Privacy Policy
This policy explains what personal data Ommelo collects, why, who we share it with, and the choices and rights you have. It reflects what the product actually does.
Effective 31 July 2026
Who we are
Ommelo ("Ommelo", "we", "us") is a UX audit and journey-analysis platform operated from Australia. For the personal data described here, Ommelo is the data controller, except where you use Ommelo to audit third-party sites or record sessions — in that case you are the controller of that captured content and Ommelo acts as your processor (see below). You can reach us about any privacy matter at alifnoushad.96@gmail.com.
What we collect, why, and for how long
The table below is the full inventory. Each entry ties a category of data to the purpose it serves and how long we keep it.
| Data | Purpose | Retention |
|---|---|---|
| Account — email, name, and Google OAuth profile | Create and secure your account and sign you in. We use Supabase Auth with Google sign-in and email magic links; there are no passwords. | Kept while your account is active; deleted when you delete your account. |
| Audit inputs — URLs, screenshots, and serialized DOM text of the sites you audit | Run the UX audit and produce your scored report. This content may contain other people’s personal data present on the audited page (see "Auditing sites you don’t own"). | Stored with the audit so you can revisit the report; deleted when you delete the audit or your account. |
| Extension recordings — screenshots, DOM, action metadata, and timing from sessions you record on your own sites | Analyse real journeys against the ruleset. Password and card values are redacted and card/password input regions are canvas-blurred before upload; redaction is best-effort and other on-screen personal data can still be captured. | Stored with the associated project/audit; deleted when you delete it or your account. |
| Test credentials (optional) | Let an authorised audit walk past your own login wall. Stored encrypted in Supabase Vault, accessible only to the service role. We never accept or store card or CVV values. | Hard-deleted on request, and when you delete your account. |
| Analytics connection (optional, where you connect GA4) | Pull per-step session counts from your own Google Analytics to contextualise findings. We store a read-only OAuth token in Vault; we do not receive your raw analytics data beyond the counts requested. | Kept until you disconnect the integration or delete your account. |
| Payment and subscription data | Process your subscription. Payments are handled by Lemon Squeezy as merchant of record — we receive your plan and billing status, not your card number. | Retained as required for tax and accounting; billing records are kept by Lemon Squeezy. |
| Product usage, feedback, and error data | Operate, debug, and improve the service. Server errors are sent to Sentry with tokens and secrets scrubbed. | Feedback kept while relevant; error diagnostics retained on a rolling short-term basis. |
| Essential cookies and local storage | Keep you signed in (host-scoped Supabase auth cookies) and remember lightweight interface state (e.g. returning-user pre-fill). Essential only — no advertising or cross-site tracking cookies. | Session/auth cookies expire per their lifetime; you can clear them any time. |
| Waitlist email | Contact you about availability if you join the waitlist. | Kept until you ask us to remove it or you create an account. |
Legal bases (EU/UK GDPR)
Where the GDPR or UK GDPR applies, we rely on: contract — to provide the service you sign up for (account, audits, subscription); legitimate interests — to secure, debug, and improve the service, kept proportionate to your privacy; consent — for anything optional you switch on, such as connecting Google Analytics, which you can withdraw at any time; and legal obligation — to keep records we are required to keep, such as billing.
AI processing
To generate audit findings, the audit inputs and captured session content described above are sent to Anthropic's Claude API for analysis. Anthropic processes this content to return results to Ommelo; under Anthropic's API terms, content submitted through the API is not used to train its models and is retained only for a limited period for operational and safety purposes. These terms can change — we verify Anthropic's current API data-handling terms before relying on them and will update this policy if they change materially.
Who we share data with
We do not sell your personal data. We share it only with the subprocessors that run the service on our behalf, each bound to process it only on our instructions. The current list — with the purpose, data categories, and hosting region for each — is maintained on our subprocessors page:
- ·Supabase — Database, authentication, file/object storage, and encrypted secrets (Vault). (Australia (ap-southeast-2))
- ·Anthropic — Claude API — analyses audit and extension content to generate findings. (United States)
- ·Vercel — Application hosting and content delivery. (United States)
- ·Lemon Squeezy — Payments and subscription management (merchant of record). (United States)
- ·Google — Google sign-in (OAuth); our own GA4 web analytics on the marketing site and sign-in flow (opt-in only, see Cookie Policy); and, where a customer connects it, read-only GA4 analytics on their own property. (United States)
- ·Sentry — Error monitoring on server routes. (United States)
International transfers
Ommelo's primary data store is in Australia (Supabase, ap-southeast-2). Some subprocessors process data in the United States (including Anthropic, Vercel, Lemon Squeezy, Google, and Sentry). Where we transfer personal data out of the EU/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum / IDTA), or an adequacy mechanism such as the EU–US Data Privacy Framework where a processor is certified.
Security
We protect data with encryption in transit and at rest, encrypted secret storage (Supabase Vault) for test credentials and analytics tokens accessible only to the service role, row-level security so tenants cannot read each other's data, and best-effort redaction of passwords and card values in extension recordings before upload. No method of transmission or storage is perfectly secure; redaction in particular is best-effort, so you should avoid capturing others' sensitive data and can delete any recording at any time.
Your rights
Subject to your local law, you can request access to your data, a copy of it (export), correction of inaccurate data, and deletion. You can delete your audits and recordings from the product directly; deleting your account hard-deletes your associated data, and test credentials are hard-deleted on request. To exercise any right, or if you are unhappy with how we handle a request, contact us at alifnoushad.96@gmail.com. EU/UK users may also complain to their supervisory authority; Australian users may complain to the Office of the Australian Information Commissioner (OAIC).
Cookies
Ommelo uses essential cookies and local storage only — host-scoped Supabase authentication cookies to keep you signed in, and lightweight interface state. We do not use advertising or cross-site tracking cookies. Because only essential cookies are used, no consent banner is required for them; if we ever add non-essential cookies, we will ask for consent first. Our Cookie Policy lists everything we store and how to manage it.
Auditing sites you don't own, and recording sessions
Ommelo lets you audit third-party sites and record real sessions. That content can include personal data you do not own. You are solely responsible for having the right to audit the target and to record any session you capture, and you act as the data controller for that content while Ommelo acts as your processor. Do not use Ommelo to capture others' personal data unlawfully. Business and team customers processing others' personal data through Ommelo should also enter into our Data Processing Agreement.
Findings are not legal advice
Ommelo's audits, scores, and compliance-related checks are informational and do not constitute legal, professional, or compliance advice. They are a starting point for your own review, not a substitute for a qualified professional.
Children
Ommelo is a paid product for professionals and is not directed to children. We do not knowingly collect data from anyone under 16 (or under 13 where that is the applicable minimum). If you believe a child has used Ommelo, contact us and we will delete the data.
Regional disclosures
Australia (Privacy Act 1988 / Australian Privacy Principles). Ommelo is operated from Australia and stores its primary data in Australia. We handle personal information in line with the APPs, including access and correction rights and the notifiable data breaches scheme. Complaints may be made to the OAIC.
EU / UK (GDPR / UK GDPR). The legal bases, transfer safeguards, and rights described above apply. Our contact address serves as the point of contact for privacy requests.
United States (CCPA / CPRA). California residents have rights to know, delete, and correct their personal information, and to not be discriminated against for exercising them. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, so no "Do Not Sell or Share My Personal Information" action is needed.
Changes to this policy
We may update this policy as the product and our processors change. When we make a material change we will update the effective date at the top and, where appropriate, notify you.
Contact
Data controller: Ommelo (Australia). For any privacy question or request, email alifnoushad.96@gmail.com.