Legal Change Log
Every revision of the documents below, newest first.
This page lists every dated version of our Privacy Policy, our Terms of Service, and our Data Deletion Instructions, with a plain summary of what changed and why. A summary is written for someone who will not read the diff, so it says what a change means rather than which sentence moved.
August 27, 2026
Privacy Policy. Material change, notified by email and in the app.
The Instagram connection now also reads the linked Facebook Page's own statistics, through the same four read-only permissions and with no additional consent; the policy's statement that Loki reads no Facebook Page metrics is replaced with a description of exactly what is read.
- The Meta connection reads, in addition to the Instagram figures already described, the linked Facebook Page's ID, name, username, link, profile picture, and follower and Page-like counts, and for the Page's own published posts the post text, timestamp, permalink, and reaction, comment, and share counts.
- No new permission is requested: the Page reads use the same four read-only permissions the policy already names. Page-level reach and impressions from Meta's insights endpoint are read only if Meta grants the app the read_insights permission; until then those figures are recorded as unavailable, never estimated.
- Loki still reads no visitor posts, no individual reactions or comments, no Stories, no direct messages, and no data about the people behind any count, and it cannot post to Facebook.
- Retention is unchanged and now names the Page data explicitly: disconnecting the connection in Loki immediately deletes every figure pulled through it, the Facebook Page's figures included.
August 24, 2026 (Loki 1.3.3)
Privacy Policy, Terms of Service, Data Deletion Instructions. Material change, notified by email and in the app.
All three legal documents were corrected to describe the three read-only social platform connections Loki actually built, Instagram through Meta, TikTok, and YouTube, replacing text that said no connection was live and that described a wider Meta integration than the one that exists.
- All three documents previously stated that no social platform connection was live in Loki. Three are: Instagram through Meta, TikTok, and YouTube. Every connection is read-only, optional, off by default, covers one client account, and can only be created by an agency owner.
- The privacy policy previously said Loki was applying to Meta for the Marketing API and would read ad account, campaign, spend, and ad performance data. That was never built and is not requested. Loki reads no advertising data on any platform and cannot create, edit, or run ads.
- The Meta section now names the four read-only permissions actually requested, instagram_basic, instagram_manage_insights, pages_show_list, and pages_read_engagement, and states that the Facebook Page is only the route to the Instagram Business account. Loki reads no Facebook Page metrics, Stories, direct messages, or comments.
- The policy previously listed impressions among the Meta metrics collected. Meta deprecated that metric and Loki does not request it. The metrics actually stored are views, reach, likes, comments, shares, and saves.
- YouTube is now described in the retention table and the platform section with the single read-only scope it requests, youtube.readonly. The claim that no write scope exists anywhere in the product was wrong, because the separate Google Drive and Calendar connections do write, so the statement is now correctly limited to YouTube.
- Retention for connected platform data is restated to match what the product does. Disconnecting a connection in Loki deletes every figure pulled through it immediately, together with the stored tokens. A deletion request is answered within 7 calendar days.
- Two retention promises that nothing in the product enforced were removed rather than left standing: a 30 day delete-or-refresh cycle for YouTube API data, and a 12 month ceiling on TikTok trend history. Revoking access at a platform stops further reading and is no longer described as triggering an automatic purge; deletion is by disconnecting in Loki or by request.
- Google Ads and LinkedIn are named as not collected, because neither connection exists.
Read the Privacy Policy Read the Terms of Service Read the Data Deletion Instructions
August 7, 2026 (Loki 1.3.0)
Privacy Policy. Material change, notified by email and in the app.
The privacy policy was revised to describe private channels and direct messages in internal team chat, to record a new log of administrative access by Omni staff, and to set shorter retention periods. Every change narrows what Omni can see or how long anything is kept.
- Internal team chat now has public channels, private channels, and direct messages, each with its own visibility. The policy previously said all chat was visible to everyone in the agency workspace, which is no longer true.
- Omni staff cannot read the content, name, topic, or membership of any private channel or direct message. This is a new commitment, and it binds our administrative tooling and the view-as session alike.
- The only route into a private conversation is a support access grant issued by the agency's own owner, for a conversation that owner is part of. A grant lasts at most 7 days, is revocable at any moment, and Omni cannot issue one to itself.
- Removing a chat message now erases its text and attachment list for everyone. Previously the record was hidden from the workspace but retained.
- A new category of record is described: a log of which Omni staff account opened which record and when, kept for 6 months and then deleted automatically.
- Audit log and usage metering retention changed from the life of the agency workspace to 12 months, after which it is deleted automatically.
- Portal sign-in can now use a second factor, so a TOTP factor record joins the portal records the policy enumerates.
July 25, 2026
Privacy Policy, Terms of Service, Data Deletion Instructions
Initial publication of the privacy policy, the terms of service, and the data deletion instructions.
Read the Privacy Policy Read the Terms of Service Read the Data Deletion Instructions
Questions
If anything on this page is unclear, or you want the reasoning behind a particular change, write to thor@omni-systems.ai and we will explain it.