Privacy Policy
Last updated: June 15, 2026
1. Who we are
OmniChat ("we", "us", "our") operates the messaging inbox platform at getomnichat.com. This Privacy Policy explains how we handle personal data when you use our service.
2. Data we collect
We may collect the following categories of information:
- Account data: email address, name, password (stored hashed by our auth provider), and profile settings you provide at signup.
- Message content: text, media metadata, and delivery status for conversations across channels you connect (WhatsApp, Telegram, Instagram, Messenger).
- Channel credentials: OAuth tokens, page IDs, bot tokens, and related identifiers required to send and receive messages on your behalf. These are stored securely in our database.
- Usage data: logs of API calls, AI autopilot actions, gem/billing usage, and diagnostic information to keep the service reliable.
- Push notification tokens: if you enable browser push notifications, we store device subscription endpoints to alert you of new messages.
3. How we use your data
We use collected data to:
- Deliver, display, and sync messages in your unified inbox
- Send outbound replies and AI-generated responses you configure
- Authenticate your account and maintain session security
- Process usage-based billing (gems) for AI features
- Improve reliability, debug issues, and prevent abuse
- Send service-related notifications you opt into
We do not sell your personal data to third parties.
4. Third-party services
OmniChat integrates with processors and platforms that may receive data as needed to operate:
- Supabase — authentication, database, and edge functions
- Meta — WhatsApp Cloud API, Instagram Messaging, and Facebook Messenger
- Telegram — Bot API for Telegram channel messages
- Vercel — application hosting
- Cloudflare R2 — media file storage
- AI providers — message content may be sent to AI models (e.g. Google Gemini) when you enable autopilot
Each third party has its own privacy policy. When you connect a channel, you also agree to that platform's terms (e.g. Meta Platform Terms).
5. Retention and deletion
We retain your data while your account is active and as needed to provide the service. When you disconnect a channel, associated tokens are revoked or marked inactive. You may request account deletion by contacting us.
For Meta-connected accounts, data deletion requests initiated through Facebook/Instagram are handled via our registered callbacks:
- Instagram:
/api/instagram/data-deletion - Messenger:
/api/messenger/data-deletion
6. Cookies and sessions
We use essential cookies and local storage to maintain your login session and OAuth state during channel connection flows. We do not use third-party advertising cookies.
7. Security
We use industry-standard measures including HTTPS, row-level security on database tables, and restricted access to production systems. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data. To exercise these rights, contact us at support@getomnichat.com.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page with an updated "Last updated" date. Continued use of OmniChat after changes constitutes acceptance of the updated policy.
10. Contact
Questions about this Privacy Policy? Email support@getomnichat.com.