1. Scope
This policy applies to the OmniTerm website, applications, and services that OmniTerm operates, including managed accounts, encrypted vault synchronization, relays, and support communications. Features and data flows depend on the platform, release, and settings you use.
It does not cover a server or device you connect to, a self-hosted deployment operated by you or your organization, or a third-party product or website. Those operators set their own privacy practices. If your organization provides your OmniTerm account, its administrators may also set rules for that account.
"OmniTerm," "we," and "us" refer to the operator of the OmniTerm service. Privacy requests can be sent to support@omnisolo.co.
2. Information we handle
Account and sign-in information
If you create or use a managed account, we handle information such as your email address, account identifier, sign-in method, verification status, and account or subscription settings. If you sign in with Google or Apple, those providers send us the identifiers and profile details needed for the sign-in you requested. If you use a passkey, the service handles its public credential and related sign-in records; your private passkey material remains with your authenticator.
Workstation and connection information
OmniTerm can store or use connection profiles, host names or IP addresses, ports, user names, labels, snippets, preferences, and credential references. Depending on the features and storage mode you choose, this may also include passwords, SSH keys, API keys, files, command history, or other content. Some information stays on your device; information you choose to sync or submit to a service is handled as described below.
When you connect to a remote host, session data can include commands, terminal output, files, clipboard content, screen content, or other data you exchange with that host. The app sends data to the host you selected. A managed or third-party relay may also transport session traffic when that connection route requires it. Connection routes and protocols differ, so OmniTerm does not make a blanket claim that every route is invisible to relay infrastructure or end-to-end encrypted in the same way.
Vault and sync information
If you enable account-backed vault sync, the client sends encrypted vault records for synchronization. The service also handles the account, vault, record, revision, device, and access information needed to authenticate, synchronize, resolve conflicts, and apply sharing permissions. Associated metadata is not necessarily encrypted together with vault content.
AI and voice information
When you use an AI feature, a request may include the prompt you enter and relevant context for that feature, such as visible terminal text, a recent command and its output, a selected file's path or contents, a working directory, or recent command history. If you activate speech or voice input, the speech or its resulting transcript may also be processed to provide that feature. Some request paths attempt to redact common secrets, but redaction can miss sensitive information. Review context before sending it and do not submit information you are not comfortable sharing with the selected provider.
AI request and usage metadata, such as the account, model, request size, timing, and metering status, may be processed to provide the service, enforce limits, and account for usage.
Purchases and support
For paid features, we may receive purchase or subscription identifiers, product and platform details, transaction status, and entitlement information from the applicable store or billing service. Payment providers handle payment credentials. If you contact support or request beta access, we handle the contact details and message content you send.
Technical and security information
When a device or browser contacts an OmniTerm-operated service, the service and its infrastructure providers may process the IP address, request time, browser or device details, requested endpoint, connection identifiers, authentication and security events, and diagnostic or error information. We use this information to deliver the service, secure accounts and connections, prevent abuse, troubleshoot failures, and meet legal obligations.
3. How we use information
We use information to operate and maintain OmniTerm; authenticate users and devices; synchronize vault records; establish and route connections; provide features you request, including AI assistance; manage subscriptions and entitlements; respond to support requests; diagnose, secure, and improve the service; prevent fraud or abuse; and comply with law.
We do not use terminal or AI content for advertising. We do not sell personal information or share it for cross-context behavioral advertising.
4. Local storage and vault sync
Depending on the client, information such as settings, connection profiles, caches, and local history may be stored on your device or in browser storage. The protections available depend on your operating system, device security, and configuration. You can remove local information through the app, browser, or device controls where those controls are available.
Vault sync is optional. Supported vault record contents are encrypted by the client before upload; the managed service receives ciphertext and the metadata needed to synchronize and authorize access. Encryption does not cover every category of account or service metadata, and this description does not mean every OmniTerm feature or connection mode is end-to-end encrypted.
Self-hosted deployments are controlled by the person or organization operating them. Their operator controls storage, logs, backups, retention, and any AI or relay providers configured for that deployment.
6. Website, cookies, and diagnostics
The public marketing website and browser-based OmniTerm interfaces do not currently use advertising trackers or a product analytics SDK. They load some font files from Google Fonts, so Google receives the network request and associated connection information needed to return those files. Cloudflare delivers the site and managed interfaces and may process request and security information as part of that service.
The application code does not currently include a third-party advertising or product analytics SDK. This does not prevent OmniTerm or its infrastructure providers from processing the technical and security information described above. Account and security features may use essential storage or cookies when needed to function; the marketing page does not use marketing cookies.
7. Retention and deletion
Local information may remain on your device until you remove it, your operating system or browser evicts it, or it is replaced through normal app use. We retain managed account and service information while it is needed to provide the service, administer your account, protect service security, resolve disputes, and meet legal or financial obligations. Retention periods vary by information type and provider; backups may continue to contain deleted information until they expire under the applicable backup process.
You can start account deletion in the account settings in the app, or contact us at support@omnisolo.co. Deletion may not remove records we must retain for legal, security, fraud-prevention, or transaction purposes, or information held by a provider you selected. Deleting your account does not delete information on a remote host, in a self-hosted deployment, or on your device unless you remove it there too.
8. Security
We use administrative, technical, and organizational measures intended to protect information handled by OmniTerm. No service or method of transmission can be guaranteed completely secure. Protect your device and account, use connection and AI settings appropriate for the information involved, and avoid placing secrets in prompts or support messages.
9. Your choices and rights
You can choose whether to create a managed account, enable vault sync, use a managed relay, enable available collaboration features, or submit context to an AI provider. You can manage local data in the app or on your device, revoke a Google or Apple sign-in authorization with that provider, and manage purchases with the store or billing provider that processed them.
Depending on where you live, you may have rights to request access to, correction or deletion of, or a copy of personal information, and to object to or restrict certain processing or withdraw consent. Send a request to support@omnisolo.co. We may ask for information needed to verify your request. You may also have the right to complain to your local privacy regulator.
10. International transfers
OmniTerm and its service providers may process information in countries other than the country where you live. Where applicable law requires it, we use appropriate safeguards for international transfers.
11. Children
OmniTerm is a developer and infrastructure operations service and is not directed to children. We do not knowingly collect personal information from children where parental authorization is required. If you believe a child has provided us with personal information, contact us so we can review and address it.
12. Changes and contact
We may update this policy as OmniTerm's features or data practices change. We will post the current version here and update the date above. If a change materially affects how we handle information, we will provide additional notice where required.
For privacy questions or requests, email support@omnisolo.co.