Legal
Privacy Policy
Last updated: 26 August 2026
Omnicore Technologies LLC (“Omnicore”, “we”, “us”) operates OmnicoreOS, a customer communication platform that lets businesses receive and answer messages and calls from their own customers across WhatsApp, Facebook Messenger, Instagram Direct, SMS and web chat.
This policy explains what we do with personal data. It covers this website, the OmnicoreOS platform, and our mobile apps for iOS and Android.
Our two roles
Read this first — it determines who is responsible for what.
- We are the controller of the data of our business customers: the people who sign up for an OmnicoreOS account, their names, emails, roles and billing details.
- We are a processor of the data of their end customers: the people who message a business through WhatsApp, Messenger, Instagram, SMS or web chat. That data belongs to the business you contacted. We handle it on that business’s documented instructions, and we do not use it for our own purposes.
Each business decides what it collects, why, on what legal basis, and for how long. It is that business — not Omnicore — that is responsible for obtaining any consent required to message its customers and for answering to its own regulator. We give businesses the tools to meet those obligations: deletion, export, retention settings and access controls.
If you messaged a business and want your data deleted, the business you contacted is your first point of contact. We will also act on a request sent directly to us — see Deleting your data.
What we collect
From our business customers (we are controller)
- Account data: name, email address, password hash, profile photo, language and interface preferences.
- Workspace data: company name, teams, roles and permissions, branches, products.
- Authentication data: session records and sign-in timestamps; if you sign in with Google, your Google account identifier, name, email and profile picture.
- Usage and billing data: message volume, AI usage records and associated costs.
- Mobile app data: when you use our mobile apps, the device push notification tokens (Apple Push Notification service tokens, including VoIP push tokens used to ring incoming calls) needed to deliver notifications and calls to your device. These tokens identify your device, not your customers, and are deleted when you sign out or your session expires.
From end customers of our business customers (we are processor)
- Messages and their attachments: text, images, video, audio, documents, reactions.
- Channel identifiers: WhatsApp business-scoped user ID and phone number, Facebook page-scoped ID (PSID), Instagram-scoped ID (IGSID), SMS phone number, web chat visitor identifier.
- Profile information the messaging platform provides: display name and profile picture.
- Voice call records: call metadata, and call recordings and transcriptions where the business has enabled them.
- Conversation metadata: assignment, status, labels, response times, outcome.
From this website
The technical logs needed to serve it and keep it secure.
Data we receive from Meta Platforms
When a business connects its WhatsApp Business Account, Facebook Page or Instagram professional account, we receive — strictly to deliver the messaging service that business asked for:
- WhatsApp Business Platform: business account and phone number identifiers, inbound and outbound messages and media, message delivery statuses, message templates and their quality ratings.
- Messenger: the Page identifier, the page-scoped ID of the person messaging, their public name and profile picture, and the message contents.
- Instagram: the professional account identifier, the Instagram-scoped ID of the person messaging, their username and profile picture, and the message contents.
We do not use Meta Platform data for advertising, we do not sell it, we do not build user profiles across unrelated businesses, and we do not transfer it to data brokers. Each business’s data is isolated from every other business on the platform.
Why we use it
- To deliver messages between a business and its customers, which is the service.
- To route conversations to the right team or agent, and to apply the business’s own attention rules and service levels.
- To generate AI-assisted replies, transcriptions and summaries when the business enables that feature.
- To produce the analytics we show a business about its own conversations.
- To secure the platform, prevent abuse and meet legal obligations.
- To bill our business customers.
AI processing
Businesses can enable AI agents that read a conversation and draft or send replies, transcribe voice calls, and classify how a conversation ended.
When enabled, the relevant conversation content is sent to OpenAI for processing. It is processed to produce that specific output and is not used to train third-party models. A business can turn AI features off; where they are off, no conversation content is sent for AI processing.
Who we share data with
We do not sell personal data. We share it only with the providers we need to run the platform:
| Provider | What for | Where |
|---|---|---|
| Meta Platforms, Inc. | Delivering and receiving WhatsApp, Messenger and Instagram messages | United States |
| Apple Inc. | Delivering push notifications and incoming call alerts to our iOS app | United States |
| OpenAI | AI replies, transcription and conversation analysis, when the business enables it | United States |
| Twilio | SMS and, where used, carrier voice calls | United States |
| Cloudflare | Media storage and delivery | Global network |
| Oracle Cloud Infrastructure | Hosting our application servers and database | United States |
We run our own database on our own infrastructure — it is not operated by a third-party database vendor.
We also disclose data where the law requires it, and to protect our rights or the safety of others.
How long we keep it
- Messages, media and conversation history: retained for 30 days, then deleted automatically. Where a business needs a different retention period to meet its own regulatory obligations, that period can be agreed in its contract with us.
- Call recordings and transcriptions: same 30-day period.
- Raw webhook payloads received from messaging platforms: deleted automatically after 30 days.
- Temporary media handled in transit: stored in a short-lived bucket and deleted automatically when its retention window expires.
- Account and billing records: for as long as the account is active, plus the period we are legally required to retain them.
When a business closes its account, we delete or irreversibly anonymise its data within 30 days, except what we must keep by law.
Deleting your data
Full instructions are at https://omnicoreos.ai/data-deletion. In short:
- If you messaged a business: ask that business, or write to privacy@omnicoreos.ai with the phone number, username or account you used.
- If you are an Omnicore customer: delete data from inside the platform, or write to privacy@omnicoreos.ai to have your workspace deleted.
- If you connected Omnicore to your Facebook or Instagram account: removing Omnicore from your Facebook settings triggers our deauthorization callback, and we delete the access tokens and connection data for that authorization.
We respond within 30 days.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive a copy of it, and to complain to a supervisory authority. Write to privacy@omnicoreos.ai and we will act on it. We do not charge for this and we will not discriminate against you for exercising it.
Where we act as a processor, we will forward your request to the business responsible for your data and support them in answering it.
Security
- All traffic travels over TLS.
- Credentials and access tokens are stored encrypted at rest with AES-256-GCM.
- Access to each workspace’s data is enforced per business and per role; no business can read another business’s conversations.
- Access to production systems is restricted and audited.
No system is perfectly secure, but we treat these controls as a floor, not a ceiling.
Where data is processed
Omnicore Technologies LLC is based in the United States, and our infrastructure and providers process data in the United States.
If you are a business subject to laws that restrict moving personal data outside your country or region, that transfer takes place under the data processing agreement you enter into with us, which sets out the safeguards that apply. As the controller of your customers’ data, you decide whether to use the service on that basis.
Children
OmnicoreOS is a business tool and is not directed to children under 16. We do not knowingly collect their data.
Changes
We will post any change on this page and update the date at the top. Material changes are notified to our business customers.
Contact
Omnicore Technologies LLC5900 Balcones Drive STE 100, Austin, TX 78731, USA
Privacy: privacy@omnicoreos.ai
Support: info@omnicoreos.ai