This Privacy Policy explains how the OmniModelChat desktop application (the “App”) and the website at omnimodelchat.com (the “Site”) handle personal data, including data you choose to make available from your Google account. It is written to align with the EU/UK General Data Protection Regulation (GDPR) and with the Google API Services User Data Policy.
1. Who we are
The App and the Site are published by Digital Gods (DigitalGods.ai) (“Digital Gods”, “we”, “us”). We are the controller of the personal data the Site processes and of anything you send us directly, such as an email. You can reach us at support@digitalgods.ai.
The App is software that runs on your own computer. The data it stores stays on your device under your control; we do not operate a service that receives it.
2. This website
Server logs. Our web server automatically records standard request information: your IP address, browser user-agent, the page or file requested, the date and time, and the referring page. We use it to operate, secure and troubleshoot the Site.
No cookies, analytics or advertising. The Site sets no cookies and uses no analytics, advertising, tracking pixels, or third-party scripts or fonts. Every file it loads is served from our own server.
Email. If you email us — for example to request early access — we process your email address, your name if you give it, and what you write, including any Google account address you ask us to add to the App's Google testing list. We use this only to reply and to provide early access, and we never use it to market unrelated products to you. Our email provider handles these messages on our behalf.
3. The app: what stays on your PC
- Your workspace. Conversations, message branches, drafts, attachments, library items, saved tool results, settings, and a cache of public model metadata are stored in a local SQLite database in
%APPDATA%\OmniModelChat, or in a folder you choose with theOMNIMODELCHAT_DATA_DIRsetting. - Credentials. API keys for model providers and services, connector tokens, and the OAuth access and refresh tokens created when you connect an app are stored in Windows Credential Manager. They are kept out of the database and out of chat exports.
- Exports. When you export a chat, the App writes a JSON file containing that conversation's branches and attachments, but no credentials, to a location you choose.
- No telemetry. The App does not send usage analytics, crash reports or content to us.
The App's database is not encrypted at rest; it is protected by your Windows account and device security. We have no access to it.
4. The app: what leaves your PC, and when
The App sends data only to services you configure, and only when an action you request needs them:
- AI model providers. The model you select for a conversation receives the context needed to generate a response: the messages on the active branch, attachments you include, and any research evidence or tool results the conversation uses. A model running on your own PC (such as LM Studio or Ollama) keeps that data on your device. A cloud provider you configure — such as OpenAI, Anthropic, Google Gemini or another OpenAI-compatible service — processes it under its own terms and privacy policy, using your account and API key.
- Web research, when you turn it on: Brave Search receives the search query, and Jina Reader receives the addresses of the pages to be read. They do not receive the rest of your conversation.
- Model metadata. To look up context limits for cloud models, the App may fetch a public model catalog from models.dev. These requests contain no keys and no conversation content, and are not made for local or LAN connections.
- Connected apps. Google, Microsoft, Notion, Slack, GitHub, Dropbox, Todoist and any custom MCP server you add receive the requests needed for the tools you allow, authorized by your own account.
- Sign-in. When you connect an account, you sign in with the provider in your own web browser. The App receives the resulting tokens through a temporary callback on your own computer (127.0.0.1).
When a conversation is marked Local only, the App blocks cloud inference, web research and connected-app calls for it until you explicitly release the restriction. Digital Gods receives none of the data described in this section.
5. Google user data
This section explains how the App accesses, uses, stores and shares Google user data when you connect a Google account.
5.1 Data the App accesses
- Gmail (permissions
gmail.readonlyandgmail.compose): your Gmail address, to confirm the connection; the results of searches you ask for; the content of messages the App reads for you, including headers such as sender, recipients, subject and date, and the text body; and the recipient, subject and body of an email draft it prepares for you. With your approval, it saves that draft to your Gmail account and sends it when you press Send email. - Google Drive (permission
drive.readonly): the names, types, links and identifiers of files that match your searches, and the text of text files and Google Docs you ask it to read. Access is read-only: the App cannot modify or delete your Drive files. - Google Calendar (permission
calendar.events), only if you connect Calendar using your own registration or token: upcoming events on your primary calendar, and events you ask the App to create. Created events have no attendees and send no invitations.
5.2 How the App uses it
Google user data is used only to provide the features you request in the App: answering questions about, summarizing or finding your email and files within a conversation; preparing an email draft for your review; sending an email you have approved; and creating calendar events you ask for. Searches and reads run when chat tools are switched on and the relevant tool is allowed. Saving a draft requires your approval, and an email is sent only when you press Send email.
5.3 How it is stored
Your Google tokens are stored in Windows Credential Manager on your PC. Content the App retrieves is stored in the App's local database on your PC, as part of the conversation and as a saved tool result in your library. Digital Gods does not store Google user data on any server.
5.4 How it is shared
Google user data is transferred only to the AI model provider you have selected for that conversation, and only as needed to respond to your request. If you select a model running on your own PC, it stays on your PC. When you choose a cloud model, that provider processes the data under its own terms; choose providers whose data practices you accept, or use a local model with Local only to keep Google data on your device.
We do not:
- sell Google user data, or transfer it to data brokers or information resellers;
- use or transfer it to serve advertising, including personalized or retargeted advertising;
- use or transfer it to determine creditworthiness or for lending purposes;
- use or transfer it to develop, improve or train generalized artificial intelligence or machine-learning models;
- read it. No one at Digital Gods can, because it never reaches us.
5.5 Limited Use
OmniModelChat's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5.6 Your controls
- Switch individual tools off under Allowed tools in Apps & tools, or turn off chat tools with the wrench control.
- Disconnect removes the account's tokens from Windows Credential Manager.
- Revoke the App's access at any time in your Google Account, at myaccount.google.com/permissions.
- Delete retrieved content by deleting the conversation or library item, or by deleting the App's data folder.
6. Other connected services
The same principles apply to Microsoft Outlook and OneDrive, Notion, Slack, GitHub, Dropbox, Todoist and custom MCP servers: tokens are kept in Windows Credential Manager, data is used only to provide the features you request, retrieved results are stored on your PC, and they are sent only to the model you choose. Every call to these services, reads as well as writes such as posting a message or creating an issue, waits for your approval. Each service's own terms and privacy policy also apply.
7. Security
Credentials are held in the operating system's credential store rather than in the App's database. All of the App's outbound requests pass through a single gateway that checks the destination and refuses redirects. Account sign-in uses OAuth with PKCE and state validation, and the temporary callback listens only on your own computer for at most five minutes. No system is perfectly secure: keep your Windows account protected, and remember that the App's database and your exports are not encrypted at rest.
8. Retention and deletion
- Site logs are kept for a short operational period and then rotated and deleted, unless a specific record must be kept longer to investigate abuse or meet a legal obligation.
- Emails you send us are kept for as long as we need them to respond and provide early access, plus a reasonable follow-up period. Ask us to delete yours at any time.
- App data stays on your device until you delete it. We hold no copy.
9. Legal basis
We process Site logs on the basis of our legitimate interests in providing and securing the Site (Article 6(1)(f) GDPR). We process emails you send us to take steps at your request and in our legitimate interest in responding (Articles 6(1)(b) and 6(1)(f) GDPR). The App processes data on your own device, and transfers it to the services you configure at your direction.
10. International transfers
The Site is served directly from our own server. Email you send us is handled by our email provider. Services you connect to the App, including AI model providers, may process data in other countries under their own terms.
11. Your rights
Subject to the GDPR, you have the right to access your personal data, have it rectified or erased, restrict or object to its processing, and receive it in a portable form. For data the App stores on your device, you can exercise these rights directly by viewing, exporting or deleting it. For anything we hold, contact us using the details below. You also have the right to lodge a complaint with a supervisory authority — in the EU/EEA, your local Data Protection Authority; in the UK, the Information Commissioner's Office (ICO).
12. Children
The App and the Site are not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has sent us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the App develops. Material changes will be posted on this page with a new effective date. This version is effective 2 October 2026.
14. Contact
Questions about this policy or your personal data? Email support@digitalgods.ai. We aim to respond within a reasonable time.