What Ominvo stores
- Your account: email address, name (if provided), hashed password (email/password accounts only), Google account identifier (OAuth accounts)
- Your business: business name, business type, subscription tier, onboarding details
- Review data: once Google Business Profile integration is live, review text, ratings, reviewer names, and dates — as returned by the GBP API. This is public data that's already visible on Google.
- AI replies: every reply draft generated, whether you approved and posted it or not
- Billing: your subscription tier and billing email. Payment method data is stored and handled by Stripe — Ominvo never sees or stores your raw card number
What Ominvo does not store
- Your Google account password
- Raw card numbers or full payment details (Stripe handles this entirely)
- Any personal data about review authors beyond what Google exposes publicly
- Analytics or tracking data beyond basic operational metrics (active session counts, error rates)
AI and Anthropic
When you request an AI reply draft, the review text, your business name, industry, and any tone preferences you've set are sent to Anthropic's API (Claude). Anthropic generates the draft and returns it.
Anthropic does not use API inputs to train their models. This is covered by their API data usage policy — see Anthropic's privacy policy for the specific language. Ominvo does not sell or share your data with any third parties beyond the infrastructure providers listed in who can see your data.
Deleting your account
Go to Settings → Account → Delete Account.
Confirming deletion triggers:
- Immediate soft-delete of your business record and associated data
- Automatic cancellation of your Stripe subscription (no further charges)
- Hard delete of your data within 30 days
After deletion, AI replies, review data, and business settings are permanently removed. This cannot be undone.
Data export
Data export isn't available in the current version. It's on the post-launch roadmap. If you need your data before that feature ships, contact support and we'll handle it manually.
GDPR and CCPA
Ominvo honours deletion requests under GDPR (EU) and CCPA (California). The account deletion flow above covers the standard case. If you need a formal data subject request processed — including access requests, rectification, or portability — contact support with your request. Include "Data Subject Request" in the subject line.
Responses to formal requests are issued within 30 days.