Legal
Privacy Policy
We built OMEGA on a local-first principle. Your data stays on your Mac.
Overview
Omega AI Systems, INC. (“OMEGA,” “we,” “our,” or “us”) operates the OMEGA desktop application for macOS, the OMEGA iOS companion app, and the website located at myomega.ai (collectively, the “Services”).
This Privacy Policy explains what information we collect, why we collect it, how we use it, and the choices you have. Please read this policy carefully. By using the Services you agree to the practices described here.
Data We Collect
Account Information
When you create an OMEGA account or purchase a subscription, we collect:
- Email address
- Full name (optional)
- Password (stored as a bcrypt hash — we never store plaintext passwords)
- Subscription tier, status, and billing history
- License key associated with your account
Payment Information
Payments are processed by Stripe, Inc. We do not store your credit card number, CVV, or full payment details on our servers. We receive and store only:
- Stripe customer ID and subscription ID
- Last four digits of your card (for display purposes only)
- Card brand and expiration month/year
- Billing country and postal code
- Invoice records required for tax compliance
Device and License Data
To enforce license terms and prevent abuse, the OMEGA desktop app sends the following to our licensing server on activation and periodically thereafter:
- License key
- A hardware fingerprint (a one-way hash of hardware identifiers — not your serial number)
- macOS version and CPU architecture
- OMEGA app version
- Number of active devices on your license
We do not collect your device serial number, Apple ID, or any personally identifiable hardware attribute in recoverable form.
Usage Analytics
We collect aggregated, anonymized telemetry to improve OMEGA. This includes:
- Feature usage frequency (e.g., which agent domains are most used)
- App session duration and crash reports
- Task completion rates at an aggregate level
- Error codes and stack traces (stripped of any user content)
Analytics events are anonymized before transmission. You can disable telemetry at any time in OMEGA Settings → Privacy.
Website and Marketing
When you visit myomega.ai, we collect standard web server logs including IP address, browser type, referring URL, and pages visited. We use this data solely for security monitoring and aggregate traffic analysis.
Support Communications
If you contact us via email or a support ticket, we retain the content of that communication and your email address to provide support and maintain a record of resolved issues.
Data We Do Not Collect
- Your conversations, prompts, or completions with any AI model
- Your API keys for OpenAI, Anthropic, Google, or any other LLM provider
- Files, documents, or browser content accessed by agents
- Screenshots, screen recordings, or clipboard contents
- Keystrokes, passwords, or credentials stored on your Mac
- The content of emails, calendar events, or messages read by agents
- Voice recordings or transcriptions from two-way voice sessions
- Your Brain knowledge graph contents
- Task history, standing orders, or workflow definitions
Because we never receive this data, we cannot disclose it to third parties, respond to subpoenas for it, or be compelled to provide it. Your intellectual work product is yours alone.
How We Use Your Data
We use the data we collect for the following purposes:
Service Delivery
- Creating and managing your account
- Processing payments and issuing licenses
- Enforcing license seat limits and preventing abuse
- Sending transactional emails (receipts, password resets, subscription notices)
Product Improvement
- Analyzing anonymized telemetry to identify performance bottlenecks
- Understanding aggregate feature adoption to prioritize development
- Diagnosing crashes and errors via anonymized stack traces
Security and Legal
- Detecting and preventing fraudulent use of licenses
- Complying with applicable laws and regulations
- Enforcing our Terms of Service
Marketing (Opt-in Only)
We will only send promotional emails if you have explicitly opted in. You can unsubscribe at any time via the link in any marketing email or by emailing privacy@myomega.ai.
Third-Party Services
We share data with the following third parties only as necessary to operate the Services:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Email, billing address, payment method |
| Amazon Web Services | Hosting our API and licensing server | Account data, license records |
| Apple, Inc. | Push notifications (iOS app) | Device push token only |
| Postmark / transactional email | Sending transactional emails | Email address, first name |
We do not sell your personal information to third parties. We do not share your data with advertising networks, data brokers, or social media platforms.
All third-party providers are contractually required to process your data only as instructed by us and in accordance with applicable data protection law.
Data Retention
- Account information: retained for the duration of your account plus 90 days after deletion, then permanently erased.
- Payment records: retained for 7 years as required by tax and accounting regulations.
- Support communications: retained for 2 years from the date of last activity on a ticket.
- Anonymized telemetry: retained indefinitely in aggregate form (no personal identifiers).
- License hardware fingerprints: deleted within 30 days of license deactivation.
- Web server logs: retained for 30 days for security purposes, then purged.
You may request deletion of your account and associated personal data at any time (see Your Rights below). Data subject to legal retention obligations will be retained only for the minimum period required by law and will not be used for any other purpose.
Security
We implement technical and organizational measures to protect your personal data against unauthorized access, loss, or disclosure:
- All data in transit is encrypted using TLS 1.2 or higher.
- Passwords are hashed using bcrypt with a per-user salt.
- API keys for our internal services use scoped, rotatable tokens.
- Our infrastructure is hosted in SOC 2 Type II certified data centers.
- Access to production systems is restricted to authorized personnel with MFA enforcement.
- We perform regular dependency audits and apply security patches promptly.
No system is perfectly secure. If you discover a security vulnerability, please disclose it responsibly to security@myomega.ai.
Your Rights
Regardless of where you are located, you have the following rights with respect to your personal data:
Access
You may request a copy of all personal data we hold about you.
Correction
You may update inaccurate or incomplete information by logging into your account or contacting us.
Deletion
You may request that we delete your account and all associated personal data. We will comply within 30 days, subject to any legal retention obligations.
Portability
You may request an export of your account data in a machine-readable format (JSON).
Opt-Out of Telemetry
You may disable anonymized usage telemetry at any time in OMEGA Settings → Privacy → Telemetry.
To exercise any right, email privacy@myomega.ai with subject line “Privacy Request.” We will respond within 30 days. We may need to verify your identity before processing your request.
GDPR — EEA and UK Residents
If you are located in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR) and UK GDPR apply to your data.
Legal Basis for Processing
- Contract performance: processing necessary to deliver the Services you have subscribed to (account management, licensing, payment).
- Legitimate interests: fraud prevention, security monitoring, and anonymized product analytics where these interests are not overridden by your rights.
- Consent: marketing emails (you may withdraw consent at any time).
- Legal obligation: retaining financial records as required by law.
International Transfers
Our servers are located in the United States. If you are in the EEA or UK, your data is transferred to the US under the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) as applicable. You may request a copy of the relevant safeguards by emailing privacy@myomega.ai.
Additional GDPR Rights
In addition to the rights listed above, EEA/UK residents have the right to restrict processing, object to processing based on legitimate interests, and lodge a complaint with their local data protection authority (e.g., the ICO in the UK, or the relevant supervisory authority in your EU member state).
CCPA — California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights.
Categories of Personal Information Collected
In the past 12 months we have collected: identifiers (name, email, IP address), commercial information (subscription records), internet or network activity (web server logs), and inferences drawn from anonymized telemetry (aggregate feature usage patterns). We have not collected sensitive personal information as defined by the CPRA.
Sale or Sharing of Personal Information
We do not sell or share your personal information for cross-context behavioral advertising. We do not have actual knowledge that we sell or share personal information of consumers under 16 years of age.
Your California Rights
- Right to know what personal information we collect, use, disclose, or sell.
- Right to delete personal information we have collected from you.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information (not applicable — we do not sell or share).
- Right to limit use of sensitive personal information (not applicable — we do not collect sensitive PI as defined by CPRA).
- Right to non-discrimination for exercising your privacy rights.
To submit a California privacy request, email privacy@myomega.ai with subject line “California Privacy Request.” You may also authorize an agent to submit a request on your behalf.
Children’s Privacy
OMEGA is not directed to children under the age of 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at privacy@myomega.ai and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address associated with your account) and by posting a notice on our website at least 30 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
For non-material changes (e.g., clarifications, corrections, or formatting), we will update the “Last updated” date at the top of this page without separate notice.
Contact
If you have any questions about this Privacy Policy or how we handle your data, please contact us:
Omega AI Systems, INC.
Privacy Team
We aim to respond to all privacy inquiries within 5 business days.