LEGAL
Privacy
Last updated 17 September 2026
This notice explains what OmniSchema collects and why. It applies to the product at omnischema.app and related site addresses.
What we collect
- Account details you give us: name, email, company name, role, site assignment.
- Business data you store in lists, pages, files, and messages.
- Technical logs needed to run the service: sign-in time, IP address used at sign-in, security events.
- Billing details processed by Stripe. We do not store full card numbers.
How we use it
To provide the product, enforce plan limits, send password-reset mail when configured, detect abuse, and meet legal duties. We do not sell customer data.
Who sees it
People you invite to your company, with the access you give them. OmniSchema infrastructure administrators use a separate, restricted environment and do not use ordinary customer accounts to browse tenant data. Processors such as Stripe (payments) and our email provider (if mail is configured) receive only what they need.
Retention
Account and business data stays until you delete it or close the company. Soft-deleted items are kept up to 30 days, then removed. Security logs are kept to investigate incidents.
Your rights
You can ask to access, correct, or delete personal data we hold, or export list data from the product. Contact privacy@omnischema.app.
Cookies
We use a signed, HttpOnly session cookie to keep you signed in, and a CSRF cookie to protect forms. We do not use advertising cookies.