Dear OmniBot user (“you”):
北京万象智维科技有限公司 (“Wanxiang Zhiwei”, “we” or “us”), with its registered address at Room 1094, 1st Floor, Blocks A and B, Yuandian Building, No. 8 Zhongguancun East Road, Haidian District, Beijing, values your privacy. This policy explains how we collect, use, store, entrust the processing of and protect your personal information when you use OmniBot, and how you can exercise your rights.
We recognize the importance of personal information and work to keep it secure and reliable. To maintain your trust, we follow the principles of accountability, clear purposes, informed choice and consent, data minimization, transparency, security and individual participation. We commit to appropriate safeguards in accordance with applicable law and established industry security standards.
Unless stated otherwise, this policy applies to the OmniBot application and related services we provide through it (together, the “OmniBot services”). The Android permissions and device features described here apply to the Android version; features may differ across platforms, versions and the functions you enable. When you use third-party services through OmniBot, those parties also process information under their own privacy policies, terms and configurations.
Please read and understand this policy before using the OmniBot services. We process personal information only with a lawful basis and in accordance with data minimization. Where consent or separate consent is required by law, we will separately inform you and obtain the required consent.
1. Information we collect and use
Personal information is information recorded electronically or otherwise that relates to an identified or identifiable natural person, excluding anonymized information. Sensitive personal information is information whose disclosure or misuse could readily harm a person's dignity or endanger their personal safety or property.
1.1 Accounts and authentication
When you register for or use an official OmniBot account, we process your email address, the password you set, email verification codes and verification results for registration, sign-in, password recovery or changes, and identity verification. The current Android version uses email and password sign-in; email codes are used for registration and password recovery. Our own email service sends these codes.
To maintain your account and provide official AI services, we also process your account identifier, registration time, sign-in sessions and their expiry and last-use times, your selected AI service mode, platform quota and model usage records. Usage records include the model used, time of the call, input and output token counts, and quota consumed.
Without account information, you cannot use official account or platform quota services that require sign-in. Bring-your-own-key and other features that do not depend on an official account can be used according to their own configurations. Keep passwords, verification codes and sign-in credentials secure. Do not email us your password, verification codes or API keys when making a request.
1.2 Model requests and task content
To understand and carry out your requests, OmniBot processes the text you enter, conversation context, images and files you select or upload, and tool parameters and results generated during tasks. When you enable screen operation, browser, file, calendar, memory or device collaboration features, relevant screenshots, page text, file contents, calendar entries or memories may also become part of a model request.
- Official AI services: requests pass through the official OmniBot model gateway to the corresponding model service, including Alibaba Cloud Model Studio (Bailian), to generate text, images or speech. Sign-in credentials verify your platform access. Official cloud model API response logs support troubleshooting, service stability and user feedback; they are retained for 7 days from creation, then automatically deleted without backups.
- Bring your own API key: when you configure your own model provider, request content, necessary headers and the API key are sent to the service address you configure. Our official account service receives only your choice of platform or bring-your-own-key mode; it does not receive your own model API key. The third party's processing location, retention period and data use depend on that service and your configuration.
- External agents, plugins and device collaboration: when you connect an external agent, MCP service, computer or other device, task instructions, selected files, tool results or relevant conversation content are sent to the service or device you connect, as needed for that feature.
Screen, file and conversation content may contain sensitive information about you or others and may be sent to cloud AI services. Provide only what is necessary for the task and ensure you have a lawful basis to provide other people's personal information. Where consent or separate consent is required, we will inform you and obtain it before the relevant processing.
1.3 Device features and local data
The Android version accesses or stores chat history, workspace files, task records, preferences, long-term memories and browser state for the relevant features. Processing on your device does not itself mean the data is uploaded to our servers. When you use that content in cloud model requests, external tools or device collaboration, necessary content is sent with the request.
For device compatibility, permission guidance, connectivity or diagnostics, the application may read the device brand and model, Android version, network status, local IP address and Android ID on your device. Application lookup reads the names, package names and icons of launchable apps to identify and open task targets; relevant results may also be used as model context. Copy, paste and related tool operations access clipboard content as needed.
The built-in browser stores cookies, website local storage and sign-in state to maintain web sessions. Websites may directly collect information you submit and network request information. When you intentionally use cookie export or related tools, credentials may be written to your workspace or supplied to the tools you choose. Authorize and share such access carefully.
1.4 Update checks and operational information
When checking for updates, the application sends the current app version, edition, update channel and download source preference, together with the device brand and model, Android and SDK versions, and a randomly generated installation identifier. Update and download services also process necessary network information such as the requesting IP address and record the request country or region and update-check or download events, for update distribution, compatibility analysis and operational statistics.
As services migrate, new versions use the backend we operate for update checks, download distribution, model catalog distribution and operational statistics. Our backend retains update statistics for 90 days from the event time and removes records beyond that period every hour. During the migration, older versions may continue to send requests through Cloudflare compatibility endpoints; historical statistics already held by the original Cloudflare service remain until their existing retention period expires. The random installation identifier distinguishes app installations and is not the Android ID. Update statistics requests do not include your chat content, password or model API keys. Because the identifier can still distinguish the same installation over time, we protect the associated information under this policy.
The application may also record operational errors, task or crash diagnostics locally.
1.5 Feedback
When you voluntarily submit feedback through the website or “Settings—About OmniBot—Send feedback” in the Android app, we process the title and description you enter, attachments you choose to upload and optional contact details to investigate, handle and respond to your feedback. Attachments may include screenshots, recordings or logs you provide. Submissions from the Android entry may also include diagnostic information such as the app version, platform and feedback source. When a signed-in user opens the feedback page, the account email is included and stored with the feedback so we can contact the user and handle the issue; contact details remain editable.
Feedback records and attachments are stored by the backend we operate, accessible only to administrators through access controls and not publicly displayed. Feedback currently has no automatic deletion after a fixed number of days and is retained until we delete it. You may request deletion through the email address in this policy; we will verify and handle requests as required by law. Submit only information relevant to your feedback and avoid uploading passwords, verification codes, API keys or unrelated personal information.
2. System permissions
The Android version requests or uses the following permissions and system capabilities depending on the features you use. You decide whether to enable permissions or special access through system prompts, app permission settings or feature controls. Refusing or withdrawing access affects the features that depend on it, without affecting unrelated features.
The audio permission described above reads audio files; it is not a microphone recording permission. The current Android main application's permission list does not request access to the microphone, contacts, SMS, call logs, phone state or precise location. This does not exclude such information from content you enter or from screens, files or webpages you authorize the app to read. If new processing purposes or permissions are added, we will update the disclosures and obtain authorization as required.
4. Exceptions to consent
Under applicable laws and regulations, processing may not require your prior consent in the following circumstances:
- It is necessary to enter into or perform a contract to which you and we are parties.
- It is necessary to fulfill statutory responsibilities or legal obligations.
- It is necessary to respond to a public health emergency or protect your life, health or property in an emergency.
- Information is processed within a reasonable scope for news reporting, public-interest oversight or similar activities in the public interest.
- Information that you have disclosed publicly, or that has otherwise been lawfully made public, is processed within a reasonable scope permitted by applicable law.
- Other circumstances provided by laws and administrative regulations apply.
Even where consent is not legally required, we follow the principles of lawfulness, legitimacy, necessity and good faith and fulfill applicable notice obligations.
5. Storage and security
5.1 Storage locations and retention
Under our current service arrangements, account and official service data under our control is stored in China. Local chats, files, memories, configuration and browser state are stored on your device. During the migration, Cloudflare compatibility forwarding for older versions and historical statistics in the original service, together with model services, websites, plugins or collaboration devices you choose, may involve processing outside China; not all such data can be described as stored domestically. We will fulfill any legally required cross-border transfer procedures or separate consent requirements.
- Account and service information: email addresses, account profiles, sign-in sessions, service modes, quota and usage information are retained for as long as needed to provide the account and services. On completion of account deletion, we delete the account and associated data under our control, unless otherwise required by law.
- Official model API response logs: retained for 7 days from creation, then automatically deleted without backups. Upon completion of account deletion, we immediately delete associated logs under our control. This rule does not apply to local chat history, Cloudflare update statistics or data retained independently by model service providers.
- Update statistics: our backend retains events for 90 days from the event time and removes records beyond that period every hour. Historical statistics migrated to our backend use the original event time for this period. Historical statistics already in the original Cloudflare service remain until their original 3-month (approximately 90-day) retention period expires. Random installation identifiers are stored separately from accounts; deleting an official account does not immediately delete statistics recorded by installation. Contact the email address in this policy to request management of related information.
- Feedback: titles, descriptions, attachments, optional contact details and related diagnostic information are stored in our backend and accessible only to administrators. There is currently no automatic deletion after a fixed number of days; the information is retained until we delete it. You may request deletion through the email address in this policy, and we will verify and handle requests as required by law.
- Local data: chats, workspace files, memories, tool records, browser state and local configuration remain until you delete them through the relevant feature or clear app data. Account deletion does not automatically remove local chats or files. You must separately manage files in external storage, exported copies and system backups.
- Device backups: Android may back up or transfer some app data according to your system settings. The dedicated encrypted stores for account credentials and model provider secrets are excluded from the app's system backup and device transfer rules. Use the system or backup service to manage deletion of other backed-up content.
Where laws or administrative regulations require longer retention, or deletion is technically difficult, we will stop processing other than storage and necessary security measures. If we discontinue a product or service, we will give prior notice as required by law and delete or anonymize relevant information after discontinuation, unless otherwise required by law.
5.2 Safeguards
Official account and model services transmit data using HTTPS. On Android, account credentials and model API keys use device-side encryption backed by Android Keystore. We apply access controls to backend data, limit access to personnel who need it for their duties and require confidentiality.
Model services, local-network tools or device connections you configure may use HTTP or other connection methods. Their transport protection depends on the service and network settings you choose. Use device collaboration on trusted networks, share connection credentials carefully and prefer HTTPS services.
We apply management, technical and physical safeguards appropriate to processing risks to protect against unauthorized access, disclosure, alteration, loss or misuse, and seek to minimize the information we collect and retain.
5.3 Risks and incident response
No internet environment or technical measure can guarantee absolute security. We make reasonable efforts to protect your information. Contact us promptly if you identify a potential security issue involving your account, email address or related data.
If personal information is or may be disclosed, altered or lost, we will take remedial action and notify authorities and affected individuals as required by law. Notices will describe the incident, possible consequences, measures taken or planned, and preventive or remedial steps you can take. Where individual notification is impracticable, we will use reasonable and effective public notices.
6. Your privacy rights
While using OmniBot, you have rights under applicable law to access, copy, correct, supplement or delete personal information, delete your account, withdraw consent and request explanations of processing rules. Use the available app features or email 2025omnimind@gmail.com. We may need to verify your identity for security.
6.1 Access, correction and supplementation
In the Android app, go to “My → Account & AI service” to view your sign-in email, platform usage and signed-in devices, and manage sessions. To correct, supplement or access other personal information, contact 2025omnimind@gmail.com.
After verifying your identity, we will handle your request in accordance with the law, unless otherwise provided by applicable laws or regulations.
6.2 Deleting personal information
You can request deletion at 2025omnimind@gmail.com. We will delete information as required by law when any of the following applies. If a statutory retention period has not expired or deletion is technically difficult, we will stop processing other than storage and necessary security measures.
- The processing purpose has been achieved, cannot be achieved or no longer requires the information.
- We stop providing the product or service, or the retention period expires.
- You withdraw consent.
- We process information in breach of laws, administrative regulations or our agreement.
- Other circumstances required by law or administrative regulations apply.
6.3 Deleting your account
Request deletion of your OmniBot account and associated data
In the Android app, go to “My → Account & AI service → Delete account”, confirm your email and enter your current password as prompted. You can also request assistance by emailing us below, without reinstalling the app. We may need to verify your identity and will respond within 15 working days after receiving the request and verifying your identity.
Once deletion is complete, we stop providing services associated with the account, permanently delete the account, sign-in sessions, platform quota and other associated data under our control, and immediately delete the email address and associated API logs, unless otherwise required by law. The Android client clears local sign-in credentials after the server confirms successful deletion.
Local chats, files, memories, browser state and copies you have saved are not automatically removed when you delete your account. Delete them through the relevant features or clear app data in Android settings. External files, backups and information retained by third parties must be handled separately. Signing out or uninstalling OmniBot does not delete your account; you can still email us to request account and data deletion.
6.4 Withdrawing consent
You may withdraw consent-based processing by stopping use of the relevant feature, using available app settings or contacting 2025omnimind@gmail.com. Withdrawal does not affect the validity of processing based on consent before it was withdrawn.
You can also revoke camera, calendar, file and other permissions in system settings, turn off accessibility services or overlays, revoke Shizuku authorization, or disconnect models, plugins and devices. The corresponding features stop using revoked permissions; information that still must be processed by law is handled under the applicable law.
6.5 Copying or transferring information
Where the conditions prescribed by law are met, you may request a copy of your personal information or its transfer to a personal information processor you designate. Send requests to 2025omnimind@gmail.com.
6.6 Responding to requests
If you cannot exercise your rights through the methods above, or believe our processing breaches the law or this policy, contact 2025omnimind@gmail.com. We will respond within 15 working days after receiving your request and verifying your identity.
As permitted or required by law, we may be unable to fulfill a request in circumstances involving:
- Our obligations under laws, regulations or requirements of industry authorities.
- National security or national defense.
- Public security, public health or significant public interests.
- Criminal investigation, prosecution, trial or enforcement of judgments.
- Sufficient evidence of bad faith or abuse of rights.
- Protection of your or another person's vital interests, such as life or property, where obtaining your consent is difficult.
- Serious harm to the lawful rights and interests of you, other individuals or organizations if the request is fulfilled.
- Trade secrets.
We generally do not charge for reasonable requests. For repetitive, excessive, manifestly unreasonable requests, or those that may harm others' lawful interests, we may charge necessary costs or refuse as permitted by law and explain why.
7. Changes to this policy
We may update this policy to reflect laws, regulations, regulatory requirements, product features or operational arrangements. Without your explicit consent, we will not reduce the rights you have under this policy and applicable law.
Material changes include, but are not limited to:
- Significant changes to our service model, such as processing purposes, information types or uses.
- Significant changes in ownership or organizational structure, such as changes of ownership through business adjustments, bankruptcy or acquisitions.
- Changes to the principal recipients of information shared externally or disclosed publicly.
- Significant changes to your rights regarding processing or how you exercise them.
- Changes to the organization responsible for information security, contact details or complaint channels.
- A personal information protection impact assessment indicating a high risk.
We will publish the revised policy and change the “Last updated” date above. Where additional notice or consent is required, we will follow the relevant procedures.
You can find the latest policy in the OmniBot app and on the publicly accessible HTTPS privacy policy webpage.
8. Children and minors
OmniBot is not directed at children and does not target users under the age of 14.
If you are a minor, read this policy with a guardian's guidance and obtain their consent before using OmniBot.
If we discover that we have processed information about a child under 14 without verifiable guardian consent, we will promptly delete it or take other necessary measures as required by law. Guardians who identify such issues should contact the email address in this policy.
9. Governing law and disputes
The formation, effectiveness, performance, interpretation and dispute resolution of this policy are governed by the laws of mainland China.
If a dispute arises concerning this policy or our processing of personal information, we and you may first seek an amicable resolution. If that fails, either party may bring proceedings before a court with jurisdiction in accordance with law, or submit complaints or reports to the relevant regulatory authorities.
10. Contact us
Operator: 北京万象智维科技有限公司
Privacy contact: 2025omnimind@gmail.com
Please email us with questions, comments, complaints or requests about this policy or personal information protection. We may need to verify your identity and will respond within 15 working days of receiving your request.