Last updated: 25 July 2026 · Applies to Omar and its authentication server
This Privacy Policy explains how Omar and its hosted authentication server (together,
the “Service”) handle information when you use the desktop app and this website.
1. Who this covers
OmarCua runs on your device. The authentication server is the hosted component that helps
with OAuth redirects and related configuration. The operator of the server you connect
to is responsible for that server’s environment and any data it stores.
2. Information we process
OAuth data. When you connect third-party accounts, authorization codes
and access/refresh tokens may be handled briefly by the authentication server and then
delivered to the OmarCua app on your device. Tokens are typically stored locally on your
device for reconnecting.
Configuration. The authentication server may hold API keys and OAuth
client credentials needed for the Service to function. Those values are server-side and
are not intended to be published.
Conversation and task data. Prompts, conversation history, and related
activity logs for the assistant are stored on your device (for example in app data),
not as a general cloud chat archive on the authentication server.
Technical logs. The authentication server may log request metadata
(such as timestamps and error messages) for operations and debugging.
3. How information is used
Information is used to:
Complete sign-in and API access you requested
Run the assistant and remember conversations on your device
Operate, secure, and troubleshoot the Service
4. Sharing
We do not sell your personal information. Data may be shared with third-party providers
you choose to connect (for example Google or other OAuth/API providers) solely to
perform the actions you authorize. Those providers process data under their own policies.
AI model providers (such as Anthropic or Qwen/DashScope) receive the prompts and context
needed to generate responses when you use those models from Omar.
5. Retention
OAuth tickets on the authentication server are short-lived. Local tokens and conversation
data remain on your device until you remove them or uninstall the app. Server logs are
retained only as long as needed for operations, subject to the operator’s practices.
6. Security
We use reasonable measures to protect the Service, including HTTPS for authentication
server traffic in production. No method of transmission or storage is completely secure.
7. Your choices
Disconnect services and delete stored tokens from Omar
Delete or clear local conversations in the app
Stop using the Service or uninstall Omar
Meta / Threads: request deletion from Meta’s Apps and Websites settings
(Settings & privacy → Settings → Apps and websites). That triggers OmarAuthServer’s
data-deletion callback and provides a confirmation status page. Also disconnect Threads
in Omar Services to clear tokens stored on your device.
8. Children
The Service is not directed to children under 13 (or the minimum age required in your
jurisdiction), and we do not knowingly collect their personal information.
9. Changes
We may update this Privacy Policy by posting a new version on this page. The “Last updated”
date will change when we do.
10. Contact
For privacy questions, contact the operator of this Omar deployment
(the party that hosts this page).