Privacy Policy
Last updated: September 21, 2026
The short version
OMU is a digital pet companion app. We try to collect as little as possible. What we do collect (your email, your pet's state, what you write in your journal, and short health event tags if you connect HealthKit) stays linked to your account, lives in our database, and is deleted when you tap Delete Account in Settings — including everything you wrote.
We never sell your data. We never use it for advertising. We don't track you across other apps or websites.
What we collect
Account information
- Your email address (so you can sign in)
- An anonymous user ID generated by our auth provider
- Your password — stored as a one-way hash, never readable by us
App data
- Your pet's state (mood, hunger, energy, happiness, species, evolution, customization)
- Journal entries you write (Rootlog, Wisdom Log, Seven Roots chakra reflections, Voice Logs)
- Voice Log audio recordings — not available in the current version. If voice journaling launches, this policy will be updated first.
- Daily care history, hydration log, streak counts
- Game progress (Migration levels, The Way, Scrabble / Hangman)
- Your birth chart inputs (date, time, place) if you fill them in for the Stars / Supernova feature
Health data (optional)
If you grant HealthKit permission, OMU reads the following from your iPhone / Apple Watch on each app open, to dramatize your Cultivar:
- Steps, exercise minutes, active calories, stand hours
- Sleep duration
- Oxygen saturation (SpO₂)
- Heart rate
- Mindful minutes (Apple Mindfulness sessions)
We do not write to HealthKit, and we don't copy your HealthKit history to our servers. When your pet reacts, we record a short event tag (e.g. “sleep_good”, “low_oxygen”) and, for some tags, the single reading that triggered it (e.g. the SpO₂ percentage or hours slept). Health data is never used for advertising or shared with anyone for marketing. You can revoke HealthKit access at any time in iOS Settings → Privacy & Security → Health → OMU.
Device info
- Device motion (gyroscope) — used only to subtly tilt your Cultivar's ears and tail. Never leaves your device.
- Microphone — only when you tap the mic button to record a Voice Log.
- iOS notification permission — so your Cultivar can send gentle reminders.
Subscriptions
OMU Pro is purchased and processed entirely by Apple. We never receive your payment details. Your Pro status is stored on your device only — it isn't sent to our servers.
What we don't collect
- No advertising IDs (IDFA, IDFV)
- No analytics SDKs that profile you across apps (no Facebook SDK, no Mixpanel, no Amplitude)
- No precise location
- No contacts, photos, calendar, or files
How we use it
- To run the app — your pet's state has to live somewhere
- To sync your pet across devices when you sign in
- To analyze the emotional tone of journal entries, and to generate the reflective guidance in “Reflect with OMU,” using Anthropic's Claude API (only the text you write is sent; never your name, email, or any identifier). This only happens with your permission: the app asks before the first time any of your writing is sent, and you can turn it off anytime in Settings → AI Reflections. With it off, journaling still works — nothing you write is sent to Anthropic. This guidance is a supportive companion feature, not professional or medical advice.
- To send local notifications (10/day max) — these never leave your device
- To recover your account if you forget your password
Who we share with
Subprocessors
- Supabase — hosts our auth + database. Stores your email, journal entries, pet state.
- Anthropic (Claude API) — receives the text of individual journal entries and reflections to classify emotional tone and to generate reflective guidance — only if you've allowed AI Reflections. No identifier is sent, and Anthropic does not use API data to train its models.
- Apple HealthKit — your data lives on your device; we read from it but never send it to Apple ourselves.
- Vercel — hosts this website (omu.pet). Receives standard server logs only — no app data.
Each subprocessor is bound by terms that protect your data at least as strongly as this policy, and receives only what it needs to do its job. We never sell your data. We never share it for marketing. If we ever change subprocessors, this list updates and the page's “Last updated” date moves.
How long we keep it
As long as your account exists. The moment you tap Delete Account in Settings (or email support@omu.pet and ask), every row tied to your user ID is removed within minutes: your auth row, your pets, your journal entries, your friend connections, your hydration log, your HealthKit event tags. Apple requires this — it's not optional.
Server backups roll over within 30 days, after which deletion is irrevocable across our entire system.
Children
OMU is not directed at children under 13. We don't knowingly collect data from children under 13. If you believe a child has signed up, email support@omu.pet and we'll delete the account.
Your rights
Wherever you live, you have the right to:
- Know what we have on you (just open Settings → Account)
- Delete your account (Settings → Account → Delete Account)
- Export your data (email support@omu.pet — we'll send a JSON dump within 30 days)
- Withdraw HealthKit permission (iOS Settings, any time)
- Stop notifications (iOS Settings or in-app)
Security
Connections to our servers are TLS-encrypted. Passwords are hashed with bcrypt. Database access is gated by row-level security — your rows are only readable by your authenticated session. Edge Functions that perform privileged operations (like account deletion) verify your session JWT before doing anything.
No system is perfectly secure. If you find a vulnerability, please email security@omu.pet before disclosing publicly.
Changes to this policy
If we make material changes, we'll bump the “Last updated” date and, where reasonable, surface a notice in the app. If you keep using OMU after a change, you're agreeing to the new version.
Contact
OMU is operated by SJ. Email support@omu.pet for any privacy question. We answer everything.