1. Who this covers
OmarCua runs on your device. The authentication server is the hosted component that helps with OAuth redirects and related configuration. The operator of the server you connect to is responsible for that server’s environment and any data it stores.
2. Information we process
- OAuth data. When you connect third-party accounts, authorization codes and access/refresh tokens may be handled briefly by the authentication server and then delivered to the OmarCua app on your device. Tokens are typically stored locally on your device for reconnecting.
- Configuration. The authentication server may hold API keys and OAuth client credentials needed for the Service to function. Those values are server-side and are not intended to be published.
- Conversation and task data. Prompts, conversation history, and related activity logs for the assistant are stored on your device (for example in app data), not as a general cloud chat archive on the authentication server.
- Technical logs. The authentication server may log request metadata (such as timestamps and error messages) for operations and debugging.
3. How information is used
Information is used to:
- Complete sign-in and API access you requested
- Run the assistant and remember conversations on your device
- Operate, secure, and troubleshoot the Service
4. Sharing
We do not sell your personal information. Data may be shared with third-party providers you choose to connect (for example Google or other OAuth/API providers) solely to perform the actions you authorize. Those providers process data under their own policies.
AI model providers (such as Anthropic or Qwen/DashScope) receive the prompts and context needed to generate responses when you use those models from OmarCua.
5. Retention
OAuth tickets on the authentication server are short-lived. Local tokens and conversation data remain on your device until you remove them or uninstall the app. Server logs are retained only as long as needed for operations, subject to the operator’s practices.
6. Security
We use reasonable measures to protect the Service, including HTTPS for authentication server traffic in production. No method of transmission or storage is completely secure.
7. Your choices
- Disconnect services and delete stored tokens from OmarCua
- Delete or clear local conversations in the app
- Stop using the Service or uninstall OmarCua
- Meta / Threads: request deletion from Meta’s Apps and Websites settings (Settings & privacy → Settings → Apps and websites). That triggers OmarAuthServer’s data-deletion callback and provides a confirmation status page. Also disconnect Threads in OmarCua Services to clear tokens stored on your device.
8. Children
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect their personal information.
9. Changes
We may update this Privacy Policy by posting a new version on this page. The “Last updated” date will change when we do.
10. Contact
For privacy questions, contact the operator of this OmarCua deployment (the party that hosts this page).