Legal
Privacy Policy
Last updated: 24 July 2026
1. Who we are
OMU SAS ("OMU", "we", "us") is the data controller for the personal data described in this policy.
- Registered office: 2 rue Jacquard, 93100 Montreuil, France
- SIREN: 103 147 971
- Contact: tim@ohmyunicorn.com
This policy covers the Oh My Unicorn platform at ohmyunicorn.com and its subdomains (the "Service"), including the app factory, Ad Studio, and the applications you create with it.
2. What we collect
2.1 Account data
When you create an account we collect and store:
| Data | Source | Why |
|---|---|---|
| Email address | Google sign-in, or email code sign-in | Identify your account, send service emails |
| Display name | Google sign-in (optional) | Show who you are in the interface |
| Profile picture URL | Google sign-in (optional) | Show your avatar |
If you sign in with Google, we receive your email address, name and profile picture. We do not receive or store your Google password. If you sign in with an email code, we store a one-way hash of the code, never the code itself.
2.2 Content you provide
- App briefs and prompts — the text you write describing what you want built. Stored so you can revisit and refine your projects.
- Files you upload — images, video, audio and other assets you add to a project, including reference photographs used in Ad Studio.
- Applications you generate — the source code and configuration produced on your behalf.
2.3 Usage and billing data
- Credit balance and transaction ledger (what you spent credits on, and when)
- Records of builds, deployments and generation jobs
- Server logs including IP address, browser user-agent, and timestamps, kept for security and troubleshooting
2.4 Payment data
Payments are processed by Stripe. We never receive or store your card number. We store only Stripe's references (a customer identifier, an event identifier) so we can reconcile your account.
3. Photographs of people
If you upload photographs containing faces — for example a reference image in Ad Studio — those images are sent to third-party AI providers to condition the generation and are stored on our servers so you can reuse them.
We do not use your images to train any AI model, and we do not build biometric templates or perform facial recognition. The images are used solely as an input to produce the output you requested.
If your images show a person, you are responsible for having that person's permission. Do not upload photographs of anyone who has not agreed to it. Under GDPR, images processed for the purpose of uniquely identifying a person are special-category data; we do not process them for that purpose, and you must not use the Service in a way that requires us to.
4. Why we process your data, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the Service you asked for | Performance of a contract (Art. 6(1)(b)) |
| Billing, credits, fraud prevention | Contract, and legitimate interests (Art. 6(1)(f)) |
| Security, abuse prevention, service logs | Legitimate interests (Art. 6(1)(f)) |
| Service emails (sign-in codes, invitations) | Contract (Art. 6(1)(b)) |
| Meeting legal and accounting obligations | Legal obligation (Art. 6(1)(c)) |
We do not sell your personal data. We do not use your personal data for advertising.
5. Who we share it with
We use the following sub-processors. Each receives only what it needs to perform its function.
| Sub-processor | Purpose | Data reaching them | Location |
|---|---|---|---|
| Hetzner Online GmbH | Hosting and storage | All platform data at rest | Germany (EU) |
| Anthropic | AI code and text generation | Your briefs and prompts | United States |
| Google Cloud / Vertex AI | AI image and text generation | Prompts, uploaded images | United States (us-central1) |
| Sign-in (OAuth) | Email, name, avatar | United States | |
| fal.ai | AI image and video generation | Prompts, uploaded images | United States |
| OpenRouter | AI text generation routing | Prompts | United States |
| Stripe | Payment processing | Payment and billing details | EU / United States |
| Resend | Transactional email delivery | Email address, message content | United States |
| OVH | Domain names and DNS | Domain configuration | France (EU) |
| Cloudflare | Anti-bot verification (Turnstile) | IP address, browser signals | United States |
If you connect an optional integration (for example GitHub or Jira), data is also shared with that provider at your instruction.
6. International transfers
Our servers are in Germany. However, the AI providers that generate your content are established in the United States, so your prompts, uploaded files and account identifiers are transferred outside the European Economic Area.
These transfers are made under the European Commission's Standard Contractual Clauses, and, where applicable, on the basis of the EU–US Data Privacy Framework. You can request further information at tim@ohmyunicorn.com.
7. How long we keep it
| Data | Retention |
|---|---|
| Account data | For as long as your account exists |
| Briefs, projects, generated apps, uploads | For as long as your account exists, unless you delete them |
| Sign-in codes | 15 minutes, then invalidated |
| Sessions | 7 days |
| Billing records | 10 years (French accounting obligation, Art. L123-22 Code de commerce) |
| Server logs | 12 months |
When you close your account we delete your personal data within 30 days, except records we are legally required to retain.
8. Your rights
Under GDPR you have the right to: access your data; correct it; erase it; restrict or object to processing; receive it in a portable format; and withdraw consent where processing relies on consent.
To exercise any of these, email tim@ohmyunicorn.com. We will respond within one month.
You may also lodge a complaint with the French data protection authority:
CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr
9. Cookies
We use only what is necessary to run the Service. We do not use advertising or analytics cookies on this site, so no consent banner is shown.
| Cookie | Purpose | Lifetime |
|---|---|---|
forge_session | Keeps you signed in to the platform | 7 days |
forge_app_session | Keeps you signed in to applications you build | 7 days |
forge_locale | Remembers your language preference | 1 year |
Authentication cookies are HttpOnly, Secure and SameSite=Lax.
Applications you build and publish may set their own cookies. You are the controller for the applications you publish, and you are responsible for their compliance, including any analytics or advertising tracking you choose to enable.
10. Security
We protect your data with encryption in transit (TLS), encrypted storage of third-party access tokens, isolated per-tenant databases, and access controls limiting who can reach production systems. No system is perfectly secure; we cannot guarantee absolute security.
11. Children
The Service is not intended for anyone under 15. We do not knowingly collect data from children under 15. If you believe a child has given us personal data, contact us and we will delete it.
12. Changes
We may update this policy. If we make a material change we will notify you by email or in the Service before it takes effect. The "last updated" date above always reflects the current version.
13. Contact
Questions about this policy, or about your data:
OMU SAS — 2 rue Jacquard, 93100 Montreuil, France — tim@ohmyunicorn.com