Privacy policy

OmniLab keeps only what learning needs: your account, your work, and your progress. This page says what we collect on the web and in the mobile app, where it lives, and how to delete it.

Last updated: 18 July 2026.

What this covers

This policy covers the OmniLab web app at omni-lab.app and the OmniLab mobile app for iOS and Android. OmniLab is used by schools: students join through a teacher's invitation, and accounts are managed by the school.

What we collect

  • Account data: email address, name, and the school (organisation) you belong to.
  • Learning activity: which skills you practise, review answers and their schedule, challenge attempts, XP, and your conversations with the coach.
  • Content you create in tasks, plus an optional profile photo.
  • Product analytics and error reports — only after you agree to analytics, pseudonymous, and stored with PostHog in the EU.
  • Audio and video during a call you booked with your teacher (via Daily.co). Calls are live only; we do not record them.

The mobile app

The mobile app works with the same account and the same data as the web app. It additionally uses:

  • A push notification token for your device, so we can remind you about due reviews and appointments. It is registered when you allow notifications and deleted when you log out or turn them off.
  • Basic device information (model, operating-system version, app version) attached to error reports and used to check whether your app version is still supported.
  • A copy of your review deck stored on the device so you can practise offline. It syncs back when you reconnect and is removed when you log out.
  • If you sign in with Google or Apple, we receive your name and email address (or Apple's private relay address) from that provider — nothing else from your account there.
  • If you set a profile photo, the picture you choose is downscaled on the device and uploaded. The app never reads your photo library beyond that one picture.

Where the data lives

OmniLab runs on a small number of processors, each for one job:

  • Supabase — the database and sign-in service that stores your account and learning data.
  • Expo push service — delivers notifications to your device; it sees your push token, not your learning data.
  • PostHog (EU) — analytics and error events, only after consent.
  • Daily.co — carries the audio and video of booked calls while they happen.

We do not sell data, we show no advertising, and we do not track you across other apps or websites.

Deletion and export

You can delete your account yourself — in the mobile app under Profile → Security & privacy, or on the web in your profile's account settings. Deletion is permanent and removes everything this page describes, including push tokens.

You can also export your data — "Download my data" on the same mobile screen, or the data-export card in your web profile.

Students and age

OmniLab is intended for learners aged 13 and over, in school-managed classes. Accounts exist only by invitation from a teacher; there is no open registration for children.

What the AI sees

How the coach, the observer, and the learning profile use your data has its own page: the transparency statement.

Questions

If anything here is unclear, or you want your data deleted, talk to your teacher — they know who to point you to.