Privacy Policy

Your privacy is not a legal checkbox for us — it is part of the product's philosophy. This policy explains what data we collect, why we collect it, how we protect it, and what your rights are, in the plainest language we could manage.

Last updated: July 20, 2026

1. What data we collect

Account data: your name, email address, password (encrypted — we can never see it), and preferred language, when you create your account.

Workspace content: the tasks, messages, posts, announcements, dues records, and files your team adds. This content is yours; we host it solely to serve you.

Usage data: limited technical information such as browser and device type, IP address, and sign-in times, used to protect the service and improve its performance.

Payment data: entered directly with our payment provider (Paymob); your card details never pass through or are stored on our servers.

2. How we use your data

To run the service as you expect it: syncing your workspace across your devices, showing dues to their owners, and delivering the notifications meant for you.

To communicate with you about your account: activation emails, payment receipts, and security alerts — no marketing emails without your consent.

To improve the product: by analyzing usage patterns in aggregate, anonymized form — never by inspecting your content.

3. Data sharing

We do not sell, rent, or share your data with advertisers. Full stop.

We share the minimum necessary with service providers working on our behalf: our hosting provider (to run the servers), Paymob (to process payments), and Resend (to send operational email). All of them are contractually bound to protect the data and never use it for their own purposes.

We may disclose data if required to do so by the laws of Saudi Arabia or a competent court order, and we will notify you unless the law prevents it.

4. Storage and security

Your data is always encrypted in transit (TLS) between your device and our servers, and stored on professional infrastructure with regular backups.

We enforce strict internal access controls: no one on the team views customer data except to fix an issue affecting you, and only with a documented, specific reason.

Inside Omiedo itself, dues privacy is enforced at the row level: each member sees only their own records, and everything else stays hidden — even from scripted access attempts.

5. Cookies

We use only essential cookies: a session cookie to keep you signed in, a language cookie to remember your choice, and a theme cookie (light or dark).

We use no advertising cookies and no third-party trackers. You can disable cookies in your browser, but sign-in will not work without the essential ones.

6. Data retention

We keep your account data and workspace content for as long as your account is active.

When an account or workspace is deleted, the data is removed from our systems within 30 days, and from backups on their normal cycle within 90 days at most.

We may retain limited financial records (invoices and payments) for as long as Saudi regulations require for accounting, zakat, and tax purposes.

7. Your rights

Access and export: you may access and export your data at any time; your workspaces and their content are exportable from settings.

Correction: edit your name, email, and preferences directly in account settings.

Deletion: delete your account from settings, or email hello@omiedo.com if you need help — we complete such requests within 30 days at most.

8. Children

Omiedo is built for teams and businesses, not for children under 18. We do not knowingly collect children's data, and we delete any such account we become aware of.

9. Changes to this policy

If we make a material change to this policy, we will announce it inside the app and email workspace owners well before it takes effect. The date of the latest update is noted at the top of this page.

10. Contact

For any privacy question, or to exercise your rights: hello@omiedo.com. We treat privacy requests as a priority and reply within a few business days.