Privacy Policy

Last updated: 18 August 2026

This policy explains what personal data OmniCLI collects and what happens to it. Contact: gava.org.tech@gmail.com.

Your platform credentials stay on your machine

The most important thing to know first: the credentials you give the command-line tool for third-party platforms are stored locally on the machine you installed it on. They are not transmitted to us and we never hold them. The same is true of the data those actions return — it flows between your machine and the platform you are calling, not through us.

What we collect

  • Account details — your email address and sign-in identity, so you can log in and we can identify your account.
  • Devices — for each machine you sign in from, an identifier and a device fingerprint. The fingerprint is hashed on your machine before it is sent: the underlying machine name and identifiers never leave your computer. We use it to keep a stable device record across reinstalls and to apply the device limits of your plan.
  • Usage records — which action ran against which platform, when, and whether it succeeded. Where an action fails we store the error text after removing values that look like secrets or personal data. We use this to show you your own usage and to operate and debug the service.
  • Subscription details — your plan, subscription status, seats, and the identifiers our payment provider uses for you. We do not receive or store your card details.
  • Team data — if you invite people to a team, the email addresses you enter so we can send the invitation.
  • Product analytics — in our production service only, we record which pages and features are used, keyed to your account identifier rather than your name or email.

Why we may use it

To provide the service and perform our contract with you (accounts, devices, subscriptions, team invitations); for our legitimate interests in keeping the service secure, reliable, and improving (usage records, error reports, analytics); and to meet legal obligations such as tax and accounting records. Where the law in your country requires consent for analytics or similar cookies, we rely on that consent and you can withdraw it.

Who else processes it

We use a small number of providers, each acting on our instructions and only for the purpose listed:

  • Paddle — payments. Paddle is the Merchant of Record for our orders and is an independent controller of the payment data you give it.
  • Clerk — sign-in and session management.
  • Mailgun — sending team invitation emails.
  • PostHog — product analytics and error reporting.
  • Our hosting provider — running the service and storing its data.

Some of these operate outside your country, including in the United States. Where personal data is transferred internationally, it is protected by appropriate safeguards such as the European Commission's standard contractual clauses. We do not sell personal data.

How long we keep it

Account and subscription data is kept while your account exists, and afterwards only as long as needed for legal and accounting obligations. Usage records are kept for a limited period that depends on your plan and are then deleted automatically. Deleting your account removes your account, devices, definitions, and usage history; billing records that we are legally required to retain are the exception.

Cookies

We use cookies that are necessary for signing in and keeping you signed in. In our production service we also use analytics cookies as described above. We do not use advertising cookies.

Your rights

Depending on where you live, you can ask for a copy of your data, correct it, delete it, receive it in a portable form, restrict or object to how we use it, and withdraw consent where we rely on it. You can delete your account yourself from your account page. For anything else, email gava.org.tech@gmail.com and we will respond within one month. If you are in the EEA or UK and are unhappy with our response, you can complain to your local data protection authority.

Security

Traffic to the service is encrypted in transit, access to production data is restricted, and the command-line tool verifies the integrity of what it installs. No system is perfectly secure, but we take reasonable measures appropriate to the data we hold — which, by design, is as little as we can operate on.

Children

The service is not directed at children and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will remove it.

Changes

We may update this policy. The date at the top shows the current version, and material changes will be notified by email or in the application before they take effect.

Pick your platforms, ship your agents

Sign up, choose the actions your workflow needs, and get a copy-paste install one-liner.

Get Started