OMINA

Legal

Privacy Policy

Effective 28 August 2026 · Last updated 28 August 2026

The short version.

1. Who we are

Omina ("Omina", "we", "us") is a software product that helps founders become legible to the rooms that matter — investors, buyers, or media. This policy covers the website at getomina.com and the application at app.getomina.com.

For anything in this policy, including access and deletion requests, write to hello@getomina.com. We answer privacy requests within 30 days.

2. What we collect

Account information

Omina has no passwords. You sign in with Google or Microsoft, and we receive from that provider your name, email address, profile picture, and the provider's own account identifier. We also store the OAuth access and refresh tokens that keep you signed in; these are held encrypted and are never exposed to your browser.

What you tell us

Google Workspace data — only if you connect it

Sign-in alone asks for your identity and nothing else. Calendar and mail access is a separate choice you make on the same consent screen, or later from Settings. If you grant it, we request exactly two scopes:

ScopeWhat we readWhat we store
calendar.readonly Events on your primary calendar. Title, a truncated description, location, start and end time, whether it is all-day, status, the organiser's email address, attendee names and email addresses (up to 50 per event), and the event's link. Cancelled events are deleted rather than kept.
gmail.readonly Message headers and labels. Metadata only: sender name and address, recipient addresses, subject, the timestamp, Gmail's own ~100-character snippet, the label list, and the thread identifier. No message bodies are ever written to our database. If you open a specific message inside Omina, that one body is fetched live from Google, shown to you, and discarded — it is not stored.

Both scopes are read-only. Omina has no ability to create, modify or delete calendar events, and no ability to send, modify or delete mail.

Microsoft data — only if you connect it

The Microsoft equivalents are Calendars.Read and Mail.ReadBasic, and they produce the same records described above. Mail.ReadBasic withholds message bodies at the permission level, so on Microsoft the metadata-only promise is enforced by Microsoft rather than by us.

Operational records

We keep a ledger of the third-party API calls made on your behalf — which job ran, how many tokens it used, and what it cost — so that spending is visible inside the product instead of only in vendors' dashboards. We also keep ordinary server logs. Neither contains message bodies.

3. What we do with it

Omina is a loop: it learns who you are, shows you where the people you need are gathering, helps you follow up, and records what happened so the next suggestion is better. Everything we collect serves that loop:

We do not use your data to build profiles of anyone for sale, to target advertising, or for any purpose you did not come here for.

4. Google user data — Limited Use

Omina's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice that means, specifically:

5. Artificial intelligence, and what reaches a model

Omina uses large language models to compose your map, structure search results, and draft follow-up messages in your voice. When you ask for one of those things, the context needed for that request is sent to our model provider over an encrypted connection.

What is deliberately not sent: message bodies, which we do not have. Where a request does involve information that originated in your calendar or mailbox — a meeting title, a person's name and address you accepted into your contacts — it is sent only to fulfil the request you made, under contractual terms that prohibit using it to train the provider's models. Model output is a suggestion for you to review; nothing is sent to anyone on your behalf without you pressing send.

6. Who else touches your data

We do not sell your data or share it for anyone else's marketing. We use a small number of vendors to run the product, each with access limited to what their job needs:

VendorWhat they do
CloudflareHosting, the database, and the network in front of it. Your data is stored here.
Google (Gemini API)The language model behind drafting, curation and structuring.
AnthropicA second language-model provider. No job is routed here today; it is listed because the product can switch providers per job, and we would rather name it in advance than change this page after the fact.
ExaWeb search over public sources, used to find rooms and public information about companies. Queries are derived from your goal and profile, not from your mail.
ApifyCollecting public event listings from one source that publishes no API. Involves no personal data of yours.

We may also disclose data if legally required to, and we will tell you unless we are prohibited from doing so.

7. Where it lives, and how it is protected

Your data is stored in Cloudflare's D1 database and moves over TLS everywhere. OAuth tokens and any private feed addresses you add are additionally encrypted at rest with AES-GCM using a key held only by the server; they are never written to your browser's storage. Every query in the application is scoped to your workspace.

No system is perfect, and we will not pretend otherwise. If we ever discover a breach affecting your data, we will tell you.

8. How long we keep it

9. Your choices

Revoking access stops future syncing but does not by itself delete what we already hold — ask us for deletion if that is what you want.

10. Children

Omina is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.

11. International transfers

Omina is operated from the United States and our vendors run globally, so your data is processed in the United States and may be processed elsewhere. If you are in the European Economic Area, the United Kingdom, or Brazil, that means your data leaves your country. Where the law requires a transfer mechanism for that, we rely on the standard contractual clauses our vendors publish.

12. Changes

If we change this policy in a way that materially affects what happens to your data, we will tell you in the product or by email before it takes effect. The effective date at the top always reflects the current version.

13. Contact

Questions, requests, or anything that looks wrong on this page: hello@getomina.com.

make your technology legible Home · Terms · © 2026 Omina