Privacy
Privacy
This notice covers the omnitrain.ai website and the OmniTrain application at app.omnitrain.ai. It explains what we collect, why, who processes it for us, how long we keep it, and how to have it deleted.
Who we are
OmniTrain is operated by OmniTrain LLC, a Florida limited liability company ("OmniTrain", "we"). We are the controller of the personal data described here. For anything in this notice, write to info@omnitrain.ai.
The website
The website uses Google Analytics 4 to count visits and see which pages are read. Google Analytics may use cookies and similar identifiers for that measurement. We do not use advertising pixels or session recording on this website, and it has no forms. Nothing you read here creates an account.
What the application collects
Your account
Your name, email address and sign-in method (email and password, or Google). If you invite collaborators, their email addresses and their role on your account.
Your business and your ads
What you tell us about your business so we can make ads for it: brand details, your website address and the analysis we make of its public pages, customer profiles, offers, prices, claims and other facts you approve, and the ads we generate for you (copy and images).
Your Meta connection
When you connect Meta, we receive an access token for your account and for the Pages you choose, and we read your ad accounts, Pages, campaigns and their performance figures. We use these only to publish the campaigns you approve, show you their results and prepare your reports. We store the access tokens so the connection keeps working until you disconnect.
Billing
Payments are handled by Stripe. We never see or store your full card number. We keep your Stripe customer reference, your plan and subscription status, your credit balance and a record of credit charges and refunds. We show the card brand, last four digits and expiry date that Stripe provides.
Usage and technical information
A record of the actions that cost credits or provider fees (for example which AI model produced an ad and how much processing it used), and the technical logs our hosting keeps to run and secure the service, which include IP addresses. The application has no analytics or tracking tools.
Why we use it, and on what basis
- To provide the service you signed up for (your account, making and publishing ads, reports, billing): because it is necessary for our contract with you.
- To keep the service secure and working, and to understand our costs: our legitimate interest in running a reliable service.
- Invoices and tax records: our legal obligations.
We do not sell your personal data, we do not use it to advertise to you, and we do not use your business content or your Meta data to train AI models.
Who processes data for us
We use these service providers. Each receives only what it needs for its part of the service.
| Provider | What it does for us |
|---|---|
| Google Cloud and Firebase | Hosting, sign-in, database, file storage and logs for the application and the website. |
| OpenAI | Writing ad copy, generating ad images, checking image quality and analysing your website. We send your business details, offer, approved facts and generated images. OpenAI's API terms say it does not use this data to train its models by default. |
| Replicate | Generating fallback ad images and repairing generated images. We send the creative brief or the image and a description of the fix. |
| Meta | Publishing the campaigns you approve and reporting their results, on your connected ad accounts and Pages. |
| Stripe | Payments, subscriptions and invoices. |
| Resend | Sending account email, such as collaborator invitations. |
| Google Analytics | Visit counts on the website. |
| Discord | Internal alerts to our team when something fails. An alert can include the email address involved. |
These providers are based in the United States. Where the law requires it for data from the European Economic Area or the United Kingdom, the transfer relies on the safeguards the provider offers, such as the European Commission's Standard Contractual Clauses.
Cookies
The application stores only what it needs to work, such as keeping you signed in and remembering the brand you are working on. It sets no analytics or advertising cookies. Stripe, which handles payments, sets its own cookies to prevent fraud. The website uses the Google Analytics cookies described above.
How long we keep it
- While your account exists, including after you cancel a subscription, we keep your account, saved work and unused credits so you can return. Canceling a subscription does not start an account-data deletion period.
- If you separately ask us to close your account, we remove its data from the live service, disable sign-in and destroy the Meta access tokens we hold. We keep a token-free copy in a restricted internal archive so an accidental closure can be reversed. The archive is not available in the application and currently has no automatic expiry.
- Billing records are kept for as long as tax and accounting law requires. Stripe keeps its own records under its own policy.
- Technical logs are kept for a limited period set by our hosting provider and then deleted automatically.
Subscription cancellation and account-data requests
To stop subscription renewals, cancel in Account → Billing. This does not close your account or delete your saved work. If you separately want to close your account or exercise a data right, email info@omnitrain.ai from the address on the account. We verify the request, explain what can be removed and what must be retained, and reply when the work is done.
This also covers the data we received from Meta: we delete it, and we destroy your Meta access tokens. An account principal can also disconnect the account's shared Meta connection from Account settings at any time. You can remove OmniTrain from the business integrations in your Meta settings.
Your rights
Depending on where you live, you can ask us for a copy of your personal data, ask us to correct or delete it, ask us to restrict or stop certain uses, ask for your data in a portable format, and withdraw any consent you have given. Write to info@omnitrain.ai. If you are in the European Economic Area, you can also complain to your data protection authority; in Romania that is the ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal).
Security
Data is encrypted in transit and stored with our hosting provider, access is limited to what each part of the service needs, and credentials such as your Meta access tokens are never shown in the application.
Children
OmniTrain is a tool for businesses and is not meant for anyone under 18.
Changes
If we change this notice in a way that matters, we update the date below and, for significant changes, tell account holders by email.
Last updated: October 2026.