Status and scope
This is a product-policy draft for private-beta review. It does not replace legal advice, and Omniaa will not publish a final legal entity, mailing address, governing-law, or liability position until those details are confirmed by the founder and counsel.
This notice describes Omniaa’s current private-beta product behavior. A workspace is a separate company environment; Omniaa is designed to keep one workspace’s records unavailable to another workspace.
Information a workspace may provide
Account information includes a name, email address, authentication/session information, and workspace membership. Workspace information can include company profiles, contacts, relationships, leads, opportunities, tasks, approvals, audit records, and Business DNA.
When enabled by a workspace, Omniaa can process uploaded documents, extracted text, company knowledge, approved website-research evidence, meeting notes or transcripts, connected email and calendar evidence, SMS messages, phone-number configuration, call metadata, transcripts, and recordings only when recording is configured and the applicable consent state permits it.
How Omniaa uses information
Omniaa uses workspace information to authenticate users, provide the requested product features, build evidence-grounded drafts and summaries, operate governed communications and scheduling, protect the service, diagnose failures, and maintain security and audit records.
AI-generated material is not automatically treated as approved company truth. Business rules follow the product’s evidence → proposal → human confirmation → approved Business DNA model.
Connected services and AI processing
A workspace can choose to connect Google Gmail/Calendar or Microsoft Outlook/Calendar using the scopes shown during authorization. Omniaa uses the authorized data only for the selected workspace features and supports disconnect/revocation. AI processing is used only when an enabled feature requests it; provider use is listed on the Subprocessors page.
Omniaa's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Omniaa does not sell customer content or use it for advertising. It does not claim to use more connected-account access than a workspace authorizes.
Retention, export, and deletion
Retention defaults are visible to workspace owners and administrators in Account → Privacy controls. They are review-oriented defaults: they do not silently destroy audit or security records. Requests for workspace/account export, deletion, document deletion, transcript deletion, recording deletion, connected-account revocation, or number release are authenticated and audited.
Direct provider disconnection revokes stored provider credentials for the connection; historical records remain subject to retention, legal, security, and operational review.
Security and international processing
Omniaa uses tenant-scoped authorization, row-level database protections, server-only credentials, approval controls, audit records, and provider webhooks to reduce unauthorized access. No system is risk-free.
Service providers may process data in locations outside a user’s jurisdiction. International transfer requirements and contractual terms require counsel review before broader international availability.
SMS opt-in data
We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. Phone numbers and SMS consent collected by a workspace using Omniaa (a product of Legend Ventures L.L.C.) are used only to send the governed business messages that workspace configures, such as appointment confirmations and follow-ups.
Contact
A final public legal contact and mailing address have not been published because the founder has not selected a public legal identity. Do not send sensitive requests to an unverified address. The in-product privacy-request flow is available to authenticated users.