Legal · what we collect (very little)
Privacy Policy
Last updated 15 August 2026 · Innisfallen Pty Ltd · ABN 12 699 798 288 · Privacy Act 1988 (Cth) & Australian Privacy Principles
This policy is short because there is very little to describe: Omitly is built so that your documents never reach us.
1. Your documents
The desktop app processes documents entirely on your device. The app never transmits any document, document content, filename or document metadata to us. There is no account, no cloud processing and no telemetry about your documents. The free web tools (leak checker, verifier) run in your browser via WebAssembly; files you check are not uploaded.
We cannot access, recover, disclose or be compelled to produce documents you process with Omitly, because the product never sends them to us. The only document content we ever hold is content you choose to send us yourself — for example, attaching a file to a support email — and we use that only to answer you.
2. What we do collect
| Data | Source | Why | Held by |
|---|---|---|---|
| Purchase details (name, email, payment method, billing country) | Stripe checkout | Processing your purchase; tax | Stripe (merchant of record on standard purchases) — see Stripe's privacy policy. We receive name, email and licence tier, not card details. |
| Licence details (licensed-to name, tier, dates) | Fulfilment | Minting your licence file | Us |
| Support correspondence | You emailing us, or the in-app support form | Answering you | Us (email) |
| Cookieless website measurement (page, referrer, campaign and coarse device/network details) | Visiting marketing pages | Understanding which pages and channels are useful | Us, through the first-party Faro service. It sets no visitor cookie or persistent identifier; free-tool and privacy pages do not load it. |
| Acquisition source (for example, that you followed the leak checker's download link) | Following a free-tool link to a measured marketing page | Understanding whether the free tool leads to downloads and purchases | Your browser for up to 14 days, without a visitor identifier. If you purchase, the coarse source is attached to the Stripe checkout and our fulfilment record. No checker result or document information is included. |
| Trial-guide email, consent record and campaign attribution | The optional trial-guide form | Confirming your request and sending the three-email guide | Us, in a consent-only register separate from licence and document systems. The trial and downloads do not require this form. |
| Optional signing timestamp (opt-in) | Digitally signing with a timestamp | RFC 3161 timestamp on your signature | The timestamp authority you configure (not us) — it receives a hash only, never document content. Off by default. |
We don't sell or share personal information for advertising profiles, we don't train anything on your data, and we don't enrich or profile.
3. The app doesn't phone home
Licence validation is offline and there is no telemetry. The desktop app makes exactly three kinds of outbound request, none of which carries document data (matching the verified enumeration on how Omitly redacts): it fetches a signed release manifest to check for updates; if you use the in-app support form, it sends the message you typed plus the app version and OS string; and if you opt in to a timestamp while digitally signing, it sends a hash — never the document — to the timestamp authority you configure.
4. Storage, access, correction and complaints
Licence and support records are retained while your licence is active and as required by Australian tax law. Trial-guide records are used only for the requested three-email sequence; unsubscribing stops the sequence, and the suppression record is retained so we do not contact that address again without fresh consent. You can ask us to access, correct or delete your personal information at hello@omitly.app. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles — as a matter of policy whether or not the small-business exemption would apply to us — and notify eligible data breaches under the Notifiable Data Breaches scheme, noting the breach surface is limited to the purchase/licence records above, never the documents you process.
If you think we have mishandled your personal information, complain to hello@omitly.app; we will acknowledge your complaint promptly and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
5. Overseas disclosure
Stripe processes payments and may store purchase data outside Australia, including in the United States. Where we disclose personal information overseas we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. Our own licence and purchase records are held in a Cloudflare D1 database running in Cloudflare's Oceania region; our support and email infrastructure runs in AWS ap-southeast-2 (Sydney).
If you are in the EEA or the United Kingdom, you can exercise your local data rights (access, correction, erasure, objection) by emailing hello@omitly.app.
Contact: hello@omitly.app