OmxusPrivacy & Terms
Contents

Omxus Privacy Policy

Signing in is a moment of trust. You're telling a service who you are. We take that seriously, keep only what signing in needs, and put you in control of it.

This Privacy Policy explains what information Omxus collects when you use your Omxus account, why we collect it, who helps us handle it, and how you can see, change, export and delete it.

Omxus is said OHM-SHUSS, with a soft "sh" like the x in pinyin. The name reads as Om, the sound of everything, times us.

Privacy at a glance

See everything we store for your account, in one table.

What we
store

Last updated 17 September 2026 Effective {{EFFECTIVE_DATE}}

Our approach to privacy

A sign-in service should know as little about you as it can and still do its job.

Omxus does one job: it lets you sign in to sites and apps with one account, and keeps that account safe. Everything in this policy follows from four ideas.

  • Your identity is yours. Signing in proves it's you. It doesn't give us, or the sites you use, a record of what you do.
  • One account, every site. You get one strong account instead of a weak password on every site.
  • A private ID for each site. Sites that sign you in through the Omxus sign-in page each get their own ID for you, so they can't match you up by it.
  • We hold what we need, and say exactly what. This policy lists it all, and so does What Omxus stores about you.

We don't show ads, we don't use your information for advertising, and we don't sell personal information.

Who we are and what this covers

Omxus is provided by {{LEGAL_ENTITY}}. In this policy, "Omxus", "we", "us" and "our" mean {{LEGAL_ENTITY}}.

This policy applies to your Omxus account: signing up, signing in, and managing your account, wherever the Omxus sign-in appears. That includes the Omxus sign-in page at auth.omxus.com and the Omxus sign-in shown on a site's own pages.

This policy doesn't cover the sites and apps you sign in to. Each one runs its own service and handles your information under its own privacy policy. When you sign in to a site, read its policy too.

Example: where Omxus stops and a site begins

You sign in to a photo site with Omxus. Omxus handles your email address, password and passkeys, and tells the site you're signed in. The photos you upload, the comments you write and the albums you follow belong to the photo site's service, and its privacy policy covers them.

Information Omxus collects

We want you to know exactly what we collect, down to the field.

Things you give us

When you create or manage your account, you give us:

  • Your email address or mobile number. You choose which. We keep it readable, because we send your codes to it. We store email addresses in lowercase, and mobile numbers in international format.
  • A username. Either one shared across sites that share usernames, or one for a particular site.
  • A password, if you choose one. Your device scrambles your password before it leaves, so we never receive it. We scramble what arrives again and keep only that one-way fingerprint.
  • Passkeys, if you save them. We keep the public part of each passkey, the site it belongs to, and technical details your device reports, like whether the passkey is backed up. The private part never leaves your device.
  • Codes you type. We check the 6-digit codes you enter against the fingerprint we stored when we sent them.
If you sign in with your name, date of birth and secret words

Your device turns these three things into a key, and makes a separate key for each site. We receive only a signed proof and the public address of the key for that site. We never receive your name, date of birth or secret words, and we can't work them out from what we receive.

Information created as you use Omxus

  • Sessions. Each sign-in records the site, how you signed in (for example password, passkey or code), when it started, when it was last used, when it expires, the first 120 characters of your browser's description of itself, and a shortened network address. For sign-ins through the Omxus sign-in page, it also records which details the site asked for.
  • Security events. A record of sign-ins, failed sign-ins, sign-outs, and changes to your password, email or mobile, passkeys, usernames and sessions, each with the time, the site and a shortened network address.
  • Attempt records. To slow down and stop guessing and message floods, we briefly record each attempt against the email address or mobile number, account or network address it involved.
  • Codes and tokens. The codes we send and the tokens that keep you signed in, stored only as one-way fingerprints, with their expiry times.
  • Account state. Whether we've turned your account off to protect people, and the reason.

Information from sites

When a site uses Omxus, we know which registered site each sign-in comes from. If a site moves its existing accounts to Omxus, it gives us, for your account:

  • your email address,
  • its old password record, which we delete after your first sign-in replaces it,
  • its own ID for you, and any role you had on the site, like moderator.

We keep the site's old ID and your roles for that site only.

Technologies we use

  • A cookie on auth.omxus.com. When you sign in on the Omxus sign-in page, we set one cookie so the next site can offer "Choose an account". Scripts can't read it, it only travels over secure connections, and it lasts up to 30 days.
  • Browser storage on sites. Sites that show the Omxus sign-in on their own pages keep your sign-in tokens in their own browser storage.
  • Server requests. Like any website, our servers see your network address and browser details when your browser contacts them. We shorten network addresses before storing them in sessions and security events.

We don't use advertising cookies, tracking pixels or analytics that follow you across sites.

Information we don't collect

  • Your password or secret words.
  • Your name, date of birth, address, gender or payment details.
  • Your contacts, photos, location or anything else on your device.
  • What you do on the sites you sign in to.

Why Omxus uses information

We use information to sign you in, keep your account safe, and nothing unrelated.

Provide the sign-in service

We use your email or mobile, password record, passkeys and sessions to create your account, sign you in, keep you signed in, and let you sign in to the sites you choose. We use your username so sites can show your name.

Keep accounts and people safe

We use security events, attempt records and shortened network addresses to detect and stop guessing, message floods, copied sign-in tokens and accounts that someone else has taken over. We use them to let you review your own activity, too.

Example: a copied sign-in

Each renewal token for a sign-in works once. If an old one shows up again, it may have been copied from a device. We end that whole sign-in on every device that shared it and record the event, so you can see it in your activity.

Communicate with you

We send codes to your email or mobile. We send notices when something important happens to your account, like someone trying to sign up with your address, or a change to your sign-in address. We tell you about significant changes to this policy or our terms. We don't send marketing.

Share with sites you choose

When you sign in to a site, we give it the details described in Sharing your information.

Meet legal obligations

We use and keep information where the law requires, for example to respond to a valid legal request.

We'll ask for your consent before using your information for a purpose this policy doesn't describe.

Our legal bases, if you're in the European Economic Area or the United Kingdom
  • Contract: to create your account, sign you in and let you sign in to sites, as our terms describe.
  • Legitimate interests: to protect accounts, people and our service from abuse, fraud and attacks, in ways you'd reasonably expect from a sign-in service.
  • Legal obligation: where the law requires us to keep or disclose information.
  • Consent: where we ask for it. You can withdraw consent at any time.

Your privacy controls

You can review and change what's on your account at any time.

Sites that use Omxus put these controls in their account settings.

Your browser gives you controls too. You can clear site data to sign out, or block cookies for auth.omxus.com. If you block site storage, you'll need to sign in more often.

Sharing your information

We don't share personal information outside Omxus except in the cases below.

With the sites you sign in to

When you sign in to a site, you're asking us to tell it who you are. What a site receives depends on how it uses Omxus.

Sites that use the Omxus sign-in page receive:

  • a private ID made for that site,
  • when and how you signed in,
  • your username for the site, if the site asks for your profile,
  • your email address and whether you verified it, if the site asks for your email,
  • your mobile number and whether you verified it, if the site asks for your phone number.

Sites that show the Omxus sign-in on their own pages receive your Omxus account ID, your username for the site, whether your email or mobile is verified, a partly hidden form of your email or mobile, and whether you have a password or passkey.

Sites that moved their accounts to Omxus also receive their own old ID for you and your roles on that site.

We never give a site your password, your passkeys, your activity, or which other sites you use. Once a site has your details, its own privacy policy applies to them.

With service providers who help us run Omxus

We use a small number of companies to run the service. They handle information only to provide their service to us.

ProviderWhat they doWhat they handle
Cloudflare, Inc.Runs our servers and database, and sends our emailsEverything Omxus stores, the requests your browser makes to us, and the emails we send you
TextBeeGateway software that sends our texts from a mobile phone Omxus operates, through that phone's mobile networkYour mobile number and the text we send you, including the code
Services your browser contacts directly

Two other services receive requests straight from your browser while you use the sign-in screen. We don't send them your account information.

  • Have I Been Pwned receives the first 5 characters of a one-way fingerprint of a new password you choose, so your device can check it against breached passwords. It receives your network address, as any website does, but not your password, your email or your account.
  • Google Fonts can supply the sign-in screen's typeface. Google receives your network address and browser details when it does.

For legal reasons

We share information outside Omxus when we believe in good faith it's reasonably necessary to:

  • meet a law, regulation, legal process or enforceable government request,
  • enforce our terms, including investigating possible breaches,
  • detect, prevent or address fraud, security or technical problems,
  • protect the rights, property or safety of our users, the public or Omxus, as the law allows.

We check each request for legal validity and share no more than the request lawfully requires. Where the law allows, we tell you before we share.

If Omxus changes hands

If Omxus is involved in a merger, acquisition or sale of assets, we'll keep your personal information confidential and tell you before it moves to a different owner or a different privacy policy applies.

What we never do

We don't sell personal information, and we don't share it for advertising. That includes selling or sharing as the California Consumer Privacy Act defines those words.

Keeping your information secure

We build protection into every account, whether or not you change a setting.

  • We never have your password. Your device scrambles it with PBKDF2 600,000 times, and we scramble that again with a random salt before storing it.
  • Secrets stay secret. Codes and sign-in tokens are stored only as one-way fingerprints.
  • Connections are encrypted. Every connection to Omxus uses HTTPS, and our responses tell browsers to always use it.
  • Guessing is slowed and stopped. Answers slow down after a few failed tries, and attempts pause for 15 minutes after 10.
  • Nobody can test whether an address has an account. Sign-in, code and sign-up screens answer the same way either way.
  • Sign-ins expire and can't be replayed. Short-lived tokens renew in the background, each renewal works once, and every sign-in ends within 90 days.
  • Changes need confirmation. Changing your password, email or mobile, removing a passkey or deleting your account asks you to confirm it's you.
  • Sites are held to their addresses. Omxus only works for a site from the web addresses it registered.
  • Access is limited. Only people who need access to run and protect the service have it, and support actions are recorded in the account's security events.

No system is perfectly secure. If we learn of a breach that's likely to cause you serious harm, we'll tell you and the relevant regulator as the law requires.

Exporting and deleting your information

You can get a copy of your information, or delete your account, at any time.

Get a copy

Send a privacy request to ask for a copy of everything we hold about your account. We confirm the request comes from the account's owner, then send your account details, email or mobile, usernames, passkeys, sessions, security events and account state in a file you can keep. Learn more.

Delete your account

You can delete your account from the account settings on a site that uses Omxus, after confirming it's you. Deleting is immediate: we delete your email or mobile, usernames, password record, passkeys, sessions, security events and everything else tied to your account, and every device signs out. Learn more.

Deleting your Omxus account doesn't delete your accounts or content on other sites. Ask each site.

Retaining your information

Different information lasts for different times, and nothing lasts longer than it needs to.

  • Until you change or delete it: your email or mobile, usernames, password record, passkeys, and the site address for the name, date of birth and secret words way in.
  • Up to 90 days: each sign-in ends within 90 days. Security events are deleted after 90 days.
  • Minutes to days: codes expire after 10 minutes, the short-lived sign-in token after 15 minutes, and renewal tokens after 30 days.
  • 15 minutes: attempt records are only used for 15 minutes.
  • 30 days for unverified accounts: an account whose email or mobile was never verified, and that nobody has used for 30 days, is deleted with everything attached to it. This does not apply to an account a site brought across from its own records: it stays until it's verified, or until that site removes it.
  • Up to 30 days for an address waiting for its code: an email or mobile typed but not yet verified is deleted after 30 days, or straight away when another account verifies it first. An address on an account a site brought across is not on this clock either.
  • Until your first sign-in: a site's old password record, for accounts that moved to Omxus.

When you delete your account, we delete its records straight away. Our hosting provider keeps short-term recovery copies of the database to protect against accidental loss. Those copies age out on a rolling schedule, and we only use them to recover from a failure. We don't delete verified accounts for being inactive.

We may keep specific information for longer if the law requires it, or while we deal with a legal claim or an investigation into abuse.

Where your information is processed

Omxus is based in Western Australia. Our hosting provider, Cloudflare, runs a network of data centres in many countries, so your information may be processed outside the country where you live, including outside Australia. Texts are sent from a phone in {{SMS_GATEWAY_COUNTRY}}.

Wherever your information is processed, we apply the protections in this policy. Before we disclose personal information to a provider overseas, we take reasonable steps to make sure it handles that information consistently with the Australian Privacy Principles, and, for people in the European Economic Area, the United Kingdom and Switzerland, we rely on recognised transfer safeguards such as standard contractual clauses.

Your privacy rights

Wherever you live, you can see, correct, export and delete your information, and complain if you think we've got it wrong.

Everyone can:

  • access the personal information we hold about you,
  • correct it, for example by changing your email, mobile or username,
  • export a copy you can take elsewhere,
  • delete your account and its information,
  • object to how we use your information, or ask us to restrict it,
  • complain to us, and to a regulator.

Ask using your account settings, or with the privacy request form. We'll respond within the time the law where you live requires. We won't treat you differently for using your rights.

Australia

We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You can ask to access or correct your personal information. If you have a complaint, contact us first with the privacy request form. We'll acknowledge it and aim to resolve it within 30 days. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

You can deal with us without identifying yourself where that's practical. Because an account needs an email address or mobile number to send codes to, you can instead use the name, date of birth and secret words way in, which gives us neither.

European Economic Area, United Kingdom and Switzerland

You have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to withdraw consent where we rely on it. You can complain to your local data protection authority. {{LEGAL_ENTITY}} is the controller of your personal data for your Omxus account. {{EU_UK_REPRESENTATIVE}}

California and other US states

You have the right to know what personal information we collect, use and disclose, to access and delete it, to correct it, and to opt out of its sale or sharing. We don't sell or share personal information as those laws define it, and we don't use sensitive personal information for purposes that would give you a right to limit it. The categories we collect are identifiers (email address or mobile number, username, account IDs, shortened network addresses) and internet activity limited to your sign-ins and security events on Omxus. You can use an authorised agent to make a request.

Children

Omxus accounts are for people at least {{MINIMUM_AGE}} years old, or older where local law sets a higher age to agree to online services. We don't knowingly create accounts for younger children. If you believe a child under that age has an account, send us a privacy request and we'll delete it.

Changes to this policy

We update this policy when Omxus changes or the law does. We won't reduce your rights under this policy without your explicit consent. The date at the top shows when we last changed it. If a change is significant, we tell you before it takes effect, including by email to the address on your account where we can.

Contact us

For questions about this policy or your information, or to make a request or complaint:

For help with signing in, visit Omxus Account Help.

Key terms

Account ID
A random string Omxus creates for your account. It contains nothing about you.
Browser storage
Space a website can use in your browser to remember things between visits, like that you're signed in. Each website's storage belongs to that website's address.
Code
A 6-digit number we send to your email or mobile. It works once, for 10 minutes.
One-way fingerprint
The result of running information through a hash function, a calculation that always gives the same result for the same input but can't be run backwards. We can check whether a code or token matches its fingerprint without storing the code or token itself.
Network address, shortened
Every device on the internet has a network address, called an IP address. We shorten it before storing it, keeping only the first part (the first three of four numbers for IPv4, the first 48 bits for IPv6), so it points to an area of a network, not your connection.
Omxus
Said OHM-SHUSS. The account and sign-in service described in this policy, provided by {{LEGAL_ENTITY}}.
Passkey
A pair of keys your device makes for one website. Your device keeps the private key and unlocks it with your fingerprint, face or PIN. The website keeps the public key, which can check a sign-in but can't be used to sign in.
Personal information
Information about an identified person, or a person who can reasonably be identified, such as your email address or mobile number.
Private ID
An ID for your account made for one site, by combining your account with that site's web address and a secret only Omxus holds. Different sites get IDs that can't be matched. Also called a pairwise identifier.
Salt
Random data mixed into a password fingerprint, so the same password gives a different fingerprint for each account.
Service provider
A company that handles information on our behalf and under our instructions, like our hosting provider.
Session
One sign-in on one device, or one site's access through the Omxus sign-in page. It ends when you sign out, when it expires, or when a security change ends it.
Site
Any website or app that uses Omxus for signing in. Each site registers with Omxus and runs its own service.