Privacy Policy
Last updated 27 August 2026
OmniaPilot is a tool for building product listings: you upload a product, and we generate images, copy and a logo for it, and can push the result to your Shopify store. This policy explains what we hold to do that, who else touches it, and how to get it back or deleted.
It covers omniapilot.com and the OmniaPilot application. It does not cover Shopify, Meta, or any other site we link to — those have their own policies.
Who we are
OmniaPilot (“we”, “us”) operates this site and the application behind it. We are the controller of the personal data described here. For anything in this policy, including access and deletion requests, write to privacy@omniapilot.com.
What we collect
We collect three kinds of thing, and it is worth separating them.
Account data. Your email address and a hashed password, or the identifier from whichever provider you signed in with. Your plan, credit balance and credit history. Your store name.
What you put into the product. Product photos and video clips you upload, product names and descriptions, brand names and brand colours, the reference links you paste into the Ad Library Downloader, and everything generated from those — image stacks, written copy, logos and analysis notes.
Data from services you connect. If you connect a Shopify store we store the access token for that store and the product data we read from it. We ask for the narrowest set of permissions the features need; see “Shopify” below.
We also keep ordinary server logs — IP address, browser, pages requested, timestamps — for security and debugging.
We do not collect payment card details. Card entry and storage happen entirely inside our payment processor. We receive a customer reference and the subscription status, never the card number.
Why we hold it
- To run the product. Generating a stack means sending your product photos and brief to a model; storing the result means holding the images. There is no version of the service that does not do this.
- To bill you. Plan, credit balance and ledger exist so we can charge the right amount and show you what you have spent.
- To keep the service up and honest. Logs, rate limits and abuse checks.
- To reply to you. Support conversations and the account they relate to.
Where the UK GDPR or EU GDPR applies, our lawful bases are performance of a contract (running the service you signed up for), legitimate interests (security, abuse prevention, improving the product) and consent (non-essential cookies, marketing email, where used).
Who we share it with
We do not sell personal data and we do not share it for advertising. We use the following processors, each doing one job:
| Category | What it does | What it sees |
|---|---|---|
| Cloud hosting and storage | Runs the site and holds your files | Account records, uploads, generated files, request logs |
| Payment processor | Takes payment and manages subscriptions | Billing details and card data, directly rather than via us |
| AI model providers | Generate images and write copy | Product photos, clips and the brief for a given run |
| Shopify | Store connection, import and publishing | Product data on stores you connect |
We name Shopify because you connect it yourself and can see exactly what it is doing. The rest are listed by category rather than by vendor. If you need the specific processors — for a due diligence review, a DPA, or a data subject request — email us and we will provide the current list.
We may also disclose data if we are legally required to, or to protect our rights, users or infrastructure. If OmniaPilot is ever acquired, account data would transfer with the business, and we would tell you before that happened.
Model providers and training
Generating images and copy means sending your content to third-party AI model providers. We use paid API tiers, which do not train foundation models on submitted content by default, and we do not opt in to training. Their handling is governed by their own terms; we can guarantee the settings we choose, not the behaviour of another company’s systems.
Do not upload anything you could not send to a third-party API. The product is not designed for personal data about other people, and photos of identifiable individuals should only be uploaded if you have the right to use them that way.
Shopify
Connecting a store is optional. When you do, you approve a fixed set of permissions: reading and writing products, reading and writing themes, and writing files. We use them to import products you choose, to publish finished listings, and to upload the images those listings use.
We do not read your orders, your customers, or your payouts, and we never ask for those permissions. You can disconnect a store at any time from the app, or uninstall the app from your Shopify admin; either revokes our access token.
Ad Library Downloader
The Ad Library Downloader reads brand pages in Meta’s public Ad Library — advertising that is already published and publicly viewable — and hands you the creative files. It is a tool over public advertising, not a way to obtain private data about a business or a person.
Captured clips are large, so they are purged on a schedule once they have been transcribed and labelled; the analysis stays, the raw video does not.
How long we keep it
- Account and billing records for as long as your account is open, and afterwards for as long as tax and accounting rules require.
- Products, images, copy and projects until you delete them or close your account.
- Captured ad clips until purged after processing; labels and transcripts remain with the brand you tracked.
- Server logs for a short operational window, then discarded.
Deleting your account removes your content from our database and file storage. Backups roll off on their own schedule, so a copy can persist briefly after deletion.
Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, export it, object to certain processing, or withdraw consent. You can do most of this from inside the app; for anything you cannot, email privacy@omniapilot.com and we will respond within 30 days.
If you are in the UK or EU and think we have handled your data badly, you can complain to your data protection authority. We would rather you told us first.
International transfers
Our providers operate in the United States and elsewhere, so your data will be processed outside your country. Where required, transfers rely on Standard Contractual Clauses or an equivalent mechanism offered by the provider.
Security
Access to production data is restricted, traffic is encrypted in transit, and stored files sit behind signed, expiring URLs rather than public links. Passwords are hashed by our authentication provider and are never visible to us. No system is perfect; if we discover a breach affecting your data we will tell you and the relevant regulator as required.
Children
OmniaPilot is for business use and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, email us and we will delete it.
Changes
We will update this policy as the product changes. The date at the top always reflects the current version, and material changes will be notified in the app or by email before they take effect.