Privacy Policy
Last updated: June 2026
1. Introduction
OmniAssist ("we", "our", or "us") is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it. By using OmniAssist, you agree to the practices described in this policy.
2. Information We Collect
We collect the following categories of information:
| Category | Examples |
|---|---|
| Account data | Name, email address, profile picture (via Manus OAuth) |
| Conversation data | Messages you send and receive, domain selections, conversation titles |
| Usage data | Pages visited, features used, timestamps, daily message counts |
| Payment data | Subscription plan, billing status (payment details handled by Stripe — we do not store card numbers) |
| Technical data | IP address, browser type, device type, session cookies |
| User-generated content | Uploaded files, voice recordings, saved prompt templates, conversation tags |
2A. Guest Free and Browser-Scoped Activity
Guest Free can be used without creating an account. It does not create saved conversation history or cross-device profile data. Language, consent, and interface preferences may be stored in your browser using local storage.
To enforce the 50-message daily Guest Free allowance and help prevent abuse, we may record a pseudonymous hash of a network identifier together with the applicable day and usage count. Clearing browser data can remove local preferences, but does not reset the server-side daily allowance.
3. How We Use Your Information
We use your data to:
- Provide, operate, and improve the OmniAssist service
- Authenticate your identity and maintain your session
- Process subscription payments and manage your billing
- Enforce daily usage limits and subscription entitlements
- Send service-related notifications (e.g., broadcast announcements from the platform owner)
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not sell your personal data to third parties. We do not use your conversation content to train AI models.
4. Legal Basis for Processing (EU/UK Users)
Where GDPR or UK GDPR applies, we process your data on the following legal bases: contract performance (to provide the service you signed up for), legitimate interests (security, fraud prevention, service improvement), legal obligation (compliance with applicable law), and consent (for optional cookies and marketing communications, where applicable).
5. Cookies and Tracking
We use the following types of cookies:
| Type | Purpose |
|---|---|
| Strictly necessary | Session authentication cookie (required for login to function) |
| Functional | Theme preference, language setting, context window size (localStorage) |
| Analytics | Anonymous page view and feature usage statistics via Umami (privacy-friendly, no cross-site tracking) |
You can manage cookie preferences via the consent banner shown on your first visit, or by clearing your browser cookies at any time.
6. Data Sharing
We share your data only with the following categories of third-party processors, under appropriate data processing agreements:
- Manus platform — authentication, hosting, and infrastructure
- Stripe — payment processing (subject to Stripe's own Privacy Policy)
- AI model providers — your conversation messages are sent to the underlying LLM to generate responses; no personally identifying account data is included beyond the message content
- Amazon S3-compatible storage — for files and voice recordings you upload
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The table below sets out our standard retention periods by data category.
| Data Category | Retention Period | Reason |
|---|---|---|
| Account profile (name, email) | Duration of account + 30 days after deletion | Required to operate the service; brief post-deletion window to handle disputes |
| Conversation history & messages | Until you delete them or close your account | User-controlled; you can delete individual conversations at any time |
| Uploaded files & voice recordings | 90 days after upload, or until manually deleted | Storage cost management; users are notified before expiry |
| Usage & analytics data | 13 months (rolling) | Standard analytics retention; allows year-on-year comparison |
| Security event logs | 90 days | Fraud detection and incident response |
| Session cookies | 1 year from last login | Keeps you signed in across sessions |
| Payment & billing records | 7 years | Legal obligation under financial and tax regulations |
| Support / problem reports | 2 years | Audit trail and quality assurance |
When a retention period expires, data is securely deleted or anonymised. You may request early deletion of your data at any time by using the Report a Problem feature or contacting us via the Help page (see Section 9 for your full rights).
8. International Transfers
OmniAssist is hosted on infrastructure that may process data in the United States and other countries. Where data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) in accordance with applicable data protection law.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data ("right to be forgotten")
- Restrict or object to certain processing
- Data portability (receive your data in a machine-readable format)
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with your local data protection authority
To exercise any of these rights, please use the Report a Problem feature in the app or contact us via the Help page. To delete your account and all associated data, you can use the Delete My Account option in your Profile page (scroll to the Danger Zone section at the bottom).
10. California Residents — CCPA Disclosure
If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you specific rights regarding your personal information. This section supplements the rest of this Privacy Policy and applies solely to California residents.
We Do Not Sell or Share Your Personal Information
OmniAssist does not sell, rent, lease, or otherwise disclose your personal information to third parties for monetary or other valuable consideration. We do not share your data with advertisers, data brokers, or marketing platforms. Your conversation content, account details, usage patterns, and any files you upload are never sold or traded. This applies to all users globally, not only California residents.
Your CCPA / CPRA Rights
As a California resident, you have the right to:
- Know — request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third parties with whom it is shared
- Delete — request deletion of personal information we have collected from you, subject to certain exceptions
- Correct — request correction of inaccurate personal information we maintain about you
- Opt out of sale or sharing — as stated above, we do not sell or share personal information; no opt-out action is required
- Limit use of sensitive personal information — we do not use sensitive personal information for purposes beyond those permitted by the CPRA
- Non-discrimination — we will not discriminate against you for exercising any of your CCPA/CPRA rights
Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information (as defined by the CCPA):
| CCPA Category | Examples Collected |
|---|---|
| Identifiers | Name, email address, account ID, IP address |
| Internet / network activity | Pages visited, features used, conversation history, message counts |
| Commercial information | Subscription plan, billing status (no card numbers stored) |
| Audio / electronic data | Voice recordings uploaded by the user (optional feature) |
| Inferences | Domain preferences derived from your usage (e.g., Healthcare, Legal) |
How to Submit a Request
To exercise any of the rights listed above, please use the Report a Problem feature in the app or visit the Help page. We will verify your identity before processing your request and respond within 45 days as required by law. Requests are free of charge, up to twice per year.
11. Children's Privacy
OmniAssist is not directed at children under the age of 13 (or 16 in the EU/UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via the in-app What's New announcement system. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact
For privacy-related enquiries, please use the Help page or the Report a Problem feature available in the sidebar. We aim to respond to all requests within 30 days.