Last updated: 20 August 2026
Omnimatch ("we", "us", "our") provides AI assistant agents that you can reach from the web app at https://omnimatch.ai, from connected messaging apps (Google Chat, Telegram, Microsoft Teams, and Discord), and, where you enable it, through a meeting notetaker that can join your video calls. This policy explains what personal data we collect across the whole service, how and why we use it, who we share it with, and the rights you have. It applies to everyone who uses the service, whether as an individual or on behalf of an organisation.
We do not use your data for advertising, and we do not sell your personal data.
Where UK or EU data protection law applies, we rely on: contract performance (to provide the service you have signed up for); legitimate interests (to secure the service, prevent abuse, and improve our products, balanced against your rights); consent (for example where you enable the meeting notetaker or opt in to marketing, which you can withdraw at any time); and legal obligation (for example tax and accounting records).
Your messages, attachments, and (for the notetaker) meeting transcripts are processed by large language models to generate replies, summaries, and other outputs. By default, inference runs on Cloudflare Workers AI, accessed through Cloudflare AI Gateway, using the GLM 5.3 model developed by Z.ai (with smaller models used for lightweight background chores such as naming a conversation, describing an image, or extracting a summary). Cloudflare licenses those models and runs them on its own infrastructure, so the content goes to Cloudflare and the data centre providers it uses, and not to the organisation that built the model. Z.ai receives nothing when you talk to an agent running GLM.
The person who builds an agent can choose a different model for it. Some of those choices are hosted by a third-party provider instead, and where one is selected your messages to that agent are sent to that provider through Cloudflare AI Gateway. The providers we route to are Anthropic, OpenAI, Google, xAI, DeepSeek, and Mistral. An agent's model is shown on its page before you use it.
Some features always use a particular provider, whichever model the agent itself runs on:
Only the content needed to produce the output is sent to the model. When an agent looks something up on your behalf, the query is sent to the provider that serves that lookup: Exa for web and research search, Google for places, routes, and listings of what is on somewhere, Semantic Scholar for academic papers, Homedata for UK property listings, and GIPHY for GIFs. AI outputs can be inaccurate or incomplete and are not a substitute for professional advice. Please review them before relying on them.
A separate, smaller model reviews the configuration of agents built on the service against our Terms, as described above. That review only flags an agent for a person at Omnimatch to look at; nothing about your account is decided by a model on its own.
Anyone with an account can build an agent and share it. When you use an agent built by another user, the messages you send it and the files you attach are visible to that agent's creator through their own account, and the agent may send what you give it to the third-party services its creator has connected to it. For the personal data you put into someone else's agent, its creator is the controller and their own privacy notice applies. We host and process that data on their behalf. If you build an agent, you are responsible for what it collects and for telling the people who use it what happens to their data.
If you enable the meeting notetaker, a bot (provided by our processor Recall.ai) joins the video meetings you direct it to and records and transcribes them. This captures the speech of everyone in the meeting, not just you. Recording and transcribing conversations is regulated in many places and can require the consent of all participants.
You are responsible for having the right to record a meeting and for obtaining any consent the law or your organisation requires before the notetaker joins. The bot is designed to be visible to participants as a meeting attendee. You can remove it or turn the feature off at any time. Recordings, transcripts, and generated notes are stored so we can provide the feature to you and are deleted when you delete them or your account (see "Retention").
We share your information only with service providers who process it on our behalf to run the service, where you direct us to (for example, a messaging platform you connect an agent to), and where required by law. We do not sell your personal data or share it for advertising. The table below names each provider and what we use it for. The full list, with each provider's legal entity, location, the data it receives, when it applies, and the transfer safeguard, is kept on its own dated page at omnimatch.ai/subprocessors.
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting and everything underneath the product: Workers, D1 databases (including document search), Durable Objects (conversation history), R2 (attachments and uploaded knowledge), Workers AI (default model inference and small background models), AI Gateway (every model request, with logging), Browser Rendering (the live browser feature), Turnstile (bot protection), Images, and transactional email (sign-in links, verification, notifications) |
| Cloudflare's own GPU capacity | Cloudflare runs some Workers AI inference on rented GPU capacity from these providers. We have no relationship with them; they are listed so that "the default model stays with Cloudflare" is read correctly: it stays inside Cloudflare's chain |
| Stripe | Payment processing, subscriptions, and payouts to agent owners who charge for their agents |
| Google (sign-in) | Sign in with Google |
| Anthropic | Reading the pages of any PDF you attach; and Claude models where an agent's owner has selected one for that agent |
| OpenAI | Image generation from the description an agent writes (a Cloudflare-hosted model is the fallback); and GPT models where an agent's owner has selected one |
| Google (models and grounding) | Gemini models where an agent's owner has selected one; and Gemini with Google Search grounding behind the "what's on" lookups (events near a place) |
| xAI | Voice conversations (speech recognition and spoken replies); and Grok models where an agent's owner has selected one |
| Alibaba Cloud | Video generation from the description an agent writes |
| ElevenLabs | Music generation from the description an agent writes |
| DeepSeek | DeepSeek models, only where an agent's owner has selected one for that agent |
| Mistral AI | Mistral models, only where an agent's owner has selected one for that agent |
| Exa | Web search, research search, and page reading when an agent looks something up |
| Google Maps Platform | Place search, routes, geocoding, and 3D flyover tiles for the map and route elements |
| GIPHY | GIF search for the memes lookup |
| Semantic Scholar | Academic paper search behind the research lookups |
| Homedata | Live UK property listings behind the property lookups |
| Recall.ai | The meeting notetaker bot that joins video calls, records, and transcribes them |
| Google Chat | Talking to an agent from Google Chat, where a workspace admin has installed it |
| Microsoft Teams | Talking to an agent from Teams, via the Bot Framework |
| Telegram | Talking to an agent from Telegram |
| Discord (channel) | Talking to an agent from a Discord server |
| Talking to an agent from WhatsApp, through the WhatsApp Business Cloud API | |
| Apps you connect | Where you link your own account so an agent can work inside it |
| Tools an agent owner adds | Agent owners can add tools from our catalogue or write their own that call an outside service with a key they hold (applicant-tracking systems, data providers, and so on) |
| Discord (our team alerts) | Alerts to our own team's private Discord: a new sign-up, a new paid subscription, negative feedback left in a conversation, and an agent flagged for review |
Our providers may process data outside the UK/EU, including in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses (with the UK Addendum) and the providers' data processing agreements; the transfer basis for each provider is on the sub-processor list. We do not yet pin stored data to a particular region. Your data protection rights continue to apply regardless of where your data is processed.
We keep personal data only as long as needed to provide the service and for the purposes above: account and conversation data are retained while your account is active and until you delete the data or your account; meeting recordings and transcripts until you delete them or your account; and financial records for as long as required by law (typically six years under UK tax law). You can request deletion at any time, subject to legal obligations.
Subject to applicable law, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. To exercise any of these, email privacy@omnimatch.work. We may need to verify your identity, and we aim to respond within 30 days. You can also delete your Omnimatch account, which removes associated data.
https://www.googleapis.com/auth/chat.bot scope; it does not request
access to your Gmail, Drive, Calendar, or Contacts, and it does not read messages in a space that are not
addressed to it. We use Google user data only to provide and improve the features described in this policy,
and we do not transfer or use it for advertising or for any unrelated purpose.
The web app uses essential cookies for signing you in and keeping your session secure, and bot-protection (Turnstile) to guard sign-in against automated abuse. We do not use advertising or cross-site tracking cookies.
We restrict access to your data, transmit it over encrypted connections, and cryptographically verify that inbound requests from messaging platforms are genuine before we act on them. If we become aware of a personal data breach that is likely to result in a risk to you, we will notify the ICO within 72 hours where required and affected users without undue delay.
Omnimatch is not directed to children under 13 (or the equivalent minimum age in your jurisdiction) and we do not knowingly collect their data.
We may update this policy; we will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you.
Privacy questions or requests: privacy@omnimatch.work. If you are in the UK or EU and believe we have not handled your data properly, you have the right to complain to a supervisory authority: in the UK, the Information Commissioner's Office (ICO), ico.org.uk/make-a-complaint. You do not need to contact us first.