Current service: demo / preview. Live model calls and real payments are not yet available.
1. Who we are
OmniRelay is operated by MIRVOS PTE. LTD., a company registered in Singapore (“we”, “us”, or “our”). This policy covers personal information handled through omnirelay.ai, its account console and APIs, and communications with us.
For privacy questions, access or correction requests, withdrawal of consent, or account deletion requests, contact [email protected], addressed to the Privacy Contact, MIRVOS PTE. LTD..
2. Information we handle
- Account information: your email address, name, account and workspace identifiers, role, status, and registration date. Supabase manages passwords for new accounts; existing legacy accounts retain salted password hashes, not original passwords.
- Login and security information: session identifiers and expiry, authentication events, API key names and prefixes, hashed API keys, and rate-limit records. Infrastructure may also process IP addresses, browser information, and request or error logs.
- Service records: selected models, request identifiers, timestamps, token counts, calculated costs, request status, account balances, ledger entries, and administrative audit events.
- Submitted content: prompts, conversation messages, and other information you submit for processing, plus communications you send to support.
- Preferences: language and appearance preferences stored in your browser.
Please do not submit passwords, payment-card details, confidential third-party material, or sensitive personal information that is not necessary for your use of the service.
3. Current preview and request content
The current product is a demo/preview. Model responses and top-ups in demo workspaces are simulated; live model calls and real payments are not currently available. The application processes submitted demo messages to calculate simulated usage, but its request-history database stores usage metadata, not prompt or response text. This does not constitute a universal zero-retention guarantee for infrastructure logs, browser state, or support communications.
Before live model processing or payments are introduced, we will update the relevant notices to explain the applicable providers, data flows, and processing arrangements. A provider logo or model listing does not by itself mean your content is currently sent to that provider.
5. Why we use information
We use information to provide accounts and workspaces, authenticate users, process requested operations, show usage and balances, answer support requests, troubleshoot faults, prevent abuse, maintain security, and meet legal obligations. We also use operational information to understand and improve reliability. Where consent is required, we seek it; where applicable law permits another basis for processing, we rely on that basis.
This preview does not include an advertising network or an application-level model-training pipeline. We do not describe future model providers as having a particular training or retention policy until their actual arrangements have been assessed and disclosed.
7. Cookies, local storage, and external resources
The application uses an essential omni_session cookie to keep you signed in, with a configured lifetime of up to seven days. Signing out invalidates that session. Authentication providers may use their own session or security cookies during sign-in. Supabase sign-in stores authentication and refresh tokens in browser local storage to maintain and refresh your session. The legacy/demo session cookie described above applies to legacy and demo accounts. Browser local storage also remembers language and theme choices; it is not an advertising identifier.
Some site styles load fonts from Google Fonts. Loading those resources sends ordinary network information, such as your IP address, to Google. You can clear cookies and local storage in your browser, but this may sign you out or reset preferences. We will provide appropriate notice and choice before introducing non-essential tracking that requires consent.
8. Retention, security, and international processing
We retain information for the purposes described here, taking account of account activity, security investigations, dispute resolution, and legal requirements. Session expiry does not necessarily mean immediate deletion of the corresponding database record. We have not established a single fixed deletion period for all categories of data. Account closure and deletion requests are reviewed against necessary legal and security retention; limited records or backups may remain until they can appropriately be removed.
We use safeguards such as password hashing, restricted account access, and secure connections. No system is completely secure. If a personal-data incident occurs, we assess it and provide notifications required by applicable law.
Our service providers may process information outside Singapore. Where personal information is transferred overseas, we are responsible for arranging protections required by applicable Singapore law; we do not promise Singapore-only data residency.
9. Your choices and requests
You may ask us about the personal information we hold, request access or correction, withdraw consent where applicable, or request account closure and deletion by emailing [email protected]. We may need proportionate identity verification before acting. Some requests are subject to legal exceptions; we will explain relevant restrictions and any permitted fee before proceeding. Withdrawal of consent may prevent us from providing features that require the information.
If you use a workspace managed by another organisation, that organisation may also be responsible for its use of your information. Contact its administrator where appropriate. If our response does not resolve your concern, you may contact Singapore’s Personal Data Protection Commission or another competent authority.
10. Age and policy updates
OmniRelay is intended for adults aged 18 or over, not for children. If you believe a child has supplied personal information, contact us so we can review and address it.
We may update this policy as the product or our practices change. The date above identifies this version. We will provide additional notice of material changes where appropriate and obtain fresh consent where required. Questions may be sent to [email protected].
4. Google and other third-party sign-in
Where offered, third-party sign-in allows an identity provider to authenticate you. For Google sign-in, we request basic identity information: your provider account identifier, email address, name, and profile image if supplied. We use that information to authenticate you, create or maintain your account, display your profile, and help secure the service. We do not request access to Gmail messages, Drive files, contacts, or calendars for sign-in.
Supabase processes authentication information when Supabase-backed sign-in is used. GitHub or Apple sign-in, if enabled, similarly supplies the identity information permitted by the provider and your choices. We do not receive your provider password. Authentication information is not submitted as model prompt content merely because you sign in.
You can revoke Google access through your Google Account connections, or use the corresponding controls for other providers. Revoking access does not automatically delete an existing OmniRelay account; contact us to request deletion.