Privacy Policy

What we collect, why we collect it, and what you can ask us to do with it.

Last updated 2026-08-29

Placeholder. The registered entity, jurisdiction and address are not filled in yet. Set them in src/lib/marketing/company.ts, and have a lawyer review this page before launch. Nothing here is legal advice.

Who we are

Omnipresence operates Omnipresence, an AI visibility measurement and optimisation platform available at getomnipresence.com. For anything in this policy, contact us at [email protected].

What we collect

  • Account data. Your name, email address and authentication details, so you can sign in and we know which account owns which project.
  • Project data. The domains, brand names and prompts you choose to track, plus the results of tracking them: model answers, cited sources and the queries the model ran.
  • Billing data. Subscription status and history. Card details are handled by Stripe and never reach our servers.
  • Credentials you supply. If you provide an API key so we can run measurements on your behalf, it is encrypted at rest and used only to run your own tracking.
  • Usage data. Standard web analytics on the public marketing pages, and application logs covering errors and service health.

Why we collect it

To provide the service you signed up for: running the measurements you configure, showing you the results, keeping your account secure and billing you correctly. We also use aggregate, non-identifying data to improve the product and to inform the research we publish. Research publications never identify a customer or their data without explicit permission.

We do not sell personal data, and we do not use your project data to benefit another customer.

Who processes it

We use a small number of processors, each for a specific purpose:

  • Supabase for the database and authentication.
  • Railway for application hosting.
  • Stripe for payments and subscription management.
  • OpenAI for running the measurement probes that produce your visibility data.
  • Resend for transactional email such as invitations and digests.
  • Google Tag Manager for analytics on the public marketing pages only. It is deliberately not loaded inside the authenticated application.

Cookies

The application sets cookies required to keep you signed in. These are strictly necessary and cannot be turned off without breaking sign-in. The public marketing pages additionally load analytics, which you can block with any standard browser control or extension.

How long we keep it

Account and project data is retained while your account is open. Measurement history is retained so that long-run comparisons remain possible, which is central to how the product works. When you ask us to delete your account we remove your personal data and your project data within 30 days, except where we are required to retain billing records for tax and accounting purposes.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to certain processing, and to complain to a supervisory authority. Email [email protected] and we will respond within 30 days.

Security

Access to customer data is restricted per account and enforced at the database level, so one account cannot reach another's projects. Secrets and customer-supplied API keys are encrypted at rest. If we become aware of a breach affecting your data we will notify you.

Changes

If this policy changes materially we will update the date at the top of this page and, where the change affects how we handle your data, notify account holders by email.