Legal
Privacy Policy
We built OMEGA on a local-first principle. Your data stays on your Mac.
Overview
Omega AI Systems, Inc. (“OMEGA,” “we,” “our,” or “us”) operates the native OMEGA application for macOS, built on Neural-Fractal Agentic AI™ (NFA) with optional user-toggled Quantum Neural-Fractal Agentic AI™ (QNFA), and the website located at myomega.ai (collectively, the “Services”).
This Privacy Policy explains what information we collect, why we collect it, how we use it, and the choices you have. Please read this policy carefully. By using the Services you agree to the practices described here.
Notice at Collection
We collect only the information needed for the specific action you choose. Before account creation, checkout, diagnostics upload, support contact, or vulnerability disclosure, the relevant form explains what will be collected and why.
- Account signup: email, optional display name, password hash, age-of-majority and legal acceptance records, and, where phone verification is required at signup, a mobile phone number verified by a one-time SMS code.
- Checkout: selected plan, legal acceptance evidence, Stripe customer/session identifiers, IP address, user agent, and billing metadata returned by Stripe.
- Diagnostics / Report to OMEGA: only the diagnostic bundle or report you choose to send after OMEGA redacts known secrets and shows the report flow.
- Support and legal forms: the contact details, topic, and message you submit.
- Security reports: vulnerability details and contact information you provide so we can investigate and coordinate disclosure.
Data We Collect
Account Information
When you create an OMEGA account or purchase a subscription, we collect:
- Email address
- Full name (optional)
- Password (stored as a bcrypt hash; we never store plaintext passwords)
- Subscription tier, status, and billing history
- License key associated with your account
- Legal acceptance records, including accepted document versions, required affirmations, timestamp, IP address, and user agent
- Where phone verification is required at signup: your mobile phone number in international (E.164) format and the timestamp of its verification (used for account verification and fraud and abuse prevention)
Phone Verification
Where phone verification is required at signup, you must provide a mobile phone number in international (E.164) format and confirm a one-time code we send to that number by SMS. Verification is performed by Twilio Inc. (United States): Twilio Lookup checks the line type, and only real mobile lines are accepted (VoIP and landline numbers are rejected; if the check cannot complete, the number is not accepted). Twilio Verify then sends the SMS code and manages code generation, expiry, and retry throttling. Successful verification issues a short-lived signed token, valid for 30 minutes, that is consumed at account creation.
- We store the verified phone number and a verification timestamp on your account.
- Each verified phone number can be associated with only one account; this uniqueness is enforced by our database.
- Your phone number and related verification metadata are shared with Twilio solely to perform the verification.
- We use phone numbers only for account verification and fraud and abuse prevention. We do not send marketing SMS, we do not call you, and we never sell phone numbers or share them beyond Twilio.
- Numbers associated with banned or fraud-revoked accounts are retained on a phone blocklist (see Data Retention below).
Payment Information
Payments are processed by Stripe, Inc. We do not store your credit card number, CVV, or full payment details on our servers. We receive and store only:
- Stripe customer ID and subscription ID
- Last four digits of your card (for display purposes only)
- Card brand and expiration month/year
- Billing country and postal code
- Invoice records required for tax compliance
Device and License Data
To enforce license terms and prevent abuse, the OMEGA desktop app sends the following to our licensing server on activation and periodically thereafter:
- License key
- A hardware fingerprint (a one-way hash of hardware identifiers, not your serial number)
- macOS version and CPU architecture
- OMEGA app version
- Number of active devices on your license
- The IP address used for the license server connection (see “License-Server IP Logs” below for full details)
We do not collect your device serial number, Apple ID, or any personally identifiable hardware attribute in recoverable form.
License-Server IP Logs
Each connection to central.myomega.ai for license validation, activation, deactivation, or session establishment is logged with: the IP address of the connecting client, a timestamp, account or session identifiers, and the response code (success / fail / blocked). We use these logs exclusively for:
- License verification: confirming the connection comes from a legitimate licensed device
- Fraud prevention: blocking known VPN, proxy, Tor, datacenter, hosting, and anonymizer IP ranges (use of OMEGA over those services is prohibited under the Acceptable Use Policy and applicable License Agreement)
- Abuse detection: identifying impossibly rapid activation/deactivation cycles, geographic-jump patterns indicative of seat-sharing, or coordinated chargeback attempts
- Limited operational security: DDoS mitigation, rate limiting, and country-level sanctions compliance
License-server IP logs are retained for 90 days and then automatically deleted. They are stored separately from any other data we hold about you and are never combined with the content of your local OMEGA usage (which we never see) or with marketing analytics. Access to IP logs is restricted to a small set of OMEGA engineers for the limited purposes above.
If you must use a corporate VPN as part of an employer-mandated security policy, contact the legal team with your account email and the static egress IP range to request a corporate-VPN exception. Personal VPNs, public VPN services, Tor, and anonymizer networks are not eligible for exceptions.
Usage Analytics
We collect aggregated, anonymized telemetry to improve OMEGA. This includes:
- Feature usage frequency (e.g., which agent domains are most used)
- App session duration and crash reports
- Task completion rates at an aggregate level
- Error codes and stack traces (stripped of any user content)
Analytics events are anonymized before transmission. You can disable telemetry at any time in OMEGA Settings → Privacy.
Website and Marketing
When you visit myomega.ai, we collect standard web server logs including IP address, browser type, referring URL, and pages visited. We use this data solely for security monitoring and aggregate traffic analysis.
If configured, the marketing website may use Google Analytics, Google Ads conversion tags, Google Translate cookies, and Fingerprint visitor IDs for aggregate measurement, language selection, fraud prevention, and abuse defense. You can disable non-essential analytics and optional fingerprinting in the controls below.
Support Communications
If you contact us via email or a support ticket, we retain the content of that communication and your email address to provide support and maintain a record of resolved issues.
Data We Do Not Collect
- Your conversations, prompts, or completions with any AI model
- Your API keys for OpenAI, Anthropic, Google, or any other LLM provider
- Your Codex or Claude subscription connection metadata
- Files, documents, or browser content accessed by agents
- Screenshots, screen recordings, or clipboard contents
- Keystrokes, passwords, or credentials stored on your Mac
- The content of emails, calendar events, or messages read by agents
- Voice recordings or transcriptions from two-way voice sessions
- Your Brain knowledge graph contents
- Task history, standing orders, or Automation definitions
Because we never receive this data, we cannot disclose it to third parties, respond to subpoenas for it, or be compelled to provide it. Your intellectual work product is yours alone.
How We Use Your Data
We use the data we collect for the following purposes:
Service Delivery
- Creating and managing your account
- Verifying mobile phone numbers at signup and screening them against the anti-abuse phone blocklist, where phone verification is required
- Processing payments and issuing licenses
- Enforcing license seat limits and preventing abuse
- Sending transactional emails (receipts, password resets, subscription notices)
- Recording required legal acknowledgements for account creation, billing, age-of-majority, acceptable use, and copyright/model responsibility
Product Improvement
- Analyzing anonymized telemetry to identify performance bottlenecks
- Understanding aggregate feature adoption to prioritize development
- Diagnosing crashes and errors via anonymized stack traces
Security and Legal
- Detecting and preventing fraudulent use of licenses
- Complying with applicable laws and regulations
- Enforcing our Terms of Service
Marketing (Opt-in Only)
We will only send promotional emails if you have explicitly opted in. You can unsubscribe at any time using the link in any marketing email. To opt out of all marketing, you can submit a privacy request.
Third-Party Services
We share data with the following third parties only as necessary to operate the Services:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Email, billing address, payment method |
| Hostinger International Ltd. | Hosting our API and licensing server (VPS) | Account data, license records |
| Apple, Inc. | Native macOS push notifications | Device push token only |
| Resend (and SMTP fallback) | Sending transactional emails (receipts, password resets, billing notices) | Email address, first name |
| Twilio Inc. (United States) | Phone verification via Twilio Verify (one-time SMS code) and Twilio Lookup (line-type check), where phone verification is required at signup | Phone number and verification metadata, for this purpose only |
| Composio and connected app providers | User-authorized app connections and tool calls | Only the data required for the app/action the user configures and authorizes |
| AI model providers selected by the user | Cloud model calls when the user chooses a non-local runtime | Prompts, files, tool context, and outputs required for that specific provider call |
| GitHub, deployment, browser, and Automation-connected services | User-authorized repository, deployment, browser automation, and Automation actions | Action-specific payloads, metadata, and credentials governed by the user's provider account |
| Google Analytics / Ads and Fingerprint, when enabled | Website measurement, conversion tracking, fraud prevention | Website event data, browser/device signals, visitor identifier |
We do not sell your personal information to third parties. We do not share your data with advertising networks, data brokers, or social media platforms.
All third-party providers are contractually required to process your data only as instructed by us and in accordance with applicable data protection law.
Provider Data Transfers
- Local MLX inference and local-only Automations remain on your Mac except for Central license checks and optional update checks.
- OpenAI, Anthropic, OpenRouter, Codex, Claude, and other AI providers receive the prompt, context, files, tool outputs, and metadata needed for the model call you authorize.
- Composio and connected apps receive the OAuth scopes, action payloads, and account data needed for the specific tool/action you configure.
- GitHub, deployment providers, browser targets, custom HTTP connectors, and Automation integrations receive data only when you connect or invoke them.
- OMEGA does not train OMEGA-owned models on your local content or sell your data. Third-party providers may have their own data-use terms; you are responsible for reviewing them before connecting the provider.
Diagnostics and Support Uploads
Report to OMEGA and diagnostic uploads are opt-in. OMEGA redacts known secrets before delivery, but you should still review the report context and avoid sending credentials, sensitive documents, private customer data, or regulated data unless support explicitly asks for a minimal redacted sample.
- Diagnostic uploads may include app version, gateway/runtime status, error messages, stack traces, route names, configuration summaries, device class, operating-system version, and steps you typed into the report form.
- Diagnostic uploads should not include raw API keys, passwords, provider tokens, payment card details, private files, prompts, completions, or model outputs unless you explicitly choose to include them.
- We retain diagnostic uploads for up to 90 days unless they are needed longer for a security, billing, legal, or abuse investigation.
- We use diagnostic uploads only to investigate the issue you reported, improve reliability, and maintain safety/security records.
Data Retention
- Account information: retained for the duration of your account plus 90 days after deletion, then permanently erased.
- Verified phone numbers: retained while the account exists and deleted with the account, except that numbers associated with banned or fraud-revoked accounts are retained on a phone blocklist after account deletion for fraud and abuse prevention. The blocklist stores the number only, with no other personal data.
- Payment records: retained for 7 years as required by tax and accounting regulations.
- Support communications: retained for 2 years from the date of last activity on a ticket.
- Diagnostics and Report to OMEGA uploads: retained for up to 90 days unless needed for a security, billing, legal, or abuse investigation.
- Legal acceptance evidence: retained for the life of the account plus the limitation period needed to resolve disputes, enforce agreements, and prove plan/document acceptance.
- Central license audit events: retained while the account or license exists and for the period needed to resolve disputes, fraud, chargebacks, or entitlement history.
- Anonymized telemetry: retained indefinitely in aggregate form (no personal identifiers).
- License hardware fingerprints: deleted within 30 days of license deactivation.
- Web server logs: retained for 30 days for security purposes, then purged.
You may request deletion of your account and associated personal data at any time (see Your Rights below). Data subject to legal retention obligations will be retained only for the minimum period required by law and will not be used for any other purpose.
Security
We implement technical and organizational measures to protect your personal data against unauthorized access, loss, or disclosure:
- All data in transit is encrypted using TLS 1.2 or higher.
- Passwords are hashed using bcrypt with a per-user salt.
- API keys for our internal services use scoped, rotatable tokens.
- Our infrastructure is hosted in SOC 2 Type II certified data centers.
- Access to production systems is restricted to authorized personnel with MFA enforcement.
- We perform regular dependency audits and apply security patches promptly.
No system is perfectly secure. If you discover a security vulnerability, please disclose it responsibly to submit a security report.
Your Rights
Regardless of where you are located, you have the following rights with respect to your personal data:
Access
You may request a copy of all personal data we hold about you.
Correction
You may update inaccurate or incomplete information by logging into your account or contacting us.
Deletion
You may request that we delete your account and all associated personal data. We will comply within 30 days, subject to any legal retention obligations.
Account deletion removes Central account data, license records that are no longer needed for fraud/dispute defense, support profile data, and non-required operational records. Billing records, Stripe event evidence, legal acceptance proof, chargeback records, and tax/accounting records may be retained for the minimum period required by law or needed to resolve disputes.
Where phone verification was required at signup, account deletion also removes the verified phone number and verification timestamp stored on your account, with one exception: if your account was banned or had access revoked for fraud, the phone number itself is retained on a phone blocklist after deletion so the same number cannot immediately be used to create a new account. This retention rests on our legitimate interest in fraud and abuse prevention (GDPR Art. 6(1)(f)) and falls within the deletion-right exception of GDPR Art. 17(3). The blocklist stores the number only, with no other personal data.
Local OMEGA workspace data lives on your Mac. You can delete it by removing local workspaces from OMEGA or deleting OMEGA’s local Application Support data after export. Central deletion does not automatically reach into a device you control.
Portability
You may request an export of your account data in a machine-readable format. OMEGA exports NDJSON (newline-delimited JSON), which you can re-import into another OMEGA installation or read with any tool that handles JSON Lines. Exports include your tasks, memories, automations, personas, agent trust tiers, and learned style preferences. The content is on your Mac, this is just the account metadata needed to rebuild it on a new install.
Central account export includes account email, the verified phone number where phone verification was required at signup, license state, device activation history, legal acceptance records, and support metadata that OMEGA controls. Provider accounts, Stripe payment data, Composio-connected app data, GitHub repositories, deployment targets, and local files must be exported from those systems or from your Mac directly.
Opt-Out of Telemetry
You may disable anonymized usage telemetry at any time in OMEGA Settings → Privacy → Telemetry.
To exercise any right, email submit a privacy request with subject line “Privacy Request.” We will respond within 30 days. We may need to verify your identity before processing your request.
GDPR: EEA and UK Residents
If you are located in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR) and UK GDPR apply to your data.
Legal Basis for Processing
- Contract performance: processing necessary to deliver the Services you have subscribed to (account management, licensing, payment).
- Legitimate interests: fraud prevention, security monitoring, retention of banned phone numbers on the anti-abuse phone blocklist, and anonymized product analytics where these interests are not overridden by your rights.
- Consent: marketing emails (you may withdraw consent at any time).
- Legal obligation: retaining financial records as required by law.
International Transfers
Our servers are located in the United States. If you are in the EEA or UK, your data is transferred to the US under the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) as applicable. You may request a copy of the relevant safeguards by emailing submit a privacy request.
Additional GDPR Rights
In addition to the rights listed above, EEA/UK residents have the right to restrict processing, object to processing based on legitimate interests, and lodge a complaint with their local data protection authority (e.g., the ICO in the UK, or the relevant supervisory authority in your EU member state).
CCPA: California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights.
Categories of Personal Information Collected
In the past 12 months we have collected: identifiers (name, email, phone number where phone verification is required at signup, IP address), commercial information (subscription records), internet or network activity (web server logs), and inferences drawn from anonymized telemetry (aggregate feature usage patterns). We have not collected sensitive personal information as defined by the CPRA.
Sale or Sharing of Personal Information
We do not sell or share your personal information for cross-context behavioral advertising. We do not have actual knowledge that we sell or share personal information of consumers under 16 years of age.
Your California Rights
- Right to know what personal information we collect, use, disclose, or sell.
- Right to delete personal information we have collected from you.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information (not applicable: we do not sell or share).
- Right to limit use of sensitive personal information (not applicable: we do not collect sensitive PI as defined by CPRA).
- Right to non-discrimination for exercising your privacy rights.
To submit a California privacy request, email submit a privacy request with subject line “California Privacy Request.” You may also authorize an agent to submit a request on your behalf.
Children’s Privacy
OMEGA is not directed to minors. You may create an account or use OMEGA only if you are at least 18 years old or the age of majority in your jurisdiction, whichever is higher. We do not knowingly collect personal information from children or minors. If you believe we have inadvertently collected information from a minor, please contact us at submit a privacy request and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address associated with your account) and by posting a notice on our website at least 30 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
For non-material changes (e.g., clarifications, corrections, or formatting), we will update the “Last updated” date at the top of this page without separate notice.
Contact
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Omega AI Systems, Inc.
Privacy Team
30 N. Gould St. STE R
Sheridan, WY 82801
United States of America
We aim to respond to all privacy inquiries within 5 business days.