// Legal

Privacy Policy

Effective 3 October 2026 · Last updated 3 October 2026
Contents
  1. Who we are
  2. The short version
  3. Information we collect
  4. How we use information
  5. Who we share it with
  6. Health and research data
  7. How long we keep it
  8. How we protect it
  9. Your rights and choices
  10. International transfers
  11. Children
  12. Cookies and local storage
  13. Changes to this policy

Who we are

This policy explains what personal information OmniBioAI collects, why, who it is shared with, how long it is kept and the choices you have. It covers this website (omnibioai.org), the hosted platform (including webstudio.omnibioai.org and the OmniBioAI API), the OmniBioAI Studio desktop application, and our documentation site.

"OmniBioAI", "we" and "us" mean the operator of these services, based in Kansas City, USA. You can reach us at [email protected] for any privacy question or request.

The short version

Information we collect

Information you give us

Information collected automatically

How we use information

PurposeInformation usedLegal basis (where GDPR/UK GDPR applies)
Provide and operate the services, including answering your requestsAccount, content, usagePerformance of our contract with you
Review beta access requests and onboard approved researchersBeta request detailsSteps taken at your request before a contract; legitimate interests
Bill usage, collect payments and keep financial recordsUsage, billingContract; legal obligation
Secure accounts, detect abuse, enforce rate limits and keep audit trailsSecurity logs, usage, API key hashesLegitimate interests; legal obligation
Fix errors and improve reliability and performanceError reports, usageLegitimate interests
Answer support requests and send service noticesContact details, support messagesContract; legitimate interests
Comply with law and respond to lawful requestsAs requiredLegal obligation

We do not use your content to train machine-learning models, and we do not sell or rent personal information or share it for cross-context behavioral advertising.

Who we share it with

We share personal information only with service providers that process it on our behalf under contract, or where you direct us to:

RecipientWhy
StripePayment processing, invoicing and fraud prevention
Cloud and hosting providers (including Cloudflare and GitHub Pages)Hosting the website, receiving beta requests, running the hosted platform, network security
Google, GitHub, MicrosoftOnly if you choose to sign in with them
Error-tracking providerDiagnosing service failures
Email providerSending service and support emails
AI model providers you enable (for example Anthropic or OpenAI)Only when you or your organization choose a premium model or connect your own provider key; your request is then sent to that provider and handled under its terms
Your organizationOrganization owners and administrators can see members, roles, API keys and usage for their organization

We may also disclose information to comply with law or a valid legal process, to protect the rights, safety and security of our users and services, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply.

Health and research data

OmniBioAI is built with HIPAA-aligned security controls, but this is not a certification, and our hosted services are not intended to receive protected health information (PHI) unless we have signed a business associate agreement (BAA) with you.

When you run OmniBioAI Studio on your own hardware, PHI and research data are stored and processed in your environment, and you are responsible for your own compliance program. Features that send data to an external service (such as a cloud AI model) are off unless enabled, and the platform screens outgoing requests for obvious sensitive data, but you remain responsible for what you choose to send.

How long we keep it

How we protect it

Protections include encryption in transit, hashed passwords and API keys, short-lived access tokens, role-based access control scoped to your organization, multi-factor authentication options, least-privilege service credentials, and an append-only audit log of security-relevant events. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you as required by law.

Your rights and choices

Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. California residents have the right to know, delete and correct personal information and to not be discriminated against for exercising these rights; we do not sell or share personal information as those terms are defined in California law.

To make a request, email [email protected]. We will verify your identity and respond within the time the law requires (generally 30 to 45 days). You can also revoke API keys and manage sign-in methods in your account at any time. If you are in the EEA or UK, you may complain to your local data protection authority.

If your organization provides your account, it controls some of your information; we may direct your request to it.

International transfers

We are based in the United States and our providers may process information in other countries. Where data protection law requires it, we rely on appropriate safeguards such as the European Commission's standard contractual clauses for transfers out of the EEA, UK or Switzerland.

Children

Our services are for researchers and professionals and are not directed to children under 16. We do not knowingly collect their personal information; if you believe we have, contact us and we will delete it.

Cookies and local storage

We use only cookies and browser storage needed to run the services: keeping you signed in, remembering preferences and protecting against abuse. We do not use advertising cookies. Blocking these may stop the hosted platform from working.

Changes to this policy

We may update this policy. We will post the new version here with a new "last updated" date and, for material changes, notify account holders by email or in the product before they take effect.

Questions: [email protected].