Omenari

Privacy

What Omenari holds, where it goes, and how to take it back.

What is collected

Your name, email address and profile picture, from Google or Apple when you sign in that way. Omenari never sees your Google or Apple password. If you hide your address when signing in with Apple, what is held is the relay address Apple gives out instead of your real one.

If you sign in with an email address and a password: the address, and a scrambled form of the password from which the password itself cannot be recovered. The password as you typed it is never written down anywhere, not in the database and not in a log.

A short record of recent sign-in attempts — the network address one came from, the mailbox it was for, and when — kept for two days and no longer. It is what stops somebody working through passwords against your account, it holds nothing you wrote and never the password that was tried, and there is no way to switch it off: an account nobody can guess their way into is not a setting.

What you choose to add: a handle, a short bio, an avatar, and what you are working toward.

Everything you write: signs, notes and dreams, whether marked shared or private.

The readings generated for you, and who you have accepted.

Your device's timezone, so that a day runs midnight to midnight where you are and the nightly reading is made at your 11:59pm rather than a server's.

How much each reading cost to generate, as token counts and a duration. It records that a reading happened and how large it was, never any part of what it said or what you wrote.

Birth date, time and place are no longer asked for and nothing reads them. Omenari used to collect them to compute a chart, and that feature is gone. If you entered them before that change they are still on your account, unused. They are removed when you delete it, or sooner if you ask.

What is not collected

There is no analytics, no advertising, no tracking pixels and no third-party cookies. The only cookie is the one that keeps you signed in, which is why there is no consent banner: it is strictly necessary and there is nothing else to consent to.

Your location is never requested. The timezone your browser reports is the closest thing to it, and it is used for clocks.

Who it is shared with

Anthropic, to generate a reading. Each entry you wrote is sent on its own, once, on the night of the day you wrote it, along with a second request that reads the week's readings together. Anthropic does not train models on API content.

Google and Apple, for sign-in, if you use them. A mail provider, for the only mail Omenari sends: a link to prove an address is yours, and a notice when a password changes. Railway, which hosts the app and the database.

Nobody else. Nothing is sold, and there is nothing here that constitutes a sale or share of personal information under US state privacy law.

People you have accepted

An entry you mark as shared is visible to people whose requests you have accepted, along with your name, handle, avatar, bio and your weekly portrait. Reactions and comments on a shared entry are visible to you and to them.

How much you have written, and how many days in a row, are shown on your profile to anyone who can see it, whether or not they can read a word of it. The counts describe the practice rather than the writing, and there is no way to turn them off.

Your readings are always private, to the account, whatever else you share.

How long it is kept

Entries and readings are kept until you delete them or delete your account, because the point of a journal is that it is still there next year.

Deleting your account removes your entries, readings, comments, reactions, connections and your password immediately. Internal ledgers survive it and your account is detached from each, so none refers to you afterwards: chiefly the record of what each reading cost to generate, and older rate-limiting rows from a feature no longer in the app. None of them holds anything you wrote.

The record of recent sign-in attempts is dropped after two days whether or not you are still here. It is keyed by an address and a mailbox rather than by an account, which is what lets it protect an address that has no account behind it.

Your rights

You can download everything, in one file, from Settings. You can delete the account, entirely, from the same place. Neither needs anyone's permission and neither is a request that gets reviewed.

Depending on where you live you may also have the right to correct what is held, to object to processing, or to complain to a data protection authority. Editing is in Settings; for anything else, get in touch.

Sensitive writing

A journal is where people write about their health, their beliefs, their relationships and their worst days. Omenari does not ask for any of that and cannot tell when you have written it, but it is the likely content and it is treated as the most sensitive thing here.

In practice that means: it is not read by anyone, it is not used to train anything, it leaves the server only to generate your own reading, and it is deleted when you say so.

Last updated 19 September 2026. Terms · Privacy