Omniscio

Privacy Policy

This page is under legal review. It describes how Omniscio works today and we intend to stand behind it, but the wording is not final and may change. If anything here matters to a decision you are making, please email legal@omniscio.com and we will confirm it in writing.

Omniscio — Privacy Policy

Effective date: 2026-08-20 Last updated: 2026-09-23


Key terms at a glance

Plain-English summary — not a substitute for the full Privacy Policy. This box is a quick, friendly overview of the points people ask about most. It is not legal language and does not replace the numbered sections below, which are the Policy that actually applies. If anything here seems to differ from those sections, the full sections control.


1. Overview

Omniscio (the "App") is a desktop application published by Omniscio LLC ("the Company," "we," "us"), a North Carolina limited liability company. Omniscio helps you run and manage AI coding agents on your own computer.

Omniscio is local-first by design. Most of your data — your projects, agent sessions, the full text of your conversations, local cost tracking, settings, and any API keys you provide — is stored on your own device and is not uploaded to us. A limited, purpose-specific set of data is handled in the cloud to run accounts, billing, support, opt-in-or-default diagnostics, and the optional team features. This policy explains both.

Where you are. The Services are currently offered only in the United States. This policy is written for US users; if we expand to other regions we will provide region-specific terms.

2. Data stored locally on your device

Stored in a local database (mission-control.db, in your OS application-data folder) and an encrypted local config file, and not sent to the Company except as described in Sections 4–6:

Some operational data also lives outside that folder. If you use the App's built-in developer tooling (the dev pipeline / cloud test offload — see §4), it writes to a folder called .amc in your user home directory: branch names, run history, job ledgers, and the App's local access token. That folder is not inside the application-data folder, so removing one does not remove the other.

To delete your local data: delete it in the App, remove the App's data folder, and remove the .amc folder in your home directory if it exists.

3. Credentials and API keys (verified)

4. Data we handle in the cloud

When you use features that need our backend (Google Firebase / Google Cloud), we process a limited set of data:

We do not upload your local session history or project code as part of using the App.

One exception, and it is not part of the App you install. The Company's own repository ships a developer tool ("cloud test offload") that our engineers can run to execute a build or test suite on Company machines instead of their own. When a developer explicitly turns it on, it uploads a bundle of the code in their working folder — including files they have not committed — plus the name and email recorded on each commit, to a Company-owned Google Cloud Storage bucket in the United States, where Company-owned worker machines unpack and run it. Bundles are deleted on a 7-day schedule and run logs on a 14-day one.

This is called out here for completeness and honesty, not because it affects you: the tool lives only in the Company's source repository and is not included in the application you download and install, so no customer installation can reach it. The people whose code and identity it handles are the Company's own contributors, working on the Company's own code.

Where your data is processed (data residency). The cloud data described above is processed and stored in the United States. Our backend — Google Firebase / Firestore / Cloud Storage / Cloud Functions — runs in a US region (us-central1, Iowa), and crash/error reports go to Sentry's US region. Mobile push notifications are delivered through Google Firebase Cloud Messaging (FCM), a global Google service, so notification content (such as a session name or message subject) transfers to Google's infrastructure. If you access the App from outside the US, you understand your data is transferred to and processed in the US. The internal developer tool described in Section 4 is US-only too: its storage bucket and worker machines run in us-central1 (Iowa), so a contributor's code snapshot and the name/email recorded on their commits are processed in the United States.

Some AI vendors are outside the US. Being offered only in the US bounds where our customers are; it does not bound where a vendor is. A small number of the helper-AI and voice vendors in Section 5 process content outside the United States on Company-held keys — most notably CrofAI (China; the automatic backup for our DeepSeek lane), DeepSeek (China), Fish Audio (China-founded; the default read-aloud relay), and the Alibaba-operated model upstream some OpenRouter requests are served by. The published Subprocessors page lists each one under "Where processing happens" with what it receives and when. We do not currently operate EU/UK regions or rely on Standard Contractual Clauses (SCCs) for those transfers.

Cookies (functional only). If you use the optional web-access feature (pairing a phone or browser to the App over your local network), the App's local server sets two strictly-necessary functional cookies. amc_web_token (HttpOnly, SameSite=Lax) keeps your paired browser signed in across page loads — its value is your session access token. amc_device_id (HttpOnly, SameSite=Lax, Max-Age of 400 days) is a persistent, server-assigned random device identifier: the App mints one for a browser that has not paired before, so it can tell your paired devices apart, show you which ones are paired, and let you sign an individual device out. Neither cookie is a tracking, analytics, advertising, or cross-site identifier, so both are exempt from cookie-consent requirements as strictly-necessary cookies (each is set as soon as you sign in to that feature, before any banner), and both are first-party — shared with no third party. Clearing amc_device_id through your browser's settings simply makes that browser look like a new device the next time you pair it. The App sets no advertising or third-party tracking cookies. Our public websites (omniscio.com and docs.omniscio.com) separately use Google Analytics to understand site traffic, behind a consent banner that keeps it off until you accept — including these legal pages, which are served from docs.omniscio.com. No analytics cookie is set on any of them until you accept. See our Cookie Notice for details and opt-out options.

5. Third parties and subprocessors

We use the following. Core services run the Services; optional ones receive data only if you enable the relevant feature.

Core subprocessors

Provider Purpose Data involved
Anthropic (Claude) Default AI provider powering agent sessions. The optional personal-development features (AI-coaching, journal reflection) also call Anthropic to generate insights — on your own Anthropic API key (the same key the agent uses), and only if you have one set. Your prompts, code, file contents, conversation context, and attachments — sent when you run an agent (directly or via our gateway) — plus, for the personal-development features, the coaching/journal text those insight calls process (on your own key).
Google — Firebase / Google Cloud Authentication, database (Firestore), cloud functions, hosting, our AI gateway (Cloud Run), secret storage Account/identity, billing/metering, aggregates, support, diagnostics, and team data described above.
Stripe, Inc. Payment processing and US sales-tax calculation Payment method and billing details (held by Stripe); the Company receives a customer identifier and subscription status.
Sentry Application crash/error reporting Crash/error reports with scrubbed messages (see Section 6).
Resend Transactional email delivery (bug reports, digests, notifications) and product activation / marketing email (the onboarding drip) The email content the App sends (e.g., your bug report and diagnostics); for activation/marketing messages, your email address and the message content.
Cloudflare Agent-email relay (inbound/outbound) Email routed through the agent-email feature.
AgentMail Feedback/bug-report intake Bug-report/feedback content sent to our intake.
Groq Cost-efficient "helper" AI model, routed via our AI gateway — inbound agent-email pre-screening/classification and other built-in helper features (e.g., reply suggestions, short spoken summaries) Content those helper features process (e.g., inbound email; the message text a suggestion or summary is generated from).
OpenRouter, OpenAI, DeepSeek (via our AI gateway) Cost-efficient "helper" AI models for built-in features — session-title generation, summaries and daily digests, Plain Speak rewrites, contact-name inference, Supermail AI email filtering + "Catch me up" thread summaries, and Inbox Pilot (which reads the recent turns of an agent session to decide whether it needs your attention, and — when you have it drafting replies — writes the suggested reply) The prompt/message content those helper features process, routed through our gateway on Company-held keys. (OpenRouter is the primary helper provider today; OpenAI and DeepSeek are provisioned in the same gateway.)
RunInfra and CrofAI (upstreams serving our DeepSeek lane) The "DeepSeek" models above are served by RunInfra on a Company-held key. If RunInfra errors, our gateway automatically retries the same request against CrofAI, also on a Company-held key — so a request sent to the DeepSeek lane may be served by either. CrofAI is China-hosted, so a request that fails over to it leaves the United States. The same prompt/message content the DeepSeek helper lane processes.
FlowVoice (Company-hosted dictation server) OS-wide voice dictation (speech-to-text) on a Company-operated hosted backend — engaged only when you turn on dictation. Live microphone audio of whatever you dictate into any app, plus the foreground app name and window title (which can itself carry a document or person name, an email subject, or a URL).
Supermail backend (mailback.jls.dev) Company self-hosted backend (US) for the Supermail inbound-email feature and its server-side contact enrichment — engaged only when you use Supermail. Inbound email content routed to the feature — sender, subject, and body — plus the contact-enrichment lookups performed on the Company backend.
LiveKit (real-time call media) — not yet active In development; not enabled in the current build, so no data reaches LiveKit today. When Team Chat voice/video calls ship, LiveKit will act as the real-time audio/video relay (SFU), engaged only when you start or join a call, with the Company minting a scoped access token on its own LiveKit account (Company-operated, lane-2). LiveKit will be added to the Subprocessors list before that path is ever enabled. Once enabled: live audio and video of the call participants (including other members on the call) plus call room/token metadata.

Optional / secondary (only when you enable them)

Voice is OFF by default. Speech-to-text and text-to-speech are turned off out of the box; unless you turn them on in Settings, no microphone audio or voice data leaves your device. If you enable voice, audio and voice data are sent to the providers listed above — which can be sensitive personal information (see Section 8).

Other sites and services. The App, our websites, our emails, and content you view through the Services may contain links to third-party websites, tools, or services we do not operate. This Policy does not apply to those third parties, and we are not responsible for their content, practices, or privacy policies. Review the privacy policy of any third-party site or service before you provide it your information.

6. Diagnostics and product telemetry (always on)

Omniscio collects diagnostic and product-usage data to keep the App reliable. This collection is always on — there is no setting that turns it off. The disclosure here is how we keep it honest, not a promise you can disable it. The one related control is "Auto-Email Crash Reports," which gates only whether a crash report is additionally emailed to us; it does not stop crash capture (Sentry) or usage telemetry.

When it starts. This diagnostic collection begins when the App first launches — before, and independent of, any sign-in or Terms-acceptance step. Some fleet-health signals (for example, an install/first-run event, aggregate error/crash reports, and the diagnostic digests) can be sent before you sign in or accept these terms. Because the collection is mandatory, not consent-based, accepting the Terms and this Policy is how you are informed of it — it is not an on/off choice.

7. How we use data

To provide, operate, and secure the Services; authenticate you; process payments and operate the AI-credit allowance; prevent abuse/fraud of credits; provide support; diagnose and improve reliability and features; and comply with legal obligations. We do not sell personal information and do not use your prompts, code, or conversations to train the Company's own models.

De-identified and aggregated data. Where we use aggregated or de-identified information, we maintain and use it only in de-identified form and do not attempt to re-identify it, except as permitted by law to test that the de-identification is effective. This paragraph does not describe the identified usage and spend aggregates covered in Section 4: those are uploaded keyed to your account and are personal information, not de-identified data, and they are handled as described in Sections 4, 6 and 9.

Disclosures for legal reasons and business transfers. We may disclose personal information when we reasonably believe it is necessary to: (a) comply with applicable law, regulation, legal process, or an enforceable governmental request; (b) enforce our terms and policies; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of the Company, our users, or the public as required or permitted by law. If the Company is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, personal information may be transferred as part of that transaction; we will require the recipient to honor this Policy or will notify you of any material change to how your information is handled.

8. Your US state privacy rights

Depending on your state of residence, you may have privacy rights under a comprehensive state privacy law — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA), and other states as their laws take effect. Subject to the exceptions in each law, these rights generally include the right to know and access the personal information we hold about you, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the "sale" of personal information, or certain profiling. We do not sell your personal information for money. However, our public websites use Google Analytics with advertising features ("Google signals"), which discloses online identifiers to Google for cross-context behavioral advertising and is therefore treated as a "share" (and, in some states, a "sale") under the CPRA and similar laws. You can opt out at any time using the "Do Not Sell or Share My Personal Information" link in our website footer, by turning on Global Privacy Control (which we honor), or via the controls in our Cookie Notice. No other category of personal information is sold or shared, and none of the data inside the App is shared for advertising.

The California-specific disclosures below (the Notice at Collection and the sensitive-personal-information right to limit) are provided for California residents; the mechanics for exercising your rights, honoring opt-out preference signals, and appeals apply to residents of every state whose law provides them.

Sources of personal information. We collect the categories below from: you (what you type, upload, or connect); your use of the Services (automatically — feature usage, diagnostics, and device and network information); service providers acting on our behalf (for example, our payment processor); and third parties you connect or who contact you through an integration you enable (for example, the senders of messages you receive in a connected channel).

Categories of personal information (Notice at Collection):

Category What we collect Purpose Disclosed to service providers? Sold or shared?
Identifiers account ID, email, display name, profile photo URL, IP address, device/install ID account, login, security, support Yes No
Commercial information plan/tier, billing and purchase records billing, subscription Yes (Stripe) No
Internet/network activity feature usage, diagnostics, crash reports reliability, product improvement Yes (e.g., Sentry) No
Geolocation (coarse) region inferred from IP address sales tax, availability Yes (Stripe Tax) No
Payment/financial payment-card details (handled by Stripe; not stored by us). Plus, if you use the Coffer personal-finance feature: structured financial data stored in your local encrypted database — bank balances, credit limits, a dated transaction ledger, and payee names (a SimpleFIN bank sync you connect is user-direct). payment; personal budgeting Card details: Stripe. Coffer data: local to your device; SimpleFIN sync user-direct No
Sensitive personal information Only if you enable voice (off by default): microphone audio / voice recordings sent to your chosen speech provider, and response text sent to the text-to-speech provider. No SSN; your credentials stay on your device. Provide the voice features you turn on Yes — to the voice provider you select (and Fish Audio or Soniox, which read aloud through Company-funded relays) No
Sensitive personal information (personal-development features) If you use the optional AI-coaching, journal/reflection, or self-assessment ("Life Inventory") features: psychological, emotional, and health-adjacent notes, ratings, and generated profile/insight text you create. Stored locally on your device. AI-coaching and journal reflection also send the relevant text to Anthropic on your own API key to generate insights; Life Inventory is computed locally with no AI call. Provide the personal-development features you use Anthropic (on your own key), for coaching/journal insight generation only No

Sharing for cross-context behavioral advertising. The online identifiers collected by our public websites (such as your IP address and a Google Analytics identifier) are shared with Google for cross-context behavioral advertising through Google Analytics' advertising features — the only "sharing" we do. You can opt out (see the "Do Not Sell or Share My Personal Information" link and Global Privacy Control described below, and our Cookie Notice). No other category in the table above is sold or shared, and nothing inside the App is shared for advertising.

Right to opt out of "sharing"; Do Not Sell or Share My Personal Information. Because our public websites use Google Analytics advertising features (a "share" for cross-context behavioral advertising, as described at the top of this Section), you have the right to opt out. To do so, use the "Do Not Sell or Share My Personal Information" link in our website footer, turn on Global Privacy Control, or use the controls in our Cookie Notice. We do not sell your personal information for money.

Opt-out preference signals (Global Privacy Control). Some browsers and extensions can send an opt-out preference signal such as Global Privacy Control (GPC). We honor GPC as a valid request to opt out of the sharing described above — when we detect a GPC signal on our website, we disable the Google Analytics advertising features for that browser.

"Do Not Track." Some browsers offer a "Do Not Track" (DNT) setting. There is no common industry standard for responding to DNT signals, and because we do not track you across third-party websites over time for advertising, we do not currently respond to DNT signals. We set no advertising or cross-site tracking cookies (see Section 4).

California "Shine the Light." California Civil Code § 1798.83 lets California residents request information about personal information disclosed to third parties for those third parties' own direct-marketing use. We do not disclose personal information to third parties for their own direct marketing, so there is nothing to report; you may still contact legal@omniscio.com with questions.

Nevada. Nevada law lets residents submit a request not to sell certain covered information. We do not sell such information, but you may direct a verified request to legal@omniscio.com.

Texas. We do not sell sensitive or biometric personal data for monetary consideration, and Texas residents may exercise the access, correction, deletion, portability, opt-out, and appeal rights described in this Section.

9. Data retention

Data Retention
Local data (sessions, messages, keys) On your device until you delete it or remove the App
Personal-development data (AI-coaching profile/insights, journal entries, Life-Inventory results) On your device until you delete it in the feature or run "erase all local data" — not automatically expired (see §8)
Account and billing records Life of your account, then up to 7 years (tax/accounting/legal)
Raw diagnostic events About 180 days
Identified usage/spend aggregates Up to 24 months, then deleted or anonymized
Support / helpdesk conversations About 12 months
Inbound agent-email content About 90 days
Search index About 13 months
Shared artifacts ("Shares") and their comments Until you delete the share. A public share may have been indexed or cached by search engines, and we cannot delete those copies
Repository bundles and run logs from the internal developer offload (§4) 7 days (bundles) / 14 days (run logs), by automatic schedule

10. Security

We use technical and organizational safeguards: encryption of credentials at rest on your device (OS secure storage), encryption in transit (HTTPS/TLS), encryption of diagnostic payloads before egress, and access controls on our backend. No system is perfectly secure.

At-rest posture for your local data. Your local database (mission-control.db) and any saved user attachments are not application-encrypted by default; they rely on your operating system's full-disk encryption (e.g., BitLocker / FileVault / LUKS) as the compensating control, together with OS file-system permissions. An optional database-encryption feature can be enabled for defense-in-depth. (Credentials and API keys are separately encrypted at rest as described above.)

Breach notification. If a breach affects your personal information, we will notify you and the appropriate authorities without undue delay and within any timeframe required by applicable law. We maintain an internal incident-response process (detect → contain → assess scope → notify affected users and regulators as required → remediate → document). (We deliberately do not commit to a single fixed number of days here, because US state breach-notification deadlines vary; "as required by law" covers the strictest applicable one.)

11. Data-processing addendum (business/team customers)

If you use Omniscio on behalf of an organization and we process personal data on your behalf through the team features, a data-processing addendum (DPA) governs that processing and lists our subprocessors. A DPA is available on request for business/organization customers — contact us at the address in Section 13. We are putting data-processing agreements in place with the subprocessors listed in Section 5: agreements are in effect with our core platform processors (Google Cloud / Firebase, Sentry, and Resend), and we are securing or confirming them for the remaining subprocessors. We maintain an internal data-processing register that records the current DPA status for each subprocessor, and we publish the current list on our Subprocessors page.

12. Children's privacy

The Services are not directed to children under 18, and we do not knowingly collect their data.

13. Contact

Privacy questions or requests: legal@omniscio.com, Omniscio LLC, 5301 Terminal St, Charlotte, NC 28208.

14. Changes

We may update this policy; material changes are indicated by the "Last updated" date and, where appropriate, additional notice. Continued use after changes take effect is acceptance.

15. Google user data

This section explains how Omniscio handles data it receives from Google when you choose Connect Google in the App. It applies in addition to the rest of this policy.

What we access, and why. Omniscio uses Google data only to provide features you can see and use in the App:

Where it's stored. Google data is processed on your own computer. Any local copies, such as a copy of your mailbox for fast search, stay on your device, and contacts are held in memory only. Your Google access token is stored on your device, encrypted with your operating system's secure storage, and is never sent to Omniscio's servers. If you turn on cloud backup or cross-device sync, that data is end-to-end encrypted on your device before it is uploaded, so Omniscio cannot read it.

When it leaves your computer.

We do not sell Google user data, use it for advertising, or use it to decide creditworthiness. We do not use Google user data to develop, improve, or train generalized AI or machine-learning models. Omniscio staff do not read your Google data unless you ask us to (for example, in a support request), it is needed for security (such as investigating abuse), or the law requires it.

Your controls. You can disconnect Google at any time in Omniscio's Settings. Disconnecting revokes Omniscio's access at Google and deletes the local copy of your mailbox, your Google Meet list, the email samples Omniscio saved from Gmail, and the people and profile details it built from your email. Past daily digests, writing-style guides you created, and agent sessions you ran on your email — including bug reports that arrived by email — stay until you delete them. You can also remove Omniscio's access at myaccount.google.com/connections.

Limited Use. Omniscio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.


Voice is OFF by default. Speech-to-text and text-to-speech are turned off out of the box; unless you turn them on in Settings, no microphone audio or voice data leaves your device. If you enable voice, audio and voice data are sent to the providers listed above — which can be sensitive personal information (see Section 8).

Other sites and services. The App, our websites, our emails, and content you view through the Services may contain links to third-party websites, tools, or services we do not operate. This Policy does not apply to those third parties, and we are not responsible for their content, practices, or privacy policies. Review the privacy policy of any third-party site or service before you provide it your information.

6. Diagnostics and product telemetry (always on)

Omniscio collects diagnostic and product-usage data to keep the App reliable. This collection is always on — there is no setting that turns it off. The disclosure here is how we keep it honest, not a promise you can disable it. The one related control is "Auto-Email Crash Reports," which gates only whether a crash report is additionally emailed to us; it does not stop crash capture (Sentry) or usage telemetry.

When it starts. This diagnostic collection begins when the App first launches — before, and independent of, any sign-in or Terms-acceptance step. Some fleet-health signals (for example, an install/first-run event, aggregate error/crash reports, and the diagnostic digests) can be sent before you sign in or accept these terms. Because the collection is mandatory, not consent-based, accepting the Terms and this Policy is how you are informed of it — it is not an on/off choice.

7. How we use data

To provide, operate, and secure the Services; authenticate you; process payments and operate the AI-credit allowance; prevent abuse/fraud of credits; provide support; diagnose and improve reliability and features; and comply with legal obligations. We do not sell personal information and do not use your prompts, code, or conversations to train the Company's own models.

De-identified and aggregated data. Where we use aggregated or de-identified information, we maintain and use it only in de-identified form and do not attempt to re-identify it, except as permitted by law to test that the de-identification is effective. This paragraph does not describe the identified usage and spend aggregates covered in Section 4: those are uploaded keyed to your account and are personal information, not de-identified data, and they are handled as described in Sections 4, 6 and 9.

Disclosures for legal reasons and business transfers. We may disclose personal information when we reasonably believe it is necessary to: (a) comply with applicable law, regulation, legal process, or an enforceable governmental request; (b) enforce our terms and policies; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of the Company, our users, or the public as required or permitted by law. If the Company is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, personal information may be transferred as part of that transaction; we will require the recipient to honor this Policy or will notify you of any material change to how your information is handled.

8. Your US state privacy rights

Depending on your state of residence, you may have privacy rights under a comprehensive state privacy law — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Texas (TDPSA), and other states as their laws take effect. Subject to the exceptions in each law, these rights generally include the right to know and access the personal information we hold about you, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the "sale" of personal information, or certain profiling. We do not sell your personal information for money. However, our public websites use Google Analytics with advertising features ("Google signals"), which discloses online identifiers to Google for cross-context behavioral advertising and is therefore treated as a "share" (and, in some states, a "sale") under the CPRA and similar laws. You can opt out at any time using the "Do Not Sell or Share My Personal Information" link in our website footer, by turning on Global Privacy Control (which we honor), or via the controls in our Cookie Notice. No other category of personal information is sold or shared, and none of the data inside the App is shared for advertising.

The California-specific disclosures below (the Notice at Collection and the sensitive-personal-information right to limit) are provided for California residents; the mechanics for exercising your rights, honoring opt-out preference signals, and appeals apply to residents of every state whose law provides them.

Sources of personal information. We collect the categories below from: you (what you type, upload, or connect); your use of the Services (automatically — feature usage, diagnostics, and device and network information); service providers acting on our behalf (for example, our payment processor); and third parties you connect or who contact you through an integration you enable (for example, the senders of messages you receive in a connected channel).

Categories of personal information (Notice at Collection):

Category What we collect Purpose Disclosed to service providers? Sold or shared?
Identifiers account ID, email, display name, profile photo URL, IP address, device/install ID account, login, security, support Yes No
Commercial information plan/tier, billing and purchase records billing, subscription Yes (Stripe) No
Internet/network activity feature usage, diagnostics, crash reports reliability, product improvement Yes (e.g., Sentry) No
Geolocation (coarse) region inferred from IP address sales tax, availability Yes (Stripe Tax) No
Payment/financial payment-card details (handled by Stripe; not stored by us). Plus, if you use the Coffer personal-finance feature: structured financial data stored in your local encrypted database — bank balances, credit limits, a dated transaction ledger, and payee names (a SimpleFIN bank sync you connect is user-direct). payment; personal budgeting Card details: Stripe. Coffer data: local to your device; SimpleFIN sync user-direct No
Sensitive personal information Only if you enable voice (off by default): microphone audio / voice recordings sent to your chosen speech provider, and response text sent to the text-to-speech provider. No SSN; your credentials stay on your device. Provide the voice features you turn on Yes — to the voice provider you select (and Fish Audio or Soniox, which read aloud through Company-funded relays) No
Sensitive personal information (personal-development features) If you use the optional AI-coaching, journal/reflection, or self-assessment ("Life Inventory") features: psychological, emotional, and health-adjacent notes, ratings, and generated profile/insight text you create. Stored locally on your device. AI-coaching and journal reflection also send the relevant text to Anthropic on your own API key to generate insights; Life Inventory is computed locally with no AI call. Provide the personal-development features you use Anthropic (on your own key), for coaching/journal insight generation only No

Sharing for cross-context behavioral advertising. The online identifiers collected by our public websites (such as your IP address and a Google Analytics identifier) are shared with Google for cross-context behavioral advertising through Google Analytics' advertising features — the only "sharing" we do. You can opt out (see the "Do Not Sell or Share My Personal Information" link and Global Privacy Control described below, and our Cookie Notice). No other category in the table above is sold or shared, and nothing inside the App is shared for advertising.

Right to opt out of "sharing"; Do Not Sell or Share My Personal Information. Because our public websites use Google Analytics advertising features (a "share" for cross-context behavioral advertising, as described at the top of this Section), you have the right to opt out. To do so, use the "Do Not Sell or Share My Personal Information" link in our website footer, turn on Global Privacy Control, or use the controls in our Cookie Notice. We do not sell your personal information for money.

Opt-out preference signals (Global Privacy Control). Some browsers and extensions can send an opt-out preference signal such as Global Privacy Control (GPC). We honor GPC as a valid request to opt out of the sharing described above — when we detect a GPC signal on our website, we disable the Google Analytics advertising features for that browser.

"Do Not Track." Some browsers offer a "Do Not Track" (DNT) setting. There is no common industry standard for responding to DNT signals, and because we do not track you across third-party websites over time for advertising, we do not currently respond to DNT signals. We set no advertising or cross-site tracking cookies (see Section 4).

California "Shine the Light." California Civil Code § 1798.83 lets California residents request information about personal information disclosed to third parties for those third parties' own direct-marketing use. We do not disclose personal information to third parties for their own direct marketing, so there is nothing to report; you may still contact legal@omniscio.com with questions.

Nevada. Nevada law lets residents submit a request not to sell certain covered information. We do not sell such information, but you may direct a verified request to legal@omniscio.com.

Texas. We do not sell sensitive or biometric personal data for monetary consideration, and Texas residents may exercise the access, correction, deletion, portability, opt-out, and appeal rights described in this Section.

9. Data retention

Data Retention
Local data (sessions, messages, keys) On your device until you delete it or remove the App
Personal-development data (AI-coaching profile/insights, journal entries, Life-Inventory results) On your device until you delete it in the feature or run "erase all local data" — not automatically expired (see §8)
Account and billing records Life of your account, then up to 7 years (tax/accounting/legal)
Raw diagnostic events About 180 days
Identified usage/spend aggregates Up to 24 months, then deleted or anonymized
Support / helpdesk conversations About 12 months
Inbound agent-email content About 90 days
Search index About 13 months
Shared artifacts ("Shares") and their comments Until you delete the share. A public share may have been indexed or cached by search engines, and we cannot delete those copies
Repository bundles and run logs from the internal developer offload (§4) 7 days (bundles) / 14 days (run logs), by automatic schedule

10. Security

We use technical and organizational safeguards: encryption of credentials at rest on your device (OS secure storage), encryption in transit (HTTPS/TLS), encryption of diagnostic payloads before egress, and access controls on our backend. No system is perfectly secure.

At-rest posture for your local data. Your local database (mission-control.db) and any saved user attachments are not application-encrypted by default; they rely on your operating system's full-disk encryption (e.g., BitLocker / FileVault / LUKS) as the compensating control, together with OS file-system permissions. An optional database-encryption feature can be enabled for defense-in-depth. (Credentials and API keys are separately encrypted at rest as described above.)

Breach notification. If a breach affects your personal information, we will notify you and the appropriate authorities without undue delay and within any timeframe required by applicable law. We maintain an internal incident-response process (detect → contain → assess scope → notify affected users and regulators as required → remediate → document). (We deliberately do not commit to a single fixed number of days here, because US state breach-notification deadlines vary; "as required by law" covers the strictest applicable one.)

11. Data-processing addendum (business/team customers)

If you use Omniscio on behalf of an organization and we process personal data on your behalf through the team features, a data-processing addendum (DPA) governs that processing and lists our subprocessors. A DPA is available on request for business/organization customers — contact us at the address in Section 13. We are putting data-processing agreements in place with the subprocessors listed in Section 5: agreements are in effect with our core platform processors (Google Cloud / Firebase, Sentry, and Resend), and we are securing or confirming them for the remaining subprocessors. We maintain an internal data-processing register that records the current DPA status for each subprocessor, and we publish the current list on our Subprocessors page.

12. Children's privacy

The Services are not directed to children under 18, and we do not knowingly collect their data.

13. Contact

Privacy questions or requests: legal@omniscio.com, Omniscio LLC, 5301 Terminal St, Charlotte, NC 28208.

14. Changes

We may update this policy; material changes are indicated by the "Last updated" date and, where appropriate, additional notice. Continued use after changes take effect is acceptance.

15. Google user data

This section explains how Omniscio handles data it receives from Google when you choose Connect Google in the App. It applies in addition to the rest of this policy.

What we access, and why. Omniscio uses Google data only to provide features you can see and use in the App:

Where it's stored. Google data is processed on your own computer. Any local copies, such as a copy of your mailbox for fast search, stay on your device, and contacts are held in memory only. Your Google access token is stored on your device, encrypted with your operating system's secure storage, and is never sent to Omniscio's servers. If you turn on cloud backup or cross-device sync, that data is end-to-end encrypted on your device before it is uploaded, so Omniscio cannot read it.

When it leaves your computer.

We do not sell Google user data, use it for advertising, or use it to decide creditworthiness. We do not use Google user data to develop, improve, or train generalized AI or machine-learning models. Omniscio staff do not read your Google data unless you ask us to (for example, in a support request), it is needed for security (such as investigating abuse), or the law requires it.

Your controls. You can disconnect Google at any time in Omniscio's Settings. Disconnecting revokes Omniscio's access at Google and deletes the local copy of your mailbox, your Google Meet list, the email samples Omniscio saved from Gmail, and the people and profile details it built from your email. Past daily digests, writing-style guides you created, and agent sessions you ran on your email — including bug reports that arrived by email — stay until you delete them. You can also remove Omniscio's access at myaccount.google.com/connections.

Limited Use. Omniscio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.