Legal
Privacy policy.
What we collect, why we have it, who else touches it (including the third-party tool provider your agent calls), and how to get it back or get it deleted.
01
The short version
We collect what running your workspace, executing the tool calls you make, and taking payment requires, and not much else.
There are no advertising trackers and no third-party analytics cookies on this site. We do not sell your data and do not share it for advertising.
That is about your own account data. Separately, some of our tools return, for a fee, publicly available professional information about OTHER people at a customer's request — if you are one of those people rather than an Omnial MCP customer, see the data sources and rights notice, which is written for you specifically.
The one place this product is structurally different from most: when your agent calls a tool, the input for that call is sent to the third-party provider that tool belongs to, because that is what executing the call means. See who that is and why.
Want a copy of your data, or want it gone? See your rights below for how to ask.
The rest of this page is the detail behind those sentences, checked against what the software actually stores rather than what a template says it should.
02
Who is responsible for your data
Pixel Labs Solutions LLC, a limited liability company formed in Georgia, USA, is the controller of the personal data described here. Reach us at pixellabsweb3@gmail.com.
We are a small US company. We have not appointed an EU or UK representative, and we are not currently set up to serve customers who need a formal data-processing agreement. If you need one, write to us before you sign up rather than after.
03
What we collect
Account information
Your email address, and your name if you give us one. Sign-in has no password: we email a one-time link, and opening it is what creates or unlocks your session. If you connect through an external identity provider instead, we receive your verified email and a reference to that account, not a password.
What you submit through your agent
Every tool call your agent makes (omnial_execute) carries an input payload: the parameters that call was made with. We store that input, and the output the call produced, as the run record your dashboard shows you. Fields that look like a credential or a secret are redacted before the row is ever written, and the input is also sent to the third-party provider that tool belongs to; that is what running the call means. Do not put anyone else's personal information, or anything confidential, into a call unless the tool's own usage doc says that is what it is for.
API keys
A key is shown to you once, at creation. We store only its prefix in readable form after that; the full value is not recoverable by us, and if you lose it the only fix is to create a new one.
Payment information
Stripe handles card payments and holds your card details. We never receive or store your full card number. We keep a Stripe customer reference, a cached card brand/last-4/expiry so your billing page does not have to call Stripe on every load, your workspace balance, and an append-only ledger of every credit purchased and spent; that ledger is how billing is kept honest and is also our accounting record.
Technical information
Our hosting and infrastructure providers process standard request data such as your IP address in order to serve requests, apply rate limits, and defend the service from abuse.
Support
If you send us a support message, we keep it and your address so we can reply and fix the thing.
04
Why we use it, and on what legal basis
- To provide the service: creating your workspace, executing the tool calls your agent makes, storing the run history that lets you and your agent see what happened. Necessary to perform our contract with you.
- To take payment: processing top-ups, auto top-up, and the credit ledger. Contract, and our legal obligation to keep financial records.
- To keep the service safe and working: rate-limiting abuse, enforcing per-key spend caps and scopes, debugging failures. Our legitimate interest in running a service that is not abused and does not lose track of anyone's money.
- To communicate with you: sign-in links, billing notices, and replies to your support messages. Contract and legitimate interest.
We do not use your data for automated decision-making with legal effects. A tool call can be refused by the pricing or scope checks; you can always contact us and have a human look at it.
07
How long we keep things
- Run history (inputs, outputs, cost): kept while your workspace exists, because it is also your record of what you were charged and why. There is no automatic deletion of a completed run today.
- Account information: kept while your account exists. Closing your account does not delete it: closing revokes your API keys and stops billing, but the account, its run history, and its ledger are kept unchanged. Deletion is a separate step: ask us to delete it; see “Your rights” below.
- The ledger and payment records: kept for as long as your account exists, and payment records for up to 7 years after the transaction, because tax and accounting law requires it. That is the one category we cannot delete on request.
- Support messages: kept for up to 2 years.
08
Your rights
Wherever you live, we will honour the following. You do not need to cite a law at us, and we will not ask you why.
- Access: get a copy of the personal data we hold about you.
- Portability: receive it in a portable, machine-readable format.
- Correction: have anything inaccurate fixed.
- Deletion: have your account and its data removed, except the payment records we are legally required to retain.
- Objection and restriction: ask us to stop using your data for a particular purpose.
- Withdraw consent: where we rely on it, at any time, without affecting what came before.
Email pixellabsweb3@gmail.com from the address on your account, or use the Close account control in your dashboard to close it yourself immediately. Closing is not deleting: it revokes your API keys and stops billing, and nothing about your stored data changes. Deleting your account and its data is a manual process on our side today: send that request and we will confirm once it is done. We will respond within 30 days, or sooner where a shorter legal deadline applies to your request. There is no self-service delete button yet, only a self-service close.
If you are in the EU or UK you also have the right to complain to your data protection authority. If you are in California, we confirm we have not sold or shared your personal information as our customer for cross-context behavioural advertising, and we will not discriminate against you for exercising any right above.
09
Security
Traffic to the site and the API is encrypted in transit. There is no password to steal; sign-in is a short-lived, single-use emailed link. Fields that look like a credential or a secret are redacted before they are ever written to a log or a stored run. Access to production systems is limited to the people who run Omnial MCP.
No service can promise perfect security, and we will not pretend otherwise. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as the law requires, and we will tell you what actually happened.
10
Children
Omnial MCP is not for children. You must be at least 18 to use it, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us their information, email pixellabsweb3@gmail.com and we will delete the account and its data promptly.
11
Changes to this policy
If we change how we handle your data, we will update this page and the effective date at the top. For a material change (a new category of data, a new purpose, or an analytics provider), we will email the address on your account before it takes effect.
Questions about any of this go to contact. See also the terms of service, the refund policy, and who we route data to.
