Trust
Last updated: 30 July 2026
Local-first by design
Audio and video analysis runs on your machine. Your sets never leave it unless you explicitly opt into a cloud feature, such as connecting a social account to post directly. There is no upload queue and no third-party processing pipeline by default.
Account data
Authentication is handled by Supabase. We store only the minimum needed to run subscriptions, workspaces and basic identity. No biometric data, and no payment card data, is stored on our side.
Social account connections
When you connect TikTok, YouTube or (in a later release) Instagram, the OAuth access and refresh tokens are stored server-side with row-level security and are never returned to the app or your browser. You can disconnect an account at any time, which revokes our access immediately. We request only the permissions each platform requires to post or schedule on your behalf, nothing broader.
Payments
Card data is handled directly by Stripe under their PCI DSS Level 1 certification. Omni DJ never sees your card number.
Security practices
HTTPS everywhere. Database row-level security on every table that touches user data. Regular dependency audits. Two-factor authentication (TOTP) is available on every account, with one-time backup codes for account recovery if you lose access to your authenticator. Production secrets, including any social-platform client secret, are stored only as server-side secrets, never in the app, a repository or an installer. Secrets are rotated on any suspected incident.
Reporting an issue
Security disclosures: [email protected]. We aim to acknowledge within one business day.