Privacy Policy
Effective 3 October 2026 · Last updated 3 October 2026Who we are
This policy explains what personal information OmniBioAI collects, why, who it is shared with, how long it is kept and the choices you have. It covers this website (omnibioai.org), the hosted platform (including webstudio.omnibioai.org and the OmniBioAI API), the OmniBioAI Studio desktop application, and our documentation site.
"OmniBioAI", "we" and "us" mean the operator of these services, based in Kansas City, USA. You can reach us at [email protected] for any privacy question or request.
The short version
- Studio is local-first. When you run OmniBioAI Studio on your own machine, your sequencing data, clinical metadata and results stay on your infrastructure. We do not receive them.
- We collect what we need to run the service: your account details, what you send to our hosted services, usage records for billing, and security logs.
- We never see your full card number. Payments are handled by Stripe.
- We do not sell your personal information and we do not use your content to train AI models.
- Do not send protected health information (PHI) to our hosted services unless we have signed a business associate agreement with you.
Information we collect
Information you give us
- Beta access requests: first and last name, institutional email, organization or lab, role, primary research area, operating system and a description of your intended analysis.
- Account information: email address, name, password (stored only as a salted hash), organization and team memberships and roles. If you sign in with Google, GitHub or Microsoft, we receive your basic profile (name, email and the provider's account identifier) from that provider.
- Billing information: billing contact, billing address and tax ID if you provide them. Card details are entered on Stripe's pages and stored by Stripe; we receive only a customer reference and limited card details such as brand, last four digits and expiry date.
- Content you submit to hosted services: questions sent to Literature AI and the API, files and data you upload, workflow parameters, chat messages and comments in shared workspaces.
- Support and feedback: emails, bug reports and community messages you send us.
Information collected automatically
- Usage records: which service you used, the resource and quantity (for example one answer or a number of tokens), time, organization and the API key used. We need these to bill you and to enforce plan limits.
- Security and audit logs: sign-ins, permission decisions, role and key changes, IP address, user agent and request identifiers. These protect your account and the platform.
- API keys: we store only a cryptographic hash and a short prefix of each key, never the key itself after it is shown to you once.
- Error reports: technical diagnostics when a service fails, which may include request metadata.
- Licence checks: the desktop application validates its licence key with our servers; this sends the licence key and basic technical information, not your research data.
- Website requests: our web host and font provider receive standard request data (such as IP address and browser type) when you load pages. This website does not use advertising or analytics trackers.
How we use information
| Purpose | Information used | Legal basis (where GDPR/UK GDPR applies) |
|---|---|---|
| Provide and operate the services, including answering your requests | Account, content, usage | Performance of our contract with you |
| Review beta access requests and onboard approved researchers | Beta request details | Steps taken at your request before a contract; legitimate interests |
| Bill usage, collect payments and keep financial records | Usage, billing | Contract; legal obligation |
| Secure accounts, detect abuse, enforce rate limits and keep audit trails | Security logs, usage, API key hashes | Legitimate interests; legal obligation |
| Fix errors and improve reliability and performance | Error reports, usage | Legitimate interests |
| Answer support requests and send service notices | Contact details, support messages | Contract; legitimate interests |
| Comply with law and respond to lawful requests | As required | Legal obligation |
We do not use your content to train machine-learning models, and we do not sell or rent personal information or share it for cross-context behavioral advertising.
Health and research data
OmniBioAI is built with HIPAA-aligned security controls, but this is not a certification, and our hosted services are not intended to receive protected health information (PHI) unless we have signed a business associate agreement (BAA) with you.
When you run OmniBioAI Studio on your own hardware, PHI and research data are stored and processed in your environment, and you are responsible for your own compliance program. Features that send data to an external service (such as a cloud AI model) are off unless enabled, and the platform screens outgoing requests for obvious sensitive data, but you remain responsible for what you choose to send.
How long we keep it
- Account information: while your account is active, and deleted or anonymized within 90 days after you close it, except where we must keep it longer by law.
- Content on hosted services: until you delete it or close your account.
- Usage and billing records: as long as needed for billing and as required by tax and accounting law (typically seven years).
- Security audit logs: up to six years, consistent with our security and compliance retention policy, or longer if subject to a legal hold.
- Beta access requests: up to two years after your request, unless you become a customer.
How we protect it
Protections include encryption in transit, hashed passwords and API keys, short-lived access tokens, role-based access control scoped to your organization, multi-factor authentication options, least-privilege service credentials, and an append-only audit log of security-relevant events. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you as required by law.
Your rights and choices
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. California residents have the right to know, delete and correct personal information and to not be discriminated against for exercising these rights; we do not sell or share personal information as those terms are defined in California law.
To make a request, email [email protected]. We will verify your identity and respond within the time the law requires (generally 30 to 45 days). You can also revoke API keys and manage sign-in methods in your account at any time. If you are in the EEA or UK, you may complain to your local data protection authority.
If your organization provides your account, it controls some of your information; we may direct your request to it.
International transfers
We are based in the United States and our providers may process information in other countries. Where data protection law requires it, we rely on appropriate safeguards such as the European Commission's standard contractual clauses for transfers out of the EEA, UK or Switzerland.
Children
Our services are for researchers and professionals and are not directed to children under 16. We do not knowingly collect their personal information; if you believe we have, contact us and we will delete it.
Changes to this policy
We may update this policy. We will post the new version here with a new "last updated" date and, for material changes, notify account holders by email or in the product before they take effect.
Questions: [email protected].