Privacy Policy

    Effective date: 2 July 2026

    omemo turns the screenshots on your iPhone into an organised, searchable library. Screenshots can hold some of the most personal things on your phone — receipts, messages, boarding passes, health appointments — so privacy isn't something we added at the end. It shapes how the product is built.

    This policy explains, in plain language, what we collect, why, where it goes, how long we keep it, and the controls you have over all of it.

    The short version

    • We only work with your screenshots — never the rest of your photo library.
    • Sensitive screenshots can be blocked on your device, before anything is ever sent to us.
    • We use AI to read and organise your screenshots. Our processing providers don't keep your images and don't use them to train their models.
    • We never sell your data and never use it for advertising or ad targeting.
    • You can turn off whole categories, delete any item, or delete everything and your account, at any time.

    This summary is here to help — the full policy below is what governs how we handle your data.

    1. Who we are

    omemo is operated by omemo, Inc., 2261 Market Street, San Francisco, CA 94114, United States. We are the data controller responsible for your personal data.

    For any privacy question or to exercise your rights: privacy@omemo.app. We aim to respond within 3 business days.

    2. How omemo works and what stays on your device

    omemo works in two stages: on your device, then in our secure cloud.

    On your device

    omemo detects new screenshots and, if you've enabled screening for a sensitive category, checks each screenshot locally before anything leaves your phone. Screenshots that match a category you've switched off are blocked on the device and never uploaded. Your regular (non-screenshot) photos are never opened, scanned, uploaded, or read.

    In our cloud

    Screenshots you haven't blocked are sent over an encrypted connection to our servers, where they're read, sorted into categories, and enriched with useful details (for example, adding the artwork for a film you screenshotted, or the address of a restaurant). This cloud step is what makes your library searchable and useful — see Section 7 for how the AI processing works.

    3. What we collect

    3.1 Information you give us

    • Account details: your email address, first name, an optional avatar, and optionally your location. You can create your account and sign in with Sign in with Apple, Google Sign-In, or an email address and password. If you use email and password, your password is stored only in hashed form — we never see or keep it in plain text. When you sign in with Apple or Google, that provider passes us only your name, email address, and (if available) profile picture, so we can set up and secure your account. If you use Sign in with Apple's private email relay, we only ever see the relay address, never your real one. We use this information solely to create and authenticate your account — never for advertising or any unrelated purpose.
    • Your language preference.
    • Your settings: which sensitive categories you allow, notification choices, and which optional actions you enable (such as adding items to your calendar or reminders).
    • Optional voice input when you create a collection by speaking — this is converted to text; the audio itself is not kept.
    • Content you create in the app: tags, favorites, edits, and deletions.

    3.2 Information derived from your screenshots

    For a screenshot you allow us to process, we may store the image, cropped or resized versions of it, a technical fingerprint used to avoid processing duplicates, the screenshot's timestamp, and the information we read from it. What we read depends on the category — for example: for shopping, the product, price, retailer and link; for travel, trip dates and destinations; for a place, its name, address and location; for a conversation, the text of the exchange and which app it came from. We extract only what's needed to make that item useful and findable.

    3.3 Device and context information

    • Your approximate country or region, so we can localise results.
    • Approximate location for "near you" and proximity features. Foreground location is used only while you're using those features; background location is off unless you opt in, and we deliberately exclude the areas where you spend the most time (such as home and work) and cap how often it's used.
    • Technical signals used to keep the app running smoothly.
    • Limited diagnostic logs, tied to an account identifier — not to the content of your screenshots.
    • A push notification token, only if you enable notifications.

    3.4 What we deliberately don't take

    • Your non-screenshot photos — the camera roll is never opened or scanned.
    • Screenshots of omemo itself.
    • Any screenshot blocked by your on-device screening for a category you've switched off.

    4. Sensitive content and your controls

    Some screenshots are more sensitive than others. omemo gives you category-level controls for Health, Finance, and Wallet content in your profile settings. Health detection is off by default.

    When a category is switched off, omemo screens for that kind of content on your device and blocks matching screenshots before they're uploaded — the image never leaves your phone. If you switch a category off later, existing items in that category are immediately hidden from view; if you switch it back on, you can restore processing.

    Regardless of your settings, we redact or reject the most sensitive identifiers and never store them: full payment card numbers, security codes, bank or account numbers, government ID numbers, biometric identifiers, and health record numbers.

    Some things you choose to save (for example in reading or personal-reflection categories) could reveal information that data protection law treats as sensitive. We process that content only to provide the service you've asked for, and you can delete it at any time.

    5. Why we process your data, and our legal bases

    Under the GDPR, we rely on the following bases:

    • Performance of our contract with yourunning the core service on the screenshots you submit.
    • Your consentfor Health processing, background location, contacts and calendar connections, push notifications, voice input, and Finance/Wallet detection when you enable it. You can withdraw consent at any time in your settings.
    • Our legitimate interestspreventing duplicate processing, keeping the service secure and reliable, and preventing abuse.
    • Legal obligationswhere the law requires us to retain or disclose data.

    Where content falls into a special category under Article 9 (such as health), we process it only with your explicit consent, and you can switch Health off entirely.

    6. How the AI and LLM processing works

    We're upfront about this because it matters: to read and organise your screenshots, omemo uses AI — including large language models and vision models — and some of that processing happens on our servers and with specialist AI processing providers acting on our instructions.

    • We do not use your screenshots, cards, or derived data to train, fine-tune, or improve any public, third-party, or omemo-owned foundation model.
    • When a screenshot is sent to an AI model for analysis, it is not tied to your name, email, account ID, or any other personal identifier. The model processes the image and its text, not who it belongs to. For example, the model does not know that a given screenshot belongs to any specific person.
    • Any LLM or vision provider we use is contractually prohibited from retaining your content after returning a result and from using it to train or improve their own models.
    • In limited cases, a small amount of data — de-identified wherever possible — may be reviewed by a person to improve quality, safety, and abuse prevention.

    For a plain-language summary, see our Help Center.

    7. Who we share data with

    We do not sell your personal data. We share it only in the situations below, and only to the extent needed.

    Service providers acting on our instructions

    We use trusted providers to run omemo. To protect our users and our business, we describe them by function rather than by name:

    • Secure cloud hosting, storage, database, and authentication.
    • AI and vision processing (reading and organising your screenshots).
    • Reference and enrichment providers that add details such as titles, artwork, ratings, place information, prices, and links. Where possible these receive only a minimal query or detail — not your raw screenshot. Brand and company logos are provided by Logo.dev.
    • Search indexing, image delivery, email delivery, maps, and push notification delivery.
    • Sign-in providers — Apple and Google — when you choose to create your account or sign in with them (see Section 3.1).

    All of these providers are bound by contract to process data only on our instructions and to keep it confidential.

    Connections you choose to make

    If you connect an external service yourself (for example, calendar syncing), we share only the specific items needed for that feature, and only while it's connected. When you connect such a service, we store its access tokens in encrypted form and use them only to perform the sync you asked for; you can disconnect at any time in your settings or revoke access from your account with that provider, which deletes the stored tokens. omemo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

    If you connect Google Calendar, omemo uses the permission only to create calendar events that you explicitly choose to add from your screenshots. omemo does not use Google Calendar data for advertising, profiling, or AI training. OAuth access tokens are stored encrypted and can be revoked at any time.

    Legal and safety

    We may disclose data where required to comply with the law, respond to lawful requests from authorities, or protect the rights and safety of our users or omemo.

    Business transfers

    If omemo is involved in a merger, acquisition, or restructuring, data may transfer subject to appropriate safeguards.

    On request, we will provide the current list of the providers who process your data and identify the recipients of your data. Contact privacy@omemo.app.

    8. International data transfers

    Depending on your location, your data is hosted in the United States or the European Union. Some of our providers process data in the United States. Where data leaves your region, we rely on appropriate safeguards, including Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

    9. How long we keep your data

    • Your screenshots and the items built from them are kept until you delete the item, delete the screenshot, or delete your account.
    • Items that failed to process are kept rather than silently discarded, so nothing disappears without your knowledge.
    • Session and diagnostic logs are short-lived and removed on a rolling basis.

    When you delete your account, we permanently remove your content and the data derived from it across our systems and our providers within 30 days.

    10. Your rights

    You have the right to access, correct, delete, restrict, or object to the processing of your personal data; to data portability; and to withdraw consent at any time.

    You can exercise most of these directly in the app: your profile settings let you change your language and avatar, adjust category and notification controls, disconnect optional features, and delete your account. Your iOS Settings control app permissions for photos, location, contacts, reminders, and the microphone.

    For anything else, contact privacy@omemo.app.

    EU / EEA and UK (GDPR)

    In addition to the rights above, you may object to or restrict certain processing and lodge a complaint with your local data protection authority (in France, the CNIL).

    California (CCPA / CPRA)

    You have the right to know what personal information we collect and how we use it, to request its deletion, and not to be discriminated against for exercising your rights. We do not sell or share your personal information as those terms are defined under California law.

    11. Security

    We protect your data with encryption in transit, access controls, and server-side safeguards, and we enforce your sensitive-category choices both on your device and on our servers. Screenshots are stored so that they can only be retrieved through short-lived, authenticated links. No system can be guaranteed perfectly secure, but we work continuously to protect your information.

    12. Children

    omemo is not directed at children under 13 (or under 16 in parts of the EEA). We do not knowingly process children's data. If you believe a child has provided us data, contact us and we will remove it.

    13. Cookies and tracking technologies

    We use only essential cookies and similar technologies — to keep you signed in, remember your preferences (such as theme and sync settings), and protect against fraud. We do not use advertising cookies or third-party tracking cookies, and we do not track you across other apps or websites.

    14. Changes to this policy

    We may update this policy from time to time. For material changes, we'll notify you through an in-app banner or by email. The effective date at the top reflects the current version.

    15. Contact us

    omemo, Inc.

    2261 Market Street

    San Francisco, CA 94114

    United States

    Email: privacy@omemo.app

    Response time: within 3 business days.


    By using omemo, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.