OMABack to the website

Privacy policy

Clear, minimal and
purposeful.

Version 2026-09-03 · Effective 3 September 2026

Our privacy commitment

OMA is a private-group communication and coordination service. We collect the information needed to provide and protect the features you choose to use. We do not sell personal data, use tracking-based advertising, upload your address book, build a public follower graph or use private-group activity to create an algorithmic public feed.

Controller and contact

OMA Labs Oy, Business ID 3645741-6, Pietarinkatu 15 B 59, 00140 Helsinki, Finland, is the controller of personal data processed through the OMA app and this website. Privacy questions and rights requests can be sent to ville@omalabs.io.

Information OMA processes

Account and access. Your display name, verified email address, optional profile photo, internal account identifier, sign-in and session records, legal-policy acceptances, and an Apple account identifier or private relay address when you use Sign in with Apple.

Private groups and content. Group memberships, roles, invitations, preferences, blocks and notification choices, together with content you choose to add: messages, reactions, Moments, comments, plans, polls, attendance, practical requests, group covers, Trip Concierge answers and shared-expense records.

Temporary location. If you deliberately start location sharing, we process your current precise coordinates, accuracy, observation time, selected group and the expiry you choose. Sharing is off by default, limited to that group and lasts between 15 minutes and 4 hours unless you stop it sooner.

Support, safety and notifications. Support messages, content reports, block records, device push token and environment, notification delivery status, and limited diagnostic or error details needed to respond and keep OMA reliable.

Optional contributions. If you make a one-time Support OMA contribution, Apple handles the payment. OMA receives the StoreKit product, transaction and purchase status, but not your payment-card details.

Optional product analytics. Analytics is off until you enable it. It records a random session identifier, feature and event names, outcome, app version and timestamps. It excludes your account ID, name, email, message text, media, contacts, precise location, advertising identifiers and session replay.

Website enquiries. For early access we process the email address you submit. For an investor, press or partner enquiry, we may also process your name, organisation, requested meeting time and message.

Where the information comes from

Most information comes directly from you when you create an account, join a group, share content, choose a permission or contact us. OMA also creates service records when features operate. Apple supplies the identity and transaction details needed for Sign in with Apple, push notifications and optional App Store contributions. Other group members provide information when they invite you, interact with your content or include you in group coordination.

Why we process it

We process account, group and user-provided content to perform our agreement with you: creating and securing your account, operating the groups you join, delivering invitations and notifications, providing requested features, and supporting export and deletion. We use limited operational, support and safety information for our legitimate interests in service reliability, fraud and abuse prevention, enforcing our Terms and protecting people. We process information to meet legal obligations where applicable. Optional analytics and device features that require consent or permission remain under your control and can be withdrawn.

Who can see or process it

Content is available to members of the private group or feature where you share it. Membership in one group does not reveal another group. Your email address and Apple sign-in identifier are not displayed to group members. People you share with may save, copy or share what they receive, so choose the audience and content carefully.

OMA may disclose information when you direct us to, when reasonably necessary to investigate a safety report or protect people, when required by law, or as part of a corporate transaction subject to appropriate confidentiality and data-protection safeguards. We do not disclose personal data to data brokers or advertising networks.

Service providers and transfers

OMA uses Amazon Web Services in Stockholm, Sweden, for the app API, database, private media, operational logs, email delivery and related infrastructure; Apple for Sign in with Apple, push notifications and StoreKit; Cloudflare for website delivery and early-access storage; and Resend for website email delivery. They process information only to provide their contracted service or, where they act independently, under their own privacy terms.

Primary app data is hosted in the European Economic Area. A provider may process limited account, delivery, support or website information outside the EEA. Where required, OMA relies on an adequacy decision, approved contractual safeguards such as the European Commission's Standard Contractual Clauses, and supplementary protections appropriate to the transfer.

Retention

We keep account and private-group information while needed to provide OMA and maintain the group record, unless you or a group administrator uses an available deletion control or a longer period is needed for safety, legal claims or a legal obligation.

One-time email sign-in challenges expire after 10 minutes. Renewable sign-in sessions expire after 90 days and are revoked when you sign out or delete your account. Invite links can be created for no more than 7 days. Temporary location disappears from the group when you stop sharing or the selected 15-minute-to-4-hour period ends. The present release does not yet automatically erase the underlying expired location record at that moment; it remains access-restricted while OMA completes the automated deletion process. You may request earlier deletion at ville@omalabs.io.

Production infrastructure is configured to keep API logs for 30 days and database backups for 7 days. Superseded or deleted private-media object versions expire after 30 days. Support, safety, consent and hashed privacy-audit records are kept only for the period reasonably needed to resolve the matter, demonstrate compliance, protect legal rights or satisfy law. Website early-access details are kept until you unsubscribe or ask us to delete them; enquiry details are reviewed and removed when no longer needed for the conversation or related obligations.

Account deletion and shared content

You can delete your account in Profile → Privacy and account settings. The current deletion flow revokes your sessions, removes active memberships, revokes invitations you created, deletes your profile photo, removes your email and private preferences, disables push delivery, removes blocks, replaces your display name with a deleted-member label and removes the text of messages you authored.

Moments and their media, comments, plans, practical requests, group records and shared-expense entries are not automatically erased by account deletion in the present release. They may remain in their original private group, associated with the deleted-member label, where needed for the group's shared context, other members' rights, financial history, safety or legal obligations. Contact ville@omalabs.io if you need deletion of particular shared content; we will assess the request under applicable law and the rights of other people.

Your controls and rights

Inside OMA you can edit your profile, manage group participation and notifications, block another member, stop location sharing, turn optional analytics off, export your account data and delete your account. Turning analytics off deletes queued analytics from your device and stops new analytics events.

Subject to applicable law, you may request access, correction, deletion, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. We may ask for information needed to verify your identity before acting on a request. You may complain to the Finnish Data Protection Ombudsman at tietosuoja.fi or to your local supervisory authority.

Security and automated decisions

OMA uses encrypted transport and managed storage, private media access links, access controls, credential hashing, data minimisation and limited operational logging. No online service can guarantee absolute security. OMA does not make solely automated decisions that produce legal or similarly significant effects about you.

Adults, changes and questions

OMA is for people aged 18 or older in this initial release. If we learn that an account belongs to someone under 18, please contact us so we can take appropriate action.

We will identify material changes with a new version and communicate them through the app, website or verified account address as appropriate. If we introduce a materially different purpose or feature, we will update this policy and request consent where required. Questions can be sent to ville@omalabs.io.

OMA Labs Oy · Business ID 3645741-6 · Helsinki, Finlandville@omalabs.io