PRIVACY POLICY

Last updated: 13 September 2026

What we collect, why we hold it, how long we keep it, and how to get it back or have it erased.

This Privacy Policy describes how Omega Studios™. ("OmegaStudios," "we," "our," or "us") collects, uses, stores, discloses, and processes your personal information when you access or interact with our platform, developer dashboard, licensing APIs, or any associated services (collectively, the "Platform").


By accessing or continuing to use OmegaStudios, you acknowledge that you have read and understood this Privacy Policy, agree to its terms, and consent to the data practices described herein, in conjunction with our Terms of Service and all applicable data protection laws. If you do not agree with any part of this Policy, you must immediately discontinue your use of the Platform.

Who is responsible for what

There are two different relationships at play on this platform, and that distinction matters when someone asks about their data.

For your own account: things like your name, email, login history, and billing - that's on us. We're the ones responsible for it.

For the people using software you built: your customers, your licence holders, their devices, that's on you. We handle that data, but only because you tell us to. So if one of your users ever wants to know what you have on them, they come to you, not us, and you handle it through the platform.

What we collect when you sign up

  • Email address and display name. Your email is verified before access to the dashboard is granted.
  • Password, stored exclusively as an argon2id hash. We have no way to read or recover it.
  • Two-factor authentication secret and backup recovery codes, encrypted at rest, if you choose to enable 2FA.
  • IP addresses tied to sign-in events and audit log entries, used for abuse detection and security review.
  • A record of which version of our Terms of Service and Privacy Policy you agreed to, including the timestamp.
  • Billing information: your active plan, billing cycle, transaction amounts, and payment provider references.

What we process on behalf of your end users

This is data generated by the people running software you distribute through our platform. We store it solely to keep licensing functional nothing else.

  • Usernames and password hashes for accounts created within your applications.
  • Hardware identifiers we never store the raw machine ID. The client device hashes it first, and we apply a second hash with a secret key before it touches our database.
  • Device metadata: operating system, application version, IP address, and approximate country.
  • Licence keys, stored as keyed digests never in plaintext.
  • Activation and validation events, surfaced in your security feed and usage analytics.

Our legal basis for holding this data

PurposeBasis
Delivering the service you subscribed toPerformance of a contract
Verifying your email address on registrationPerformance of a contract
Abuse prevention, rate limiting, and blockingLegitimate interests
Security logging and incident investigationLegitimate interests
Invoice generation and accounting complianceLegal obligation
Fraud detection and payment verificationLegitimate interests

We do not use your data for advertising or marketing purposes, we do not build behavioural profiles, and there is no automated decision making with any legal or significant effect applied to your account.

How long we retain your data

Retention is enforced automatically, not manually. A scheduled job runs every hour and purges anything that has passed its retention window.

DataKept for
Audit log entries180 days
Licence activation and validation events365 days
Webhook delivery records30 days
Support messages, once resolved730 days
Accounts with unverified email addresses7 days, then permanently deleted
Full device IP addresses30 days, then truncated
Invoices and payment recordsAs long as applicable accounting law requires

Your rights

You have the right to access, portability, rectification, erasure, restriction, and objection. If you are based in California, you also hold the right to know and the right to delete. Two of these are available as self-service actions in the dashboard under Settings - Privacy & Data:

  • Export — generates a complete JSON copy of all data held against your account, on demand. Credentials are excluded: password hashes, 2FA secrets, application secrets, and licence keys are never included in exports.
  • Erasure — permanently closes your account and destroys all associated personal data.

For any other request, contact us directly and we will respond within one month, or within 45 days for requests originating from California.

What erasure actually removes

Your name, email address, password, recovery key, and two-factor secret are permanently destroyed. Audit log entries retain the event record but lose all identifying information, who performed it and from where. Device and contact IP addresses are cleared. The account cannot be accessed or recovered after this point.

Two categories of data deliberately survive erasure, and we want to be direct about why:

  • Invoice and payment records, with your name removed. Accounting law requires us to retain them, and GDPR Article 17(3)(b) explicitly permits this.
  • Licences purchased by your end users, so their software continues to function. That data belongs to them, not you, and we are not in a position to delete it on your behalf.

Who we share your data with

We do not sell personal information, and we do not share it for cross-context behavioural advertising. Under CCPA that means there is nothing to opt out of we say it directly rather than expecting you to infer it.

Changes to this policy

When this policy is updated, the version recorded against your account is updated accordingly. Material changes are communicated before they take effect. The date displayed at the top of this page is the authoritative version indicator.

Questions about your data?

Data-subject requests, questions about this policy, or anything you would rather ask a person.

EMAIL US

© 2026 Frost Auth. Built for developers. All rights reserved.