Scope
This Policy applies to the omnilume.app website, the OmniLume Reel desktop application, account login, analysis quota validation, subscriptions and billing, software updates, feedback, support emails, and related support services we provide.
This Policy does not cover third-party video platforms, AI model services, payment services, or other third-party services accessed or processed through OmniLume Reel. Such services handle data under their own terms and privacy policies.
Local Data and Asset Content
Your imported videos, project organization, cached thumbnails, analysis task status, notes, tags, scene indexes, clip collections, and export results are stored on your device by default. We do not automatically upload this content merely because you install or launch the application.
When you actively initiate features requiring network services—such as account login, analysis quota validation, subscription management, software update checks, feedback submission, support emails, online imports, third-party platform access, or AI analysis—those features may transmit necessary information to our services or third-party services.
Unless strictly required to fulfill your requested network functionality, we do not persistently store your video files, frames, audio, transcribed text, scene descriptions, search terms, local file paths, browser Cookie, or third-party platform session credentials in our online service layer.
Accounts, Devices, and Installation Identifiers
If you choose to log in to an account, we process your email address, login verification status, session state, account creation and most recent login timestamps, subscription entitlement status, and device installation records associated with that account.
To support anonymous quota allocation, prevent abuse, associate account sessions across the same device, and improve compatibility, the desktop application generates a stable installation identifier. Official desktop builds prioritize deriving this identifier from locally computed hardware-based hashes; raw hardware serial numbers or native device identifiers are never transmitted to us in plaintext.
We may also process application version, system platform, system architecture, language, time zone, and coarse-grained operating system information for compatibility, updates, quota control, security, and operational analytics.
Analysis Quotas and AI Analysis
OmniLume Reel uses analysis quotas and task pre-allocation to manage AI/video analysis resources. Related requests may include account or anonymous installation scope, application version, estimated analysis token units, pre-allocation records, task status, and authorization metadata.
When you initiate AI analysis, transcription, scene understanding, vector retrieval, or similar functions, the application may send the minimal necessary media segments, frames, audio, transcribed text, or derived prompt data to configured AI model services. We strive to limit transmission scope, but AI analysis inherently requires processing the content you select for analysis.
Our AI gateway holds server-side API keys and enforces quota, signing, and replay protection. Desktop clients do not receive our upstream model service API keys; we also strip client-side signatures, resource authorizations, and Cookie-like headers before forwarding requests to upstream model services.
Optional Diagnostics and Usage Statistics
Usage statistics and diagnostic functionality in the desktop application are optional. When enabled, the application may transmit the installation identifier, page routes, application version, platform, language, time zone, OS profile, launch or activity status, and sanitized error summaries, error sources, and stack fragments.
Diagnostics and usage statistics are designed to avoid transmitting media content, account content, passwords, browser Cookie, local file paths, URLs, search terms, transcribed text, or scene descriptions. We use this data to troubleshoot crashes, analyze compatibility, assess feature adoption, and improve product stability.
Raw page visits and diagnostic logs are typically retained for up to 365 days; aggregated installation, activity, and trend data may be retained longer for operational reporting.
Feedback, Support Emails, and Attachments
If you submit feedback within the desktop application or contact us via support email, we process the subject line, body, email address, attachments, application version, platform, language, source page, conversation state, and support response records.
Feedback conversations continue using locally stored access tokens; only token hashes are retained. Attachments may be stored in private object storage and used solely to address your feedback or support request.
Support emails are received, parsed, spam-filtered, and stored in the support inbox via Cloudflare Email Routing and Workers. Support replies originate from the corresponding support email address and may reference your most recent message to preserve thread context.
Subscriptions, Payments, and Tax
Paid subscriptions, checkout, and customer portals are managed by the payment provider as the merchant of record or authorized reseller. This payment service may process payment methods, billing email, billing address, transactions, invoices, tax, VAT/GST/sales tax, anti-fraud, and compliance-related information per its policies.
We retain the payment customer ID, subscription ID, transaction or checkout intent, subscription status, price or product ID, entitlement status, current billing period end time, cancellation or scheduled change status, and most recent event handling status—only as needed to fulfill product authorization. We do not store payment service API keys or full payment card details in the desktop application.
You may also be required to accept the payment provider's applicable checkout or buyer terms at checkout. Refund-related procedures are outlined in Refunds.
Third-Party Platforms and Browser Sessions
If you use OmniLume Reel to access third-party video platforms, import online content, or invoke system browser capabilities, such requests may be communicated directly between your local device and the third-party platform, potentially leveraging your existing browser sessions, Cookie, login state, or platform access context.
You are responsible for ensuring you have the right to access, import, analyze, and use such content, and for complying with third-party platform terms, copyright rules, and privacy obligations. We do not collect your third-party platform passwords, full Cookie, session tokens, or unsolicited account content for diagnostics or operational analytics.
Infrastructure and Service Providers
We use Cloudflare to deliver our website, Workers, D1 database, R2 object storage, Email Routing, email delivery, and related security capabilities. This provider may process request metadata, network logs, security events, email routing data, and information necessary to operate its services per its policies.
We may engage additional infrastructure, model, analytics, error monitoring, or operational service providers to deliver product functionality. We limit third-party access where possible and require them to process data solely for service delivery, security, compliance, or support purposes.
Due to differences in service providers, user locations, and network paths, related information may be processed outside your region. We implement reasonable measures to protect cross-border data transfers as required by applicable law.
How We Use Information
We use the information described above to provide, maintain, and improve OmniLume Reel—including account authentication, entitlement validation, analysis quota enforcement, AI analysis requests, software updates, subscription management, payment status synchronization, customer support, error troubleshooting, security protection, anti-spam, anti-abuse, and compliance logging.
We do not sell your personal information nor share your asset content for third-party advertising purposes. We do not use your local video library or project content to train our own models. When you explicitly use AI analysis or similar features, selected content may be sent to the relevant AI model service for processing, subject to that service’s terms and privacy policy.
Data Retention
Your imported videos and project data remain on your device until you delete them via the application, operating system, or file management tools. Uninstalling the application, clearing local data, or deleting projects may remove that data, depending on your system and installation method.
Account, subscription, session, entitlement, quota, feedback, support email, and audit records are retained for as long as necessary to provide services, fulfill contractual obligations, resolve disputes, ensure security, or comply with tax or legal requirements. Optional diagnostic raw events are typically retained for up to 365 days, unless a shorter retention period applies or we need to retain records for security, compliance, or dispute resolution.
When data is no longer needed, we delete, anonymize, or aggregate it—unless retention is required by law, accounting standards, security, fraud prevention, or dispute resolution.
Security
We implement reasonable technical and organizational measures to protect server-side data, including access controls, private object storage, token hashing, server-side key management, signature validation, replay protection, spam filtering, and cybersecurity capabilities provided by our infrastructure service provider.
No internet transmission or local device storage can be guaranteed absolutely secure. You should safeguard your device, system accounts, browser sessions, third-party platform accounts, and login email, and promptly install security updates.
Your Choices and Rights
You may manage optional usage statistics and diagnostics in the application settings. You may delete local assets, projects, caches, and exported files, or sign out of your account or cancel your subscription to stop future renewals.
Depending on applicable law in your jurisdiction, you may have the right to request access to, correction of, deletion of, export of, restriction of, or objection to processing of your personal information—or withdraw consent related to optional diagnostics/statistics. We will respond to verified requests as required by applicable law.
For privacy requests, account data requests, or questions about this Policy, please contact support@omnilume.app. To protect account and data security, we may require identity verification before fulfilling such requests.
Children
OmniLume Reel is intended for users legally capable of using professional desktop software and subscription services and is not directed at children. Minors using the Product must obtain consent from a parent or guardian and comply with applicable local laws and platform rules.
Policy Updates
We may update this Privacy Policy due to changes in product features, service providers, legal requirements, or operational practices. Updated versions will be posted on this page, with the effective date reflected in the 'Last Updated' timestamp. Material changes may be notified via the website, application, or other reasonable means.