OMINA
Legal
Privacy Policy
Effective 28 August 2026 · Last updated 28 August 2026
The short version.
- We never sell your data and we run no advertising.
- Everything we ask of Google and Microsoft is read-only. Omina cannot write to your calendar and cannot send mail as you.
- From your mailbox we store metadata only — sender, recipients, subject, date, thread, and the short preview line your provider already generates. We do not store message bodies.
- Calendar and mail are kept in a rolling 90-day window and older records are deleted automatically.
- Connecting your calendar and mail is optional. You can decline at sign-in, connect later, disconnect at any time, and ask us to delete everything.
1. Who we are
Omina ("Omina", "we", "us") is a software product that helps founders become legible to the rooms that matter — investors, buyers, or media. This policy covers the website at getomina.com and the application at app.getomina.com.
For anything in this policy, including access and deletion requests, write to hello@getomina.com. We answer privacy requests within 30 days.
2. What we collect
Account information
Omina has no passwords. You sign in with Google or Microsoft, and we receive from that provider your name, email address, profile picture, and the provider's own account identifier. We also store the OAuth access and refresh tokens that keep you signed in; these are held encrypted and are never exposed to your browser.
What you tell us
- Your profile: role, company, industry, the customers you are trying to reach, and the goal you picked.
- Birth date, time and place, if you provide them. These are used for one purpose — computing the personality chart Omina uses to help you articulate your own positioning. They are personal data and are treated as such: stored with your profile, never shared, never used for any other purpose, and deleted with your account.
- The people you add, the notes you keep on them, the messages you draft, and the outcomes you log.
- Anything you type into the product, including your answers in the guided interview.
Google Workspace data — only if you connect it
Sign-in alone asks for your identity and nothing else. Calendar and mail access is a separate choice you make on the same consent screen, or later from Settings. If you grant it, we request exactly two scopes:
Both scopes are read-only. Omina has no ability to create, modify or delete calendar events, and no ability to send, modify or delete mail.
Microsoft data — only if you connect it
The Microsoft equivalents are Calendars.Read and Mail.ReadBasic, and they produce the same records described above. Mail.ReadBasic withholds message bodies at the permission level, so on Microsoft the metadata-only promise is enforced by Microsoft rather than by us.
Operational records
We keep a ledger of the third-party API calls made on your behalf — which job ran, how many tokens it used, and what it cost — so that spending is visible inside the product instead of only in vendors' dashboards. We also keep ordinary server logs. Neither contains message bodies.
3. What we do with it
Omina is a loop: it learns who you are, shows you where the people you need are gathering, helps you follow up, and records what happened so the next suggestion is better. Everything we collect serves that loop:
- Your profile and goal shape which rooms and people are surfaced to you.
- Your calendar tells us which rooms you actually attended, so we can ask you how they went and stop suggesting ones you have already decided about.
- Your mail metadata tells us who you are already in contact with and whether a conversation got a reply. That is the single strongest signal for ranking who to follow up with. We use who, when and which thread — not what was said.
- Outcomes you log feed back into the profile so later suggestions reflect what actually worked.
We do not use your data to build profiles of anyone for sale, to target advertising, or for any purpose you did not come here for.
4. Google user data — Limited Use
In practice that means, specifically:
- We use Google user data only to provide and improve the features described in this policy, and for no other purpose.
- We do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to you.
- We do not use Google user data for advertising of any kind.
- We do not allow humans to read your Google user data, except where you have given specific consent, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
- We do not use Google user data to develop, improve or train generalised artificial-intelligence or machine-learning models.
5. Artificial intelligence, and what reaches a model
Omina uses large language models to compose your map, structure search results, and draft follow-up messages in your voice. When you ask for one of those things, the context needed for that request is sent to our model provider over an encrypted connection.
What is deliberately not sent: message bodies, which we do not have. Where a request does involve information that originated in your calendar or mailbox — a meeting title, a person's name and address you accepted into your contacts — it is sent only to fulfil the request you made, under contractual terms that prohibit using it to train the provider's models. Model output is a suggestion for you to review; nothing is sent to anyone on your behalf without you pressing send.
6. Who else touches your data
We do not sell your data or share it for anyone else's marketing. We use a small number of vendors to run the product, each with access limited to what their job needs:
We may also disclose data if legally required to, and we will tell you unless we are prohibited from doing so.
7. Where it lives, and how it is protected
Your data is stored in Cloudflare's D1 database and moves over TLS everywhere. OAuth tokens and any private feed addresses you add are additionally encrypted at rest with AES-GCM using a key held only by the server; they are never written to your browser's storage. Every query in the application is scoped to your workspace.
No system is perfect, and we will not pretend otherwise. If we ever discover a breach affecting your data, we will tell you.
8. How long we keep it
- Calendar events and mail metadata: a rolling 90-day window. Records older than that are deleted automatically on each sync. Nothing is ever deleted from Google or Microsoft — the older data is simply no longer ours to hold.
- Message bodies: never stored, so nothing to retain.
- Your profile, contacts, drafts and outcomes: kept while your account exists, because they are the product's memory.
- Operational logs and the usage ledger: kept for a limited period for security and accounting.
9. Your choices
- Decline. You can sign in without granting calendar or mail access. The product works with less in it, and says so honestly rather than inventing filler.
- Disconnect. Revoke Omina's access at any time from your Google account permissions or the equivalent Microsoft page. Access stops immediately.
- Delete. Ask us at hello@getomina.com and we will delete your account and its data, including everything derived from your calendar and mailbox.
- Access and correction. Ask and we will tell you what we hold and correct anything wrong. Depending on where you live you may also have rights of portability and objection under the GDPR, the LGPD, or comparable law; we honour them regardless of where you are.
Revoking access stops future syncing but does not by itself delete what we already hold — ask us for deletion if that is what you want.
10. Children
Omina is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
11. International transfers
Omina is operated from the United States and our vendors run globally, so your data is processed in the United States and may be processed elsewhere. If you are in the European Economic Area, the United Kingdom, or Brazil, that means your data leaves your country. Where the law requires a transfer mechanism for that, we rely on the standard contractual clauses our vendors publish.
12. Changes
If we change this policy in a way that materially affects what happens to your data, we will tell you in the product or by email before it takes effect. The effective date at the top always reflects the current version.
13. Contact
Questions, requests, or anything that looks wrong on this page: hello@getomina.com.