O
Omnox
← Back to platform
Legal

CRM Privacy Notice

Version 1.2 — Effective August 2026

This covers data processed by the Omnox CRM product itself (crm.omnox.ai) — your workspace, its accounts/contacts/opportunities, and the AI and billing features built on top of it. It's distinct from the marketing site's privacy policy, which only covers omnox.ai itself.

Beta Status

Omnox CRM is in beta, built by a very small team. This notice describes what's actually true today — not aspirational compliance language. See our Security page for what's built and what isn't yet.

1.What we collect

Signing up and using the CRM involves:

  • Your name, work email, and company name at signup.
  • Your password, stored as a salted scrypt hash — never in plain text, never logged.
  • Whatever business data you or your team enter: accounts, contacts, opportunities, activities, tasks, notes, and uploaded documents.
  • Usage telemetry (which features are used, AI credit consumption) to operate billing and improve the product.

2.Cookies

We keep this short because the list is short — no advertising or marketing trackers, nothing sold to a data broker. Just:

Session cookie
Strictly necessary. HttpOnly, set on login, keeps you signed in. Never in localStorage, never readable by page scripts.
Turnstile
Cloudflare's privacy-preserving anti-bot check on signup, where enabled. No cross-site tracking.
Sentry
Error monitoring — helps us catch bugs before you have to report them. No ad tracking.

3.Third-party processors

Data your workspace touches, and why:

Anthropic
Powers AI features (opportunity coaching, document extraction, email drafting, command bar, Scribe's meeting analysis). Only the specific record content relevant to a given AI call is sent, at the moment you trigger it — never in the background, never used to train models.
Deepgram
Powers Scribe's live, speaker-identified meeting transcription, on deployments where it's enabled. Microphone (and, if you choose it, shared browser-tab) audio streams directly from your browser or the Scribe desktop app to Deepgram in real time over an encrypted connection — the raw audio never passes through Omnox's own servers. Every request carries Deepgram's mip_opt_out flag, so Deepgram never uses it to train their models and retains it only for the moments needed to process that request, then discards it. What DOES persist in your workspace afterward is the same as any other Scribe session: the text transcript, speaker labels, your own typed notes, and the AI analysis — stored as a normal CRM record, governed by the rest of this notice, not by Deepgram.
Railway
Backend hosting. Account/auth data (logins, sessions, passkeys, password-reset tokens, the audit log) lives in a SQLite store on a persistent Railway volume — confirmed durable across deploys.
Neon
Business data — accounts, contacts, opportunities, activities, tasks, notes.
Vercel
Frontend hosting for crm.omnox.ai. No persistent business data stored here — request/response pass-through only.
Resend
Transactional and lifecycle email — welcome emails, password reset links, notification digests, invoice reminders.
Stripe
Billing (your Omnox subscription) and, if you use Stripe Connect invoicing, payment collection from your own customers on your behalf.
Clerk
Optional SSO sign-in (email/Google), where enabled.

4.Tenant isolation

Every record is scoped to your workspace's tenant ID, enforced on every read and write. Other Omnox customers can never see your data, and it's never used to answer questions or improve the product for anyone else's workspace.

5.How long we keep it

Your data persists for as long as your workspace is active. On a written request to offboard, all tenant data is deleted within 30 days, including from backups on their normal expiry cycle. Deletion is permanent — we don't currently offer a soft-delete grace period at the workspace level.

6.Export

You can request a full export of your workspace's data — accounts, contacts, opportunities, activities, tasks, documents — as CSV or JSON, at any time, not only at offboarding. Several list views already have CSV export built in; a full-workspace export is available on request via hello@omnox.ai while the self-serve version is on our roadmap.

7.Your choices

Email hello@omnox.ai to ask what we have on file, correct it, export it, or have it deleted. We'll respond within a reasonable time.

8.Changes

If this notice changes in a meaningful way, we'll update the version number and date at the top of this page.

9.Contact

Questions about this notice: hello@omnox.ai. For a formal DPA, ask the same address.

Omnox — CRM Privacy Notice — Version 1.2

This is a working draft written for an early beta, not a substitute for review by your own legal counsel. If you are a paying customer under a signed agreement, that agreement's data-processing terms control over this page.