Privacy Policy
What we collect, why we collect it, and the choices you have. The short version: we collect the minimum to run the service, and we never sell it.
1. What we collect
- Account data: email address, hashed password (or OAuth identity), and account preferences.
- Your memories: the structured context you (or your connected clients) write to your vault.
- Operational data: timestamps, request logs, and metadata required to keep the service running and secure.
2. How we use it
To store, structure, and sync your memories as you direct. To authenticate you. To prevent abuse. To bill paid accounts. That's it.
3. How we don't use it
We do not sell your data. We do not train our models — or any third party's models — on your memories. Your content is never an input to model training. See How AI interacts with your data.
4. Sharing
We share data only with the subprocessors required to run the service, under contracts that limit their use. We disclose data to authorities only when legally compelled, and we will notify you unless prohibited.
5. Your rights
- Access and export: Export your data
- Deletion: Delete your data
- Revoke client access: Connected apps
- End active sessions: Active sessions
EU and UK users have additional rights under GDPR — see our Data Processing Addendum.
6. Retention
We keep your memories for as long as your account is active, and for up to 30 days after deletion (in case of accidental removal). Details in Data retention.
7. Security
Encryption in transit and at rest, strict access controls, and least-privilege engineering. See Security.
8. International transfers
OmegaVault may process data in multiple regions. We rely on Standard Contractual Clauses and adequacy decisions for cross-border transfers.
9. Contact
Privacy questions: hello@omegavault.app.