Privacy and account controls
Privacy notice
This draft includes the operator-approved identity and retention policy. Operational verification of deletion and encrypted backup rotation, plus the complete processor disclosures, is still pending. This notice is not marked release-approved.
Operator and controller
OMNIMIND is operated by Michail Aristidou as an individual operator and controller. Contact the operator at master@omnimindai.app.
The information you choose to save
OMNIMIND stores your account information, saved memories, uploaded documents and media, extracted fields, dates, reminders and other information you enter. Features you enable may also store family sharing permissions, study and medication schedules, notification registrations, plan state and security records.
Purposes and proposed legal bases
We use account details to authenticate you and saved content to provide storage, retrieval, requested AI processing, reminders and sharing. This draft proposes contract necessity under Article 6(1)(b) for those requested services. Limited security and abuse prevention serve the legitimate interests of protecting accounts and the service under Article 6(1)(f). Information required by an applicable legal duty uses Article 6(1)(c); optional processing that expressly asks for consent uses Article 6(1)(a).
These proposed bases require operator legal review before this notice is finalized. Health and other special-category information also require an applicable Article 9 condition; a general service basis alone does not establish that condition. The eligibility and safeguards for such information remain part of that review. Account details are needed for sign-in; uploads are optional, and a requested feature cannot process content you do not provide.
Hosting and encryption
The production service runs on Hetzner infrastructure. Connections to the public website use HTTPS. Private notes and private Vault media use encryption with keys managed by the server. Ordinary uploaded documents are stored separately and do not have the same application-level encryption. This is not end-to-end encryption; server operators and infrastructure access remain relevant to privacy.
How AI uses your information
The configured deployment processes selected note and document text with a local AI model on the same Hetzner infrastructure. OCR reads scanned document images locally, and the candidate voice pipeline uses local speech transcription. Your requests still require content processing by server-side software. AI output can be inaccurate; check important fields and answers against the original source.
The current deployment has no external OpenAI API key configured. Changes to AI providers or processing locations must be disclosed before use. Processing and model quality release checks remain separate from this description of the configured architecture.
Recipients and delivery providers
Hetzner supplies the hosting infrastructure used for application processing and storage. Authorized operators may access infrastructure for maintenance, security and support. Information you explicitly share can be available to the members you authorize.
Email you send to the support address passes through your mail provider and the operator's support mailbox provider. Send only what is necessary for your request. Browser push, when enabled and used, involves your browser's push service and may send an endpoint, encrypted notification and delivery metadata. Browser-push delivery is still being verified.
Application email delivery is currently disabled, and mobile FCM/APNS delivery is not configured. An available support mailbox does not establish that the app can send recovery emails. These inactive application delivery integrations are not described as receiving your saved content.
Provider locations, contractual safeguards and any transfer outside the EEA still require provider-specific review before this draft is finalized. Hosting on Hetzner alone does not establish the location of support-email or browser-push processing. Request the current recipient and transfer information from the operator before relying on it.
Access and sharing
Account data is scoped to your account. Sharing features use explicit permissions. The owner dashboard is designed for operations and does not include a private-content reader; this does not remove the access available to a server administrator.
Your controls
You can view your saved items, export account information and use password-confirmed account deletion in account settings. You can control browser notification permissions on your device and revoke sharing. Review the retention policy below before deleting information.
Privacy rights and requests
Where applicable, you may request access, correction, deletion, restriction and portability of your personal information, and object to processing based on legitimate interests. You may withdraw consent for processing based on consent without affecting earlier lawful processing, and complain to a competent data-protection authority.
Send requests to master@omnimindai.app. The operator may request only information needed to verify your identity. Do not send a password or access token. Requests are handled without undue delay, normally within one month; any permitted extension must be explained within that first month.
The disclosure framework follows the GDPR, including Article 13. This reference does not certify legal compliance or finalize the proposed bases above.
Deletion and retention
The approved policy requires deleted content and accounts to be removed from active systems within 30 days. Encrypted disaster-recovery and system backups expire under normal rotation within 90 days. Backup copies are not ordinarily restored to retrieve deleted information. Where feasible, recorded deletions are reapplied after disaster recovery.
Only the minimum information necessary may be retained longer for legal, accounting, fraud, security or dispute duties. Verification of these operational controls is still in progress; this draft does not claim that backup encryption, rotation or recovery has passed its release checks.
Cookies and browser storage
The app uses localStorage for the account session and your language preference. These are functional storage, not advertising or nonessential analytics. You can sign out to remove the active session and clear site storage in your browser; clearing it also removes saved browser preferences. Do not keep a confidential session on a shared browser.
Security records
Limited security and authentication logs support account protection and abuse prevention. They must not include document or memory content, passwords or tokens. The approved retention limit is 30 days, with bounded rotating logs. Enforcement is being verified before this notice is finalized.
Questions and requests
See support information for the available account controls and the contact address. Account and privacy requests can also be sent to master@omnimindai.app.