Privacy Policy — OmniAssist | OmniAssist
OMNIASSIST

Privacy Policy

Last updated: June 2026

1. Introduction

OmniAssist ("we", "our", or "us") is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it. By using OmniAssist, you agree to the practices described in this policy.

2. Information We Collect

We collect the following categories of information:

CategoryExamples
Account dataName, email address, profile picture (via Manus OAuth)
Conversation dataMessages you send and receive, domain selections, conversation titles
Usage dataPages visited, features used, timestamps, daily message counts
Payment dataSubscription plan, billing status (payment details handled by Stripe — we do not store card numbers)
Technical dataIP address, browser type, device type, session cookies
User-generated contentUploaded files, voice recordings, saved prompt templates, conversation tags

2A. Guest Free and Browser-Scoped Activity

Guest Free can be used without creating an account. It does not create saved conversation history or cross-device profile data. Language, consent, and interface preferences may be stored in your browser using local storage.

To enforce the 50-message daily Guest Free allowance and help prevent abuse, we may record a pseudonymous hash of a network identifier together with the applicable day and usage count. Clearing browser data can remove local preferences, but does not reset the server-side daily allowance.

3. How We Use Your Information

We use your data to:

  • Provide, operate, and improve the OmniAssist service
  • Authenticate your identity and maintain your session
  • Process subscription payments and manage your billing
  • Enforce daily usage limits and subscription entitlements
  • Send service-related notifications (e.g., broadcast announcements from the platform owner)
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your conversation content to train AI models.

4. Legal Basis for Processing (EU/UK Users)

Where GDPR or UK GDPR applies, we process your data on the following legal bases: contract performance (to provide the service you signed up for), legitimate interests (security, fraud prevention, service improvement), legal obligation (compliance with applicable law), and consent (for optional cookies and marketing communications, where applicable).

5. Cookies and Tracking

We use the following types of cookies:

TypePurpose
Strictly necessarySession authentication cookie (required for login to function)
FunctionalTheme preference, language setting, context window size (localStorage)
AnalyticsAnonymous page view and feature usage statistics via Umami (privacy-friendly, no cross-site tracking)

You can manage cookie preferences via the consent banner shown on your first visit, or by clearing your browser cookies at any time.

6. Data Sharing

We share your data only with the following categories of third-party processors, under appropriate data processing agreements:

  • Manus platform — authentication, hosting, and infrastructure
  • Stripe — payment processing (subject to Stripe's own Privacy Policy)
  • AI model providers — your conversation messages are sent to the underlying LLM to generate responses; no personally identifying account data is included beyond the message content
  • Amazon S3-compatible storage — for files and voice recordings you upload

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The table below sets out our standard retention periods by data category.

Data CategoryRetention PeriodReason
Account profile (name, email)Duration of account + 30 days after deletionRequired to operate the service; brief post-deletion window to handle disputes
Conversation history & messagesUntil you delete them or close your accountUser-controlled; you can delete individual conversations at any time
Uploaded files & voice recordings90 days after upload, or until manually deletedStorage cost management; users are notified before expiry
Usage & analytics data13 months (rolling)Standard analytics retention; allows year-on-year comparison
Security event logs90 daysFraud detection and incident response
Session cookies1 year from last loginKeeps you signed in across sessions
Payment & billing records7 yearsLegal obligation under financial and tax regulations
Support / problem reports2 yearsAudit trail and quality assurance

When a retention period expires, data is securely deleted or anonymised. You may request early deletion of your data at any time by using the Report a Problem feature or contacting us via the Help page (see Section 9 for your full rights).

8. International Transfers

OmniAssist is hosted on infrastructure that may process data in the United States and other countries. Where data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) in accordance with applicable data protection law.

9. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data ("right to be forgotten")
  • Restrict or object to certain processing
  • Data portability (receive your data in a machine-readable format)
  • Withdraw consent at any time (where processing is based on consent)
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, please use the Report a Problem feature in the app or contact us via the Help page. To delete your account and all associated data, you can use the Delete My Account option in your Profile page (scroll to the Danger Zone section at the bottom).

10. California Residents — CCPA Disclosure

If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you specific rights regarding your personal information. This section supplements the rest of this Privacy Policy and applies solely to California residents.

We Do Not Sell or Share Your Personal Information

OmniAssist does not sell, rent, lease, or otherwise disclose your personal information to third parties for monetary or other valuable consideration. We do not share your data with advertisers, data brokers, or marketing platforms. Your conversation content, account details, usage patterns, and any files you upload are never sold or traded. This applies to all users globally, not only California residents.

Your CCPA / CPRA Rights

As a California resident, you have the right to:

  • Know — request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third parties with whom it is shared
  • Delete — request deletion of personal information we have collected from you, subject to certain exceptions
  • Correct — request correction of inaccurate personal information we maintain about you
  • Opt out of sale or sharing — as stated above, we do not sell or share personal information; no opt-out action is required
  • Limit use of sensitive personal information — we do not use sensitive personal information for purposes beyond those permitted by the CPRA
  • Non-discrimination — we will not discriminate against you for exercising any of your CCPA/CPRA rights

Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information (as defined by the CCPA):

CCPA CategoryExamples Collected
IdentifiersName, email address, account ID, IP address
Internet / network activityPages visited, features used, conversation history, message counts
Commercial informationSubscription plan, billing status (no card numbers stored)
Audio / electronic dataVoice recordings uploaded by the user (optional feature)
InferencesDomain preferences derived from your usage (e.g., Healthcare, Legal)

How to Submit a Request

To exercise any of the rights listed above, please use the Report a Problem feature in the app or visit the Help page. We will verify your identity before processing your request and respond within 45 days as required by law. Requests are free of charge, up to twice per year.

11. Children's Privacy

OmniAssist is not directed at children under the age of 13 (or 16 in the EU/UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes via the in-app What's New announcement system. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact

For privacy-related enquiries, please use the Help page or the Report a Problem feature available in the sidebar. We aim to respond to all requests within 30 days.

OmniAssist is committed to digital accessibility. See our Accessibility Statement for information on our WCAG 2.1 AA conformance, known limitations, and how to request assistance.