OmniLoop
AboutPricingPrivacyTermsRefundsDeliveryContactData Deletion

Privacy Policy

Last updated: September 3, 2026

This Privacy Policy explains how OmniLoop (“OmniLoop,” “we,” “us,” or “our”), a product operated by KCN Life Private Limited, collects, uses, stores, shares, and protects information when you use the OmniLoop social media management platform at omniloop.app (the “Service”). By using the Service you agree to the practices described here.

1. Who we are

OmniLoop is a social media scheduling and management tool that lets you connect your social media accounts, compose and schedule posts and first comments, publish content, manage an inbox of interactions, and view analytics. The data controller is KCN Life Private Limited, a company registered in India with its registered office at Plot 95A, Block B, Vikas Nagar, New Delhi, Delhi 110059, India. “The Indie Earth India,” under which some of our social-platform integrations are registered, is a brand of KCN Life Private Limited. You can reach us at privacy@omniloop.app.

2. Information we collect

We collect only what we need to operate the Service:

a. Account information

When you create an OmniLoop account we collect your name, email address, and authentication details. If you sign in with Google, we receive your basic profile information (name, email, and profile image) from Google to create your account. We do not receive or store your Google password.

b. Connected social account data

When you connect a social account (for example a Facebook Page, Instagram professional account, Threads profile, YouTube channel, X, or Bluesky account), we receive and store, on your instruction:

  • Access tokens issued by the platform, which authorize OmniLoop to act on your behalf. These are encrypted at rest and are never shown to you or third parties.
  • Account identifiers and profile metadata such as the Page or account ID, name/handle, and profile picture, used to display your accounts in the app.
  • Meta Platform data obtained through the Facebook Graph API and Instagram Graph API, limited to the permissions you grant: your Pages and linked Instagram accounts (pages_show_list, instagram_basic), the ability to publish posts and media you create (pages_manage_posts, instagram_content_publish), the ability to publish the first comment you write on your own posts (pages_manage_engagement, instagram_manage_comments), and engagement/read data used for your unified inbox and analytics (pages_read_engagement, business_management).
  • Threads data obtained through the Threads API, limited to the permissions you grant: your basic Threads profile (threads_basic), the ability to publish posts you create to your own Threads profile (threads_content_publish), reading replies to your own Threads posts to power your unified inbox (threads_read_replies), and hiding or unhiding replies on your own posts (threads_manage_replies).
  • YouTube and Google data obtained through YouTube API Services, limited to the permissions you grant: your basic YouTube channel information and the publish status of videos you post through OmniLoop (youtube.readonly), and the ability to upload and publish videos you create to your own channel (youtube.upload). See Section 5 (YouTube API Services) for full details.

c. Content you create

The posts, captions, first comments, images, and videos you upload or schedule through OmniLoop, together with their scheduling metadata (target accounts, times, and status).

d. Engagement and analytics data

Comments, mentions, and messages retrieved from your connected accounts to power the unified inbox, and post performance metrics (such as impressions, likes, comments, and clicks) to power analytics.

e. Usage and technical data

Basic technical information needed to run and secure the Service, such as log data and device/browser information. We do not sell this data or use it for advertising.

f. Payment information

OmniLoop is a paid service. When you buy a subscription or OmniLoop Credits, our payment processor, Razorpay, collects and processes the payment and billing details needed to complete your purchase (such as card or UPI information and billing contact details). We do not store full card numbers on our servers; we keep a record of your purchases, invoices, and the payment reference needed for billing, tax, and support. See Section 4 (How we share information) for how this is shared.

3. How we use information

  • To provide the Service: scheduling, publishing, first comments, inbox, and analytics.
  • To publish content to the connected accounts you select, at the times you choose.
  • To display your connected accounts, profile pictures, and post status in the app.
  • To provide optional AI-assisted content features (such as caption and content suggestions) when you choose to use them.
  • To authenticate you and keep your workspace and data secure.
  • To communicate with you about the Service, including important notices.

We use Meta Platform data and YouTube API Services data solely to provide the features you use within OmniLoop. We do not use it for advertising, we do not sell it, and we do not transfer it except as described in this policy.

4. How we share information

We share information only in these limited cases:

  • Social platforms. When you publish, we send your content to the platform you selected (for example Meta, Threads, YouTube, X, or Bluesky) so it can be posted. Your use of those platforms is governed by their own terms and privacy policies.
  • Payment processor. We use Razorpay (Razorpay Software Private Limited), an India-based payment processor, to take and process payments. When you pay, your contact and payment information is shared with Razorpay to complete the transaction, under its own Privacy Policy.
  • Infrastructure providers. We use hosting (Hostinger), content-delivery and object storage (Cloudflare, including Cloudflare R2), and email-delivery providers to run the Service. They process data on our behalf under appropriate safeguards.
  • AI provider. When you use OmniLoop’s optional AI content features, the prompt and content you submit for generation are sent to our AI provider, OpenAI, to return a suggestion. This is used only to provide the feature and, under OpenAI’s API terms, is not used to train their models.
  • Legal. We may disclose information if required by law or to protect the rights, safety, and security of our users and the Service.

We do not sell your personal information, your Meta Platform data, or your YouTube API Services data.

5. YouTube API Services

OmniLoop uses YouTube API Services to let you connect your own YouTube channel and upload, publish, and schedule videos to it from within OmniLoop.

  • Agreement to YouTube’s terms. By connecting a YouTube channel and using OmniLoop’s YouTube features, you agree to be bound by the YouTube Terms of Service.
  • Google Privacy Policy. OmniLoop’s use of information received from YouTube API Services is subject to the Google Privacy Policy (https://policies.google.com/privacy), in addition to this Privacy Policy.
  • Limited Use. OmniLoop’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • What we access. With your authorization via Google OAuth, and limited to the scopes you grant, OmniLoop accesses your basic YouTube channel information and the status of videos you publish through OmniLoop (youtube.readonly), and the ability to upload and publish videos that you create, to your own channel (youtube.upload). We only ever access channels you own and have connected.
  • How we use it. We use YouTube data solely to provide OmniLoop’s features to you: uploading and scheduling your videos to your channel, displaying your connected channel, and showing the publish status of your posts. We do not use YouTube data for advertising, we do not sell it, we do not transfer it to third parties except to YouTube/Google to carry out the actions you request, and we do not use it to train machine-learning or AI models.
  • How we store it. Access and refresh tokens for your YouTube connection are encrypted at rest and are never shown to you or to third parties. Stored YouTube data is retained only while your channel is connected.
  • How to revoke access. You can disconnect your YouTube channel at any time from Connect Accounts in OmniLoop, which removes its stored tokens. You can also revoke OmniLoop’s access to your Google/YouTube account at any time through Google’s security settings at https://myaccount.google.com/permissions.
  • How to delete your data. To delete your OmniLoop account and associated data, see our Data Deletion page. We fulfil data-deletion requests within 30 days, except where retention is required by law.

6. Cookies and analytics

OmniLoop uses a small number of cookies and similar technologies, and keeps them to the minimum needed to run and improve the Service.

  • Essential cookies. Strictly necessary cookies that keep you signed in, maintain your session and workspace context, and help protect against fraud and abuse. The Service cannot function without these, so they are always on and do not require consent.
  • Cookie-consent preference. When you respond to our cookie banner, we store your choice (for example, in local storage or a first-party cookie) so we do not have to ask again on every visit.
  • First-party analytics. We use light, privacy-respecting first-party analytics to understand which features are used and to improve the Service. This is limited to aggregate usage and basic technical data; we do not use third-party advertising cookies, and we do not sell this data or use it for advertising.

You can control non-essential cookies through the choice offered in our cookie banner, and you can clear or block cookies at any time in your browser settings. Blocking essential cookies may prevent parts of the Service from working.

7. Data storage and security

Access tokens and other secrets are encrypted at rest using strong encryption. Your data is logically isolated per workspace so that one customer cannot access another customer’s data. We restrict internal access, and we take reasonable technical and organizational measures to protect your information. No method of transmission or storage is completely secure, but we work to protect your data and to promptly address issues.

8. Data retention and deletion

We retain your data for as long as your account is active or as needed to provide the Service. You can disconnect any social account at any time from Connect Accounts, which removes its stored tokens from OmniLoop. You can request deletion of your account and associated data at any time — see our Data Deletion page for instructions. When you delete your account, we delete or de-identify your personal data within a reasonable period (and within 30 days for data obtained through YouTube API Services), except where retention is required by law.

9. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@omniloop.app.

Data export. To request a portable copy of your data, email privacy@omniloop.app and we will provide an export of your personal data. To delete your account and data, see our Data Deletion page.

10. Grievance Officer and India-specific rights

In accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, KCN Life Private Limited has appointed a Grievance Officer to address questions, requests, and complaints about how we handle your personal data. If you have a grievance about our data practices, you may contact:

Grievance Officer: Sandeep Saini
KCN Life Private Limited
Plot 95A, Block B, Vikas Nagar, New Delhi, Delhi 110059, India
Email: privacy@omniloop.app

We will acknowledge and address grievances within the timelines required by applicable law. If a grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India. Under the DPDP Act you may also nominate another individual to exercise your rights in the event of your death or incapacity.

11. Children

The Service is intended for businesses and users aged 18 and over. It is not directed to children, and we do not knowingly collect personal information from children.

12. International users

OmniLoop serves customers in multiple regions, including India and the United States. Your information may be processed in countries other than your own — including India, the United States, and Malaysia, where our service providers operate — with appropriate safeguards in place.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, where appropriate, notify you of material changes.

14. Contact us

For any privacy questions or requests, contact KCN Life Private Limited at privacy@omniloop.app.

OmniLoop — a KCN Life Private Limited productContact: privacy@omniloop.app