Privacy Policy
What omg collects, why we collect it, who else sees it, and what you can ask us to do about it.
Last updated August 9, 2026
The short version
We collect your email address so you can sign in, billing details through Stripe if you pay us, and the code and prompts you give your agent so it can do the work you asked for. We use privacy-friendly analytics with masked inputs. We don't sell your data, and we don't train models on your code.
What we collect
Account data
Your email address, and the sign-in codes and session records that let you stay logged in. We don't ask for a password — sign-in is by one-time code — so there is no password for us to store or leak.
Your content
The prompts you send, the repositories and files you connect or upload, and the state of the Computers we run for you (including snapshots taken so a paused machine can be restored). We process this to operate the service and for no other purpose.
Billing data
If you buy a plan, Stripe processes the payment and stores your card details. We never see or store full card numbers — we keep only the subscription status and identifiers we need to know what you're entitled to.
Usage and diagnostics
We run a self-hosted Umami instance on our own infrastructure for page and event analytics, plus session replay that is sampled and recorded with input masking — form values are masked before they leave your browser, and sensitive dashboard panes (chat, terminal, inspect and secrets) are excluded from recording entirely. Server logs and errors go to Axiom so we can debug failures.
iMessage
If you choose to use the iMessage entry point, we process the messages you send to omg and the phone number they come from, in order to route your task to your agent and reply to you.
Why we're allowed to process it
- To perform our contract with you — running your Computers, storing your work, taking payment.
- Our legitimate interests — keeping the service secure, preventing abuse of sandbox compute, and understanding aggregate usage so we can improve the product.
- Legal obligation — tax and accounting records for payments.
Model providers
Running an agent means sending your prompts, and the files relevant to the task, to the model provider behind that agent so it can respond. Which provider depends on the agent you pick. We do not use your code or prompts to train our own models, and we do not sell your data to anyone.
Who else processes your data
We use these subprocessors to run omg. Each one sees only what it needs for its stated purpose:
- Stripe — Payment and subscription processing
- Resend — Transactional email (sign-in codes, notices)
- Convex — Application database for accounts and projects
- Hetzner — Compute hosting for the sandbox fleet
- Cloudflare — DNS, CDN and edge routing
- Tigris — Object storage for snapshots and media
- Axiom — Server logs and error diagnostics
- Anthropic — Claude models, when you run a Claude agent
- OpenAI — Codex models, when you run a Codex agent
We may also disclose data if the law requires it, or where it's necessary to protect our rights, our users, or the safety of others.
How long we keep it
- Account data — while your account is open, then deleted or anonymised after closure.
- Sandboxes and snapshots — deleted on a rolling basis once a Computer is reaped or an account closes. Treat your own git remote as the durable copy.
- Logs and analytics — retained on a rolling window for debugging and trend analysis, then discarded.
- Billing records — kept as long as tax and accounting rules require.
Security
Every Computer runs in its own hardware-isolated Firecracker microVM rather than a shared container, so one tenant's agent cannot reach another's files. Traffic is encrypted in transit, secrets are stored encrypted and are excluded from analytics and session replay, and administrative access to the fleet is restricted and audited.
No system is perfectly secure. If you find a vulnerability, please report it to support@omg.dev rather than disclosing it publicly, and we'll work with you on a fix.
Your rights
Depending on where you live — including in the EEA and UK under the GDPR, and in California under the CCPA — you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or export it. You can also complain to your local data protection authority.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
To exercise any of this, email privacy@omg.dev. We'll respond within 30 days. You can also delete your account yourself from the dashboard at any time.
International transfers
Our infrastructure and our subprocessors operate in the United States and Europe, so your data may be transferred across borders. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
Children
omg isn't intended for children under 13, and we don't knowingly collect their personal data. If you believe a child has given us data, contact us and we'll delete it.
Changes
If we make a material change to this policy we'll update the date at the top and notify you in the product or by email.
Contact
Privacy questions and data requests: privacy@omg.dev. Anything else: the contact page.