Privacy Policy — Omni

Effective Date: July 14, 2026 | Last updated: June 26, 2026

Executive Summary

Omni is a 100% advertisement-free and third-party analytics-free health and nutrition tracking application. We do not contain Google AdMob, Firebase Analytics, or any behavioral tracking SDK. The vast majority of your data never leaves your device. Where external processing is required (AI features, weather, subscriptions), we use the minimum data necessary and rely exclusively on Apple's and Google's enterprise-grade infrastructure.

1. Data Controller

The data controller responsible for your personal data is:

Enes Beyaz
Email: support.omniapp@gmail.com

If you are located in the European Economic Area (EEA) and have questions about how your personal data is processed, please contact the Service Provider at the address above.

2. What Data We Collect and Why

2.1 Data You Provide Directly

The following information is stored locally on your device via Apple SwiftData and is never uploaded to the Service Provider's servers:

2.2 Apple HealthKit

With your explicit permission, the Application reads the following HealthKit data types:

HealthKit data is governed by strict rules:

2.3 Camera and Image Data

The Application uses your device camera for:

Images are transmitted to the Google Gemini API solely for real-time analysis. Images are not stored on the Service Provider's servers. They are discarded immediately after analysis is complete.

2.4 Location Data (Apple WeatherKit)

The Application accesses your device's approximate location to:

Location data is processed momentarily via Apple's WeatherKit framework. Coordinates are never logged, stored historically, or shared with third parties for advertising. You may restrict location access at any time in your device settings.

2.5 Subscription Data (RevenueCat)

Premium subscription validation is managed through RevenueCat. RevenueCat receives anonymized transaction identifiers from Apple's App Store to verify entitlement status. The Service Provider does not have access to your payment card or billing details.

RevenueCat Privacy Policy: https://www.revenuecat.com/privacy

2.6 Technical Data

3. Artificial Intelligence and Google Gemini API

The Application uses the Google Gemini API to power:

Data transmitted to Gemini:

When AI features are active and you have granted AI health consent, the following non-identifiable context may be transmitted: age range, weight range, health goal type, food allergies, diagnosed medical conditions, weekly aggregate nutrition totals, derived wellness signals (such as heart-rate variability trend, sleep duration, and activity level), local weather context (temperature and humidity) used to calculate dynamic hydration goals, anonymized behavioral usage patterns (for example, typical logging times learned on-device), and food or supplement images. This list is illustrative and not exhaustive; in all cases the data is aggregated, de-identified, and never accompanied by your name, email, or account identifier.

Critical safeguards:

This processing is governed by Google's Privacy Policy and the Google Gemini API Terms of Service:
https://ai.google.dev/gemini-api/terms

GDPR — Automated Decision-Making and Profiling (Article 22):
The Application uses automated processing of your data to generate personalized recommendations (recipes, hydration goals, coaching tips). This constitutes profiling under GDPR. These recommendations are informational and do not produce legal effects or significantly affect you in a similarly serious manner. You have the right to object to this profiling at any time by disabling the AI Master Toggle.

EU AI Act Compliance:
The AI features in this Application are classified as low-risk under the EU AI Act. All AI outputs are clearly presented as informational suggestions and do not replace professional medical or nutritional advice.

4. Advertising

The Application does not contain any advertising. There are no third-party advertising SDKs (including Google AdMob), no behavioral tracking pixels, and no advertising identifiers collected. Neither free nor premium users are shown advertisements.

5. Third-Party Analytics

The Application does not use any third-party behavioral analytics SDKs (including Firebase Analytics, Flurry, Mixpanel, or similar services). In-app data visualizations (charts, trends) are computed locally on your device using Apple's native frameworks.

6. Data Storage and Architecture

Data Type Where Stored
Profile, logs, recipes, streaks Your device (Apple SwiftData — local only)
HealthKit metrics Apple Health app (Service Provider has no server copy)
Weather data Momentary — not stored
Camera images Momentary — discarded after Gemini analysis
Subscription status RevenueCat (anonymized transaction ID)
Payment details Apple App Store (Service Provider never accesses these)

The Service Provider does not operate any servers that store personal user data.

7. Lawful Basis for Processing (GDPR — EEA Users)

Processing Activity Lawful Basis
Health, nutrition, and dietary data Explicit consent — Article 6(1)(a) and Article 9(2)(a)
Camera image analysis via Gemini Explicit consent — Article 6(1)(a)
Location data for WeatherKit Explicit consent — Article 6(1)(a)
Core app functionality Performance of a contract — Article 6(1)(b)
Subscription and payment records Legal obligation — Article 6(1)(c)

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawal does not prevent you from continuing to use the Application's core features.

8. International Data Transfers

Google LLC (Gemini API) and RevenueCat process data on servers located in the United States. Where such transfers occur from the EEA, the Service Provider relies on:

You may request a copy of applicable transfer safeguards by contacting: support.omniapp@gmail.com

9. Data Retention

Data Type Retention Period
Profile and health data Duration of app use + 12 months, unless you delete the app or request erasure
Notification history 90 days (local, on-device)
Camera images Zero — discarded immediately after analysis
HealthKit data Accessed in real time; no copy retained by Service Provider
Subscription and payment records 7 years (tax and accounting legal obligation)
Anonymized and aggregated data Indefinitely (contains no personal data)

Uninstalling the Application immediately and permanently deletes all locally stored data from your device.

10. Your Rights Under GDPR (EEA Users)

If you are located in the EEA, you have the following rights:

To exercise any of these rights, contact: support.omniapp@gmail.com

The Service Provider will respond within 30 days. This period may be extended by two further months where necessary. You also have the right to lodge a complaint with your national data protection supervisory authority. A directory of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

11. Your Rights — General (All Users)

Regardless of your location, you may at any time:

Contact: support.omniapp@gmail.com

12. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the right to:

The Service Provider does not sell or share personal information with third parties for cross-context behavioral advertising.

To exercise your CCPA/CPRA rights, contact: support.omniapp@gmail.com

13. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, the Service Provider will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, you will also be notified directly without undue delay, as required by GDPR Article 34.

14. Children's Privacy

The Application is not directed to children under the age of 16. The Service Provider does not knowingly collect personal information from children under 16. If the Service Provider becomes aware that a child under 16 has provided personal information, that information will be deleted promptly. If you are a parent or legal guardian and believe your child has provided personal information to the Application, please contact: support.omniapp@gmail.com

15. Security

The Service Provider implements appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. All data transmitted to external services (Gemini API, RevenueCat, WeatherKit) is encrypted in transit using industry-standard TLS. Locally stored data is protected by Apple's iOS Data Protection framework.

16. Changes to This Privacy Policy

The Service Provider may update this Privacy Policy from time to time. For material changes, you will be notified via an in-app notification and the updated policy will be posted with a new effective date. Where required by applicable law (including GDPR), your consent will be sought before material changes take effect. Previous versions are available upon request at: support.omniapp@gmail.com

17. Contact

Enes Beyaz
Email: support.omniapp@gmail.com

For complaints that cannot be resolved directly, EEA users may contact their national data protection supervisory authority:
https://edpb.europa.eu/about-edpb/about-edpb/members_en