Privacy Policy
Last updated May 3, 2026
This Privacy Policy explains what information MyOmnihub ("we", "our", "us") collects when you use our service (the "Service"), why we collect it, how we use it, and what choices you have.
1. Information we collect
Information you provide directly
- Account info: name, email address, password (stored hashed), and any optional profile details (company, phone, language, time zone, avatar) you choose to provide.
- Content you create: text, images, and videos you upload to publish through the Service. Files you upload are kept for 5 days by default, after which they are automatically deleted from our servers (you can adjust this in admin settings).
- Communications: messages you send to our support team.
Information from connected social platforms
When you connect a third-party account (Facebook, Instagram, TikTok, Google Business, etc.) via OAuth, we receive only the data the platform exposes for the permissions you grant — typically:
- Account ID and display name
- Profile picture
- A page-level or location-level access token (and optional refresh token)
- Basic account metadata (e.g., follower count, page category, business address)
Access tokens are stored encrypted at rest and used solely to act on your behalf when you publish or schedule content. We do not read your private messages, mailbox, or any data outside what's needed to fulfill the publishing functions you authorize.
Information collected automatically
- Usage data: pages you visit within the Service, actions you take, and timestamps. Used for debugging and product improvement.
- Device & connection data: IP address, browser type, OS, and similar metadata. Used for security and analytics.
- Cookies & local storage: session cookies for authentication and small preferences (e.g., dark mode). We do not use third-party advertising cookies.
2. How we use your information
We use the information we collect to:
- Operate, maintain, and improve the Service;
- Authenticate you and protect your account;
- Publish content to the third-party accounts you've connected (only when you direct us to);
- Communicate with you about service updates, security alerts, and support requests;
- Comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information to third parties. We do not use your content to train AI models without your explicit consent.
3. How we share your information
We share information only in these limited cases:
- With third-party platforms you authorize. When you publish to Facebook, Instagram, etc., the content you publish (text, images, videos) is transmitted to those platforms via their public APIs. Their handling of that content is governed by their own privacy policies.
- Service providers. We rely on infrastructure providers (hosting, database, email delivery, AI inference such as OpenAI) that process data on our behalf. These providers are contractually bound to confidentiality and to use the data solely to provide their services to us.
- Legal compliance. We may disclose information if required by law, court order, or government request, or to protect the rights, property, or safety of our users, our company, or the public.
- Business transfers. If the Service is acquired or merged, your data may be transferred to the new entity, subject to the same protections as this policy.
4. Use of Meta Platform data
When you connect a Facebook Page or Instagram Business account, we use the data Meta returns about that connection (page name, page ID, IG account ID, follower count, profile picture, page-level access token) only to:
- display the connected channel within your dashboard; and
- publish content you author through the Service to that channel.
We do not retain or use Meta data for any other purpose. We do not share Meta-derived data with any third party other than infrastructure providers necessary for operating the Service. Meta access tokens are stored encrypted and are revoked from our end when you disconnect a channel.
5. Use of Google Platform data
When you connect a Google Business Profile, we receive an OAuth access token, refresh token, and the names/IDs of the business locations you manage. We use this data only to:
- list your locations so you can pick which to connect; and
- publish local posts to the location(s) you select.
Google access tokens are stored encrypted. Refresh tokens are used solely to renew expired access tokens for the connected location, never to access other Google services. We comply with the Google API Services User Data Policy, including the Limited Use requirements.
6. Data retention
- Account data: retained while your account is active.
- Uploaded media files: retained for 5 days by default, then automatically deleted from our servers (the originals you keep on your own devices are unaffected).
- Posts you publish: post records (text, target channels, status, timestamps) are retained for analytics purposes; the underlying media is deleted per the rule above.
- Logs: server logs are retained for up to 30 days for debugging and security.
- After account deletion: we delete or anonymize your account data within 90 days, except where retention is required by law (e.g., tax or audit records).
7. Your rights
Depending on your jurisdiction, you may have rights to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Delete your account and associated data;
- Export your data in a portable format;
- Object to or restrict certain processing;
- Withdraw consent (where processing is based on consent).
To exercise these rights, contact us at the email below. We will respond within 30 days.
8. Security
We use reasonable technical and organizational measures to protect your data, including encrypted access tokens at rest, HTTPS for all data in transit, and access controls on production systems. No method of transmission or storage is 100% secure; however, we work to follow industry best practices and respond promptly to any security incident.
9. Children
The Service is not directed to children under 13 (or 16 in the EEA), and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
10. International transfers
We are based in the United States and may process data on servers located there or with our service providers globally. By using the Service, you consent to the transfer of your data to the United States and other jurisdictions as needed to operate the Service.
11. Changes to this policy
We may update this Privacy Policy. The "Last updated" date at the top reflects the current version. Material changes will be communicated through the Service or by email. Continued use after the effective date constitutes acceptance.
12. Contact
For privacy questions or to exercise your rights, contact us at hello@omnitech.pro.