Welcome

Trust & Security

Last updated: 26 July 2026

This page is maintained by EGNITE to answer common security and privacy questions about the OmniGEO Shield platform. It describes the controls that are currently enabled and how we handle your data.

Platform & hosting

  • The application is built on Lovable Cloud and runs on a managed backend infrastructure.
  • Database, authentication, and storage are provided by the Lovable Cloud backend service.
  • All public traffic is served over HTTPS with TLS encryption.
  • The platform receives regular automated security scans; findings are reviewed and remediated.

Access & authentication

  • Accounts are protected by email/password or social sign-in via the Lovable Auth broker.
  • Passwords are never stored in plain text; the backend handles hashing and secure credential storage.
  • Sessions are short-lived and refreshed automatically.
  • Admin roles are stored in a separate table and checked server-side; regular users cannot escalate privileges.

What we collect & store

  • Account data: email, name, company, and optional profile fields you provide.
  • Workspace data: brands, products, competitors, prompts, and scan results you create.
  • Usage data: scan timestamps, model selections, and recommendation history.
  • Billing metadata: plan, subscription status, and Paddle customer ID. We do not store card numbers.

AI provider data handling

This is the part most clients ask about. Here is exactly what happens when you run a scan:

  • We send only the prompt text, the brand name, and any public context you entered (products, competitors, market, region).
  • We do not send your email, company name, account ID, or any other personal information to the AI providers.
  • We route calls through the Lovable AI Gateway or direct enterprise API endpoints that do not use your data to train foundation models.
  • Each user's prompts, scan results, and brand data are stored in rows that only that user (or an admin) can read. Your competitors cannot see your data, and neither can other users on the platform.

Supported engines: ChatGPT (OpenAI), Claude (Anthropic), Perplexity, Gemini (Google), Copilot (OpenAI), Grok (xAI), and DeepSeek.

Encryption & isolation

  • All data is encrypted in transit using TLS.
  • Data is encrypted at rest by the backend provider.
  • Every user-facing table has Row-Level Security (RLS) enabled: queries are filtered by the authenticated user ID, so one user cannot read another user's rows.
  • Privileged operations (admin actions, webhooks) run under service-role credentials and are never exposed to the browser.

Retention & deletion

  • Account and scan data are retained while your account is active.
  • After you delete your account, personal profile and workspace data are removed within 30 days.
  • Scan logs are anonymised (user reference removed) so aggregate analytics remain accurate without identifying you.
  • Billing records are kept for the period required by tax law.

Your privacy controls

You can export a full copy of your data or delete your account at any time from Settings → Privacy. You can also email us at privacy@omnigeo.app.

Subprocessors & integrations

  • Lovable Cloud / backend — hosting, database, authentication, server functions.
  • Paddle — subscription billing and tax handling.
  • Resend / Lovable Email — transactional and newsletter emails.
  • AI providers — OpenAI, Anthropic, Google, Perplexity, xAI, DeepSearch — receive only prompt/brand context as described above.

Shared responsibility

Platform security (infrastructure, database hardening, auth, TLS) is managed by Lovable Cloud and the backend provider. EGNITE configures access controls, RLS policies, and secure coding practices on top of that platform. You remain responsible for keeping your password safe and for the content of the prompts and brand data you submit.

Security contact

Questions or concerns? Email privacy@omnigeo.app or contact us.

This page is provided for transparency and is not an independent security certification, audit report, or legal contract. See also: Privacy Policy and Terms of Service.