Legal · what we collect (very little)
Privacy Policy
Last updated 26 July 2026 · Innisfallen Pty Ltd · ABN 12 699 798 288 · Privacy Act 1988 (Cth) & Australian Privacy Principles
This policy is short because there is very little to describe: Omitly is built so that your documents never reach us.
1. Your documents
The desktop app processes documents entirely on your device. The app never transmits any document, document content, filename or document metadata to us. There is no account, no cloud processing and no telemetry about your documents. The free web tools (leak checker, verifier) run in your browser via WebAssembly; files you check are not uploaded.
We cannot access, recover, disclose or be compelled to produce documents you process with Omitly, because the product never sends them to us. The only document content we ever hold is content you choose to send us yourself — for example, attaching a file to a support email — and we use that only to answer you.
2. What we do collect
| Data | Source | Why | Held by |
|---|---|---|---|
| Purchase details (name, email, payment method, billing country) | Stripe checkout | Processing your purchase; tax | Stripe (merchant of record on standard purchases) — see Stripe's privacy policy. We receive name, email and licence tier, not card details. |
| Licence details (licensed-to name, tier, dates) | Fulfilment | Minting your licence file | Us |
| Support correspondence | You emailing us, or the in-app support form | Answering you | Us (email) |
| Website ad-conversion measurement | Visiting marketing pages | Measuring whether ads work | Google (tag configured with consent mode; analytics cookie storage denied). The free-tool pages — leak checker and verifier — load no third-party scripts at all. |
| Optional signing timestamp (opt-in) | Digitally signing with a timestamp | RFC 3161 timestamp on your signature | The timestamp authority you configure (not us) — it receives a hash only, never document content. Off by default. |
We don't sell or share personal information for advertising profiles, we don't train anything on your data, and we don't enrich or profile.
3. The app doesn't phone home
Licence validation is offline and there is no telemetry. The desktop app makes exactly three kinds of outbound request, none of which carries document data (matching the verified enumeration on how Omitly redacts): it fetches a signed release manifest to check for updates; if you use the in-app support form, it sends the message you typed plus the app version and OS string; and if you opt in to a timestamp while digitally signing, it sends a hash — never the document — to the timestamp authority you configure.
4. Storage, access, correction and complaints
Licence and support records are retained while your licence is active and as required by Australian tax law. You can ask us to access, correct or delete your personal information at [email protected]. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles — as a matter of policy whether or not the small-business exemption would apply to us — and notify eligible data breaches under the Notifiable Data Breaches scheme, noting the breach surface is limited to the purchase/licence records above, never the documents you process.
If you think we have mishandled your personal information, complain to [email protected]; we will acknowledge your complaint promptly and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
5. Overseas disclosure
Stripe processes payments and may store purchase data outside Australia, including in the United States. Where we disclose personal information overseas we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
If you are in the EEA or the United Kingdom, you can exercise your local data rights (access, correction, erasure, objection) by emailing [email protected].
Contact: [email protected]