OmniLink
Privacy Policy
This Privacy Policy explains how OmniLink Technology Inc. (“OmniLink,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use our websites, dashboards, APIs, SDKs, libraries, command-line tools, and related services (collectively, the “Services”). It also describes the choices and rights you have over your information and how to contact us.
Privacy at a glance
OmniLink is designed so that humans, not machines, stay in control of their data. We collect only the information needed to operate the Services, never sell personal information, and do not train our own foundation models on customer content. When you ask an OmniLink agent to think, we forward the request to the third-party AI provider you select — Google, OpenAI, Anthropic, xAI, or OpenRouter — authenticated with your own key, so that provider’s privacy terms apply to your prompts and you can see and revoke that traffic from your own provider console. When the agent acts on a real system, the action runs on your hardware through the OmniLink local runtime. This Policy explains where each piece of data lives and how it is handled at every step.
1. Scope and definitions
This Policy applies to personal information processed by OmniLink
when you visit our websites under
omnilink-agents.com and related domains, sign in to
the OmniLink Dashboard, generate or use Omni Keys, install the
OmniLink Python library or VS Code extension, run the local
runtime, call the OmniLink REST API, build or operate agents
through OmniSim, or otherwise interact with the Services.
It does not apply to information collected by third-party AI providers under their own terms, to information processed locally by the OmniLink runtime on your own hardware and never transmitted to us, or to the practices of websites, devices, or applications that we do not operate.
Key terms used in this Policy
- Customer
- The individual, company, or other organization that has created an OmniLink account, agreed to our Terms of Service, and pays for or accesses the Services. Accounts are single-user: there is no team workspace and no invited teammate.
- User
- Any natural person who accesses the Services on behalf of a Customer — the account owner, anyone the owner allows to use their account or Omni Key, and end users of agents built on top of OmniLink.
- Customer Content
- The inputs, prompts, system instructions, conversation history, agent memory, tool definitions, and configuration that a Customer or its Users submit to the Services, together with the outputs that AI models or tools generate in response.
- Personal information
- Information that identifies, relates to, describes, or could reasonably be linked with an identifiable individual or household. Equivalent to “personal data” under the GDPR and UK GDPR.
- Processing
- Any operation performed on personal information, including collection, recording, storage, retrieval, use, disclosure, transmission, restriction, erasure, or destruction.
- Third-party AI provider
- A foundation model or inference provider that we integrate with so that you can route reasoning through their models using your own account with them. At the time of writing this is Google, OpenAI, Anthropic, xAI, and OpenRouter.
2. Information we collect
We collect information in three ways: information you give us directly, information we collect automatically when you use the Services, and information we receive from third parties.
2.1 Information you provide directly
- Account information. When you create an account we collect your name, email address, password (hashed by Supabase Auth, which handles sign-in — we never see or store the password itself), profile picture if you choose to upload one, organization name, and timezone.
- Billing information. When you subscribe to a paid plan, our payment processor (Stripe) collects your payment method, billing address, and tax identification number. OmniLink itself never sees full card numbers or bank details — we only receive a token, the last four digits, card brand, country, and the result of each charge.
- Model-provider credentials (bring-your-own-key). OmniLink does not include model inference: to run an agent you connect your own credential for the provider you chose — an API key for Google, OpenAI, Anthropic, xAI, or OpenRouter, or a Google Cloud service-account JSON where the provider requires one, which contains a private key. We store that credential server-side, encrypted at rest with AES-256-GCM, because the platform has to call the provider on your behalf when a scheduled agent wakes up and you are not there. See Section 7 for what is done with it and Section 9 for how long it is kept.
- Account configuration. The names, system prompts, tool definitions, routing rules, integration scopes, schedules, and agent profiles you save to your account.
- Customer Content. The prompts, conversations, files, voice clips, robot telemetry, and tool inputs you submit through the Services, along with the outputs returned by AI models and tools.
- Support communications. Messages you send to our support team, feedback you submit through the dashboard, survey responses, and recordings of meetings you explicitly agree to record.
- Marketing and event information. Information you provide if you subscribe to our newsletter, register for a webinar, attend an event, or apply for an open role.
2.2 Information collected automatically
- Usage and telemetry. The endpoints you call, request and response sizes, timestamps, status codes, error codes, model selection, token counts, estimated provider cost, latencies, and the version of the SDK or library you use.
- Device and environment data. IP address, browser type and version, operating system, language preferences, time zone, and — if you enable push notifications — a device push token. We do not run a crash-reporting or product-analytics SDK in the web app.
- Log data. Server logs that record the time, origin, route, headers (minus secrets), and outcome of each API request, with secrets such as Omni Keys redacted before logs are written.
- Cookies and similar technologies. See Section 12 for details on cookies, local storage, and session tokens.
2.3 Information from third parties
- Identity providers. If you sign in with a third-party identity provider, we receive the email address and unique identifier associated with that account, and any profile information you authorize the provider to share.
- Payment processors. Confirmation of payment, fraud signals, chargeback notifications, and subscription status from Stripe.
- Connected messaging channels. If you connect an agent to a channel such as Discord, Slack, or WhatsApp, we receive the messages sent to that agent and the channel’s identifier for the sender, so the agent can reply.
2.4 Sensitive information
We do not ask for sensitive personal information (such as government identifiers, financial account numbers, precise location, biometric data, or information about health, race, religion, sexual orientation, or political views) and we ask that you do not submit it through the Services. If you choose to put sensitive information into a prompt, a conversation, or an agent’s instructions, you do so under your own responsibility and must have a lawful basis for that processing.
3. How we use information
We use information to operate, secure, and improve the Services. We do not use Customer Content to train our own foundation models, and we do not sell personal information.
3.1 Service delivery
- Create and maintain your account, authenticate you, and establish secure sessions.
- Forward prompts to the third-party AI provider you select, using the credential you supplied for it, execute tool calls, and return outputs to you.
- Synchronize agent profiles, schedules, and conversation history between the Dashboard and the local runtime.
- Process subscription payments, invoice you, and report your usage and estimated provider cost back to you.
- Provide customer support, respond to requests, and notify you about changes to your account or the Services.
3.2 Reliability, abuse prevention, and safety
- Detect and investigate abuse, fraud, account takeover, scraping, denial-of-service activity, and other violations of our Acceptable Use Policy.
- Enforce rate limits, monitor system health, diagnose outages, and protect the security of the Services and other users.
- Apply automated and, where appropriate, human review to a small sample of requests that trip safety filters, to verify that the Services are not being used for prohibited purposes. Reviewers see only the minimum information necessary and are subject to confidentiality obligations.
3.3 Product improvement
- Measure aggregate usage of features, tools, and integrations to decide what to build, deprecate, or harden. This is done from our own server-side request records — there is no third-party product-analytics service in the Services.
- Improve the reliability and quality of our prompt orchestration and routing logic.
- Generate de-identified or aggregated statistics that cannot reasonably be linked back to you or your account.
3.4 Communications
- Send service messages such as confirmations, security alerts, billing notices, and policy updates. These cannot be opted out of while your account is active.
- Send product news, launch announcements, or educational content if you have opted in. You can unsubscribe at any time from the link in those emails or from your Dashboard.
3.5 Legal and compliance
- Comply with our legal obligations, respond to lawful requests from government authorities, and enforce our contracts and policies.
- Establish, exercise, or defend legal claims, and protect the rights, property, or safety of OmniLink, our users, or others.
4. Legal bases for processing (EEA, UK, Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and equivalent laws:
- Performance of a contract to deliver the Services to you, set up your account, and process the requests you submit through the Services.
- Legitimate interests in operating, securing, and improving the Services, preventing abuse, ensuring the integrity of our platform, and growing our business. Where we rely on legitimate interests, we balance our interests against your rights and freedoms.
- Compliance with legal obligations when we are required to retain records for tax, accounting, or anti-fraud purposes, or to respond to lawful government requests.
- Consent for optional activities such as marketing emails, certain cookies, and processing of information you choose to share beyond what is necessary to deliver the Services. You can withdraw consent at any time without affecting the lawfulness of prior processing.
You can ask us which legal basis we rely on for a specific processing activity by writing to privacy@omnilinktechnology.com.
6. Service providers and subprocessors
We engage the following categories of subprocessors. A current list of named subprocessors is available on request to privacy@omnilinktechnology.com and we maintain a subprocessor change notification list that you can subscribe to.
| Category | Example providers | Purpose |
|---|---|---|
| Cloud infrastructure | Google Cloud Run | Hosting of the OmniLink API and static frontend with managed autoscaling and DDoS protection. |
| Database, auth, storage, and account email | Supabase (on AWS) | Managed PostgreSQL, authentication, row-level security, file storage, and the transactional email behind sign-up confirmation and password reset. |
| Third-party AI providers | Google, OpenAI, Anthropic, xAI, OpenRouter | Inference for the AI engine you select for a given agent, called with your own credential for that provider. |
| Payments and billing | Stripe | Payment processing, subscription management, tax calculation, and fraud detection. |
| Push notifications | Firebase Cloud Messaging (Google) | Delivering agent notifications to a mobile device you have registered. Only used if you enable push. |
| Messaging channels you connect | Discord, Slack, WhatsApp (Meta) | Carrying messages between an agent and a channel you chose to connect it to. |
That is the whole list. In particular, we do not use a third-party product-analytics service, a crash-reporting service, an advertising network, or a hosted help-desk tool — support conversations are handled inside OmniLink’s own database rather than sent to a ticketing vendor.
All subprocessors are subject to the data-protection terms in their standard agreements, which limit their use of personal information to the services they provide to us, require them to apply appropriate security measures, and obligate them to assist with subject requests where required by law.
7. AI inputs, outputs, and model training
Because OmniLink is an AI-agent platform, this section explains how prompts and responses are handled in more detail.
7.1 What gets sent to third-party AI providers
When you submit a prompt through the Services, we forward the minimum information required to run the request to the third-party AI provider you have chosen. This typically includes the system prompt, the user message, any tool definitions, the agent’s short-term memory, and prior conversation turns. We do not send your Omni Key, your billing details, or any other account’s data to the model provider.
Be clear about who is doing what here, because it decides whose privacy policy governs your prompts. The call is authenticated with the credential you supplied for that provider. So the prompt arrives in your account with them, is retained on their schedule, is subject to their abuse-review and safety processes, and is visible to you in their console. OmniLink’s role is to assemble the request and forward it; the provider’s role, and the provider’s contract with you, cover what happens to it after that.
7.2 Training on Customer Content
We do not train OmniLink-owned foundation models on Customer Content, and we do not sell or share it with anyone other than the provider you routed the request to.
What we cannot do is promise a training opt-out on your behalf at a provider we are not a party to. Because inference runs on your key, whether a provider may train on your inputs and outputs is set by your agreement with them and by any setting in their console. Most major providers exclude API traffic from training by default; some free tiers do not. Check the policy of the provider you connect — it is your decision to make and yours to change.
7.3 Abuse and safety review
The AI provider you route to runs its own safety filters on your content, on its own terms. On our side, abuse handling is mostly structural — rate limits, per-account ceilings, suspension — but where we are investigating a specific report or a suspected violation of the Acceptable Use Policy, a person at OmniLink may read the relevant content. That is done only for that purpose, only to the extent needed, and under confidentiality obligations.
7.4 Outputs and accuracy
AI outputs are generated probabilistically and may be inaccurate, incomplete, or otherwise unsuitable for your use case. You are responsible for evaluating the accuracy and suitability of any output before relying on it, and for not using outputs in ways prohibited by the Terms of Service or Acceptable Use Policy.
7.5 Local-runtime data
The OmniLink local runtime executes tools on hardware you control. Inputs, sensor readings, file contents, and other tool-side state remain on that device unless the agent itself decides to send them back to the cloud as part of an action or analysis step. You can disable specific tools or restrict the information they expose at any time.
8. International data transfers
The OmniLink application runs in Google Cloud’s
europe-west1 region; our managed database
provider, our payment processor, and the AI provider you
select each operate from their own regions, which may include
the United States. When you use the Services, your personal
information may therefore be transferred to, stored in, and
processed in countries other than the one in which you reside,
including jurisdictions whose data-protection laws differ from
those of your home country. If you need to know where a
specific piece of data sits, ask and we will tell you.
Where required, we rely on lawful transfer mechanisms such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss Federal Data Protection and Information Commissioner’s model clauses, and adequacy decisions, supplemented by technical and organizational measures that take account of the destination country’s legal framework.
You can request a copy of the safeguards we have put in place for international transfers by writing to privacy@omnilinktechnology.com.
9. Data retention
We retain personal information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods include:
| Category | Default retention | Notes |
|---|---|---|
| Account profile | Life of the account | Deleted within 30 days of an account-deletion request made by email (see Section 11), subject to legal holds. |
| Agent profiles and configuration | Life of the account | Deletable at any time from the Dashboard. Never expires on any plan. |
| Conversations and messages | Your plan’s retention window — 30 days on Free through unlimited on Agent Lord | Deletable at any time from the Dashboard. The plan window is not being enforced yet — see below. |
| Short-term memory | Rolling window of recent turns | Cleared on reset, or when an agent goes unused. |
| Model-provider credentials (BYOK) | Until you delete them | Encrypted at rest; deletable from the Dashboard, and revocable at the provider without involving us. |
| Run history for scheduled agents | Your plan’s retention window | Same enforcement caveat as conversations. |
| Our own request and usage logs | 48 hours to 90 days, depending on the log | Rate-limit records 48 hours, per-request usage records 35 days, plan-demand telemetry 90 days. Aggregate, de-identified statistics may be retained longer. |
| Audio for speech-to-text and text-to-speech | Not stored | Streamed in memory and discarded after processing. |
| Billing records and invoices | 7 years | Retained to meet tax and accounting obligations. |
| Support tickets and correspondence | Up to 3 years | Retained to handle follow-up issues and improve support. |
One thing in that table is not yet true, and you should know which. The scheduled job that implements the per-plan retention windows for conversations, messages, idle agent memory, and run history is currently running in report-only mode: it counts what would age out and deletes nothing. So today that history is being retained rather than swept, on every plan. We will announce a date before enforcement starts, so nobody loses history to a policy that began quietly. Everything else in the table — deletion on request, deletion you perform yourself from the Dashboard — happens now.
The window that applies to you is the one attached to your current plan, not the plan you were on when the history was created. Downgrading shortens it, and once enforcement is live, history older than the shorter window will be removed.
When personal information is no longer required, we delete, anonymize, or aggregate it in a manner that prevents re-identification. Backups are retained for a limited period and overwritten on a rolling schedule.
10. How we protect information
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. The full program is described on our Security page. Key measures include:
- Encryption of data in transit with TLS 1.2 or higher and encryption of data at rest by our cloud providers.
- An additional layer of application-level AES-256-GCM encryption on every model-provider credential, with the encryption key held outside the database.
- Multi-factor authentication and least-privilege access for the people who operate the platform.
- Isolation of every account’s data by user id, enforced by Postgres row-level security on browser-originated queries and by scoped queries in the API service.
- Log review, redaction of secrets before logs are written, and rate limiting to contain abuse.
- A documented incident-response process, including breach notification consistent with applicable laws.
For symmetry, the things we do not do are listed just as plainly on the Security page: there is no security certification, no third-party penetration test, and no automated vulnerability scanning today, and Omni Keys are stored as their key value rather than as a hash. Read that page before you decide what to put into an agent.
No method of transmission or storage is perfectly secure. You are responsible for keeping your credentials, Omni Keys, and devices safe. Notify us immediately if you suspect your account or any credentials have been compromised.
11. Your rights and choices
Depending on where you live and the role you have, you may have the following rights regarding your personal information. We honor these rights for all users where it is reasonable to do so, even if a specific law does not require it.
- Access. Request a copy of the personal information we hold about you.
- Correction. Request that we correct inaccurate or incomplete information.
- Deletion. Request deletion of personal information, subject to limited exceptions (for example, where we are required to retain records by law).
- Portability. Receive an export of personal information you provided to us in a structured, machine-readable format.
- Restriction. Ask us to restrict certain processing of your personal information.
- Objection. Object to processing that we base on legitimate interests, including for direct marketing.
- Withdrawal of consent. Withdraw consent for processing that is based on consent, at any time.
- Automated decision-making. Request human review of significant decisions made by automated means without meaningful human involvement. OmniLink does not use personal information to make decisions producing legal or similarly significant effects without human review.
- Complaint. Lodge a complaint with your local data-protection authority. We would appreciate the chance to address your concerns first.
Some of this you can do yourself, right now, from the Dashboard: delete an agent profile, delete a conversation and all of its messages, clear an agent’s short-term memory, delete a stored model-provider credential, and revoke an Omni Key. Those take effect immediately and need no request to us.
Deleting your whole account, and exporting your data, are not self-serve yet. There is no “delete my account” button and no export button in the product today, and we would rather say that than point you at a control that is not there. Both are handled by hand: email privacy@omnilinktechnology.com from the address associated with your account, with “Data subject request” in the subject line, and tell us which you want. The same address is the route for access, correction, restriction, objection, and withdrawal of consent. We may need to verify your identity before completing your request. We will respond within the time required by applicable law, typically within 30 days. You have the right not to be discriminated against for exercising your rights.
If your personal information was provided to us by a Customer (for example, because your employer uses OmniLink), we will forward your request to that Customer and support them in responding to you.
12. Cookies and similar technologies
The web app uses very little of this, and no advertising or tracking technology at all. There is no analytics cookie, no advertising pixel, and therefore no cookie-consent banner to click through — not because we skipped it, but because there is nothing to consent to.
12.1 What is actually stored in your browser
-
Your sign-in session. Authentication is
handled by the Supabase client library, which keeps a
short-lived session token in your browser’s
localStorage— not in anhttpOnlycookie. That is a real trade-off worth knowing: it means a successful cross-site-scripting attack on our page could read the token, and it is why the app ships a strict Content Security Policy. Clearing site data signs you out. - Preferences. Local settings such as theme and the last view you had open.
-
An Omni Key you paste in. Kept in
sessionStoragerather thanlocalStorage, deliberately, so it is discarded when you close the tab instead of persisting on the device.
12.2 Your choices
You can block or delete cookies and site data through your browser settings. Doing so signs you out and clears your preferences; it will not remove anything from your account.
13. Children’s privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, please contact privacy@omnilinktechnology.com so that we can delete the information and close the account. Customers building consumer-facing products on top of OmniLink are responsible for complying with applicable child privacy laws, including COPPA and the GDPR’s rules on consent of children.
14. Third-party services and integrations
The Services may link to or integrate with third-party websites, services, devices, and APIs that we do not own or control. When you connect a third-party service to OmniLink or follow a link off the platform, the third party’s privacy practices apply to the information they collect. We encourage you to review their notices before connecting them.
Third-party AI providers we forward inference requests to process your inputs under their own privacy policies and under your own account with them (see Section 7). Information an agent pulls in from a source you connect remains subject to the terms under which you obtained it.
15. Region-specific disclosures
15.1 European Economic Area, United Kingdom, and Switzerland
OmniLink acts as a controller for the personal information of account owners and Users when we operate the Services generally, and as a processor for Customer Content that Customers submit to deliver their own services. Our Data Processing Addendum, incorporating the Standard Contractual Clauses and the UK Addendum, is available on request and is deemed accepted by enterprise customers under our standard contracting terms.
15.2 California
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (the “CCPA”), California residents have the rights described in Section 11 and the following additional rights:
- The right to know the categories of personal information we collect, the categories of sources, the business purposes, and the categories of third parties with whom we share personal information.
- The right to opt out of the sale or sharing of personal information. OmniLink does not sell personal information for monetary consideration and does not share personal information for cross-context behavioral advertising.
- The right to limit the use of sensitive personal information. We use the limited sensitive personal information we may receive only for permitted business purposes.
15.3 Other US states
Residents of Colorado, Connecticut, Virginia, Utah, Texas, and other states with comprehensive privacy laws have rights comparable to the CCPA. We honor these rights consistent with the requirements of each applicable law. To exercise them, use the contact details in Section 17.
15.4 Brazil
If the Brazilian General Data Protection Law (LGPD) applies, you have the rights of confirmation, access, correction, anonymization, blocking, deletion, portability, information about sharing, and revocation of consent. Our representative for LGPD matters can be reached through the contact details below.
15.5 Australia
If the Australian Privacy Act applies, you have the rights to access and correct your personal information and to make a complaint about how we handle it. You can complain to the Office of the Australian Information Commissioner if you are not satisfied with our response.
16. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by posting the updated Policy on this page, updating the “Last updated” date at the top, and, where appropriate, sending a notice through the Dashboard or by email. We encourage you to review this Policy periodically. Your continued use of the Services after the effective date of a revised Policy indicates your acceptance of the changes.
17. How to contact us
If you have questions, complaints, or requests regarding this Policy or your personal information, contact us at:
- Email (general privacy inquiries)
- privacy@omnilinktechnology.com
- Email (data subject requests)
- privacy@omnilinktechnology.com with subject line “Data subject request.”
- Email (security)
- security@omnilinktechnology.com
- Postal mail
- OmniLink Technology Inc., Attn: Privacy, available on request through the privacy email above.
If your data-protection authority requires a single point of contact in your region, we will provide one on request.