Omni

Privacy Policy

Last updated 2026-09-26

Omni operates an omnichannel inbox: businesses ("customers") connect their website chat widget, WhatsApp, Instagram, Messenger and email accounts so their support and sales teams can reply to end customers ("contacts") from one shared inbox. This policy describes what we process to provide that service, both for our customers (the organizations that sign up) and for the contacts who message them.

Data we process

  • Channel messages — the content of messages, comments and their attachments sent between a contact and a customer's connected channel accounts.
  • Contact details — names, phone numbers, email addresses and any custom fields a customer records about the people who message them.
  • Email content — for customers who connect an email channel (Gmail, Outlook or IMAP), the messages in that mailbox's threads.
  • Account and usage data — staff/agent accounts, login sessions, audit logs of actions taken in the product, and product usage needed for billing.
  • AI processing — when a customer enables AI features (reply suggestions, summaries, auto-labeling, knowledge-base search), message content is sent to third-party model providers to generate a response; knowledge-base documents are converted into embeddings for retrieval.

Subprocessors

We rely on the following subprocessors to run the service:

  • AWS — hosting, databases and backups.
  • Cloudflare — CDN, DNS, edge security and object storage.
  • Stripe — billing and payment processing.
  • Anthropic — AI reply suggestions, summaries and other generative AI features, when a customer enables them.
  • OpenAI — knowledge-base embeddings for AI-powered search and retrieval.
  • Resend / Amazon SES — transactional email (invites, alerts, receipts).
  • Expo — push notifications to our mobile app.

Where data is stored

Customer data is hosted in AWS Sydney (ap-southeast-2) or AWS Mumbai (ap-south-1), depending on which region a customer's organization is provisioned in. Each organization's data is isolated at the database level and encrypted with its own data key.

Retention

Data is kept for as long as needed to provide the service, then removed on the following schedule:

  • Messages — up to 13 months in the live database (or the customer's plan history length), then archived and exported.
  • Conversation activity and AI run history — 13 months, then rolled into aggregate usage counters.
  • Audit logs — 24 months, then archived.
  • Raw webhook payloads — 14 days, then deleted.
  • Deleted or erased data — removed from live systems immediately; encrypted backups age out after 35 days.

Your rights

Depending on where you are, you may have rights to access, correct or delete your personal data, including under the Australian Privacy Principles (Privacy Act 1988, Cth) and Nepal's Individual Privacy Act 2075 (2018). See Data Deletion for how to request deletion.

Contact

Questions about this policy? Email privacy@example.com.