Privacy Policy
Last updated · May 1, 2026
OmniVAI is built around a simple promise: collect the minimum needed to run the studio, never sell what we collect, and give you complete control over your data.
What we collect
- Account profile. Email, display name, optional avatar, language preference.
- Content you create. Prompts, uploaded references, generated outputs, library assets, projects, comments.
- Billing. Plan, credit balance, transaction history. Card numbers are handled by Stripe and never reach our servers.
- Usage telemetry. Which models you used and how many credits each request consumed — needed for quotas and quality monitoring.
- Device data. IP address, browser, and basic security signals to detect abuse.
How we use it
- Deliver the studio (auth, generation, library, sharing).
- Bill you and prevent fraud.
- Send service emails (receipts, security alerts, password resets). Marketing email is opt-in only.
- Improve the product through aggregated, anonymized analytics.
- Respond to legal requests when valid and required.
We do not use your prompts or generations to train models. We do not sell your data to advertisers or data brokers.
Who we share it with
Generation requests are forwarded to the model provider you selected. Stripe handles payments. A full live list is on our Sub-processors page.
Social media capabilities provided by Ayrshare.
Connected social accounts
When you connect a social account so the platform can publish on your behalf, we only receive what is needed to post and track the result.
- What we access. The account name, avatar, account type, and the performance metrics of posts published through the platform.
- What we never access. Private messages, follower lists, or posts not published through the platform.
- Where it goes. Publishing is handled by a third-party provider. Access tokens are held by that provider, not stored by us.
- How to revoke. You can disconnect any account at any time from the Connections page inside Social Studio, or from the social platform’s own settings.
- Retention. After you disconnect an account, the provider can no longer publish for you. We keep a record of posts already published so you can still view historic performance, but we delete that history when you delete your account.
How long we keep it
- Account data: until you delete your account.
- Generations & library: until you delete them, or 30 days after account deletion.
- Billing records: 7 years (legal retention requirement).
- Security logs: 90 days.
Google sign-in and Google user data
If you sign in with Google, we receive only your name, email address, Google account ID and profile picture — the minimum needed to create and secure your account. We never request access to Gmail, Drive, Contacts or Calendar.
- Google user data is used only to authenticate you and display your profile inside the studio.
- We do not transfer Google user data to third parties except as needed to run the service (hosting and authentication infrastructure), for security, or where the law requires it.
- Google user data is never used for advertising, and never used to train AI models.
- You can revoke our access at any time at myaccount.google.com/permissions; deleting your OmniVAI account deletes the stored Google profile data.
OmniVAI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies and analytics
We use strictly necessary cookies for sign-in and security, and privacy-respecting analytics to understand product usage in aggregate. We do not run third-party advertising trackers or sell audience data. Details and controls are on our Cookies page.
Where your data is processed
OmniVAI is operated from the United Arab Emirates and our infrastructure and model providers may process data in the EU and the United States. For transfers out of the EEA, UK or Switzerland we rely on Standard Contractual Clauses with each processor — see our GDPR / DPA page.
How we protect it
Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to staff who need it and is logged. Row-level security isolates every account’s content. If a breach affects your personal data, we notify affected users and the relevant regulator without undue delay.
Your rights
You can access, export, correct, or delete your data at any time from Settings → Account. You may also object to or restrict certain processing, and withdraw consent where processing is consent-based. EEA, UK and Swiss users have additional rights detailed on our GDPR page. Email privacy@omnivai.ai and we respond within 30 days. You also have the right to complain to your local data-protection authority.
Children
OmniVAI is not directed at children under 16. If we learn we have collected personal data from a child without parental consent, we delete it.
Changes
We notify active users by email at least 30 days before any material change. This policy was last updated on the date shown above.
Who we are & how to contact us
OmniVAI is the data controller for the personal data described here.
OmniVAI — Dubai, United Arab Emirates.
Privacy: privacy@omnivai.ai · General: hello@omnivai.ai
Questions about this policy? Email legal@omnivai.ai
Back to OmniVAI