omneone
Sign inRequest access
Legal

Privacy Policy

Effective 2026-07-03

Omneone — Privacy Policy

This policy explains what the hosted Omneone service collects, what it deliberately never sees, and how we handle your information. It reflects Omneone's core design: your Okta tokens and System Log data never leave your browser.

1. The short version. Omneone's diagnosis runs entirely in your browser, talking directly to your own Okta org. The hosted service is an onboarding and account portal only — it never receives your Okta tokens, System Log, or user and policy data. We store only the non-secret account and configuration data needed to run your account.

2. What we collect. To operate your account we store: your account email and authentication metadata; the intake information you submit when requesting access; your approval status; your assigned subdomain; a record of the Terms you accepted, with timestamps; and your tenant's non-secret Okta configuration (org URL and public PKCE client ID). These are not credentials.

3. What we deliberately never collect. We do not receive or store your Okta access or refresh tokens, your Okta System Log records, your Okta users, apps, groups, or policies, or the results of any diagnosis. All log retrieval and analysis happen in your browser and are discarded when you close or refresh the page.

4. Data stored only in your browser. The diagnosis app keeps your settings — your Okta org URL and client ID, timezone and display preferences, and (if you provide one) your Anthropic API key — in your browser's local storage. This never leaves your device or reaches our servers. Your Okta sign-in tokens are likewise held only in your browser's token store.

5. Optional AI analysis. If — and only if — you opt in per diagnosis, Omneone sends a PII-sanitized payload (emails, IPs, names, and hostnames replaced with placeholders), which you review beforehand, directly from your browser to Anthropic using your own API key. This call does not pass through our servers, and we never see its contents. Your use of Anthropic is governed by your own agreement with Anthropic.

6. Cookies, analytics, and similar technologies. We use the browser storage necessary to keep you signed in and remember your preferences. On our public pages — the homepage and your account page — we also use Google Analytics to understand aggregate usage; it sets first-party analytics cookies. The diagnosis app itself contains no analytics or tracking. We do not use third-party advertising or cross-site ad-tracking cookies, and we do not sell your personal information. You can opt out of analytics using your browser's privacy controls or Google's opt-out browser add-on.

7. Email. We send transactional email only — sign-in codes and links, and approval and account-setup notices — through our email provider. We do not send marketing email during early access.

8. Service providers (sub-processors). We rely on a small set of vendors to run the service: Supabase (authentication and database), Vercel (application hosting), Cloudflare (DNS and content delivery), Resend (transactional email), and Google Analytics (aggregate usage measurement on our public pages). They process data only to provide these functions on our behalf.

9. Where data is stored. Account data is stored in the United States. If you access Omneone from outside the United States, you consent to processing there.

10. Retention. We keep your account data for as long as your account is active. If your account is terminated or deleted, we remove the account metadata described above. Because we never held your Okta tokens or log data, there is nothing of that kind for us to retain.

11. Your rights. You may request access to, correction of, or deletion of your account data, and you may withdraw from early access at any time. Depending on where you live (for example, under GDPR or CCPA), you may have additional rights; contact us and we will honor applicable requests.

12. Security. Access to account data is protected by row-level security and authenticated access controls — anonymous and cross-tenant reads are blocked — and all traffic is encrypted in transit (TLS).

13. Children. Omneone is a workplace tool for Okta administrators. It is not directed to children under 16, and we do not knowingly collect their information.

14. Changes. We may update this policy as the service evolves; material changes will be communicated to your account email or shown in the portal. The version identifier at the top of this page reflects the current policy.

15. Contact. Questions or privacy requests: hey@omneone.com.

omneoneYour Okta tokens and System Log data never leave your browser.
Get startedPrivacyTermsContact
© 2026 Omneone v1.1.0 (42df064)