OmniScrypt Studio · Legal

Privacy Policy

What this website collects, what it does not, and how to exercise your rights.

Effective Date: September 7, 2026 Last Updated: September 7, 2026 Version: 1.0

Two things to know before you read further

WE DO NOT SELL YOUR PERSONAL INFORMATION, AND WE NEVER HAVE. WE DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING, AND WE DO NOT USE IT TO TRAIN ARTIFICIAL-INTELLIGENCE MODELS. THERE ARE NO ADVERTISING OR ANALYTICS TRACKERS ON THIS WEBSITE.

THIS POLICY COVERS THIS WEBSITE ONLY. Our applications — Akashic Compass, BloodlineAI, PillTally, and any application we release in the future — each have their own Privacy Policy, because each handles different information in different ways. This policy does not describe, govern, or apply to any of them. See Section 2.

1Who We Are

This Privacy Policy explains how OmniScrypt Studio, a software development business operating under an assumed business name registered in the State of Idaho (“OmniScrypt Studio,” “we,” “us,” or “our”), collects, uses, discloses, and protects information in connection with the website at omniscryptstudio.com (the “Website”).

OmniScrypt Studio is the “controller” (or, under California law, the “business”) responsible for the personal information described here. This policy is incorporated into our Terms of Use. Our contact details are in Section 19.

2Scope: This Website Only

The main point of this page

This policy applies only to information collected through this website. It does not apply to any information collected by an OmniScrypt Studio application, or by any third party. If you want to know how an application handles your information, read that application's policy — not this one.

Each of our applications collects different information for different purposes and is covered by its own Privacy Policy, which you accept inside that application and which is available in the application and on that application's own website:

  • BloodlineAI — genealogy and DNA research. Governed by the BloodlineAI Privacy Policy and, for residents of Washington, Nevada, and Connecticut, the BloodlineAI Consumer Health Data Privacy Policy.
  • Akashic Compass — guidance, reflection, and personal tracking. Governed by the Akashic Compass Privacy Policy.
  • PillTally — medication tracking, in development. Will be governed by its own Privacy Policy on release.

This policy also does not apply to information you provide to the Apple App Store, Google Play, or any other third-party service, or to any website we link to. If you want to know how an application handles your information, read that application's policy — not this one.

3Information We Collect

The Website is a brochure site. There are no accounts, no logins, no purchases, and no user-generated content. We collect only the following.

3.1 Information you give us through the contact form

If you choose to send us a message, we collect what you type into the form:

  • your name (either a full name, or a first and last name, depending on your screen size);
  • your email address;
  • a website or URL, if you choose to enter one (this field is optional); and
  • the contents of your message.

Your submission is delivered to us by email. We do not maintain a separate database of contact-form submissions; the message lives in our email inbox and in the logs our web host keeps for outgoing mail.

Please do not send sensitive information through the contact form. The form is not designed or secured for health, genetic, biometric, financial-account, precise-location, government-identifier, or other sensitive information, and email is not a confidential medium. If your message concerns an account, a subscription, or a privacy-rights request for one of our applications, please use that application's own support or privacy address instead.

3.2 Information you give us by emailing us directly

If you write to support@omniscryptstudio.com or legal@omniscryptstudio.com, we receive your email address, any name or signature block you include, and whatever you choose to tell us, together with the ordinary technical headers your mail provider attaches.

3.3 Information collected automatically by our web host

Like essentially every website, ours runs on a server that keeps standard access logs. These logs are created by our hosting provider, not by any tracking code we added, and typically record:

  • your Internet Protocol (IP) address;
  • the date and time of your request;
  • the page or file requested and the response status;
  • your browser type, version, and operating system (from the user-agent string);
  • the referring page, if any; and
  • the approximate region an IP address is associated with.

We use these logs to keep the Website running, to diagnose errors, and to detect and stop abuse such as spam submissions, scraping, and attacks. We do not use them to build a profile of you, and we do not link them to your identity.

4What We Do Not Collect or Do

We think it is as useful to tell you what is absent as what is present. On this Website:

  • there are no advertising networks, ad pixels, conversion trackers, or retargeting tags;
  • there is no third-party analytics — no Google Analytics, no Meta Pixel, no heatmap or session-recording tools;
  • there are no social-media embeds, share widgets, or login buttons;
  • there are no accounts, passwords, or user profiles;
  • we do not process payments and never see a payment card number;
  • we do not operate a newsletter or mailing list, and we will not add you to one because you used the contact form;
  • we do not buy personal information from data brokers or append data from outside sources;
  • we do not use your information to train, fine-tune, or evaluate any artificial-intelligence model, and we do not feed contact-form messages into any AI system; and
  • we do not make automated decisions that produce legal or similarly significant effects about you, and we do not engage in profiling.

5Cookies and Similar Technologies

This Website does not set any cookies of its own. We do not use advertising, analytics, personalization, or preference cookies, and there is nothing to consent to or opt out of. Your browser may cache page files and fonts as part of its normal operation; that cache lives on your device and is not readable by us.

If this ever changes — for example, if we add privacy-respecting analytics or a preference cookie — we will update this Section, revise the “Last Updated” date, and, where consent is required, ask for it before setting the cookie.

6Third-Party Content Loaded by This Website

We want to be precise about this, because it is the one place where a third party sees a request from your browser.

Third partyWhat it doesWhat it necessarily receives
Google Fonts
(fonts.googleapis.com, fonts.gstatic.com)
Delivers the typefaces used on this Website (Space Grotesk and Inter). Your IP address, your browser and operating system, and the fact that your browser requested a font file from a page on our Website. Google states that Google Fonts does not set cookies and does not use these requests for advertising.
Our web hosting provider Serves the Website's files and delivers contact-form messages to our inbox. The server-log information in Section 3.3, and the contents of any contact-form submission as it passes through the mail system.
Our email provider Receives and stores messages sent to our support and legal addresses. Your email address, your message, and standard mail headers.

These providers act as our service providers or processors. They are permitted to use the information only to provide their service to us, and are not permitted to sell it or use it for their own marketing. Each has its own privacy policy, which governs its own practices.

7How We Use Information

We use the information described in Section 3 for these purposes and no others. Where the laws of the European Economic Area or United Kingdom apply, the corresponding legal basis is noted in brackets.

  • To read and answer your message. To understand what you asked, reply to you, and follow up if needed. [Legitimate interests; steps taken at your request prior to entering a contract.]
  • To route your message correctly. To forward an application-specific question to the right support address. [Legitimate interests.]
  • To operate, maintain, and secure the Website. To serve pages, diagnose errors, prevent and investigate spam, scraping, fraud, and attacks, and keep the site available. [Legitimate interests; legal obligation.]
  • To comply with law and protect rights. To respond to valid legal process, enforce our Terms of Use, and protect the rights, property, and safety of OmniScrypt Studio, our users, and the public. [Legal obligation; legitimate interests.]

We do not use your information for marketing, advertising, profiling, or product research, and we do not use it for any purpose that is materially different from, unrelated to, or incompatible with the purposes described here without telling you first.

8How We Share Information

We share personal information only in the limited circumstances below.

  • Service providers. Our hosting and email providers, described in Section 6, process information on our behalf and under our instructions.
  • Legal requirements. We may disclose information if we believe in good faith that disclosure is required by law or legal process, or is reasonably necessary to protect the rights, property, or safety of OmniScrypt Studio, our users, or the public. Where we are legally permitted to do so, we will notify you before responding to a request for your information, unless doing so would be unlawful, would endanger someone, or would be futile.
  • Professional advisers. Our attorneys, accountants, and insurers, when reasonably necessary and under a duty of confidentiality.
  • Business transfer. If OmniScrypt Studio is involved in a merger, acquisition, financing, reorganization, or sale of all or substantially all of its assets, information may be transferred as part of that transaction. We will require the recipient to honor this policy, or give you notice and a choice before your information becomes subject to a materially different policy.
  • With your direction. When you ask us to share information, or direct us to do so.

We do not disclose personal information to advertisers, data brokers, marketing partners, or artificial-intelligence developers, and we do not permit any service provider to use it for those purposes.

9We Do Not Sell or Share Your Information

OmniScrypt Studio does not sell personal information, and does not share personal information for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act and comparable state laws. We have not done so in the twelve months preceding the Effective Date of this policy. We also do not sell or share the personal information of any consumer we know to be under 16 years of age. Because we do not sell or share, there is no opt-out to offer — but if that ever changes, we will update this policy and provide a clear opt-out mechanism before any such activity begins.

10How Long We Keep Information

InformationHow long we keep it
Contact-form submissions and email correspondenceUp to 24 months after our last exchange with you, then deleted, unless a longer period is needed to resolve a dispute, enforce our agreements, or comply with law.
Correspondence documenting a legal notice, dispute, or privacy-rights requestAs long as needed for that matter, plus the applicable limitations period. Records of rights requests are kept because several state laws require us to keep them.
Web-server access logsThe retention period set by our hosting provider, typically 30 to 90 days, after which they are overwritten or deleted.
Security incident recordsAs long as reasonably necessary to investigate, remediate, and document the incident.

11How We Protect Information

We use reasonable administrative, technical, and physical safeguards appropriate to the very limited amount of information this Website handles. These include serving the Website over encrypted HTTPS connections, keeping the number of people with access to our inboxes to a minimum, protecting our accounts with strong credentials and multi-factor authentication, validating and filtering contact-form input to block injection and spam, and collecting no more than we need in the first place — which is the most effective safeguard of all.

No method of transmission or storage is completely secure, and email in particular is not a confidential channel. We cannot guarantee absolute security, and you send information to us at your own risk. If we become aware of a security breach affecting your personal information, we will notify you and any regulator as required by applicable law.

12Your Privacy Rights and How to Use Them

Depending on where you live, you may have some or all of the following rights regarding personal information we hold about you. We extend these rights to every visitor, regardless of state of residence, to the extent they apply to the small amount of information described in this policy.

  • Know and access. Confirm whether we hold personal information about you and obtain a copy, along with the categories collected, the sources, the purposes, and the categories of recipients.
  • Correct. Ask us to correct inaccurate personal information.
  • Delete. Ask us to delete personal information we hold about you.
  • Portability. Receive a copy in a portable, readily usable format, where technically feasible.
  • Opt out of sale, sharing, targeted advertising, and profiling. We do not do any of these, as explained in Section 9, so there is nothing to opt out of.
  • Limit use of sensitive personal information. We do not collect sensitive personal information through the Website.
  • Non-discrimination and non-retaliation. We will never deny you service, charge you a different price, or provide a different level of quality because you exercised a privacy right.
  • Withdraw consent. Where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.

How to make a request

Email support@omniscryptstudio.com with the subject line “Privacy Request” and tell us what you would like us to do. Please write from the email address you used to contact us, or give us enough detail to locate your information.

Verification. Before we act on a request to access, correct, delete, or port information, we must reasonably verify that the request comes from you. Because the only identifier we usually hold is an email address, we ordinarily verify by confirming that you can receive and reply from that address. We may ask a limited follow-up question if the request is unclear. We use information provided for verification only for that purpose.

Authorized agents. You may use an authorized agent to make a request. We may ask the agent for written, signed permission from you, and may ask you to verify your identity with us directly.

Timing. We will acknowledge your request promptly and respond within 45 days, and we may extend that period by an additional 45 days where permitted, in which case we will tell you why before the first period ends. There is no charge unless a request is manifestly unfounded, excessive, or repetitive, in which case we will tell you the reason and any fee before proceeding.

Appeals. If we decline your request in whole or in part, we will explain why. You may appeal by replying to our decision or by emailing legal@omniscryptstudio.com with the subject line “Privacy Appeal.” We will review the appeal and respond in writing within 45 days (or 60 days where a state's law allows), explaining our reasoning. If we deny the appeal, we will tell you how to file a complaint with your state Attorney General or other supervisory authority.

Limits. Some rights are subject to exceptions. For example, we may need to keep information to comply with a legal obligation, to establish or defend a legal claim, or to complete a transaction you requested. We will tell you if an exception applies to your request.

13Notice at Collection and California Disclosures

This Section supplements the rest of the policy for California residents and serves as our notice at collection under the California Consumer Privacy Act, as amended (“CCPA”).

CCPA category Do we collect it here? Purpose Disclosed to
A. Identifiers (name, email address, IP address)Yes — contact form, email, server logsRespond to your message; operate and secure the WebsiteHosting and email providers; legal advisers; as required by law
B. Customer records information (Cal. Civ. Code § 1798.80)Yes — only your name and email addressRespond to your messageHosting and email providers
C. Protected classification characteristicsNo
D. Commercial informationNo
E. Biometric informationNo
F. Internet or network activity (pages requested, referrer, user-agent)Yes — server logs only; no tracking across sitesOperate, debug, and secure the WebsiteHosting provider
G. Geolocation dataCoarse only — approximate region inferred from IP address. We do not collect precise geolocation.Security and abuse preventionHosting provider
H. Sensory data (audio, video, images)No
I. Professional or employment informationOnly if you volunteer it in a messageRespond to your messageEmail provider
J. Education informationNo
K. Inferences drawn to create a profileNo — we draw no inferences and build no profiles
L. Sensitive personal informationNo — and please do not send any

Sources. Directly from you, and automatically from your browser and our hosting provider.

Sale, sharing, and sensitive information. We have not sold personal information, have not shared it for cross-context behavioral advertising, and have not collected sensitive personal information through the Website in the preceding twelve months. We do not use or disclose sensitive personal information for purposes that would require us to offer a right to limit.

Retention. See Section 10.

“Shine the Light.” California Civil Code § 1798.83 permits residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We make no such disclosures.

Exercising your rights. Use the method in Section 12. Because the Website has no account system, that email method is the only one we offer, and it is the one designated for California requests.

14Other State Disclosures

A growing number of states — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, and Rhode Island — have comprehensive consumer privacy laws. Most of them apply only to businesses that process personal information about a large number of consumers or that derive revenue from selling it, and a brochure website with a contact form ordinarily falls well below those thresholds. We nevertheless extend the substantive rights in Section 12 to residents of every state, along with the appeal process described there.

Consumer health data (Washington, Nevada, Connecticut). We do not collect consumer health data through this Website, and we ask that you not send health information through the contact form. BloodlineAI, which does handle health-adjacent information, maintains a separate Consumer Health Data Privacy Policy available in that application and on its website.

Nevada. Nevada residents may direct a covered business not to sell certain covered information. We do not sell covered information, but you may submit a verified request to support@omniscryptstudio.com.

Genetic privacy. Several states regulate direct-to-consumer genetic data specifically. This Website collects no genetic data of any kind. Genetic data handled by BloodlineAI is addressed exclusively in the BloodlineAI Privacy Policy.

15Children's Privacy

The Website is intended for a general adult audience. It is not directed to children, and we do not knowingly collect personal information from anyone under 13 years of age, or from anyone under 16 for the purposes of sale or sharing (which we do not engage in). If you believe a child has provided us personal information through the contact form, please email support@omniscryptstudio.com and we will delete it promptly.

16Visitors Outside the United States

We operate from the United States, and our hosting and email providers store information in the United States. If you visit the Website or contact us from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your country. Where required, we rely on appropriate transfer mechanisms, including the European Commission's Standard Contractual Clauses. Residents of the European Economic Area and the United Kingdom may also have the right to lodge a complaint with their local supervisory authority.

17Do Not Track and Global Privacy Control

Some browsers transmit a “Do Not Track” signal or an opt-out preference signal such as Global Privacy Control. Because this Website does not track visitors across sites and does not sell or share personal information, there is nothing for such a signal to turn off, and its presence or absence does not change how we handle your information. We honor these signals in the sense that our practices already comply with what they ask for.

18Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date and version number at the top of this page. If we make a material change — for example, if we begin using analytics, add a mailing list, or change how we use information we already hold — we will post a prominent notice on the Website before the change takes effect, and, where the law requires it, obtain your consent. We encourage you to review this page periodically.

19How to Contact Us

OmniScrypt Studio

Privacy questions and rights requests: support@omniscryptstudio.com (subject line: “Privacy Request”)
Privacy appeals and legal notices: legal@omniscryptstudio.com
Mail: OmniScrypt Studio, 9169 W State St #4414, Garden City, ID 83714, United States

For a privacy request concerning a specific application and the data it holds, please use that application's own privacy address. We cannot access application data from this Website, and routing your request correctly is the fastest way to have it honored within the deadline the law sets.