request and your state's law provides an appeal (for example, Virginia, Colorado, or Connecticut), you may appeal by replying to our decision or emailing legal@omniscio.com with "Appeal" in the subject line. We will respond with our decision and the reasons for it within the period your state's law requires (generally 45–60 days). If we deny your appeal, your state's law may allow you to submit a complaint to your state Attorney General.
Right to opt out of "sharing"; Do Not Sell or Share My Personal Information. Because our public websites use Google Analytics advertising features (a "share" for cross-context behavioral advertising, as described at the top of this Section), you have the right to opt out. To do so, use the "Do Not Sell or Share My Personal Information" link in our website footer, turn on Global Privacy Control, or use the controls in our Cookie Notice. We do not sell your personal information for money.
Opt-out preference signals (Global Privacy Control). Some browsers and extensions can send an opt-out preference signal such as Global Privacy Control (GPC). We honor GPC as a valid request to opt out of the sharing described above — when we detect a GPC signal on our website, we disable the Google Analytics advertising features for that browser.
"Do Not Track." Some browsers offer a "Do Not Track" (DNT) setting. There is no common industry standard for responding to DNT signals, and because we do not track you across third-party websites over time for advertising, we do not currently respond to DNT signals. We set no advertising or cross-site tracking cookies (see Section 4).
California "Shine the Light." California Civil Code § 1798.83 lets California residents request information about personal information disclosed to third parties for those third parties' own direct-marketing use. We do not disclose personal information to third parties for their own direct marketing, so there is nothing to report; you may still contact legal@omniscio.com with questions.
Nevada. Nevada law lets residents submit a request not to sell certain covered information. We do not sell such information, but you may direct a verified request to legal@omniscio.com.
Texas. We do not sell sensitive or biometric personal data for monetary consideration, and Texas residents may exercise the access, correction, deletion, portability, opt-out, and appeal rights described in this Section.
9. Data retention
| Data | Retention |
|---|---|
| Local data (sessions, messages, keys) | On your device until you delete it or remove the App |
| Personal-development data (AI-coaching profile/insights, journal entries, Life-Inventory results) | On your device until you delete it in the feature or run "erase all local data" — not automatically expired (see §8) |
| Account and billing records | Life of your account, then up to 7 years (tax/accounting/legal) |
| Raw diagnostic events | About 180 days |
| Identified usage/spend aggregates | Up to 24 months, then deleted or anonymized |
| Support / helpdesk conversations | About 12 months |
| Inbound agent-email content | About 90 days |
| Search index | About 13 months |
| Shared artifacts ("Shares") and their comments | Until you delete the share. A public share may have been indexed or cached by search engines, and we cannot delete those copies |
| Repository bundles and run logs from the internal developer offload (§4) | 7 days (bundles) / 14 days (run logs), by automatic schedule |
10. Security
We use technical and organizational safeguards: encryption of credentials at rest on your device (OS secure storage), encryption in transit (HTTPS/TLS), encryption of diagnostic payloads before egress, and access controls on our backend. No system is perfectly secure.
At-rest posture for your local data. Your local database (mission-control.db) and any saved user attachments are not application-encrypted by default; they rely on your operating system's full-disk encryption (e.g., BitLocker / FileVault / LUKS) as the compensating control, together with OS file-system permissions. An optional database-encryption feature can be enabled for defense-in-depth. (Credentials and API keys are separately encrypted at rest as described above.)
Breach notification. If a breach affects your personal information, we will notify you and the appropriate authorities without undue delay and within any timeframe required by applicable law. We maintain an internal incident-response process (detect → contain → assess scope → notify affected users and regulators as required → remediate → document). (We deliberately do not commit to a single fixed number of days here, because US state breach-notification deadlines vary; "as required by law" covers the strictest applicable one.)
11. Data-processing addendum (business/team customers)
If you use Omniscio on behalf of an organization and we process personal data on your behalf through the team features, a data-processing addendum (DPA) governs that processing and lists our subprocessors. A DPA is available on request for business/organization customers — contact us at the address in Section 13. We are putting data-processing agreements in place with the subprocessors listed in Section 5: agreements are in effect with our core platform processors (Google Cloud / Firebase, Sentry, and Resend), and we are securing or confirming them for the remaining subprocessors. We maintain an internal data-processing register that records the current DPA status for each subprocessor, and we publish the current list on our Subprocessors page.
12. Children's privacy
The Services are not directed to children under 18, and we do not knowingly collect their data.
13. Contact
Privacy questions or requests: legal@omniscio.com, Omniscio LLC, 5301 Terminal St, Charlotte, NC 28208.
14. Changes
We may update this policy; material changes are indicated by the "Last updated" date and, where appropriate, additional notice. Continued use after changes take effect is acceptance.
15. Google user data
This section explains how Omniscio handles data it receives from Google when you choose Connect Google in the App. It applies in addition to the rest of this policy.
What we access, and why. Omniscio uses Google data only to provide features you can see and use in the App:
- Gmail — to show your inbox in Omniscio and let you read, search, reply to, forward, draft and send email; mark mail read or unread; archive, label, star, snooze, or move threads to trash or spam; and clean up your inbox by archiving or unsubscribing from senders. When you ask, Omniscio creates a Gmail filter that auto-archives future mail from a sender. Omniscio never permanently deletes your email.
- Google Calendar — to show your calendars and let you, or an agent you direct, create, edit, move and delete events, add Google Meet links, find free time, and see your daily agenda.
- Google Drive, limited to files Omniscio creates or that you open with it — to publish documents and spreadsheets from Omniscio and keep them up to date.
- Google Docs and Google Sheets — to open, import, create and edit the documents and spreadsheets you choose.
- Google Contacts (read-only) — to suggest recipients while you write an email.
- Google Meet (read-only) — only if you turn on the Google Meet feature, to list your meetings, participants, recordings and transcripts in Omniscio.
Where it's stored. Google data is processed on your own computer. Any local copies, such as a copy of your mailbox for fast search, stay on your device, and contacts are held in memory only. Your Google access token is stored on your device, encrypted with your operating system's secure storage, and is never sent to Omniscio's servers. If you turn on cloud backup or cross-device sync, that data is end-to-end encrypted on your device before it is uploaded, so Omniscio cannot read it.
When it leaves your computer.
- AI features. When you use an AI feature on your Google data — for example a thread summary, reply suggestions, Email Cleanup suggestions, the daily digest, or asking an agent to read an email or check your calendar — the content that request needs is sent to the AI provider that powers the feature. For the App's built-in features that is Anthropic, or a model reached through OpenRouter; if you use your own API key or choose your own AI provider, it is the provider you chose, under its terms. Some of these requests pass through Omniscio's AI gateway on Google Cloud in the United States, which forwards them without storing their content and records only usage amounts for billing. Where a provider offers a setting that stops it keeping or training on the data, Omniscio requests it. On new installs, Gmail and Calendar are left out of the daily digest until you turn them on; the digest never reads them while the Gmail or Calendar integration is switched off, and you can remove either from the digest in its settings at any time.
- Phone notifications. By default, new-email notifications on your phone contain only a reference to the message; the sender and subject are included only if you turn that on.
- Supermail's own sign-in. If you sign in to Supermail with its own Google sign-in instead of using Omniscio's Gmail connection, Supermail keeps your mail on its server (see §5).
- Things you choose to share. Content you publish, share or send goes where you send it.
We do not sell Google user data, use it for advertising, or use it to decide creditworthiness. We do not use Google user data to develop, improve, or train generalized AI or machine-learning models. Omniscio staff do not read your Google data unless you ask us to (for example, in a support request), it is needed for security (such as investigating abuse), or the law requires it.
Your controls. You can disconnect Google at any time in Omniscio's Settings. Disconnecting revokes Omniscio's access at Google and deletes the local copy of your mailbox, your Google Meet list, the email samples Omniscio saved from Gmail, and the people and profile details it built from your email. Past daily digests, writing-style guides you created, and agent sessions you ran on your email — including bug reports that arrived by email — stay until you delete them. You can also remove Omniscio's access at myaccount.google.com/connections.
Limited Use. Omniscio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Voice features (off by default) — if you turn on voice, speech-to-text streams your microphone audio to the provider you select (Deepgram, ElevenLabs, Groq, or Meta — whose "Muse Voice Transcribe" engine is also reachable through OpenRouter) on your own key; text-to-speech sends the response text to Fish Audio by default through a Company-funded relay, and to Soniox the same way if you select it (both are Company subprocessors for this path), or to xAI Grok / ElevenLabs / Speechify / Pika on your own key.
Voice is OFF by default. Speech-to-text and text-to-speech are turned off out of the box; unless you turn them on in Settings, no microphone audio or voice data leaves your device. If you enable voice, audio and voice data are sent to the providers listed above — which can be sensitive personal information (see Section 8).
Other sites and services. The App, our websites, our emails, and content you view through the Services may contain links to third-party websites, tools, or services we do not operate. This Policy does not apply to those third parties, and we are not responsible for their content, practices, or privacy policies. Review the privacy policy of any third-party site or service before you provide it your information.
6. Diagnostics and product telemetry (always on)
Omniscio collects diagnostic and product-usage data to keep the App reliable. This collection is always on — there is no setting that turns it off. The disclosure here is how we keep it honest, not a promise you can disable it. The one related control is "Auto-Email Crash Reports," which gates only whether a crash report is additionally emailed to us; it does not stop crash capture (Sentry) or usage telemetry.
When it starts. This diagnostic collection begins when the App first launches — before, and independent of, any sign-in or Terms-acceptance step. Some fleet-health signals (for example, an install/first-run event, aggregate error/crash reports, and the diagnostic digests) can be sent before you sign in or accept these terms. Because the collection is mandatory, not consent-based, accepting the Terms and this Policy is how you are informed of it — it is not an on/off choice.
- What we collect: app version, operating system/platform, OS version, CPU architecture and core count, a coarse total-memory figure (rounded to whole gigabytes, never an exact size), feature-usage counts, crash/error reports, and the identified daily spend/usage aggregates described in Section 4. This also includes two typed-text streams — the text you type into Settings search and the questions you ask the in-app help / Ask-Omniscio assistant. Both are scrubbed of credentials and file paths and keyed only to a per-install identifier (never your name, account, or a session). About that identifier: when you are signed in, AI requests routed through our gateway also carry a device identifier so we can spot one machine abusing a free trial. It is a one-way hash and it is not your name, email, or account — but it is generated once per installation and stored on your device, and deleting your account does not by itself delete it. Removing the App's local data (§2) resets it. The Settings-search term is reduced to a short scrubbed snippet. The full text of your Ask-Omniscio help question is collected (scrubbed of credentials and file paths, bounded to about 2,000 characters), so we can understand and fix the problems people are actually having — a help question can therefore include personal details you type into it, so treat it like a support message.
- Reduction and encryption: reports are automatically processed to reduce personal identifiers — we attempt to remove usernames, file paths, and message content, and error messages are truncated. This reduction is best-effort, not a guarantee that every identifier is removed (identifiers embedded in free-text error strings may remain). Our fleet-diagnostic payloads (sent to our diagnostics endpoint) are encrypted on your device before they leave it. Our crash-report and weekly-digest emails are sent over TLS (encrypted in transit) but their bodies are not additionally encrypted; in those emails the subject line carries only a shortened, hashed hostname token, while the full device hostname remains in the email body (so reports from different machines can be told apart).
- What we don't do: we do not read your code or the content of your agent conversations for telemetry, and we do not sell this data.
7. How we use data
To provide, operate, and secure the Services; authenticate you; process payments and operate the AI-credit allowance; prevent abuse/fraud of credits; provide support; diagnose and improve reliability and features; and comply with legal obligations. We do not sell personal information and do not use your prompts, code, or conversations to train the Company's own models.
De-identified and aggregated data. Where we use aggregated or de-identified information, we maintain and use it only in de-identified form and do not attempt to re-identify it, except as permitted by law to test that the de-identification is effective. This paragraph does not describe the identified usage and spend aggregates covered in Section 4: those are uploaded keyed to your account and are personal information, not de-identified data, and they are handled as described in Sections 4, 6 and 9.
Disclosures for legal reasons and business transfers. We may disclose personal information when we reasonably believe it is necessary to: (a) comply with applicable law, regulation, legal process, or an enforceable governmental request; (b) enforce our terms and policies; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of the Company, our users, or the public as required or permitted by law. If the Company is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, personal information may be transferred as part of that transaction; we will require the recipient to honor this Policy or will notify you of any material change to how your information is handled.
8. Your US state privacy rights
Depending on your state of residence, you may have privacy rights under a comprehensive state privacy law — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA), and other states as their laws take effect. Subject to the exceptions in each law, these rights generally include the right to know and access the personal information we hold about you, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the "sale" of personal information, or certain profiling. We do not sell your personal information for money. However, our public websites use Google Analytics with advertising features ("Google signals"), which discloses online identifiers to Google for cross-context behavioral advertising and is therefore treated as a "share" (and, in some states, a "sale") under the CPRA and similar laws. You can opt out at any time using the "Do Not Sell or Share My Personal Information" link in our website footer, by turning on Global Privacy Control (which we honor), or via the controls in our Cookie Notice. No other category of personal information is sold or shared, and none of the data inside the App is shared for advertising.
The California-specific disclosures below (the Notice at Collection and the sensitive-personal-information right to limit) are provided for California residents; the mechanics for exercising your rights, honoring opt-out preference signals, and appeals apply to residents of every state whose law provides them.
Sources of personal information. We collect the categories below from: you (what you type, upload, or connect); your use of the Services (automatically — feature usage, diagnostics, and device and network information); service providers acting on our behalf (for example, our payment processor); and third parties you connect or who contact you through an integration you enable (for example, the senders of messages you receive in a connected channel).
Categories of personal information (Notice at Collection):
| Category | What we collect | Purpose | Disclosed to service providers? | Sold or shared? |
|---|---|---|---|---|
| Identifiers | account ID, email, display name, profile photo URL, IP address, device/install ID | account, login, security, support | Yes | No |
| Commercial information | plan/tier, billing and purchase records | billing, subscription | Yes (Stripe) | No |
| Internet/network activity | feature usage, diagnostics, crash reports | reliability, product improvement | Yes (e.g., Sentry) | No |
| Geolocation (coarse) | region inferred from IP address | sales tax, availability | Yes (Stripe Tax) | No |
| Payment/financial | payment-card details (handled by Stripe; not stored by us). Plus, if you use the Coffer personal-finance feature: structured financial data stored in your local encrypted database — bank balances, credit limits, a dated transaction ledger, and payee names (a SimpleFIN bank sync you connect is user-direct). | payment; personal budgeting | Card details: Stripe. Coffer data: local to your device; SimpleFIN sync user-direct | No |
| Sensitive personal information | Only if you enable voice (off by default): microphone audio / voice recordings sent to your chosen speech provider, and response text sent to the text-to-speech provider. No SSN; your credentials stay on your device. | Provide the voice features you turn on | Yes — to the voice provider you select (and Fish Audio or Soniox, which read aloud through Company-funded relays) | No |
| Sensitive personal information (personal-development features) | If you use the optional AI-coaching, journal/reflection, or self-assessment ("Life Inventory") features: psychological, emotional, and health-adjacent notes, ratings, and generated profile/insight text you create. Stored locally on your device. AI-coaching and journal reflection also send the relevant text to Anthropic on your own API key to generate insights; Life Inventory is computed locally with no AI call. | Provide the personal-development features you use | Anthropic (on your own key), for coaching/journal insight generation only | No |
Sharing for cross-context behavioral advertising. The online identifiers collected by our public websites (such as your IP address and a Google Analytics identifier) are shared with Google for cross-context behavioral advertising through Google Analytics' advertising features — the only "sharing" we do. You can opt out (see the "Do Not Sell or Share My Personal Information" link and Global Privacy Control described below, and our Cookie Notice). No other category in the table above is sold or shared, and nothing inside the App is shared for advertising.
- Sensitive personal information: we collect voice/biometric data only if you turn on voice features (off by default). If you do, you have the CPRA right to limit the use of sensitive personal information — exercise it by turning voice off in Settings (which stops any further voice data) or by emailing legal@omniscio.com. We use voice data solely to provide the voice features you enabled — never to infer characteristics about you, and never sold or shared.
- Personal-development features (AI-coaching, journal, Life Inventory): if you use these optional features, they can hold psychological, emotional, and health-adjacent information you record about yourself. This data is stored locally on your device. The AI-coaching and journal-reflection features additionally send the relevant text to Anthropic on your own Anthropic API key to generate insights (if you have no API key set, those AI features don't run); Life Inventory is computed on your device with no AI call. You can delete this data in each feature's own screen, and the App's "erase all local data" function now removes these personal-development stores as well — including the on-disk AI-coaching files the feature writes under your
~/Claudefolder. Because these features use your own API key, the Company does not receive this data, and we do not use it to train the Company's own models (Anthropic processes it under your own Anthropic account's terms). You have the CPRA right to limit its use — turn the feature off, delete the data, or email legal@omniscio.com. - Screen captures and meeting audio: the optional Snip-to-Text and meeting-transcription features can capture sensitive on-screen content or the voices of other people on a call. They run only when you enable or trigger them, and captured images are sent to an AI provider unredacted (an image cannot be scrubbed).
- How to exercise your rights: email legal@omniscio.com (or use any in-App request tool we provide). We will confirm receipt and verify your request by matching it to the information associated with your account; we may ask for additional information to confirm your identity, which we use only to process the request. We will respond within the time your state's law requires — for California, within 45 days, extendable once by another 45 days when reasonably necessary, with notice. We will not discriminate against you for exercising these rights.
- Authorized agents: you may use an authorized agent to submit a request on your behalf. We will require written proof of the agent's authorization and may still verify your identity directly before acting.
- Right to appeal: if we decline your request and your state's law provides an appeal (for example, Virginia, Colorado, or Connecticut), you may appeal by replying to our decision or emailing legal@omniscio.com with "Appeal" in the subject line. We will respond with our decision and the reasons for it within the period your state's law requires (generally 45–60 days). If we deny your appeal, your state's law may allow you to submit a complaint to your state Attorney General.
Right to opt out of "sharing"; Do Not Sell or Share My Personal Information. Because our public websites use Google Analytics advertising features (a "share" for cross-context behavioral advertising, as described at the top of this Section), you have the right to opt out. To do so, use the "Do Not Sell or Share My Personal Information" link in our website footer, turn on Global Privacy Control, or use the controls in our Cookie Notice. We do not sell your personal information for money.
Opt-out preference signals (Global Privacy Control). Some browsers and extensions can send an opt-out preference signal such as Global Privacy Control (GPC). We honor GPC as a valid request to opt out of the sharing described above — when we detect a GPC signal on our website, we disable the Google Analytics advertising features for that browser.
"Do Not Track." Some browsers offer a "Do Not Track" (DNT) setting. There is no common industry standard for responding to DNT signals, and because we do not track you across third-party websites over time for advertising, we do not currently respond to DNT signals. We set no advertising or cross-site tracking cookies (see Section 4).
California "Shine the Light." California Civil Code § 1798.83 lets California residents request information about personal information disclosed to third parties for those third parties' own direct-marketing use. We do not disclose personal information to third parties for their own direct marketing, so there is nothing to report; you may still contact legal@omniscio.com with questions.
Nevada. Nevada law lets residents submit a request not to sell certain covered information. We do not sell such information, but you may direct a verified request to legal@omniscio.com.
Texas. We do not sell sensitive or biometric personal data for monetary consideration, and Texas residents may exercise the access, correction, deletion, portability, opt-out, and appeal rights described in this Section.
9. Data retention
| Data | Retention |
|---|---|
| Local data (sessions, messages, keys) | On your device until you delete it or remove the App |
| Personal-development data (AI-coaching profile/insights, journal entries, Life-Inventory results) | On your device until you delete it in the feature or run "erase all local data" — not automatically expired (see §8) |
| Account and billing records | Life of your account, then up to 7 years (tax/accounting/legal) |
| Raw diagnostic events | About 180 days |
| Identified usage/spend aggregates | Up to 24 months, then deleted or anonymized |
| Support / helpdesk conversations | About 12 months |
| Inbound agent-email content | About 90 days |
| Search index | About 13 months |
| Shared artifacts ("Shares") and their comments | Until you delete the share. A public share may have been indexed or cached by search engines, and we cannot delete those copies |
| Repository bundles and run logs from the internal developer offload (§4) | 7 days (bundles) / 14 days (run logs), by automatic schedule |
10. Security
We use technical and organizational safeguards: encryption of credentials at rest on your device (OS secure storage), encryption in transit (HTTPS/TLS), encryption of diagnostic payloads before egress, and access controls on our backend. No system is perfectly secure.
At-rest posture for your local data. Your local database (mission-control.db) and any saved user attachments are not application-encrypted by default; they rely on your operating system's full-disk encryption (e.g., BitLocker / FileVault / LUKS) as the compensating control, together with OS file-system permissions. An optional database-encryption feature can be enabled for defense-in-depth. (Credentials and API keys are separately encrypted at rest as described above.)
Breach notification. If a breach affects your personal information, we will notify you and the appropriate authorities without undue delay and within any timeframe required by applicable law. We maintain an internal incident-response process (detect → contain → assess scope → notify affected users and regulators as required → remediate → document). (We deliberately do not commit to a single fixed number of days here, because US state breach-notification deadlines vary; "as required by law" covers the strictest applicable one.)
11. Data-processing addendum (business/team customers)
If you use Omniscio on behalf of an organization and we process personal data on your behalf through the team features, a data-processing addendum (DPA) governs that processing and lists our subprocessors. A DPA is available on request for business/organization customers — contact us at the address in Section 13. We are putting data-processing agreements in place with the subprocessors listed in Section 5: agreements are in effect with our core platform processors (Google Cloud / Firebase, Sentry, and Resend), and we are securing or confirming them for the remaining subprocessors. We maintain an internal data-processing register that records the current DPA status for each subprocessor, and we publish the current list on our Subprocessors page.
12. Children's privacy
The Services are not directed to children under 18, and we do not knowingly collect their data.
13. Contact
Privacy questions or requests: legal@omniscio.com, Omniscio LLC, 5301 Terminal St, Charlotte, NC 28208.
14. Changes
We may update this policy; material changes are indicated by the "Last updated" date and, where appropriate, additional notice. Continued use after changes take effect is acceptance.
15. Google user data
This section explains how Omniscio handles data it receives from Google when you choose Connect Google in the App. It applies in addition to the rest of this policy.
What we access, and why. Omniscio uses Google data only to provide features you can see and use in the App:
- Gmail — to show your inbox in Omniscio and let you read, search, reply to, forward, draft and send email; mark mail read or unread; archive, label, star, snooze, or move threads to trash or spam; and clean up your inbox by archiving or unsubscribing from senders. When you ask, Omniscio creates a Gmail filter that auto-archives future mail from a sender. Omniscio never permanently deletes your email.
- Google Calendar — to show your calendars and let you, or an agent you direct, create, edit, move and delete events, add Google Meet links, find free time, and see your daily agenda.
- Google Drive, limited to files Omniscio creates or that you open with it — to publish documents and spreadsheets from Omniscio and keep them up to date.
- Google Docs and Google Sheets — to open, import, create and edit the documents and spreadsheets you choose.
- Google Contacts (read-only) — to suggest recipients while you write an email.
- Google Meet (read-only) — only if you turn on the Google Meet feature, to list your meetings, participants, recordings and transcripts in Omniscio.
Where it's stored. Google data is processed on your own computer. Any local copies, such as a copy of your mailbox for fast search, stay on your device, and contacts are held in memory only. Your Google access token is stored on your device, encrypted with your operating system's secure storage, and is never sent to Omniscio's servers. If you turn on cloud backup or cross-device sync, that data is end-to-end encrypted on your device before it is uploaded, so Omniscio cannot read it.
When it leaves your computer.
- AI features. When you use an AI feature on your Google data — for example a thread summary, reply suggestions, Email Cleanup suggestions, the daily digest, or asking an agent to read an email or check your calendar — the content that request needs is sent to the AI provider that powers the feature. For the App's built-in features that is Anthropic, or a model reached through OpenRouter; if you use your own API key or choose your own AI provider, it is the provider you chose, under its terms. Some of these requests pass through Omniscio's AI gateway on Google Cloud in the United States, which forwards them without storing their content and records only usage amounts for billing. Where a provider offers a setting that stops it keeping or training on the data, Omniscio requests it. On new installs, Gmail and Calendar are left out of the daily digest until you turn them on; the digest never reads them while the Gmail or Calendar integration is switched off, and you can remove either from the digest in its settings at any time.
- Phone notifications. By default, new-email notifications on your phone contain only a reference to the message; the sender and subject are included only if you turn that on.
- Supermail's own sign-in. If you sign in to Supermail with its own Google sign-in instead of using Omniscio's Gmail connection, Supermail keeps your mail on its server (see §5).
- Things you choose to share. Content you publish, share or send goes where you send it.
We do not sell Google user data, use it for advertising, or use it to decide creditworthiness. We do not use Google user data to develop, improve, or train generalized AI or machine-learning models. Omniscio staff do not read your Google data unless you ask us to (for example, in a support request), it is needed for security (such as investigating abuse), or the law requires it.
Your controls. You can disconnect Google at any time in Omniscio's Settings. Disconnecting revokes Omniscio's access at Google and deletes the local copy of your mailbox, your Google Meet list, the email samples Omniscio saved from Gmail, and the people and profile details it built from your email. Past daily digests, writing-style guides you created, and agent sessions you ran on your email — including bug reports that arrived by email — stay until you delete them. You can also remove Omniscio's access at myaccount.google.com/connections.
Limited Use. Omniscio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.