OMISPHERE

Legal

Privacy Policy

Last updated: May 2026

This policy explains what OMISPHERE collects, why, and the choices you have. OMISPHERE is a tool for analyzing publicly available social-media activity; we have designed it to collect as little personal data about you as possible.

Account data we collect

  • Your email address — for login, account recovery, and billing receipts.
  • A one-way bcrypt hash of your password. We never store or see your actual password.
  • A log of the scans you run, used to meter credits and bill accurately.
  • A one-way hash of the IP address you signed up from, used solely to detect free-trial abuse. We do not store your raw IP address.
  • Your referral code and, if you were referred, who referred you.
  • Your notification preferences and, if you set one, an outbound webhook URL.
  • Payment details are handled exclusively by Stripe. We never receive or store your card number.
  • A small first-party log of product actions (viewing a featured example, exporting or sharing a report, a public report being opened, and your optional answer to one feedback question) — used only to learn what users find useful. No IP addresses, no device fingerprinting, no session recording, and no third-party analytics of any kind.

Public social-media data we process

When you scan a YouTube channel or video, OMISPHERE retrieves publicly available data through the YouTube Data API: channel metadata, comment text, public engagement counts, and creation timestamps. From this we compute behavioral fingerprints and coordination signals. We only process data that is already public; we do not access private messages, non-public account details, or anything behind a login.

How we use data

  • To run detections and present results to you.
  • To improve accuracy over time. Behavioral fingerprints derived from scans feed a shared detection database — the core of how OMISPHERE gets smarter as more content is analyzed.
  • To meter credits, process subscriptions, and prevent abuse.
  • To deliver the alerts and notifications you opt into.

Cookies

We use a single, signed, httpOnly session cookie to keep you logged in. We do not use advertising cookies, third-party trackers, or cross-site analytics.

Sharing and subprocessors

We do not sell your data and we do not share your scan history with third parties for their own purposes. We rely on a small set of subprocessors to operate the service: Stripe (payments), our hosting and managed-database providers (application + storage), an optional SMTP provider (alert and account emails), and — only when you explicitly generate analyst commentary on an investigation — Anthropic's API for that single request.

Your rights

You can request access to, export of, or deletion of your account and associated personal data at any time. Deleting your account removes your login, scan logs, saved investigations, watchlists, and graphs. Aggregated, de-identified detection signals that do not identify you may be retained as part of the shared detection database. To exercise any of these rights, email privacy@omisphere.ai.

Data retention

Account data is kept for as long as your account is active and deleted on request. De-identified behavioral fingerprints may be retained indefinitely as part of the detection dataset.

Security

Passwords are hashed with bcrypt, sessions are signed and httpOnly, and traffic is served over TLS in production. No system is perfectly secure, but we work to protect your data and to minimize what we hold.

Children

OMISPHERE is not intended for anyone under 16, and we do not knowingly collect data from children.

Changes

We may update this policy as the product evolves. Material changes will be reflected in the “last updated” date above.

Contact

Questions about privacy? Email privacy@omisphere.ai.

This policy describes our current data practices in plain language. It is not legal advice. If your use is governed by a specific regime (GDPR, CCPA, or another), contact us with any questions.