Skip to content
Eden Engine

Legal

Privacy policy.

What we collect, why we have it, who else touches it (including the third-party tool provider your agent calls), and how to get it back or get it deleted.

Effective 1 September 2026Pixel Labs Solutions LLC

01

The short version

We collect what running your workspace, executing the tool calls you make, and taking payment requires, and not much else.

There are no advertising trackers and no third-party analytics cookies on this site. We do not sell your data and do not share it for advertising.

That is about your own account data. Separately, some of our tools return, for a fee, publicly available professional information about OTHER people at a customer's request — if you are one of those people rather than an Omnial MCP customer, see the data sources and rights notice, which is written for you specifically.

The one place this product is structurally different from most: when your agent calls a tool, the input for that call is sent to the third-party provider that tool belongs to, because that is what executing the call means. See who that is and why.

Want a copy of your data, or want it gone? See your rights below for how to ask.

The rest of this page is the detail behind those sentences, checked against what the software actually stores rather than what a template says it should.

02

Who is responsible for your data

Pixel Labs Solutions LLC, a limited liability company formed in Georgia, USA, is the controller of the personal data described here. Reach us at pixellabsweb3@gmail.com.

We are a small US company. We have not appointed an EU or UK representative, and we are not currently set up to serve customers who need a formal data-processing agreement. If you need one, write to us before you sign up rather than after.

03

What we collect

Account information

Your email address, and your name if you give us one. Sign-in has no password: we email a one-time link, and opening it is what creates or unlocks your session. If you connect through an external identity provider instead, we receive your verified email and a reference to that account, not a password.

What you submit through your agent

Every tool call your agent makes (omnial_execute) carries an input payload: the parameters that call was made with. We store that input, and the output the call produced, as the run record your dashboard shows you. Fields that look like a credential or a secret are redacted before the row is ever written, and the input is also sent to the third-party provider that tool belongs to; that is what running the call means. Do not put anyone else's personal information, or anything confidential, into a call unless the tool's own usage doc says that is what it is for.

API keys

A key is shown to you once, at creation. We store only its prefix in readable form after that; the full value is not recoverable by us, and if you lose it the only fix is to create a new one.

Payment information

Stripe handles card payments and holds your card details. We never receive or store your full card number. We keep a Stripe customer reference, a cached card brand/last-4/expiry so your billing page does not have to call Stripe on every load, your workspace balance, and an append-only ledger of every credit purchased and spent; that ledger is how billing is kept honest and is also our accounting record.

Technical information

Our hosting and infrastructure providers process standard request data such as your IP address in order to serve requests, apply rate limits, and defend the service from abuse.

Support

If you send us a support message, we keep it and your address so we can reply and fix the thing.

04

Why we use it, and on what legal basis

  • To provide the service: creating your workspace, executing the tool calls your agent makes, storing the run history that lets you and your agent see what happened. Necessary to perform our contract with you.
  • To take payment: processing top-ups, auto top-up, and the credit ledger. Contract, and our legal obligation to keep financial records.
  • To keep the service safe and working: rate-limiting abuse, enforcing per-key spend caps and scopes, debugging failures. Our legitimate interest in running a service that is not abused and does not lose track of anyone's money.
  • To communicate with you: sign-in links, billing notices, and replies to your support messages. Contract and legitimate interest.

We do not use your data for automated decision-making with legal effects. A tool call can be refused by the pricing or scope checks; you can always contact us and have a human look at it.

05

Cookies and tracking

This site runs no advertising pixels and no third-party tracking cookies. There is nothing here to opt out of, which is why you have not been shown a cookie banner.

Your session is kept by a short-lived, strictly-necessary cookie, so you stay signed in without re-authenticating on every request. It is not shared with anyone, and signing out clears it. Our hosting provider may set cookies necessary for security and traffic routing. If we ever add analytics, this section will be updated before it goes live, not after.

06

Who we share it with

We do not sell your personal data, and we do not share it for advertising. Data goes to three kinds of third party, each for a specific reason:

  • The infrastructure that runs the product: payment processing, hosting, and transactional email. Named, with exactly what each one receives, on the subprocessors page.
  • The third-party tool provider you call: the input for that specific call, and only that call. This product is a directory and a payment layer in front of other companies' APIs; running a tool means sending its input to the company that operates it, described by mechanism, with the two non-synthetic entries named, on the subprocessors page. We route the call; we do not control, and cannot audit, what that provider does with the input on its own systems once it receives it. If that call returns information about a person who is not our customer, our data sources and rights notice covers what we process about them and their rights — this page is about your own data as our customer.
  • Nobody else, unless we are legally required to disclose something, or to protect our rights or someone's safety. If the business is ever sold or merged, account data would transfer with it; we would tell you before that happened.

Where these actually run is not uniform: the server that stores your account, run history, ledger and API keys runs in Hetzner's Germany datacenter, so that data lives in the EU. Stripe holds your card and billing data in the US. Vercel serves this site's public marketing pages from US infrastructure. Brevo, which sends transactional email, is a French company. See the subprocessors page for the full breakdown, including what is independently confirmed. A third-party tool provider you call may be based anywhere; that provider's own privacy practices govern what it does with the input you sent it, and its usage doc is where that should be disclosed. Review a provider's own privacy policy before sending it anything sensitive; we are not responsible for that provider's own handling of your data, to the extent the terms of service's liability limits allow.

07

How long we keep things

  • Run history (inputs, outputs, cost): kept while your workspace exists, because it is also your record of what you were charged and why. There is no automatic deletion of a completed run today.
  • Account information: kept while your account exists. Closing your account does not delete it: closing revokes your API keys and stops billing, but the account, its run history, and its ledger are kept unchanged. Deletion is a separate step: ask us to delete it; see “Your rights” below.
  • The ledger and payment records: kept for as long as your account exists, and payment records for up to 7 years after the transaction, because tax and accounting law requires it. That is the one category we cannot delete on request.
  • Support messages: kept for up to 2 years.

08

Your rights

Wherever you live, we will honour the following. You do not need to cite a law at us, and we will not ask you why.

  • Access: get a copy of the personal data we hold about you.
  • Portability: receive it in a portable, machine-readable format.
  • Correction: have anything inaccurate fixed.
  • Deletion: have your account and its data removed, except the payment records we are legally required to retain.
  • Objection and restriction: ask us to stop using your data for a particular purpose.
  • Withdraw consent: where we rely on it, at any time, without affecting what came before.

Email pixellabsweb3@gmail.com from the address on your account, or use the Close account control in your dashboard to close it yourself immediately. Closing is not deleting: it revokes your API keys and stops billing, and nothing about your stored data changes. Deleting your account and its data is a manual process on our side today: send that request and we will confirm once it is done. We will respond within 30 days, or sooner where a shorter legal deadline applies to your request. There is no self-service delete button yet, only a self-service close.

If you are in the EU or UK you also have the right to complain to your data protection authority. If you are in California, we confirm we have not sold or shared your personal information as our customer for cross-context behavioural advertising, and we will not discriminate against you for exercising any right above.

09

Security

Traffic to the site and the API is encrypted in transit. There is no password to steal; sign-in is a short-lived, single-use emailed link. Fields that look like a credential or a secret are redacted before they are ever written to a log or a stored run. Access to production systems is limited to the people who run Omnial MCP.

No service can promise perfect security, and we will not pretend otherwise. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as the law requires, and we will tell you what actually happened.

10

Children

Omnial MCP is not for children. You must be at least 18 to use it, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us their information, email pixellabsweb3@gmail.com and we will delete the account and its data promptly.

11

Changes to this policy

If we change how we handle your data, we will update this page and the effective date at the top. For a material change (a new category of data, a new purpose, or an analytics provider), we will email the address on your account before it takes effect.

Questions about any of this go to contact. See also the terms of service, the refund policy, and who we route data to.