Privacy Policy
This Policy describes how Omega Tools collects, uses, and protects personal data. We comply with the Korean Personal Information Protection Act (PIPA) and align with GDPR principles for international users.
1. Data we collect
Account: email, name (from Clerk identity provider). Workspace: workspace name, plan, invoices. Operational: hashed IP and user-agent (SHA-256 truncated, 16 hex chars), audit events with action/actor/target. Provider keys: stored KMS-encrypted at rest; never logged in plaintext. Payment: Stripe-hosted card details (we never see PAN/CVV).
2. Why we collect it
To operate the Service (authentication, billing, run execution), to comply with legal obligations (audit trail, tax invoice), to detect abuse (rate-limit, gitleaks, council guardrails), and to communicate service notices (email, in-app).
3. Retention
Account: until you delete the account or 5 years after last activity (Korean retention requirements for e-commerce records). Audit events: 90 days hot, 1 year cold archive. Run artifacts: tier-dependent (Free 7d, Starter 30d, Team 180d). Provider keys: until you revoke or 90 days dormant (auto-marked dormant).
4. Sharing
We do not sell personal data. Sub-processors: Clerk (auth), Stripe (payments), Neon (Postgres), Upstash (Redis), Cloudflare (R2 storage and Workers AI), Fly.io (compute), Vercel (web hosting and Vercel Web Analytics). Each is contractually bound to GDPR/PIPA-compatible terms. We disclose only what each sub-processor strictly requires. Vercel Web Analytics is cookieless and collects only anonymous page-view metrics (no personal identifiers).
5. Your rights
You may access, correct, export, or delete your personal data at any time. Export and account deletion are self-serve via /settings; for any other request, email the Privacy Officer (see footer). We will respond within 10 business days.
6. Security
TLS in transit, KMS encryption at rest for sensitive secrets, audit logs, helmet/CSP security headers, regular npm audit and gitleaks scans, KMS rotation runbook (quarterly). Incidents are disclosed to affected users within 72 hours (PIPA and GDPR alignment).
7. Children
Users under 14 cannot use the Service. For users aged 14–18, parental or legal-guardian consent is required for paid subscriptions; the platform itself can be used for educational evaluation in line with school or guardian guidance.
8. International transfers
Data is processed in Singapore (Upstash AWS), the United States (Stripe, Vercel, Clerk), and the EU/global (Neon, Cloudflare R2). All transfers rely on Standard Contractual Clauses or equivalent legal mechanisms.
9. Contact
Privacy Officer: see the footer of this site. We respond to verifiable requests within 10 business days.