Privacy Policy

Last updated: [Date]
Effective date: [Date]

[Your Legal Entity Name] (“Ompo,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the Ompo desktop application, website, MCP server, and related services (collectively, the “Service”).

This policy should be read together with our [Terms and Conditions].

If you have questions, contact us at [privacy@ompo.ai].

1. Summary

  • Ompo is primarily a local visual editor for projects you run on your machine (for example, localhost).

  • Your website content and most edits stay on your device unless you use cloud account features or purchase MCP credits.

  • We collect account and billing information needed to authenticate you, manage MCP credits, and operate the Service.

  • We use service providers (such as Supabase and Stripe) to run core infrastructure.

  • We do not sell your personal information.

2. Information we collect

2.1 Information you provide



DataPurpose

Email address and password

Create and secure your account (via Supabase Auth)

Name

Display in your profile

Profile photo

Display in the app (uploaded to our storage provider)

Payment-related actions

Process MCP credit purchases (handled by Stripe)

Support communications

Respond to requests and troubleshoot issues

You may also set preferences stored with your account, such as whether you have completed onboarding or are permitted to use custom preview URLs.

2.2 Information collected automatically



DataPurpose

Account session data

Keep you signed in and sync MCP authentication locally

MCP token balance and usage

Enforce credit limits when you use Ompo MCP tools

Purchase records

Record credit pack purchases, amounts, and Stripe transaction references

App version and update status

Deliver app updates and compatibility fixes

Basic operational logs

Security, fraud prevention, debugging, and service reliability

We may collect device and app information such as operating system, app version, and general error reports. We do not intend to collect precise geolocation through the desktop app.

2.3 Information stored locally on your device

Much of Ompo’s core functionality operates on your computer. This may include:

  • Edit bundles (structured records of visual changes you make), typically under ~/.ompo/edits/

  • MCP session credentials used by the local MCP server, typically under ~/.ompo/session.json

  • Local billing cache for MCP edit token charges, typically under ~/.ompo/edit-billing.json

  • Authentication/session storage used by the desktop app

  • Preview content from URLs you load (for example, localhost pages)

  • Image files you select for background fills (referenced locally; not uploaded to Ompo servers except profile photos)

This local data is generally not transmitted to us unless a feature explicitly requires cloud access (for example, signing in, refreshing token balance, or purchasing credits).

2.4 Information we do not intentionally collect

We do not intentionally collect:

  • The full contents of your source code repositories

  • Your localhost site content for storage on our servers (preview rendering happens in the app)

  • Passwords for third-party tools (Cursor, Claude, Codex, etc.)

When you use third-party AI tools with Ompo edit data, their privacy policies apply to what you share with them.

3. How we use information

We use personal information to:

  1. Provide the Service — accounts, previews, editing, MCP integration, and credit management

  2. Process payments — sell and grant MCP credits

  3. Authenticate MCP usage — verify your session and deduct credits when MCP tools are used

  4. Improve and secure the Service — fix bugs, prevent abuse, and maintain infrastructure

  5. Communicate with you — support, important service notices, and (where permitted) product updates

  6. Comply with law — respond to lawful requests and enforce our Terms

We do not use your project preview content to train AI models.

4. Legal bases for processing (EEA / UK users)

Where GDPR or UK GDPR applies, we rely on:



BasisExamples

Contract

Providing accounts, MCP credits, and the Service you request

Legitimate interests

Security, fraud prevention, improving reliability, minimal analytics

Consent

Optional marketing emails or non-essential cookies (if used)

Legal obligation

Tax, accounting, and regulatory compliance

You may withdraw consent where processing is consent-based, without affecting the lawfulness of prior processing.

5. How we share information

We do not sell personal information. We share information only as follows:

5.1 Service providers (processors)



ProviderRole

Supabase

Authentication, database, file storage, serverless functions

Stripe

Payment processing for MCP credit purchases

Google Fonts

Font listing/metadata when you browse fonts in the editor

Hosting / CDN providers

App update distribution (for example, Supabase Storage)

These providers process data under contractual terms appropriate to their role.

5.2 Legal and safety

We may disclose information if we believe it is reasonably necessary to:

  • Comply with law, regulation, legal process, or governmental request

  • Enforce our Terms or protect rights, property, or safety

  • Detect, prevent, or address fraud, security, or technical issues

5.3 Business transfers

If we are involved in a merger, acquisition, or asset sale, your information may transfer as part of that transaction, subject to continued protections.

6. International data transfers

We and our providers may process information in countries other than where you live (including the United States). Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

7. Data retention

We retain personal information only as long as needed for the purposes described above:



Data typeTypical retention

Account data

While your account is active, then deleted or anonymized within [30–90] days after deletion request (unless law requires longer)

Purchase records

As required for tax, accounting, and dispute resolution (often 7 years where applicable)

MCP usage / token records

While account is active and as needed for billing integrity

Support messages

[24 months] unless a longer period is needed for an open issue

Local device data

Controlled by you; remains on your device until you delete it or uninstall Ompo

You can delete local Ompo data by removing files under ~/.ompo/ on your machine.

8. Security

We implement technical and organizational measures designed to protect personal information, including encryption in transit, access controls, and secure authentication practices.

No method of transmission or storage is 100% secure. You are responsible for keeping your account credentials safe and securing your development environment.

9. Your rights and choices

Depending on where you live, you may have rights to:

  • Access personal information we hold about you

  • Correct inaccurate information

  • Delete your account and associated cloud data

  • Export certain account data

  • Object to or restrict certain processing

  • Withdraw consent where processing is consent-based

  • Lodge a complaint with your local data protection authority

How to exercise your rights

Email [privacy@ompo.ai] with your request. We may need to verify your identity. We will respond within the timeframe required by applicable law.

Account deletion

You may request account deletion by contacting [privacy@ompo.ai]. Deleting your account will remove or deactivate cloud-held account data, subject to retention exceptions (for example, billing records).

Uninstalling the app does not automatically delete your cloud account.

10. California privacy notice (CCPA / CPRA)

If you are a California resident, you have additional rights:

  • Right to know what personal information we collect, use, and disclose

  • Right to delete personal information (subject to exceptions)

  • Right to correct inaccurate personal information

  • Right to opt out of sale/share — we do not sell or share personal information for cross-context behavioral advertising

To exercise rights, email [privacy@ompo.ai]. We will not discriminate against you for exercising privacy rights.

Categories collected (last 12 months): identifiers (email, user ID), commercial information (purchases), internet/electronic activity (session and operational logs), and visual information (profile photo you upload).

11. Children’s privacy

The Service is not directed to children under 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [privacy@ompo.ai] and we will take appropriate steps to delete it.

12. Cookies and similar technologies

Website

If you use [ompo.ai], we may use essential cookies for security and session management. We do not describe use of non-essential advertising cookies here; update this section if that changes.

Desktop app

The desktop app uses local storage mechanisms (including auth session storage) to keep you signed in and operate MCP features. These are necessary for core functionality.

13. Third-party links and integrations

The Service may link to or integrate with third-party tools (IDEs, AI assistants, payment pages, tutorial videos, etc.). Their privacy practices are governed by their own policies. We encourage you to review them before sharing information.

14. Changes to this policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice (for example, in-app, by email, or on our website). The “Last updated” date at the top reflects the latest revision.

15. Contact us

[Your Legal Entity Name]
[Registered address]
Privacy: [privacy@ompo.ai]
Support: [support@ompo.ai]
Website: [https://ompo.ai/privacy]

If you are in the EEA/UK and require a data protection contact, you may designate: [DPO / EU representative contact, if applicable]