Skip to policy
OmniBot
Back to home

PRIVACY POLICY

OmniBot Privacy Policy

Version: 1.0 Last updated: Effective:

Dear OmniBot user (“you”):

北京万象智维科技有限公司 (“Wanxiang Zhiwei”, “we” or “us”), with its registered address at Room 1094, 1st Floor, Blocks A and B, Yuandian Building, No. 8 Zhongguancun East Road, Haidian District, Beijing, values your privacy. This policy explains how we collect, use, store, entrust the processing of and protect your personal information when you use OmniBot, and how you can exercise your rights.

We recognize the importance of personal information and work to keep it secure and reliable. To maintain your trust, we follow the principles of accountability, clear purposes, informed choice and consent, data minimization, transparency, security and individual participation. We commit to appropriate safeguards in accordance with applicable law and established industry security standards.

Unless stated otherwise, this policy applies to the OmniBot application and related services we provide through it (together, the “OmniBot services”). The Android permissions and device features described here apply to the Android version; features may differ across platforms, versions and the functions you enable. When you use third-party services through OmniBot, those parties also process information under their own privacy policies, terms and configurations.

Please read and understand this policy before using the OmniBot services. We process personal information only with a lawful basis and in accordance with data minimization. Where consent or separate consent is required by law, we will separately inform you and obtain the required consent.

1. Information we collect and use

Personal information is information recorded electronically or otherwise that relates to an identified or identifiable natural person, excluding anonymized information. Sensitive personal information is information whose disclosure or misuse could readily harm a person's dignity or endanger their personal safety or property.

1.1 Accounts and authentication

When you register for or use an official OmniBot account, we process your email address, the password you set, email verification codes and verification results for registration, sign-in, password recovery or changes, and identity verification. The current Android version uses email and password sign-in; email codes are used for registration and password recovery. Our own email service sends these codes.

To maintain your account and provide official AI services, we also process your account identifier, registration time, sign-in sessions and their expiry and last-use times, your selected AI service mode, platform quota and model usage records. Usage records include the model used, time of the call, input and output token counts, and quota consumed.

Without account information, you cannot use official account or platform quota services that require sign-in. Bring-your-own-key and other features that do not depend on an official account can be used according to their own configurations. Keep passwords, verification codes and sign-in credentials secure. Do not email us your password, verification codes or API keys when making a request.

1.2 Model requests and task content

To understand and carry out your requests, OmniBot processes the text you enter, conversation context, images and files you select or upload, and tool parameters and results generated during tasks. When you enable screen operation, browser, file, calendar, memory or device collaboration features, relevant screenshots, page text, file contents, calendar entries or memories may also become part of a model request.

  • Official AI services: requests pass through the official OmniBot model gateway to the corresponding model service, including Alibaba Cloud Model Studio (Bailian), to generate text, images or speech. Sign-in credentials verify your platform access. Official cloud model API response logs support troubleshooting, service stability and user feedback; they are retained for 7 days from creation, then automatically deleted without backups.
  • Bring your own API key: when you configure your own model provider, request content, necessary headers and the API key are sent to the service address you configure. Our official account service receives only your choice of platform or bring-your-own-key mode; it does not receive your own model API key. The third party's processing location, retention period and data use depend on that service and your configuration.
  • External agents, plugins and device collaboration: when you connect an external agent, MCP service, computer or other device, task instructions, selected files, tool results or relevant conversation content are sent to the service or device you connect, as needed for that feature.

Screen, file and conversation content may contain sensitive information about you or others and may be sent to cloud AI services. Provide only what is necessary for the task and ensure you have a lawful basis to provide other people's personal information. Where consent or separate consent is required, we will inform you and obtain it before the relevant processing.

1.3 Device features and local data

The Android version accesses or stores chat history, workspace files, task records, preferences, long-term memories and browser state for the relevant features. Processing on your device does not itself mean the data is uploaded to our servers. When you use that content in cloud model requests, external tools or device collaboration, necessary content is sent with the request.

For device compatibility, permission guidance, connectivity or diagnostics, the application may read the device brand and model, Android version, network status, local IP address and Android ID on your device. Application lookup reads the names, package names and icons of launchable apps to identify and open task targets; relevant results may also be used as model context. Copy, paste and related tool operations access clipboard content as needed.

The built-in browser stores cookies, website local storage and sign-in state to maintain web sessions. Websites may directly collect information you submit and network request information. When you intentionally use cookie export or related tools, credentials may be written to your workspace or supplied to the tools you choose. Authorize and share such access carefully.

1.4 Update checks and operational information

When checking for updates, the application sends the current app version, edition, update channel and download source preference, together with the device brand and model, Android and SDK versions, and a randomly generated installation identifier. Update and download services also process necessary network information such as the requesting IP address and record the request country or region and update-check or download events, for update distribution, compatibility analysis and operational statistics.

As services migrate, new versions use the backend we operate for update checks, download distribution, model catalog distribution and operational statistics. Our backend retains update statistics for 90 days from the event time and removes records beyond that period every hour. During the migration, older versions may continue to send requests through Cloudflare compatibility endpoints; historical statistics already held by the original Cloudflare service remain until their existing retention period expires. The random installation identifier distinguishes app installations and is not the Android ID. Update statistics requests do not include your chat content, password or model API keys. Because the identifier can still distinguish the same installation over time, we protect the associated information under this policy.

The application may also record operational errors, task or crash diagnostics locally.

1.5 Feedback

When you voluntarily submit feedback through the website or “Settings—About OmniBot—Send feedback” in the Android app, we process the title and description you enter, attachments you choose to upload and optional contact details to investigate, handle and respond to your feedback. Attachments may include screenshots, recordings or logs you provide. Submissions from the Android entry may also include diagnostic information such as the app version, platform and feedback source. When a signed-in user opens the feedback page, the account email is included and stored with the feedback so we can contact the user and handle the issue; contact details remain editable.

Feedback records and attachments are stored by the backend we operate, accessible only to administrators through access controls and not publicly displayed. Feedback currently has no automatic deletion after a fixed number of days and is retained until we delete it. You may request deletion through the email address in this policy; we will verify and handle requests as required by law. Submit only information relevant to your feedback and avoid uploading passwords, verification codes, API keys or unrelated personal information.

2. System permissions

The Android version requests or uses the following permissions and system capabilities depending on the features you use. You decide whether to enable permissions or special access through system prompts, app permission settings or feature controls. Refusing or withdrawing access affects the features that depend on it, without affecting unrelated features.

Camera
Used for actions you initiate, such as scanning a pairing code, and websites you allow to use the camera in the built-in browser. Used only after the relevant feature is authorized.
Images, audio and file storage
Used to select, read, save or share images and files, detect screenshots, access workspaces, and choose local audio as an alarm sound. Depending on the Android version, access may use the system file picker or “All files access”. Content used with models or external tools is sent with the corresponding requests.
Installed app information
Reads the names, package names and icons of launchable apps for selection, lookup and automation tasks. Tool lookup results may become model context.
Accessibility and screen content
After you enable Android screen operation, accesses window text, controls, interaction state and screenshots, and performs actions such as tapping, scrolling and typing. Screen information is used to carry out your tasks and may be sent to the corresponding model service when cloud vision or reasoning is used. You can turn off OmniBot's service in the system Accessibility settings.
Display over other apps
Shows task controls, status and interaction entry points above other apps. You can turn this off in the system's special app access settings.
Calendar
Reads calendars and events or creates and edits events when you invoke calendar tools. Necessary information such as event titles, times and notes may become task and model context.
Bluetooth, network and system settings
Used for device connections, network status checks, and related device controls or settings changes you request. Bluetooth scanning is declared as not being used to derive location. Device actions enabled through Shizuku require separate authorization, which you can revoke in its management tool.
Notifications, background activity and alarms
Used for task notifications, foreground services, scheduled tasks, exact reminders, audio playback, vibration and necessary wake locks. Previously configured tasks may resume after a reboot. You decide whether to enable settings such as battery optimization exemptions.
App installation
In distribution versions that provide in-app APK updates, used to download and request installation of an update package. Installation still requires system confirmation.

The audio permission described above reads audio files; it is not a microphone recording permission. The current Android main application's permission list does not request access to the microphone, contacts, SMS, call logs, phone state or precise location. This does not exclude such information from content you enter or from screens, files or webpages you authorize the app to read. If new processing purposes or permissions are added, we will update the disclosures and obtain authorization as required.

3. Service providers and disclosure

3.1 Entrusted processing and third-party services

We may engage service providers to process necessary personal information for the OmniBot services. We agree with them on processing purposes, duration, methods, information types, safeguards and responsibilities, require protection no less than this policy and applicable law require, and supervise the relevant processing.

Our own account and email services handle account registration, sign-in and verification emails. The following describes the main external services and when they process data. Services receive necessary data only when the corresponding feature is used.

Third-party services and data processing
Service and providerPurpose and informationProcessing, location and retention
Alibaba Cloud Model Studio (Bailian)
通义云启(杭州)信息技术有限公司
Provides model inference and processes text, context, images or other content relevant to the selected model feature.Receives and processes API requests. Mainland China model endpoints process data in their corresponding service regions. The specific location and retention depend on the model, service configuration and contract. Bailian may retain call data as required by law; its retention period is separate from our own 7-day log period. See the Bailian privacy notice and service agreement.
Cloudflare
Cloudflare, Inc.
During the migration, forwards compatibility requests from older versions for update checks, downloads, model catalogs and related endpoints, processing those requests and necessary network information. Historical update statistics held by the original service include the information listed in Section 1. Our backend stores update statistics from new versions and feedback.Compatibility endpoints forward requests to our backend and may use nodes outside China. Historical statistics already in Cloudflare Workers Analytics Engine remain until their original 3-month (approximately 90-day) retention period expires. Other service data is processed under the applicable service terms and configuration. See the Cloudflare privacy policy and statistics retention documentation.
Model services you chooseBuilt-in configurable services include DeepSeek, Xiaomi MiMo, Moonshot, MiniMax and Alibaba Cloud Model Studio, together with compatible services you add. The corresponding service receives the model requests, credentials and necessary context you choose to send.Requests are sent only to the provider and service address you enable. The recipient, service region and retention depend on that provider and your account configuration. Read the selected service's privacy policy before configuring it. You can stop using it and remove its local configuration.
Websites, agents, plugins or devices you connectSupports browsing, tools, file processing and device collaboration. Receives relevant web requests, task instructions, files or tool results according to your actions.Information is sent to the destination you visit or connect, under its terms, permissions and configuration. You can disconnect, remove plugins or stop visiting a service. To manage or delete information already sent, contact the relevant recipient.

When providing personal information to third-party AI or other services, we will disclose the recipient, processing purpose and information involved as required by law, and obtain consent or separate consent where needed. For service providers we engage, your deletion requests will also be passed on for handling under applicable law and our processing arrangements. For accounts or authorizations you establish independently with third parties, you can also request revocation or deletion from those parties.

Where required by law, legal proceedings or a competent authority acting lawfully, we may provide personal information to the relevant authority to the extent necessary.

3.2 Corporate and business changes

If a merger, division, dissolution, acquisition, business or asset transfer, restructuring, bankruptcy liquidation or similar change involves transferring personal information, we will inform you of the recipient's name and contact information and require it to remain bound by this policy. If the recipient changes the original purposes or methods of processing, it must obtain consent again as required by law.

If we become bankrupt without a successor, we will delete or anonymize personal information as required by law.

3.3 Public disclosure

As a rule, we do not publicly disclose your personal information. Where public disclosure is necessary, we will inform you of its purpose and the information involved, apply necessary safeguards and obtain separate consent where required by law.

5. Storage and security

5.1 Storage locations and retention

Under our current service arrangements, account and official service data under our control is stored in China. Local chats, files, memories, configuration and browser state are stored on your device. During the migration, Cloudflare compatibility forwarding for older versions and historical statistics in the original service, together with model services, websites, plugins or collaboration devices you choose, may involve processing outside China; not all such data can be described as stored domestically. We will fulfill any legally required cross-border transfer procedures or separate consent requirements.

  • Account and service information: email addresses, account profiles, sign-in sessions, service modes, quota and usage information are retained for as long as needed to provide the account and services. On completion of account deletion, we delete the account and associated data under our control, unless otherwise required by law.
  • Official model API response logs: retained for 7 days from creation, then automatically deleted without backups. Upon completion of account deletion, we immediately delete associated logs under our control. This rule does not apply to local chat history, Cloudflare update statistics or data retained independently by model service providers.
  • Update statistics: our backend retains events for 90 days from the event time and removes records beyond that period every hour. Historical statistics migrated to our backend use the original event time for this period. Historical statistics already in the original Cloudflare service remain until their original 3-month (approximately 90-day) retention period expires. Random installation identifiers are stored separately from accounts; deleting an official account does not immediately delete statistics recorded by installation. Contact the email address in this policy to request management of related information.
  • Feedback: titles, descriptions, attachments, optional contact details and related diagnostic information are stored in our backend and accessible only to administrators. There is currently no automatic deletion after a fixed number of days; the information is retained until we delete it. You may request deletion through the email address in this policy, and we will verify and handle requests as required by law.
  • Local data: chats, workspace files, memories, tool records, browser state and local configuration remain until you delete them through the relevant feature or clear app data. Account deletion does not automatically remove local chats or files. You must separately manage files in external storage, exported copies and system backups.
  • Device backups: Android may back up or transfer some app data according to your system settings. The dedicated encrypted stores for account credentials and model provider secrets are excluded from the app's system backup and device transfer rules. Use the system or backup service to manage deletion of other backed-up content.

Where laws or administrative regulations require longer retention, or deletion is technically difficult, we will stop processing other than storage and necessary security measures. If we discontinue a product or service, we will give prior notice as required by law and delete or anonymize relevant information after discontinuation, unless otherwise required by law.

5.2 Safeguards

Official account and model services transmit data using HTTPS. On Android, account credentials and model API keys use device-side encryption backed by Android Keystore. We apply access controls to backend data, limit access to personnel who need it for their duties and require confidentiality.

Model services, local-network tools or device connections you configure may use HTTP or other connection methods. Their transport protection depends on the service and network settings you choose. Use device collaboration on trusted networks, share connection credentials carefully and prefer HTTPS services.

We apply management, technical and physical safeguards appropriate to processing risks to protect against unauthorized access, disclosure, alteration, loss or misuse, and seek to minimize the information we collect and retain.

5.3 Risks and incident response

No internet environment or technical measure can guarantee absolute security. We make reasonable efforts to protect your information. Contact us promptly if you identify a potential security issue involving your account, email address or related data.

If personal information is or may be disclosed, altered or lost, we will take remedial action and notify authorities and affected individuals as required by law. Notices will describe the incident, possible consequences, measures taken or planned, and preventive or remedial steps you can take. Where individual notification is impracticable, we will use reasonable and effective public notices.

6. Your privacy rights

While using OmniBot, you have rights under applicable law to access, copy, correct, supplement or delete personal information, delete your account, withdraw consent and request explanations of processing rules. Use the available app features or email 2025omnimind@gmail.com. We may need to verify your identity for security.

6.1 Access, correction and supplementation

In the Android app, go to “My → Account & AI service” to view your sign-in email, platform usage and signed-in devices, and manage sessions. To correct, supplement or access other personal information, contact 2025omnimind@gmail.com.

After verifying your identity, we will handle your request in accordance with the law, unless otherwise provided by applicable laws or regulations.

6.2 Deleting personal information

You can request deletion at 2025omnimind@gmail.com. We will delete information as required by law when any of the following applies. If a statutory retention period has not expired or deletion is technically difficult, we will stop processing other than storage and necessary security measures.

  1. The processing purpose has been achieved, cannot be achieved or no longer requires the information.
  2. We stop providing the product or service, or the retention period expires.
  3. You withdraw consent.
  4. We process information in breach of laws, administrative regulations or our agreement.
  5. Other circumstances required by law or administrative regulations apply.

6.3 Deleting your account

Request deletion of your OmniBot account and associated data

In the Android app, go to “My → Account & AI service → Delete account”, confirm your email and enter your current password as prompted. You can also request assistance by emailing us below, without reinstalling the app. We may need to verify your identity and will respond within 15 working days after receiving the request and verifying your identity.

Email a deletion request · 2025omnimind@gmail.com

Once deletion is complete, we stop providing services associated with the account, permanently delete the account, sign-in sessions, platform quota and other associated data under our control, and immediately delete the email address and associated API logs, unless otherwise required by law. The Android client clears local sign-in credentials after the server confirms successful deletion.

Local chats, files, memories, browser state and copies you have saved are not automatically removed when you delete your account. Delete them through the relevant features or clear app data in Android settings. External files, backups and information retained by third parties must be handled separately. Signing out or uninstalling OmniBot does not delete your account; you can still email us to request account and data deletion.

6.4 Withdrawing consent

You may withdraw consent-based processing by stopping use of the relevant feature, using available app settings or contacting 2025omnimind@gmail.com. Withdrawal does not affect the validity of processing based on consent before it was withdrawn.

You can also revoke camera, calendar, file and other permissions in system settings, turn off accessibility services or overlays, revoke Shizuku authorization, or disconnect models, plugins and devices. The corresponding features stop using revoked permissions; information that still must be processed by law is handled under the applicable law.

6.5 Copying or transferring information

Where the conditions prescribed by law are met, you may request a copy of your personal information or its transfer to a personal information processor you designate. Send requests to 2025omnimind@gmail.com.

6.6 Responding to requests

If you cannot exercise your rights through the methods above, or believe our processing breaches the law or this policy, contact 2025omnimind@gmail.com. We will respond within 15 working days after receiving your request and verifying your identity.

As permitted or required by law, we may be unable to fulfill a request in circumstances involving:

  • Our obligations under laws, regulations or requirements of industry authorities.
  • National security or national defense.
  • Public security, public health or significant public interests.
  • Criminal investigation, prosecution, trial or enforcement of judgments.
  • Sufficient evidence of bad faith or abuse of rights.
  • Protection of your or another person's vital interests, such as life or property, where obtaining your consent is difficult.
  • Serious harm to the lawful rights and interests of you, other individuals or organizations if the request is fulfilled.
  • Trade secrets.

We generally do not charge for reasonable requests. For repetitive, excessive, manifestly unreasonable requests, or those that may harm others' lawful interests, we may charge necessary costs or refuse as permitted by law and explain why.

7. Changes to this policy

We may update this policy to reflect laws, regulations, regulatory requirements, product features or operational arrangements. Without your explicit consent, we will not reduce the rights you have under this policy and applicable law.

Material changes include, but are not limited to:

  • Significant changes to our service model, such as processing purposes, information types or uses.
  • Significant changes in ownership or organizational structure, such as changes of ownership through business adjustments, bankruptcy or acquisitions.
  • Changes to the principal recipients of information shared externally or disclosed publicly.
  • Significant changes to your rights regarding processing or how you exercise them.
  • Changes to the organization responsible for information security, contact details or complaint channels.
  • A personal information protection impact assessment indicating a high risk.

We will publish the revised policy and change the “Last updated” date above. Where additional notice or consent is required, we will follow the relevant procedures.

You can find the latest policy in the OmniBot app and on the publicly accessible HTTPS privacy policy webpage.

8. Children and minors

OmniBot is not directed at children and does not target users under the age of 14.

If you are a minor, read this policy with a guardian's guidance and obtain their consent before using OmniBot.

If we discover that we have processed information about a child under 14 without verifiable guardian consent, we will promptly delete it or take other necessary measures as required by law. Guardians who identify such issues should contact the email address in this policy.

10. Contact us

Operator: 北京万象智维科技有限公司
Privacy contact: 2025omnimind@gmail.com

Please email us with questions, comments, complaints or requests about this policy or personal information protection. We may need to verify your identity and will respond within 15 working days of receiving your request.