Privacy Policy
Last updated: [Date]
Effective date: [Date]
[Your Legal Entity Name] (“Ompo,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the Ompo desktop application, website, MCP server, and related services (collectively, the “Service”).
This policy should be read together with our [Terms and Conditions].
If you have questions, contact us at [privacy@ompo.ai].
1. Summary
Ompo is primarily a local visual editor for projects you run on your machine (for example,
localhost).Your website content and most edits stay on your device unless you use cloud account features or purchase MCP credits.
We collect account and billing information needed to authenticate you, manage MCP credits, and operate the Service.
We use service providers (such as Supabase and Stripe) to run core infrastructure.
We do not sell your personal information.
2. Information we collect
2.1 Information you provide
DataPurpose
Email address and password
Create and secure your account (via Supabase Auth)
Name
Display in your profile
Profile photo
Display in the app (uploaded to our storage provider)
Payment-related actions
Process MCP credit purchases (handled by Stripe)
Support communications
Respond to requests and troubleshoot issues
You may also set preferences stored with your account, such as whether you have completed onboarding or are permitted to use custom preview URLs.
2.2 Information collected automatically
DataPurpose
Account session data
Keep you signed in and sync MCP authentication locally
MCP token balance and usage
Enforce credit limits when you use Ompo MCP tools
Purchase records
Record credit pack purchases, amounts, and Stripe transaction references
App version and update status
Deliver app updates and compatibility fixes
Basic operational logs
Security, fraud prevention, debugging, and service reliability
We may collect device and app information such as operating system, app version, and general error reports. We do not intend to collect precise geolocation through the desktop app.
2.3 Information stored locally on your device
Much of Ompo’s core functionality operates on your computer. This may include:
Edit bundles (structured records of visual changes you make), typically under
~/.ompo/edits/MCP session credentials used by the local MCP server, typically under
~/.ompo/session.jsonLocal billing cache for MCP edit token charges, typically under
~/.ompo/edit-billing.jsonAuthentication/session storage used by the desktop app
Preview content from URLs you load (for example, localhost pages)
Image files you select for background fills (referenced locally; not uploaded to Ompo servers except profile photos)
This local data is generally not transmitted to us unless a feature explicitly requires cloud access (for example, signing in, refreshing token balance, or purchasing credits).
2.4 Information we do not intentionally collect
We do not intentionally collect:
The full contents of your source code repositories
Your localhost site content for storage on our servers (preview rendering happens in the app)
Passwords for third-party tools (Cursor, Claude, Codex, etc.)
When you use third-party AI tools with Ompo edit data, their privacy policies apply to what you share with them.
3. How we use information
We use personal information to:
Provide the Service — accounts, previews, editing, MCP integration, and credit management
Process payments — sell and grant MCP credits
Authenticate MCP usage — verify your session and deduct credits when MCP tools are used
Improve and secure the Service — fix bugs, prevent abuse, and maintain infrastructure
Communicate with you — support, important service notices, and (where permitted) product updates
Comply with law — respond to lawful requests and enforce our Terms
We do not use your project preview content to train AI models.
4. Legal bases for processing (EEA / UK users)
Where GDPR or UK GDPR applies, we rely on:
BasisExamples
Contract
Providing accounts, MCP credits, and the Service you request
Legitimate interests
Security, fraud prevention, improving reliability, minimal analytics
Consent
Optional marketing emails or non-essential cookies (if used)
Legal obligation
Tax, accounting, and regulatory compliance
You may withdraw consent where processing is consent-based, without affecting the lawfulness of prior processing.
5. How we share information
We do not sell personal information. We share information only as follows:
5.1 Service providers (processors)
ProviderRole
Supabase
Authentication, database, file storage, serverless functions
Stripe
Payment processing for MCP credit purchases
Google Fonts
Font listing/metadata when you browse fonts in the editor
Hosting / CDN providers
App update distribution (for example, Supabase Storage)
These providers process data under contractual terms appropriate to their role.
5.2 Legal and safety
We may disclose information if we believe it is reasonably necessary to:
Comply with law, regulation, legal process, or governmental request
Enforce our Terms or protect rights, property, or safety
Detect, prevent, or address fraud, security, or technical issues
5.3 Business transfers
If we are involved in a merger, acquisition, or asset sale, your information may transfer as part of that transaction, subject to continued protections.
6. International data transfers
We and our providers may process information in countries other than where you live (including the United States). Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
7. Data retention
We retain personal information only as long as needed for the purposes described above:
Data typeTypical retention
Account data
While your account is active, then deleted or anonymized within [30–90] days after deletion request (unless law requires longer)
Purchase records
As required for tax, accounting, and dispute resolution (often 7 years where applicable)
MCP usage / token records
While account is active and as needed for billing integrity
Support messages
[24 months] unless a longer period is needed for an open issue
Local device data
Controlled by you; remains on your device until you delete it or uninstall Ompo
You can delete local Ompo data by removing files under ~/.ompo/ on your machine.
8. Security
We implement technical and organizational measures designed to protect personal information, including encryption in transit, access controls, and secure authentication practices.
No method of transmission or storage is 100% secure. You are responsible for keeping your account credentials safe and securing your development environment.
9. Your rights and choices
Depending on where you live, you may have rights to:
Access personal information we hold about you
Correct inaccurate information
Delete your account and associated cloud data
Export certain account data
Object to or restrict certain processing
Withdraw consent where processing is consent-based
Lodge a complaint with your local data protection authority
How to exercise your rights
Email [privacy@ompo.ai] with your request. We may need to verify your identity. We will respond within the timeframe required by applicable law.
Account deletion
You may request account deletion by contacting [privacy@ompo.ai]. Deleting your account will remove or deactivate cloud-held account data, subject to retention exceptions (for example, billing records).
Uninstalling the app does not automatically delete your cloud account.
10. California privacy notice (CCPA / CPRA)
If you are a California resident, you have additional rights:
Right to know what personal information we collect, use, and disclose
Right to delete personal information (subject to exceptions)
Right to correct inaccurate personal information
Right to opt out of sale/share — we do not sell or share personal information for cross-context behavioral advertising
To exercise rights, email [privacy@ompo.ai]. We will not discriminate against you for exercising privacy rights.
Categories collected (last 12 months): identifiers (email, user ID), commercial information (purchases), internet/electronic activity (session and operational logs), and visual information (profile photo you upload).
11. Children’s privacy
The Service is not directed to children under 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [privacy@ompo.ai] and we will take appropriate steps to delete it.
12. Cookies and similar technologies
Website
If you use [ompo.ai], we may use essential cookies for security and session management. We do not describe use of non-essential advertising cookies here; update this section if that changes.
Desktop app
The desktop app uses local storage mechanisms (including auth session storage) to keep you signed in and operate MCP features. These are necessary for core functionality.
13. Third-party links and integrations
The Service may link to or integrate with third-party tools (IDEs, AI assistants, payment pages, tutorial videos, etc.). Their privacy practices are governed by their own policies. We encourage you to review them before sharing information.
14. Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice (for example, in-app, by email, or on our website). The “Last updated” date at the top reflects the latest revision.
15. Contact us
[Your Legal Entity Name]
[Registered address]
Privacy: [privacy@ompo.ai]
Support: [support@ompo.ai]
Website: [https://ompo.ai/privacy]
If you are in the EEA/UK and require a data protection contact, you may designate: [DPO / EU representative contact, if applicable]