// LEGAL
Privacy Policy
ArtifactBridge is operated by Omnim Inc. (“ArtifactBridge,” “we,” “us,” or “our”), a Delaware corporation with its principal place of business at 1111B Governors Ave STE 28169, Dover, DE 19904, United States. ArtifactBridge is a document and artifact layer that turns AI-generated output into managed, versioned documents, imports and comments on documents in connected sources such as Google Docs and Notion, and exposes those documents to AI agents through a secure MCP server. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have. Omnim Inc. is the controller of the account, billing, and security data described below. For the content of your workspaces, we act as a processor on your instructions.
1. Information We Collect
Account information
When you create an account, we collect your name and email address. You may sign in with Google, in which case Google shares the basic profile information (name and email) you authorize with us. You may also sign up with an email address and password.
Connected source data
When you connect a Google Drive / Google Docs account, a Notion workspace, a Slack workspace, or another supported source, we retrieve and store the documents and content you choose to sync, along with document metadata such as the file name, modification time, version, revision identifiers, view links, and comments associated with those documents.
Document and collaboration content
We store the managed documents, versions, folders, workspaces, comment threads, review requests, proposals, and audit records you and your agents create or import within ArtifactBridge.
Agent and integration data
When an AI agent (such as Claude) connects through our MCP server, we record scoped API-token activity, agent tool calls, and consent decisions. When you use the built-in chat companion, semantic search, or another AI feature that runs inside the Service, we send the document text that the feature needs to the model providers named on our subprocessor list. We do not use your content to train a general-purpose AI model, and our contracts with those providers do not permit them to do so. If you enable push notifications we store device tokens needed to deliver them.
Billing data
When you buy a paid subscription, our payment provider collects and processes your payment details. We do not store your full card number. We store billing records: the workspace, the plan, the amount, the currency, the tax, the billing interval, the invoice identifier, the payment status, and the payment provider customer identifier.
Transactional email data
We send transactional email, such as sign-in links, security notices, billing notices, and legal-update notices. Our email provider processes your email address and the message content, and records delivery events.
Usage and technical data
We collect logs, metadata, and similar technical information about your use of the Service, including authentication events, IP address, browser type, and access times for security, reliability, and auditing.
Acquisition analytics
On the public landing site we record cookieless funnel events (page views, call-to-action clicks, and first-time signups and product-update leads). The browser talks only to our own collector. We forward those events, together with the visitor IP address for coarse country or region, to PostHog Cloud in the European Union. We do not set an analytics cookie, we do not build a person profile from these events, and we do not send your email address, user id, or workspace id with them.
Signup source. When you create an account, we record where your signup first reached us:
the campaign tags on the link you followed (for example utm_source and utm_medium),
or, when you start from an AI assistant, a short label for it (ChatGPT, Claude, a local agent, or another
agent). We record this once, after you verify your email address, and only while your account is less than
seven days old and does not yet belong to a workspace. We can record it before you accept the terms. We keep
this record with your account in our own database. Only our operators see it. We use it to learn which
channels bring accounts that go on to use the Service. We do not send this record to analytics providers or
to our team chat. Separately, the anonymous signup events that we send to PostHog can carry the same campaign
tags or assistant label; those events carry no email address, user id, or workspace id. We delete the record
when we delete your account.
Product analytics
When you use the Service signed in, we record which product features you use, including the steps of the product tour, and we tie those events to your user id so we can see where people succeed or get stuck. This includes actions taken by AI agents you authorize, which we tie to your user id. We send these events to PostHog Cloud in the European Union. They carry your user id, the feature name, the AI tool your agent used, and timing, and short details of the action, for example the plan you chose or the source you connected. They never carry document content, comments, or messages. When you delete your account, after the 30-day grace period, we delete this person record, its events, and any recordings at PostHog.
Session recording (beta). During the beta we record how you move through the Service while you are signed in: clicks, scrolling, and page changes. Text you see and text you type are masked in your browser before anything is sent. Documents are replaced by blank blocks, pictures included. Profile pictures in the page frame are recorded. Page addresses, link targets, and the names of page elements are recorded as they are. The recording is tied to your user id. We send it to PostHog Cloud in the European Union and use it only to improve the Service and how new members start with it. You can turn this off at any time in Settings → Account. Turning it off deletes nothing already recorded. Deleting your account deletes the recordings.
2. How We Use Your Information
- To provide, operate, and maintain the Service, including importing documents from your connected sources and writing the comments and messages you or your agents author.
- To create, store, version, and organize your managed documents and artifacts.
- To authenticate you and authorize AI agents to act within the workspaces you grant them access to.
- To run the AI features you use inside the Service, such as the chat companion and semantic search.
- To bill you for a paid subscription and keep the financial records the law requires.
- To communicate with you about your account, security, billing, legal updates, and the Service.
- To monitor and prevent fraud, abuse, and security incidents.
- To measure how people find and start using the Service (campaign, page, and conversion counts, and coarse location), including the first signup source of your account.
- To understand how people use the Service once signed in, including the product tour, so we can improve it. This includes actions of AI agents you authorize.
- To comply with our legal obligations.
Where the General Data Protection Regulation (GDPR) applies, we rely on the performance of our contract with you for the first six purposes, on our legitimate interest in a secure and measurable Service for security, analytics, and the improvement of the Service, including the session recording during the beta, which we limit by masking text and by the off switch in Settings → Account, and on our legal obligations for records and disclosures the law requires.
3. Google API Data and Limited Use
ArtifactBridge's access to and use of information received from Google API Services complies with the Google API Services User Data Policy, including the Limited Use requirements. We only request the scopes necessary to read and export the Google Docs you choose to sync and to post the comments you or your agents author on them. We do not use Google API data for advertising, and we do not transfer or sell it to third parties for that purpose.
4. How We Share Information
We do not sell your personal information. We share data only as described below:
- Service providers: We use infrastructure, integration, model, payment, and email providers that process data on our behalf. Our subprocessor list names every provider, states what data it receives and where it processes that data, and describes how we announce a change. The list includes Supabase (database hosting), Cloudflare (application hosting and the models behind the chat companion), Pipedream (which brokers your authorized connections to Google Drive, Notion, and Slack), OpenAI (text embeddings for semantic search), PostHog (landing funnel events with the visitor IP for coarse location, and signed-in product events tied to your user id, and during the beta masked session recordings tied to your user id), Stripe (payment processing), and Postmark (transactional email). These providers are bound by contract to protect your data and to use it only to provide their services to us.
- Integrations you authorize: When you connect Google Docs, Notion, Slack, or another supported source, we exchange data with that service to the extent necessary to perform the import, comment, and collaboration features you requested. Enabled comment mirroring can send comment bodies, quoted document text, author attribution, and discussion links to Google Docs or Notion. Configured Slack review notifications can include a document title, proposal summary, author attribution, and review link.
- Configured webhooks and agent runtimes: Workspace activity hooks can deliver event metadata, including actor identity, workspace, action, target, and time, to external endpoints configured for the workspace. This includes activity from MCP calls that retrieve data; the activity envelope excludes tool arguments and results. Separately, configured Room hooks and agent runtimes can receive Room event content needed for the requested collaboration or delegated task. External recipients may retain delivered data or take actions that ArtifactBridge cannot recall.
- Agents you authorize: When you grant an AI agent access to a workspace, the agent and the platform that hosts it receive the documents and data that the agent requests within its scope. That platform's own privacy policy governs what it does with the data.
- Within your workspaces: Members of a workspace you belong to may see documents, comments, and activity you create there, in accordance with workspace membership and permissions.
- Share links: If you create a share link, anyone with the link may view the shared document according to the visibility you set.
- Room image links: Uploaded Room images have capability-token URLs; anyone who obtains the URL can retrieve the image, so treat these links as part of the content you share.
- Business transfers: If Omnim Inc. is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will give notice before your personal data becomes subject to a different privacy policy.
- Legal requirements: We may disclose information when required by law, court order, or to protect the rights, property, or safety of ArtifactBridge, our users, or others.
5. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Imported external document content is retained until you delete the document or choose to delete content when disconnecting a backing Google or Notion account. Comment history and audit records may be retained as conversation and system history even after document content is removed. Disconnecting or deleting an account inside ArtifactBridge never edits, archives, or deletes the original document in Google Docs, Notion, or any other source outside ArtifactBridge.
You can delete your account yourself in Settings → Account. You can delete a workspace you own in the workspace settings danger zone. Both deletions start a grace period during which you can cancel them: 30 days for an account, 7 days for a workspace. After the grace period we permanently remove the data from our live systems and keep only a deletion record that contains step names, counts, and timestamps. Three kinds of copy remain for a limited time after that: our database backups, until the backup window ends; our service providers' own operational logs, until their retention period ends; and payment and invoice records, which our payment processor and we must keep for the statutory financial record period. Those billing records are pseudonymized and hold transaction amounts and identifiers, not document content. Landing funnel events and the visitor IP we send to PostHog have no person identifier and remain there until PostHog's project retention window ends. Signed-in product events are tied to your user id, and we delete that person record at PostHog when we delete your account. Session recordings remain at PostHog until PostHog’s project retention window ends or we delete your account, whichever comes first. When we delete your account we delete the person record, its events, and its recordings together. If that delete fails, we complete it manually and record that step. The signup source of your account is deleted with your account.
Legal hold. We keep data that a law, a court order, or an active legal claim requires us to keep. We keep that data only for the period the obligation requires, and we delete it when the obligation ends. If self-serve deletion is not available to you, you can still request deletion by contacting us at the address below.
6. Data Security
We protect your data using industry-standard measures. We store only SHA-256 hashes of your
afb_ API tokens and never the raw value. Agents get OAuth 2.1 scoped access that you can revoke.
Row-level security policies enforce the workspace boundary in our database. We do not store the OAuth
credentials of your connected Google, Notion, or Slack accounts; our connection broker holds them and encrypts
them at rest. Data in transit is encrypted with TLS, and our providers encrypt stored data at rest. Our
Security page describes the current controls. No method of transmission or
storage is fully secure, but we work to protect your information using reasonable technical and organizational
safeguards.
7. Your Choices and Rights
- Manage connections: You can connect or disconnect Google, Notion, or Slack accounts at any time, and choose whether to keep or delete imported content on disconnect.
- Revoke agent access: API tokens and OAuth grants are revocable. You can delete tokens or deny consent requests from your settings.
- Export: You can export your documents and workspace content through the Service at any time.
- Access and deletion: You can delete your account in Settings → Account, and a workspace you own in the workspace settings danger zone. You may request access to or correction of your personal data, or deletion by another route, by contacting us.
- Notifications: You can enable or disable push notifications from your account or device settings.
- Session recording: During the beta you can turn the session recording off in Settings → Account.
If you are located in the European Economic Area, the United Kingdom, or certain other jurisdictions, you may have additional rights under applicable data protection laws, including the right to access, port, rectify, restrict, or object to processing, and the right to lodge a complaint with your local data protection authority. If you are a California resident, you have the right to know, delete, and correct your personal information and the right not to be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioral advertising. To exercise a right, contact us at the address below. We answer within the period the applicable law sets.
8. International Transfers
Omnim Inc. is established in the United States, and our providers process data in the United States, the European Union, and the other regions named on the subprocessor list. Where we transfer personal data out of the European Economic Area or the United Kingdom to a country without an adequacy decision, we use the European Commission Standard Contractual Clauses (SCCs), together with the United Kingdom International Data Transfer Addendum where United Kingdom law applies, as the transfer mechanism. We apply the same mechanism in our contracts with the service providers listed in Section 4. You may request a copy of the transfer terms at the address below.
9. Children's Privacy
The Service is not directed to children under 16. Our Terms of Service require every user to be at least 16 years old. We do not verify age, so we do not know the age of a user unless someone tells us. If you believe a user is under 16, contact us at the address below. We will review the report and delete the account and its personal data if we confirm the report.
10. Changes to This Policy
We may update this Privacy Policy. We publish every revision as a numbered version with an effective date, and we show that version and date above. For a non-material change, we post the revised policy and send you a notice by email or in the Service before the effective date. For a material change, we send you a notice and ask you to accept the new version explicitly before you continue to use the Service. Section 15 of the Terms of Service states the same contract and lists the account actions you keep while your acceptance is pending.
11. Contact Us
If you have questions about this Privacy Policy or your personal data, contact us at support@omnim.ai, or write to Omnim Inc., 1111B Governors Ave STE 28169, Dover, DE 19904, United States.