Legal
Privacy
Policy
Last updated August 26, 2026
OmniMark (“OmniMark”, “we”, “us”) runs AI marketing specialists that plan, draft, and — once you approve — execute advertising, social, email, and support work inside your own accounts on platforms like Meta, Google Ads, LinkedIn, X, Apple Ads, Instagram, Google Search Console, and Resend.
This policy explains what we collect, why, who we share it with, and how you get it back or get it deleted. It covers the marketing site at omnimark.ai, the OmniMark dashboard, and the specialists that act on your behalf. Questions or requests: privacy@omnimark.ai.
01Who we are
OmniMark is operated from the United States and is the controller of the personal information described here. Our clients remain the controller of the personal information inside their own connected accounts — customer lists, subscriber records, support inboxes — and we process that information as their service provider, on their instructions.
02What we collect
Information you give us.
- Service requests. When you submit the form on omnimark.ai we store your email address, business name, the budget range you picked, your message, and whether you asked us to run your ads or to get platform access.
- Account information. Sign-in is handled by Clerk. We receive your email address, name, and an account identifier. We never see your password.
- Your brief and your instructions. The business description, goals, audience, offers, budgets, brand rules, and everything you type to a specialist in chat.
- Credentials for the accounts you connect. OAuth tokens for Meta, Google (Google Ads, Search Console, Google Analytics) and LinkedIn, the Apple Ads API identifiers you paste (client id, team id, key id — the signing key pair is generated and held by us, encrypted), and API keys you paste for Stripe, Clerk, PostHog, Resend, DataForSEO, and BytePlus ModelArk. See section 4.
Information we pull from the accounts you connect, only for the scopes you granted:
- Campaign structure and performance from Meta Ads and Google Ads — campaigns, ad sets, ads, budgets, spend, impressions, clicks, conversions.
- Instagram content, comments, and engagement metrics for the accounts you connect.
- From LinkedIn: the ad accounts and company Pages you administer, campaign structure and performance, audience demographics, the Page’s posts, comments, follower and engagement statistics, and the name and identifier of the member who connected — so a specialist can propose posts as the Page or as that member, which are published only after that member approves them.
- From X: the profile, follower counts and subscription status of the accounts you connect (the founder’s and the brand’s), their posts and the metrics X reports on them, replies and mentions of those accounts, and the public posts and profiles a specialist looks up for research — so it can propose posts, threads and replies, which are published only after you approve them (posts written as the founder always are).
- From Apple Ads: the ad accounts your API user can reach and its role on each, the apps the account owns, campaign structure and performance (spend, impressions, taps, installs, search terms, impression share), and public App Store listing data.
- From Google Search Console and Google Analytics: search queries, pages, clicks, impressions, positions, sitemaps, indexing status, and organic traffic for the properties you select.
- From DataForSEO, with the account you paste: keyword volumes, difficulty, rankings, competitor domains, backlinks, and search results for the keywords the SEO specialist researches. This is market data, not data about your customers.
- Product, subscription, and revenue data from Stripe, and product analytics from PostHog.
- Audiences, contacts, segments, and delivery statistics from Resend, plus the content of support email you forward to a per-project OmniMark receiving address.
That data can include personal information about your customers — email addresses, names, purchase history, message contents. We only handle it to do the work you asked for.
Information we generate. Chat transcripts with your specialists, the proposals in your approval queue and your decisions on them, run logs, and the images and video the specialists create for your campaigns.
Information collected automatically. Standard server and request logs (IP address, user agent, timestamps, paths) kept for security and debugging, and the cookies described in section 7.
03How we use it
- To run the service: plan campaigns, draft creative and copy, and execute the actions you approve.
- To show you what a specialist wants to do before it happens, and to record your decision.
- To email you about your account, your approval queue, failures, and new service requests.
- To keep the platform secure, prevent abuse, debug, and enforce our Terms.
- To improve the product in aggregate, and to comply with law.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use your data or your customers’ data to train AI models.
04Credentials and connected accounts
Access tokens, refresh tokens, and API keys are encrypted with AES-256-GCM before they are written to our database, are decrypted only in memory at the moment a call is made, and are never shown back to you or sent to your browser. Disconnecting an integration in the dashboard deletes the stored credential.
We ask for the narrowest scopes that let the work happen, and we never post, spend, or send on your behalf except through an action you approved — or an action you explicitly set to run automatically.
05Google user data
LinkedIn. When you connect LinkedIn we request the Marketing API scopes needed to read and manage the ad accounts and company Pages you administer and to post on behalf of the member who connected (r_ads, rw_ads, r_ads_reporting, r_organization_social, w_organization_social, r_organization_admin, rw_organization_admin, w_member_social, r_basicprofile). We store your LinkedIn member identifier and name, the ad account and Page you select, and an encrypted access token (and refresh token where LinkedIn issues one). We use that access only to read those accounts and to publish the campaigns, ads, posts, and comment replies you have approved — nothing is ever published under a member’s name without that member’s approval, and we never send messages, connection requests, or engagement on other people’s content. Our use of LinkedIn data follows the LinkedIn API Terms of Use; you can revoke access at any time from the project’s Connections settings or from LinkedIn’s Permitted Services page, after which we delete the token.
X. When you connect an X account we request the OAuth 2.0 scopes needed to read that account and its posts, publish on its behalf, upload media, and hide replies under its own posts (tweet.read, tweet.write, users.read, offline.access, media.write, tweet.moderate.write). We store the account’s id, handle and display name and an encrypted access token and refresh token. We use that access only to read the connected accounts, mentions of them and public posts you ask a specialist to research, and to publish the posts, threads, replies, reposts and deletions you have approved. We never like, follow, message, or otherwise engage on your behalf without an approved proposal, never post the same content from two accounts, and never train models on X content. Our use of X data follows the X Developer Agreement and Policy; you can revoke access at any time from the project’s Connections settings (which also revokes the token at X) or from X’s Connected apps page, after which we delete the token.
OmniMark’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect Google Ads we request the adwords scope; when you connect Search Console we request the webmasters and analytics.readonly scopes. We store your Google account email, the Google Ads customer ID, Search Console property and Analytics property you select, and an encrypted refresh token. We use that access only to read those accounts and to create or change campaigns, ad groups, ads, budgets, and sitemap submissions that you have approved. We do not transfer Google user data to third parties except as needed to provide the service, we do not use it for advertising to you, and no human at OmniMark reads it except to fix a problem you reported, with your permission, or where law requires it. You can revoke access at any time in the dashboard or from your Google account permissions.
08How long we keep it
- Service requests: until you ask us to delete them.
- Account, project, and brief data: for as long as your account is active, then deleted or anonymized within 90 days of closure.
- Credentials: until you disconnect the integration or close your account.
- Approval-queue rows: they expire automatically 30 days after they are created.
- Server logs: typically 30 days.
We keep what we must to meet legal, tax, or dispute-resolution obligations.
09Security
Data is encrypted in transit (TLS) and at rest, credentials get a second layer of application-level encryption, each client project is isolated with its own agent instance and its own credentials, and access to production is limited to the people who need it. No system is perfect; if a breach affects you, we will notify you as the law requires.
10Your rights and choices
Wherever you live, you can ask us to access, correct, export, or delete your personal information, and you can withdraw consent or disconnect an integration at any time. Email privacy@omnimark.ai and we will respond within 30 days. We will not discriminate against you for exercising a right.
If you are in California, that includes the rights to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal information as those terms are defined by the CCPA. If you are in the EEA or UK, our lawful bases are performance of a contract (running the service), legitimate interests (security, product improvement, our own marketing measurement), consent (advertising cookies), and legal obligation; you also have the right to complain to your supervisory authority.
If your data reached us because one of our clients is our customer, send your request to them; if you send it to us, we will pass it on and help them answer it.
11International transfers
We operate in the United States and our providers may process data in the United States and other countries. Where we move personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses.
12Children
OmniMark is a business tool and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child gave us information, write to us and we will delete it.
13Changes to this policy
We will update this page when our practices change and move the “last updated” date. If a change is material, we will tell account holders by email or in the dashboard before it takes effect.
14Contact us
Privacy questions, data requests, and complaints: privacy@omnimark.ai.