Last Updated: 2026-05-07
Version: 1.0
Effective Date: May 21, 2026
This Privacy Policy explains how Teo Bridoux, an individual sole proprietor d/b/a Omnilys ("Omnilys", "we", "us"), collects, uses, shares, and protects information when you use the Omnilys service at omnilys.com and any related software (the "Service").
This Policy is designed to satisfy the California Consumer Privacy Act / California Privacy Rights Act ("CCPA/CPRA"), and to extend equivalent rights to users elsewhere (including the EU/UK GDPR and the Swiss FADP) as a courtesy.
If anything here is unclear, write to us at privacy@omnilys.com.
The rest of this Policy is the formal version with the detail regulators expect.
Operator: Teo Bridoux, sole proprietor d/b/a Omnilys
Based in: San Diego, California, USA
Mailing address: Available on request — write to legal@omnilys.com
Privacy contact: privacy@omnilys.com
Legal contact: legal@omnilys.com
Omnilys is a U.S.-based service. Our servers are operated by Railway, Inc. and located in us-west2 (Oregon, USA).
We are the "business" under the CCPA/CPRA when you use the Free Tier or use the Pro Tier without BYOK. When you use BYOK on Pro, we are still the business with respect to your account information and the analyses you store with us, but the actual AI model API calls and any data sent through them are billed and transmitted on your account, not ours.
For B2B customers who sign a Data Processing Agreement (DPA) with us, we act as a service provider (CCPA) / processor (GDPR) for your end users' personal information.
When you create an account we collect: your email address, a bcrypt-hashed password (we never store the plain password), an account creation timestamp, and email-verification status.
If you fill out the optional company profile, we collect the company name, industry, KPIs, and competitor list you provide. This is used to give the AI Models more context for your analyses.
If you save your own API keys (Anthropic, OpenAI, Google, xAI) in Settings, we store them encrypted at rest in our user database. We use them to call those AI Models on your behalf. We do not show them back to you in plain text after saving (only a "Saved" status indicator).
When you run an analysis, you provide data in one of these ways:
The data we send to AI Models is a text summary computed from your data: column names, types, statistics (min, max, mean, distribution), correlations, outliers, and a sample of actual rows (typically 50–120 rows). The summary contains real values from your data — including column names that you may consider sensitive (e.g. employee names, customer IDs, revenue figures). It is not anonymized.
We store the outputs of each analysis on our servers in a SQLite database. These outputs include:
These outputs are kept until you delete the job or close your account.
If you set up a scheduled analysis or alert, we store: the schedule definition, the destination (email, Slack webhook, custom webhook), and a record of each scheduled run.
If you invite teammates to a workspace, we store the workspace name, the invited email addresses, the role assigned to each member, and acceptance status of pending invites.
When you subscribe, we collect your billing email, plan, and a Stripe customer ID. We do not store your credit-card number — that is held by Stripe. Stripe sends us webhook events recording successful payments, cancellations, and disputes.
We automatically collect, when you use the Service:
We use a small number of strictly-functional cookies and browser-storage items. See the Cookie Notice at /cookies for the full list.
We do not collect: your real-time location, your device sensors, your microphone or camera, your contacts list, advertising identifiers (we run no ads), or biometric data.
We use the information described above for the following purposes (CCPA "business purposes" / GDPR "purposes of processing"):
We rely on the following legal bases under the GDPR (for users to whom GDPR applies):
| Purpose | Legal basis |
|---|---|
| Providing the Service to you | Contract (Art. 6(1)(b)) |
| Sending billing communications | Contract |
| Account security, fraud prevention | Legitimate interest (Art. 6(1)(f)) — securing the Service |
| Aggregated, anonymized analytics | Legitimate interest — improving the Service |
| Material changes / legal updates | Legal obligation (Art. 6(1)(c)) and Contract |
| Marketing emails (if any, and opt-in only) | Consent (Art. 6(1)(a)) |
We do not engage in "automated decision-making with legal or similarly significant effects" within the meaning of GDPR Article 22 with respect to you. (Output from the Service may be used by you for such decisions; see Terms §9 — that is your responsibility, not ours.)
We do not sell personal information. We do not "share" personal information for cross-context behavioral advertising as defined under the CCPA/CPRA. We have not done so in the prior 12 months.
If this ever changes, this Policy will be updated and (where required) a "Do Not Sell or Share My Personal Information" link will appear on our website.
We share personal information only with the categories of recipients below, and only as necessary to operate the Service. The complete current list with provider names is at /subprocessors.
| Category | What they do | What they receive |
|---|---|---|
| AI Model providers (Anthropic, OpenAI, Google, xAI) | Run inference on the data summary to produce findings | The data summary (which contains real values from your Customer Data), your question, and your company-profile context. Free Tier: routed through our API accounts. Pro Tier with BYOK: routed through your accounts. |
| Hosting (Railway) | Run our application servers and store the SQLite databases | All data stored by the Service, at rest |
| Payments (Stripe) | Subscription billing | Billing email, plan, charge events. We do not give Stripe your Customer Data. |
| Email delivery (Gmail SMTP) | Verification emails, password resets, scheduled-report emails | Recipient email and email content (which may include analysis findings on scheduled reports) |
| Error monitoring (Sentry) | Capture crash reports to fix bugs | Stack traces, request paths, masked user identifiers. We configure Sentry to scrub Customer Data from error events. |
| DNS (Namecheap) | Domain name resolution | Domain configuration only |
| Customer-supplied destinations | Slack, custom webhooks for notifications | Whatever data you've configured to send. You control these. |
We require each of the above to maintain reasonable security and to use the data only to provide their services to us, except where they are independent controllers (like Stripe for fraud prevention).
We may also disclose personal information:
We are based in the United States and our infrastructure is in Oregon, USA. Some of our subprocessors are also U.S.-based (Anthropic, OpenAI, Stripe, Sentry, Railway). Some have global infrastructure (Google).
If you are in the EU, UK, or Switzerland, your information will be transferred to the United States. We rely on:
You can request a copy of our transfer safeguards at privacy@omnilys.com.
| Data | Retention |
|---|---|
| Account email, hashed password, profile | Until you delete your account |
| Saved API keys (BYOK) | Until you remove them or delete your account |
| Customer Data — raw uploaded files | Deleted from disk within minutes of the analysis completing (or sooner on cancel/error) |
| Customer Data — database/Sheets connection content | Held in memory for the duration of the analysis only; not persisted |
| Customer Data — sent to AI Model providers | Per the AI provider's retention policy (see §6 link). We do not control AI providers' retention. |
| Analysis findings, conflicts, narrative reports | Until you delete the job or close your account |
| Workspace and team data | Until you leave the workspace or close your account |
| Billing records | 7 years (U.S. tax-record retention) |
| Server access logs | 30 days |
| Sentry error events | 90 days |
| Backups (encrypted, off-site) | 30 days rolling |
When you close your account, we delete or anonymize personal information within 30 days of the account closure, except (i) information we are required by law to retain (billing records), and (ii) information in encrypted backups, which is purged on the rolling 30-day backup cycle.
You can do all of the following at any time, without paying a fee:
GET /auth/data/export.)In addition to §9.1, you have the right to:
To exercise these rights, write to privacy@omnilys.com or use the in-product controls. We will verify your identity using your account login and respond within 45 days (extendable by 45 more days where allowed).
You can designate an authorized agent to make a request on your behalf. We will require proof of authorization.
In addition to §9.1, you have the right to:
We do not appoint a EU representative because we do not target EU customers as our primary market. EU users may still contact us at privacy@omnilys.com.
We take reasonable measures to protect personal information against loss, theft, misuse, and unauthorized access. These include:
No method of transmission or storage over the internet is 100% secure. If we discover a breach affecting your personal information, we will notify you and, where required, the relevant regulator within the time required by law (e.g., 72 hours for GDPR-covered users).
To report a security issue, email security@omnilys.com. We commit not to pursue legal action for good-faith research that complies with our [Responsible Disclosure Policy] (forthcoming).
The Service is not intended for, and we do not knowingly collect data from, children under 16. If you believe we have collected data from a child, write to privacy@omnilys.com and we will delete it.
Some browsers send a "Do Not Track" signal. There is no consensus standard for how websites should respond. Our Service does not change behavior based on this signal because we do not track you across sites for advertising. We honor the more recent Global Privacy Control (GPC) signal as an opt-out request under the CCPA/CPRA.
We may update this Policy. Material changes will be announced by email and at the top of the page at /privacy at least 30 days before they take effect, unless the change is required by law, in which case we will give as much notice as the law allows. Continued use after the effective date means you accept the change.
| For | Contact |
|---|---|
| General privacy questions | privacy@omnilys.com |
| Subject-rights requests (CCPA/GDPR/FADP) | privacy@omnilys.com |
| Security reports | security@omnilys.com |
| Legal/disputes | legal@omnilys.com |
| Postal mail | Available on request via legal@omnilys.com (Operator: Teo Bridoux d/b/a Omnilys, San Diego, California, USA) |
[LAWYER REVIEW] before publishing. Particular attention to: §3.3 (data sent to AI providers — confirm subprocessor disclosures match actual data flow), §8 retention periods (verify against your actual code), §9.2 CCPA notice content for completeness, §10 security claims (do not over-claim — only state what is actually implemented), and the §7 international transfers section if you decide to actively target EU customers.