Privacy policy
Last updated September 29, 2026
Who we are
Omnicoro is a tool that lets an organisation run its social media accounts from one place: it connects Facebook Pages, Instagram business accounts, WhatsApp business numbers, X accounts and Telegram bots, and gives the team one inbox, one composer, one calendar and one set of reports for them.
This policy covers the Omnicoro service and its public website. "We" and "us" mean the team that operates Omnicoro. You can reach us at rashid@lajward.dev.
Omnicoro is independent. It is not affiliated with, endorsed by or operated by Meta, X, Telegram, Google or Apple.
Two kinds of people, two roles
People who use Omnicoro: the admins, agents and client reviewers of a workspace. For their account data, we decide how it is used, and this policy is our promise to them.
People who write to a business that uses Omnicoro: its customers and followers, who send a message, leave a comment or fill in a form. That business decides what it does with their data, and Omnicoro only processes it on the business's behalf and on its instructions. If you are one of those people, the business is the first place to ask; if you write to us instead, we will pass your request to the business and help it answer.
What we collect about people who use Omnicoro
- Your account: name, email address, and your password stored only as an Argon2 hash that cannot be turned back into the password. Also your language, colour theme and time zone.
- Sign-in with Google, Apple or Facebook: the provider's id for your account, the email address it gives us (Apple may give a private relay address) and whether the provider has verified it, and your name when we first create your account. We do not receive your password there, and we do not store your picture, contacts or anything else from that account.
- Security: the secret behind two-step sign-in, encrypted; recovery codes and password reset links, stored only as one-way hashes.
- Workspace activity: a record of who did what in the workspace, such as who published a post, connected an account or changed a setting. It does not record your IP address or device.
- Billing, when paid plans are on: Paddle takes the payment. We keep the Paddle customer and subscription ids and the billing notices Paddle sends us. We never see or store card numbers.
- What you send us when you ask for support.
What we collect from the accounts you connect
- Access tokens that let Omnicoro act for the account, encrypted with AES-256-GCM and only decrypted to call the platform.
- The account's id, name, username and profile picture as the platform reports them.
- Conversations: direct messages, comments and mentions, with the sender's name or username, profile picture and platform id (for WhatsApp that id is the phone number, for Telegram the Telegram user id), the text and any attachments, and the replies and internal notes your team writes.
- The notifications the platform sends us when something happens on the account, kept only for a short time (see "How long we keep it").
- Posts and media: what your team writes and uploads, and copies of attachments on incoming messages, so a conversation still reads correctly after the platform's own links expire.
- Analytics: the figures the platform reports for the account and its posts, stored per day.
What a business adds about its own customers
- Contacts: name, picture, platform id, and the email address, phone number, tags, notes, custom details and purchase value the business adds, with a record of each opt-in and opt-out and the exact wording that was agreed to.
- Broadcasts and sequences: who was sent which message, and when.
- Lead forms on link-in-bio pages: the answers someone submits, the consent wording they agreed to, their country, and a one-way code computed from their IP address and browser. The IP address and browser string themselves are not stored.
- Tracked links: when someone opens one, we record the time, their country, whether the device is a phone or a computer, the page they came from, and the same kind of one-way code.
- Client review links: the name and email address a reviewer types in, and when the link was opened.
How we use it
Only to run Omnicoro: to show the inbox, send the replies your team writes, publish and schedule posts, draw reports, run the automation rules and broadcasts a business sets up, sign people in and keep accounts secure, bill for paid plans, answer support requests, and find and fix faults.
To stop abuse, sign-in, sign-up and form requests are counted per IP address for a short window. Those counters expire on their own within an hour.
We do not sell, rent or trade personal data. We do not share it with advertisers or data brokers, we do not build advertising profiles, and we do not use your content or your customers' conversations to train AI models.
AI features
Two features use an AI model: the Smart Direct assistant, which drafts or sends replies, and the content studio, which drafts posts. Both are off until a workspace turns them on.
When one runs, the text it needs is sent to the AI provider the workspace uses: Anthropic, or another service the workspace configures. For a reply that means the persona and knowledge the business wrote, its catalogue, the customer's name and saved details, and up to the last 20 messages of that conversation. The provider returns a draft and Omnicoro stores the result.
A workspace that brings its own provider key is also bound by its own agreement with that provider.
Google user data
If you sign in with Google, we receive your Google account id, your email address, whether Google has verified it, and your name. We use them only to sign you in and to show which Google account is linked in Settings. We ask for nothing else from your Google account.
We do not use Google user data for advertising, we do not sell it, and nobody reads it except with your permission, to keep the service secure, or where the law requires.
Omnicoro's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
Who else receives it
Nobody else.
- The platforms you connect (Meta for Facebook, Instagram and WhatsApp; X; Telegram): what is needed to publish, reply and read the account.
- Google, Apple or Facebook, when you use them to sign in: they learn that you signed in to Omnicoro.
- The AI provider a workspace uses, only while an AI feature is on, as described above.
- Paddle, the merchant of record for paid plans, which processes payments under its own privacy policy.
- The email provider that delivers invitations, notifications and password reset messages.
- DigitalOcean, which runs the servers Omnicoro is hosted on, and Cloudflare, which provides the domain name service (DNS) for its address.
- Wherever a workspace sends data itself, through Omnicoro's API or its outgoing webhooks.
- Authorities, when the law requires it, and a successor if Omnicoro is ever transferred, in which case you will be told first.
Where it is stored
Omnicoro's database and uploaded media are kept on servers rented from DigitalOcean. The providers listed above may handle data in other countries, including the United States. Where the law asks for safeguards for such a transfer, we rely on the ones those providers offer.
How long we keep it
- Accounts, workspaces, conversations, contacts, media, reports and the activity record are kept while the workspace uses Omnicoro, until they are deleted in the product or you ask us to delete them.
- The notifications platforms send us have their contents erased after 30 days, and the records themselves are deleted after 180 days.
- Disconnecting an account stops Omnicoro reading from or writing to it at once. What was already stored stays until it is deleted.
- When you ask us to close a workspace or an account, we delete it within 30 days. Database copies taken before maintenance are kept only as long as needed to recover from a failed update, and then deleted.
- A record of each Facebook data deletion request is kept for 90 days, so its status page keeps working.
- The cookies used while signing in expire within 15 minutes or when the browser is closed; every cookie is listed below.
How we protect it
Traffic runs over HTTPS. Access tokens and other secrets are encrypted with AES-256-GCM, passwords are hashed with Argon2, and API keys and review links are stored only as hashes. Two-step sign-in is available to everyone, and a workspace can require it. Every database query is limited to one workspace, so one customer cannot read another's data. Media is served through signed links that expire, and repeated sign-in attempts are slowed down.
No system is perfectly secure. If a breach affects your data, we will tell the affected workspaces without undue delay.
Your rights
You can ask to see, correct, export or delete your data, to restrict or object to how it is used, and to withdraw a consent you gave. Much of this is in the product: edit your profile, export contacts as a CSV file, unlink sign-in methods, delete posts and media, remove members. For anything else, write to rashid@lajward.dev. We will confirm who you are, then act within 30 days.
If you are a customer of a business that uses Omnicoro, ask that business first. You can also complain to the data protection authority where you live.
Cookies and browser storage
Omnicoro only uses cookies it needs to work. There are no advertising, analytics or tracking cookies.
- authjs.session-token: keeps you signed in, for up to 30 days.
- authjs.csrf-token, authjs.callback-url, authjs.state, authjs.nonce and authjs.pkce.code_verifier: protect a sign-in against forgery, for the browser session or 15 minutes.
- social_intent (15 minutes), social_pending (10 minutes) and social_grant (2 minutes): carry a Google, Apple or Facebook sign-in from one step to the next.
- mfa_challenge: a two-step sign-in in progress, for 4 minutes.
- ws: which workspace you have open, for a year.
- locale and site-locale: your language in the app and on the website, for a year.
- palette and tz: your colour palette and time zone, for a year.
- meta_oauth_state, meta_connect_candidates and x_oauth: an account connection in progress, for 10 minutes.
- In the browser's own storage: your light or dark mode, your recent searches in the command menu, and whether you closed a reminder banner.
- On the billing page, Paddle's checkout runs and may set its own cookies under Paddle's policy. Tracked links add a click id to the address they lead to; they do not set a cookie.
Children
Omnicoro is a tool for organisations and is not directed at children. We do not knowingly create accounts for anyone under 16.
Changes to this policy
When this policy changes, we update this page and the date at the top. We announce material changes in the product or by email to workspace admins before they take effect.
Questions about this page? Write to rashid@lajward.dev and we will answer within 30 days.