Skip to content
omi

Security and data.

What Omi accesses, what it collects, where it is stored, how long it is kept, and who processes it.

Last updated: September 16, 2026

On this page

Shopify permissions

When you install Omi, Shopify shows the permissions it asks for. This is what each one is used for. Omi does not modify your products, prices, orders, or store settings.

Products, inventory, and collections
Read. To show and recommend your products, check what is available, and keep the catalog current as it changes.
Orders
Read. To attribute Omi-assisted sales, and to answer a shopper’s order-status question when they provide the order number and the email on the order. Omi does not edit orders.
Theme
Read. To check that the Omi app embed is enabled in your live theme.
App proxy
To serve the associate on your storefront under your own domain.
Not requested
Omi does not request access to customer records, store pages or blog posts, discounts, checkout, payments, or staff accounts.

What Omi collects from shoppers

Omi collects what it needs to run the associate and to show your team how it is doing. Shoppers browse as guests by default; nothing ties a guest session to a person unless the shopper signs in to your store or gives an email to look up an order.

Conversations
The shopper’s messages, Omi’s replies, the products it showed, and which cards were opened or added to cart.
Context on your store
The page type and the product or collection on it, cart contents, and the products a shopper viewed or saved. Only on your store, and only while the associate is present on the page.
Preferences
Sizes, budgets, and style preferences a shopper shares in conversation, kept in their profile for your store so later conversations start from there.
Identifiers
A random ID stored in the shopper’s browser. For shoppers signed in to your store, the Shopify customer ID that Shopify passes along. An email address only when the shopper provides it to look up an order or to be contacted by support. Omi does not collect names, addresses, or payment details unless a shopper types them into a support request.
Photos
Only if you enable photo search and a shopper chooses to upload one. Photos are deleted after 90 days.
Usage analytics
How the associate is used: opened, messaged, product shown, added to cart. No session replay, no autocapture, and no analytics cookies. The associate shows shoppers a privacy notice with a link to the privacy policy the first time they open it.

Where data lives

Omi runs on Amazon Web Services in the United States. Data is encrypted in transit and at rest. Each store’s catalog index, conversations, and shopper profiles are kept separately from every other store’s, and one store’s data is never used to answer shoppers on another.

Your Shopify access token is stored server-side and never reaches the storefront. Access to production systems is limited to the Omi engineers who operate and support the service.

How long data is kept

Catalog copy and search index
Kept while Omi is installed. Deleted when you uninstall.
Shopper profiles, saved items, browsing history
Deleted 90 days after the shopper’s last activity on your store.
Conversation transcripts
Kept for the life of your subscription so your team can review them in the Dashboard. Deleted when you leave, or earlier on request.
Uploaded photos and raw conversation logs
Deleted after 90 days.
Server logs
Technical logs are kept for two weeks and hold no more than the conversation itself.
Account and billing records
Kept for the business relationship and the period tax and accounting rules require. Card details live with Stripe and never reach Omi.

Deletion and privacy requests

When you uninstall Omi, your store’s data is deleted: the catalog index, store records, shopper profiles, saved items, browsing history, and conversations. Shopify sends a final redaction request 48 hours after an uninstall, and anything that remains is removed then. You can also request deletion of your store’s data at any time while Omi is installed.

A shopper can ask your store to see or delete what Omi holds about them. Requests reach us from you or through Shopify’s privacy webhooks, and we compile or delete the data linked to that shopper. Guest sessions use random IDs that cannot be tied to a Shopify customer, so for a shopper who never signed in there is nothing to link. A shopper can also ask the associate directly to forget their preferences.

Model training

Omi does not train or fine-tune AI models on your catalog, your store information, your Skills, or your shoppers’ conversations. Skills and store information are instructions the associate reads at conversation time, which is why a change applies immediately and can be undone just as fast.

The language model that writes the answers is provided by Google under commercial API terms that do not allow Google to use prompts or responses to improve its models. Google keeps request logs only briefly, for abuse detection. The same applies to the AWS service that turns catalog text into search representations.

Service providers

These providers process data on Omi’s behalf, strictly to run and support the service. Personal information is never sold.

Amazon Web Services
Hosting, databases, file storage, the numerical representations used to search your catalog, and transactional email. United States.
Google Gemini
The language model that writes the associate’s answers. For each turn it receives the conversation, the relevant catalog items, and your store information, under commercial API terms that do not allow Google to use the content to improve its models.
Pinecone
The search index for your catalog, kept in a namespace that belongs to your store alone.
Shopify
The platform Omi installs on: catalog, orders, theme, and the app proxy that serves the associate on your storefront.
PostHog
Usage analytics for the associate: named events, no session replay.
Stripe
Merchant subscriptions and payments.
Netlify
Hosts this website and relays storefront requests between Shopify and Omi.
Gorgias
Only when you connect it, to create tickets from support requests.
UPS, FedEx, DHL
Only when a shopper asks about a shipment, to look up the tracking number on the order.

Details and contact

Read our privacy policy and terms of service, see how Omi works, or contact accounts@youromi.com. Security questionnaires and data processing agreements go to the same address.