omg

Privacy Policy

What omg collects, why we collect it, who else sees it, and what you can ask us to do about it.

Last updated August 9, 2026

The short version

We collect your email address so you can sign in, billing details through Stripe if you pay us, and the code and prompts you give your agent so it can do the work you asked for. We use privacy-friendly analytics with masked inputs. We don't sell your data, and we don't train models on your code.

What we collect

Account data

Your email address, and the sign-in codes and session records that let you stay logged in. We don't ask for a password — sign-in is by one-time code — so there is no password for us to store or leak.

Your content

The prompts you send, the repositories and files you connect or upload, and the state of the Computers we run for you (including snapshots taken so a paused machine can be restored). We process this to operate the service and for no other purpose.

Billing data

If you buy a plan, Stripe processes the payment and stores your card details. We never see or store full card numbers — we keep only the subscription status and identifiers we need to know what you're entitled to.

Usage and diagnostics

We run a self-hosted Umami instance on our own infrastructure for page and event analytics, plus session replay that is sampled and recorded with input masking — form values are masked before they leave your browser, and sensitive dashboard panes (chat, terminal, inspect and secrets) are excluded from recording entirely. Server logs and errors go to Axiom so we can debug failures.

iMessage

If you choose to use the iMessage entry point, we process the messages you send to omg and the phone number they come from, in order to route your task to your agent and reply to you.

Why we're allowed to process it

  • To perform our contract with you — running your Computers, storing your work, taking payment.
  • Our legitimate interests — keeping the service secure, preventing abuse of sandbox compute, and understanding aggregate usage so we can improve the product.
  • Legal obligation — tax and accounting records for payments.

Model providers

Running an agent means sending your prompts, and the files relevant to the task, to the model provider behind that agent so it can respond. Which provider depends on the agent you pick. We do not use your code or prompts to train our own models, and we do not sell your data to anyone.

Who else processes your data

We use these subprocessors to run omg. Each one sees only what it needs for its stated purpose:

  • StripePayment and subscription processing
  • ResendTransactional email (sign-in codes, notices)
  • ConvexApplication database for accounts and projects
  • HetznerCompute hosting for the sandbox fleet
  • CloudflareDNS, CDN and edge routing
  • TigrisObject storage for snapshots and media
  • AxiomServer logs and error diagnostics
  • AnthropicClaude models, when you run a Claude agent
  • OpenAICodex models, when you run a Codex agent

We may also disclose data if the law requires it, or where it's necessary to protect our rights, our users, or the safety of others.

How long we keep it

  • Account data — while your account is open, then deleted or anonymised after closure.
  • Sandboxes and snapshots — deleted on a rolling basis once a Computer is reaped or an account closes. Treat your own git remote as the durable copy.
  • Logs and analytics — retained on a rolling window for debugging and trend analysis, then discarded.
  • Billing records — kept as long as tax and accounting rules require.

Security

Every Computer runs in its own hardware-isolated Firecracker microVM rather than a shared container, so one tenant's agent cannot reach another's files. Traffic is encrypted in transit, secrets are stored encrypted and are excluded from analytics and session replay, and administrative access to the fleet is restricted and audited.

No system is perfectly secure. If you find a vulnerability, please report it to support@omg.dev rather than disclosing it publicly, and we'll work with you on a fix.

Your rights

Depending on where you live — including in the EEA and UK under the GDPR, and in California under the CCPA — you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or export it. You can also complain to your local data protection authority.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

To exercise any of this, email privacy@omg.dev. We'll respond within 30 days. You can also delete your account yourself from the dashboard at any time.

International transfers

Our infrastructure and our subprocessors operate in the United States and Europe, so your data may be transferred across borders. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.

Children

omg isn't intended for children under 13, and we don't knowingly collect their personal data. If you believe a child has given us data, contact us and we'll delete it.

Changes

If we make a material change to this policy we'll update the date at the top and notify you in the product or by email.

Contact

Privacy questions and data requests: privacy@omg.dev. Anything else: the contact page.