OmniCommsAI
BlogPricingRequest Access

Privacy Policy

Effective Date: April 20, 2026

OmniCommsAI Inc. ("OmniCommsAI", "we", "our", or "us") provides an artificial intelligence-powered communications platform that enables professionals to send, receive, and intelligently respond to messages, calls, and other communications across multiple channels (the "Service"). This Privacy Policy explains what personal data we collect, how we use and share it, how long we retain it, and what rights you have over it.

This Policy applies to all users of app.omnicomms.ai, our marketing site at omnicomms.ai, our mobile applications, and our APIs. If you are a customer of an OmniCommsAI subscriber (for example, you received an SMS from a real-estate agent who uses our platform), please see Section 11 ("Customer-of-Customer Data").

At a Glance

  • We are a business-to-business platform; we do not sell personal data.
  • We do not sell, rent, or share mobile phone numbers or SMS opt-in consent with third parties or affiliates for marketing or promotional purposes. See Section 14 (SMS / Text Messaging).
  • We process communications content (messages, call audio, attachments) to deliver the Service and to power AI Employee features.
  • We use third-party LLM providers (OpenAI, Anthropic) to generate AI responses; their use is governed by their respective enterprise data processing agreements.
  • We do not use customer data to train shared AI models. AI processing is per-request inference only.
  • You can export, correct, or delete your data at any time.
  • You can choose to bring your own credentials (BYOK) for LLM providers and telephony carriers, in which case data flows through your own accounts.

1. Who We Are

The data controller for personal data processed under this Policy is:

OmniCommsAI Inc.
30 N Gould St Ste R
Sheridan, WY 82801
United States
Privacy contact: privacy@omnicomms.ai

For business customers, OmniCommsAI generally acts as a data processor (sometimes called a "service provider" under California law) for the personal data of your contacts, leads, and end customers that you bring into the platform. You, the subscriber, remain the data controller of that information. For your own account information, OmniCommsAI is the data controller.

2. Information We Collect

2.1 Information You Provide

  • Account information: Name, business name, email address, phone number, password (hashed), profile photo (optional), time zone, language.
  • Workspace and team information: Workspace name, role assignments, invited team member email addresses.
  • Billing information: Billing name, billing address, country, VAT/tax ID, payment method last-4 digits and brand. Full card numbers are processed by Paddle and never touch our servers.
  • Communications content: Messages you send, draft, or import (SMS, email, WhatsApp, social DMs); voicemails; call recordings (when recording is enabled); attachments and uploaded files.
  • CRM data: Contact records (names, phone numbers, email addresses, custom fields), deal/transaction records, task records, notes, tags, and other structured CRM data you create or import.
  • Knowledge base content: Documents, scripts, SOPs, and other materials you upload or paste into the AI knowledge base for retrieval-augmented generation.
  • Voice samples: Audio recordings you provide to enable AI voice cloning (Solopreneur and Business plans).
  • Third-party credentials (BYOK / BYOA): API keys and OAuth tokens you choose to connect for LLM providers, telephony carriers, email providers, calendars, and other integrations. These are encrypted at rest using envelope encryption with keys we cannot decrypt without a hardware security module.
  • Support communications: Messages you send to our support team and any attached information.

2.2 Information Generated Automatically

  • Usage data: Features used, pages viewed, requests made to our APIs, timestamps, response times, error logs.
  • Device and connection data: IP address, browser type and version, operating system, mobile device identifiers, language preference.
  • Cookies and similar technologies: Session cookies (essential, for authentication), preference cookies (optional), and analytics cookies (only when you consent in jurisdictions where consent is required).
  • Communications metadata: Sender/recipient phone numbers and email addresses, message timestamps, call duration, delivery status, channel type, and message size — collected in the ordinary course of routing and metering communications.
  • AI processing metadata: Number of tokens consumed, model used, response time, success/failure indicators — used for billing and service quality monitoring.
  • Audit logs: Records of significant account events (logins, permission changes, exports, deletions) for security and compliance.

2.3 Information from Third Parties

  • Authentication providers: If you sign in via Google or another OAuth provider, we receive your name, email, profile photo, and provider user ID.
  • Carrier and provider responses: Delivery status, error codes, and metadata returned by telephony carriers (Twilio, Telnyx) and email providers (Postmark) when handling your messages.
  • Payment processor: Transaction outcomes, billing dispute notifications, and tax-determination data from Paddle.
  • Compliance lookups: Public license records (e.g., NMLS lookups for mortgage professionals) when you enable a verification feature that requires such lookups.

3. How We Use Personal Data

We use personal data for the following purposes, with the corresponding legal bases under the GDPR (where applicable) noted in brackets:

  • To provide the Service — routing your messages, holding your CRM records, generating AI responses, syncing your inbox, processing payments. [Performance of Contract]
  • To power AI features — including sending message context to LLM providers (OpenAI, Anthropic, or your BYOK endpoint) to generate replies, summaries, and analyses. [Performance of Contract]
  • To bill and invoice — meter usage, calculate charges, issue invoices, and reconcile with our payment processor. [Performance of Contract; Legal Obligation for tax records]
  • To secure the Service — detect fraud, abuse, anti-money-laundering review, account compromise, and to enforce our acceptable use policy. [Legitimate Interest; Legal Obligation]
  • To support you — respond to your support requests, troubleshoot issues, and notify you of service changes. [Performance of Contract; Legitimate Interest]
  • To improve the Service — measure feature usage in aggregate, identify bugs, and prioritize roadmap items. We do not use the content of your communications to improve the Service unless you explicitly opt in. [Legitimate Interest]
  • To send service communications — transactional messages about your account (billing, security alerts, policy updates). You cannot opt out of these. [Performance of Contract; Legitimate Interest]
  • To send marketing communications — only if you opt in. You can withdraw consent at any time via the unsubscribe link in any marketing email. [Consent]
  • To comply with law — respond to lawful requests from regulators and law enforcement, retain records required by tax and financial laws. [Legal Obligation]

4. AI / LLM Processing — Important Disclosures

4.1 What Happens When AI Is Invoked

When you (or an AI Employee on your behalf) trigger an AI feature, the following data is sent to the configured large language model (LLM) provider for inference:

  • The current message and recent conversation history (the "context window");
  • Relevant snippets retrieved from your knowledge base via similarity search (Retrieval-Augmented Generation);
  • System prompts and instructions you have configured for the AI Employee;
  • Metadata such as the customer's name and current pipeline stage, where relevant.

By default, the LLM provider is OpenAI or Anthropic (chosen per workspace configuration). On Solopreneur and Business plans, you may configure a Bring Your Own Keys (BYOK) endpoint that points to your own LLM account, in which case your messages never traverse OmniCommsAI's OpenAI or Anthropic accounts.

4.2 No Training on Your Data

We do not use your communications content, CRM data, knowledge base documents, or AI conversation history to train shared AI models. We have configured our LLM provider integrations to use enterprise-grade endpoints that disable training on submitted data. Your data is used only for the immediate inference request.

4.3 Voice Cloning

Voice cloning is an opt-in feature that requires you to upload audio samples of your own voice. Voice models created from your samples are stored encrypted and used only to generate audio outputs for your account. We do not share, sell, or otherwise make voice models available to other accounts. You can delete your voice model at any time from workspace settings; deletion is permanent.

4.4 Automated Decision-Making

AI Employees may, when you configure them to, send replies, route conversations, or update CRM records without per-action human review. These decisions may have legal or similarly significant effects in regulated industries (e.g., a quote sent to a potential borrower). You retain full control over the configuration and may at any time require human review before any AI action is taken. If you are an EU/UK data subject and an AI decision concerning you was made without meaningful human involvement, you may request human review by contacting privacy@omnicomms.ai.

5. How We Share Personal Data

We do not sell personal data. We share personal data with the following categories of recipients, all under written agreements that restrict their use of the data:

  • Subprocessors — service providers acting on our behalf to host, transmit, store, and process data (see Section 6 for the current list).
  • Your authorized integrations — when you connect an integration (Twilio, Gmail, etc.), we share data with that service to fulfill the integration's purpose.
  • Telephony and email carriers — to deliver outbound messages, calls, and emails to their intended recipients.
  • Compliance and legal recipients — when required by law, valid legal process, or to protect the rights, property, or safety of OmniCommsAI, our users, or the public.
  • Successors in interest — in the event of a merger, acquisition, financing due-diligence review, or sale of assets, subject to confidentiality obligations and to this Policy continuing to apply.

Mobile numbers and SMS consent are excluded from all sharing. No mobile information collected through our text messaging program will be sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are never shared with any third party, with the sole exception of the aggregators and messaging service providers that transmit the messages on our behalf (for example, Twilio), who are contractually restricted to that purpose. See Section 14.

6. Subprocessors

The current list of subprocessors that may process personal data on our behalf:

VendorPurposeData ProcessedRegion
Cloudflare, Inc.CDN, DNS, R2 object storage, edge securityAccount metadata, file uploads, call recordings, attachmentsGlobal (US-primary)
Supabase Inc.PostgreSQL database hosting, authenticationAll structured account data, authentication credentialsUnited States
Twilio Inc.SMS, MMS, voice, programmable messaging (managed numbers)Phone numbers, message content, call audioUnited States
Telnyx LLCSIP trunking, voice termination (managed numbers)Phone numbers, call signaling, call audioUnited States
Postmark (ActiveCampaign LLC)Transactional email send + inbound parsingEmail addresses, message content, attachmentsUnited States
OpenAI, L.L.C.LLM inference (default provider)Message content, conversation context, knowledge base snippets included in promptsUnited States
Anthropic, PBCLLM inference (alternative provider)Message content, conversation context, knowledge base snippets included in promptsUnited States
LiveKit, Inc.Real-time voice / video conferencing (when used)Audio / video streams, room metadataGlobal
Paddle.com Market LimitedPayment processing, subscription billing, tax compliance (Merchant of Record)Billing name, billing address, payment method, transaction amountsGlobal
RevenueCat, Inc.Subscription state management, entitlement trackingAnonymous user ID, subscription status, plan tierUnited States
Linode LLC (Akamai)Compute infrastructure (Kubernetes nodes, multi-region)All workloads — encrypted at restUnited States, EU, Asia-Pacific

We update this list when new subprocessors are added. Material changes are communicated to active customers by email at least 14 days in advance. You may object to a new subprocessor by terminating your subscription before it takes effect.

7. International Data Transfers

Our primary infrastructure is located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other jurisdictions where our subprocessors operate.

For transfers from the European Economic Area, United Kingdom, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) (or the UK International Data Transfer Addendum where applicable) with each of our U.S.-based subprocessors. We supplement the SCCs with appropriate technical and organizational measures, including encryption in transit (TLS 1.3 or higher) and at rest (AES-256), restricted access controls, and audit logging.

8. Data Retention

We retain personal data for as long as necessary to provide the Service, to comply with our legal obligations (including tax, accounting, and regulatory record-keeping), and to resolve disputes. Specific retention periods:

  • Account data: Retained while your account is active and for 90 days after permanent deletion, then purged from production systems.
  • Communications content (messages, recordings, transcripts): Retained per your configured retention setting (default: indefinite while your account is active). You can configure shorter retention windows in workspace settings.
  • Backups: Encrypted backups are retained for up to 35 days after deletion from production.
  • Billing records: Retained for at least seven (7) years to comply with tax and financial recordkeeping laws.
  • Audit and security logs: Retained for at least one (1) year, longer where required for incident investigation.
  • Industry-specific retention: If you operate in mortgage, real estate, or insurance, you may need longer retention windows under TRID, RESPA, or state advertising rules. You are responsible for configuring retention to meet your applicable regulatory obligations.

9. Security

We implement industry-standard administrative, technical, and physical safeguards appropriate to the sensitivity of the data:

  • TLS 1.3 in transit; AES-256 at rest for object storage and database backups.
  • Envelope encryption for customer-owned secrets (BYOK) using a hardware security module via OpenBao.
  • Role-based access controls and principle of least privilege for employee access; multi-factor authentication required for all engineering accounts.
  • Network isolation between workloads using zero-trust service mesh (Linkerd mTLS).
  • Continuous vulnerability scanning, dependency monitoring, and penetration testing on a recurring schedule.
  • Incident response procedures aligned with ISO 27001 controls. Confirmed breaches affecting personal data are notified to affected customers and applicable regulators within the timeframes required by law (typically 72 hours under GDPR).

No system is perfectly secure. You are responsible for protecting your account credentials and for keeping the systems you use to access OmniCommsAI up to date.

10. Your Rights

10.1 Rights Available to Most Users

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Ask us to correct inaccurate or incomplete data.
  • Deletion: Ask us to delete your personal data, subject to limited exceptions for data we must retain (e.g., tax records).
  • Portability: Receive your data in a machine-readable format.
  • Objection / restriction: Object to or ask us to restrict certain processing activities.
  • Withdraw consent: Where processing is based on consent, withdraw consent at any time.
  • Lodge a complaint: File a complaint with your local data protection authority.

To exercise these rights, email privacy@omnicomms.ai from the email address on your account. We respond within 30 days (extendable in complex cases). Most rights can also be exercised directly from your account settings.

10.2 California Residents (CCPA / CPRA)

California residents have the right to know what personal information we collect, to request deletion of personal information, to correct inaccurate personal information, to opt out of the sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising), and to limit the use of sensitive personal information. We do not discriminate against you for exercising any of these rights.

To exercise California-specific rights, email privacy@omnicomms.ai with the subject line "California Privacy Request".

11. Customer-of-Customer Data

If you received a message, call, or email sent through OmniCommsAI by one of our business subscribers (for example, a real-estate agent), the subscriber — not OmniCommsAI — is the data controller of your information. To exercise your rights, contact the subscriber directly. If you cannot identify the subscriber or do not receive a response, you may contact privacy@omnicomms.ai and we will help route your request.

To stop receiving messages from a particular subscriber, reply STOP to any SMS or click the unsubscribe link in any email. These instructions are processed at the subscriber level and apply to that subscriber's communications.

12. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information through the Service, contact us at privacy@omnicomms.ai and we will promptly delete it.

13. Cookies

We use a minimal set of cookies and similar technologies:

  • Essential cookies for authentication, session management, and security.
  • Preference cookies to remember your interface settings.
  • Analytics cookies in jurisdictions where consent is not required, or with your consent where required.

You can manage cookies through your browser settings. Disabling essential cookies will prevent you from logging into the Service.

14. SMS / Text Messaging

This section applies to the OmniCommsAI text messaging programs — the messages OmniCommsAI Inc. sends to people who have opted in directly with us. Messages may be sent from any of the telephone numbers we operate for these programs, and the sending number may change over time or vary between messages. Those numbers are not monitored for inbound voice calls; use the contacts in Section 14.5 to reach us. This section does not govern messages that our business subscribers send to their own contacts using the platform; for those, see Section 11.

14.1 Two Separate Programs

We operate two separate text messaging programs, each with its own consent. Joining one does not join the other, and opting out of one does not opt you out of the other.

  • Account Alerts (transactional): password and security changes, account setting changes, billing and payment notices, subscription and renewal reminders, and scheduled maintenance or service disruption alerts.
  • Marketing: webinar invitations, reminders and join links, new content and resources you requested, product announcements, and promotional offers.

14.2 How We Obtain Consent

You join a program only by an affirmative act that you take yourself. Each program has its own consent checkbox, never pre-selected, and checking one has no effect on the other.

  • Account Alerts: entering your mobile number and actively checking the account alerts consent box when you create an account at app.omnicomms.ai, or later in your notification settings. This program has no keyword enrollment.
  • Marketing: entering your mobile number and actively checking the marketing consent box on a form at omnicomms.ai or on our webinar registration page; scanning a QR code on our marketing materials, which opens that same web form; or texting our opt-in keyword AI to the number shown on the campaign or marketing material where you found it, and replying Y to the verification message.

When you text an opt-in keyword we reply with a verification message describing the program, its frequency, and the rate, HELP, and STOP disclosures, and we do not enroll you until you reply Y. On confirmation we send a single enrollment message identifying OmniCommsAI and repeating the HELP and STOP instructions. The carrier-standard keywords START, YES, and UNSTOP resume messages on a program you previously stopped.

Consent to receive text messages is never a condition of purchase or of using the Service, for either program. We record which program you consented to, the exact consent language you were shown, the page URL, the timestamp, and the IP address, and we retain that record for at least four (4) years after your last message, as required for TCPA recordkeeping.

14.3 Message Frequency

Message frequency varies based on your account activity and the program you opted into. You will receive up to 6 messages per month per program.

14.4 Message and Data Rates

Message and data rates may apply. Charges depend on your mobile phone service plan and are billed by your wireless carrier, not by OmniCommsAI. Carriers are not liable for delayed or undelivered messages.

14.5 Opting Out and Getting Help

Reply STOP to any message to cancel at any time. We will send a single confirmation and then stop sending messages of that kind to that number. A STOP reply applies to the program that sent the message you replied to; if you are enrolled in both programs and want to leave both, reply STOP to a message from each, or email us and we will remove you from both. Reply HELP for help, or email support@omnicomms.ai. To rejoin after opting out, text START or opt in again through the method for that program in Section 14.2.

14.6 No Sharing of Mobile Information

No mobile information will be sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text message services. Those messaging providers (currently Twilio Inc. and Telnyx LLC — see Section 6) may process your mobile number solely to transmit messages on our behalf and are contractually barred from using it for any other purpose. Mobile numbers and SMS consent are also excluded from any information sharing that would constitute a "sale" or "sharing" under the CCPA/CPRA or similar state laws.

14.7 Data We Collect Through the Program

Your mobile number, per-program opt-in and opt-out status and history, the consent record described in Section 14.2, message content and timestamps, and carrier-reported delivery status. This data is retained per Section 8 and, for the opt-out suppression list, indefinitely so we do not message a number that has opted out.

15. Changes to This Policy

We may update this Privacy Policy. The current version is always available at https://omnicomms.ai/#/privacy and the effective date is shown at the top. Material changes are communicated to account holders by email at least 30 days before taking effect.

16. Contact Us

For privacy questions, requests, or complaints:

OmniCommsAI Inc. — Privacy
30 N Gould St Ste R
Sheridan, WY 82801
United States
Email: privacy@omnicomms.ai

OmniCommsAI Inc.
30 N Gould St Ste R, Sheridan, WY 82801, United States
Contact: legal@omnicomms.ai · Privacy: privacy@omnicomms.ai · Support: support@omnicomms.ai

OmniCommsAI
Investor Inquiries
Blog•Pricing•Privacy•Terms•Refund Policy•Data Retention

© 2026 OmniCommsAI Inc. All rights reserved.