Last updated: 23 September 2026
1. Who is responsible and what this notice covers
Omilo is the data controller for the personal data described in this notice. Privacy and general support requests can be sent to contact.omiloai@gmail.com.
This notice applies when you use the Omilo mobile application, visit omiloai.com, contact support, buy an offer, or request account deletion.
2. Data we process
- Optional website measurement: only after your website consent, PostHog EU receives a page category, language, and clicks on App Store, Google Play, or Contact links. A random identifier lasts only for the current page and is not connected to your Omilo account. Sentry receives fixed website error codes and page/language tags, without raw error messages or stacks. We do not send form contents, email addresses, page query strings, referrers, or conversations through these tools. Service providers necessarily receive network connection information when handling requests.
- Account data: account identifier, email address, display name, authentication provider, and session information.
- Live voice and text: audio, transcript, source language, and translated output needed to perform a translation.
- Preferences and usage: app language, language choices, subscription status, remaining time, conversation timing, and security or rate-limit records. Omilo's own usage records do not contain the words spoken.
- Purchases: product, transaction, subscription, and entitlement information supplied by Apple, Google, and RevenueCat. Omilo does not receive the full payment-card number.
- Support data: name, email address, subject, message, request language, and deletion confirmation submitted through Formspree or email.
- Optional product analytics: a random pseudonymous identifier, platform, app and update versions, selected language pair, plan category, technical attempt identifiers, tutorial steps and completion mode, press and recording duration, translation latency and outcome, microphone-permission status, credit use, commercial variant and products displayed, paywall availability and views, and purchase progress or outcome. These events do not contain conversations, audio, transcripts, translations, email addresses, or the internal Supabase account identifier.
- Diagnostics and updates: technical issue code, affected screen, device model, operating-system and app versions, update channel, runtime and update identifiers, stack information, and update delivery, adoption, or failed-installation information where available.
- Local app data: authentication session, preferences, selected and favorite languages, analytics choice, tutorial and offer-state markers, and temporary technical queues needed for offline operation.
- Other technical data: information reasonably needed to operate, secure, diagnose, and protect the service, including privacy-preserving device or request identifiers where used.
3. Voice processing and OpenAI
When you hold the microphone button, Omilo captures audio temporarily on the device. After a sustained press of at least half a second, audio can be sent through a secured real-time connection to OpenAI to transcribe and translate the sentence and produce spoken output. Shorter presses are discarded locally without sending audio or using your time. No audio is sent while the app is idle.
Omilo does not intentionally save audio recordings or conversation transcripts in its own database or on the device. OpenAI may include customer content in abuse-monitoring logs retained for up to 30 days by default, unless a longer period is legally required or reasonably necessary to prevent harm. Data sent through the OpenAI API is not used to train or improve OpenAI models unless the API customer explicitly opts in.
4. Why we process data
- Contract: provide transcription, translation, playback, accounts, purchases, balances, requested support, and application updates.
- Legitimate interests: secure the service, prevent fraud and abuse, investigate technical failures through Sentry, maintain reliable update delivery through Expo/EAS Update, and defend legal claims, after balancing those interests against user rights.
- Legal obligations: retain or disclose limited records when required by accounting, tax, consumer, platform, or other applicable law.
- Consent: send optional pseudonymous product analytics to PostHog EU. You may refuse without losing access to Omilo and may withdraw this consent at any time in the app settings. Microphone access is also controlled by the device permission, which can be changed in system settings.
5. Service providers and international transfers
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, standard contractual clauses, or another valid legal safeguard. Each store also processes purchases under its own privacy terms.
- Supabase: authentication, account records, server functions, security, and usage metering.
- OpenAI: real-time voice transcription, translation, and spoken response processing.
- RevenueCat, Apple, and Google: purchases, subscriptions, receipts, and entitlement status.
- Formspree: website contact and external account-deletion forms.
- Hostinger International Limited: hosting and delivery of omiloai.com.
- PostHog EU: optional product analytics hosted in the European Union, only after your explicit consent to account-linked analytics. PostHog groups events under a random pseudonymous identifier. The link to your Omilo account is kept separately in a restricted Supabase table; PostHog does not receive your email address or internal Supabase account identifier. A previous analytics choice does not authorize this new account link, and historical installation identifiers are not merged into it.
- Sentry: technical error and sampled performance diagnostics, using the project’s German data region. Omilo filters JavaScript diagnostic events to remove user identity, request content, free-form data, audio, transcripts, translations, and other conversation text. Native crash reports and reports from older versions may contain technical identifiers or approximate location data supplied by the diagnostic service. Development files uploaded privately to Sentry help interpret errors; they are not user conversations.
- Expo/EAS Update: automatic checks and downloads for application updates, plus technical information needed to distribute updates and diagnose their adoption or installation.
6. Retention
- Website privacy choice: stored in this browser for 180 days, or for the current page if browser storage is unavailable. You can refuse or withdraw using Privacy choices at the bottom of the site. No optional PostHog or Sentry requests are sent before consent; withdrawal stops further requests and clears the current page identifier. Previously received website events are not linked to an Omilo account, so account deletion cannot locate them. They are retained only while needed to compare website use and diagnose faults; contact us for requests concerning this data.
- Audio and transcripts: not intentionally stored by Omilo; OpenAI abuse-monitoring logs may retain customer content for up to 30 days by default.
- Account, preferences, balances, and entitlements: while the account remains active, then deleted or anonymized when the account is deleted, subject to limited legal exceptions.
- Conversation metering audit without spoken content: up to 30 days. Short-lived rate-limit records: up to 24 hours.
- Formspree submissions: up to 30 days in Formspree on the configured plan; related support email is deleted no later than 12 months after the request is closed, unless needed for a dispute or legal obligation.
- PostHog EU analytics: kept while needed to evaluate activation, reliability, and purchases, taking into account the period needed to compare app versions and resolve product issues. Withdrawal of consent or account deletion removes the account link and queues deletion of the associated pseudonymous profile and events. Local collection stops immediately on withdrawal; server processing requires connectivity and deletion by PostHog is asynchronous. Historical installation events are not linked to the account and cannot be located using the account alone; contact us for a data request.
- Sentry diagnostics: retained for the event-retention period configured for Omilo's Sentry project, then deleted under Sentry's retention process.
- Expo/EAS Update technical records: retained according to the configured service period and for as long as needed to distribute, measure adoption of, and diagnose application updates.
- Data stored locally by the app: kept until replaced, cleared through the relevant setting, account deletion or sign-out where applicable, or removal of the app, subject to operating-system secure-storage and backup behavior. Temporary offline queues are cleared after transmission, withdrawal of analytics consent where applicable, or local reset.
- Strictly necessary accounting and transaction evidence: for the period required by applicable law. Apple, Google, and RevenueCat may retain their own records under their respective obligations.
7. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability of your personal data and withdraw consent where processing is based on consent. You can refuse optional PostHog analytics or withdraw consent at any time in the app settings. Withdrawal stops future analytics without affecting processing performed before withdrawal.
You can delete your account in the app or use the account-deletion page if you no longer have access. For the new account-linked analytics, deleting the account also queues deletion of the associated PostHog profile and events. Withdrawing analytics consent in Settings has the same analytics effect without deleting your Omilo account. If you consent again later, a new pseudonymous identifier is created.
Send a request to contact.omiloai@gmail.com. We may verify that you control the account before acting. We aim to respond within one month, subject to lawful extensions. You may also lodge a complaint with the French data protection authority, the CNIL, at cnil.fr.
8. Security, age, and changes
Omilo uses proportionate technical and organizational safeguards, including secured connections, server-side access controls, and limited data collection. No online service can guarantee absolute security.
Omilo is intended for people aged 16 or older. Do not create or use an account if you are younger than 16. Users aged 16 or 17 should use the automated AI service with appropriate adult guidance, avoid sharing sensitive personal information, and independently verify important translations.
We may update this notice when the service or legal requirements change. The current version and update date are published on this page.