What OMAI stores, and where
The categories of information OMAI holds for your business, where the core infrastructure runs, which providers process parts of it, and how to download a copy of your own data.
- Who
- Anyone with a dashboard account
- Plan
- All plans
- Role
- Downloading the export needs Owner or Admin
This article is a plain-language map of the information OMAI holds while it runs your WhatsApp assistant, and of the places that information sits. The binding document is the Privacy Policy; this page explains the same facts in the order a business owner usually asks about them.
Two roles run side by side. For your own business account — your name, your email address, your billing details — OMAI decides how the information is used. For the messages your customers send you, OMAI processes them on your behalf and under your instructions; you remain responsible for those conversations towards your customers.
What is held, by category
Everything below is created either by you, by your team, by your customers messaging your number, or by the providers OMAI connects to. Nothing is bought from a data broker and nothing is imported from a source you did not connect.
| Category | Examples | Where it is kept |
|---|---|---|
| Account and team | Name, email address, role in the organization, sign-in and permission records | OMAI database |
| Business information | Display name, description, address, city, opening hours, closures, services and prices, FAQs, policies | OMAI database |
| Uploaded documents | The PDF, Word, CSV, text or Markdown files you add to the knowledge base, and the passages extracted from them | File storage for the file itself, database for the passages |
| WhatsApp connection | Your business phone number, the WhatsApp Business Account ID (WABA ID), the Phone Number ID and the connection status | OMAI database |
| Provider access tokens | The WhatsApp access token used to send and receive on your number | Azure Key Vault. The database holds only a reference to the vault entry, not the token |
| Conversations | Your customers’ WhatsApp phone numbers, the text of inbound and outbound messages, and a reference to any media they sent — its type, its caption and Meta’s identifier for it | OMAI database. The media file itself is not downloaded and stays with Meta |
| Leads and tags | The enquiries a member of your team marked as worth following up, and the fields recorded on them | OMAI database |
| Billing | Billing contact details, card brand and last 4 digits, an encrypted payment token, invoices and charges | OMAI database. Full card numbers are never stored |
| Operational records | Usage counts, audit-log entries, AI processing records, and a record that a webhook from Meta was received | OMAI database |
Message content and media
Message text is stored so the shared inbox can show a conversation and so the assistant can read the recent history before it answers. When a customer sends a photo, a document or a voice note, OMAI records the caption, the file type and Meta’s identifier for that file — it does not download the file itself, and the conversation view does not display it.
Records of incoming webhooks from Meta store a hash of the payload and a status, not the payload itself. Message content and customer phone numbers are kept out of routine application logs.
What goes to the AI provider
Replies are generated by Microsoft’s Azure OpenAI Service, not the public OpenAI service. To produce one reply, OMAI sends the incoming message, recent conversation history and the business information the search step found relevant. Under Microsoft’s terms your content is not used to train Microsoft’s foundation models; Microsoft may process content for abuse monitoring under its own terms.
OMAI keeps a record of each AI reply for operating the service. That record holds technical facts only:
- The model name, and the number of prompt and completion tokens.
- How long the call took.
- Which knowledge passages were retrieved, by their identifiers.
- Any safety flags raised, the handoff reason if one applied, and the final action taken.
- The language of the exchange.
The text of the customer’s message and the text of the reply are not copied into that record — they live in the conversation itself.
Where the core infrastructure runs
The application, the database, file storage and the secret store run on Microsoft Azure in the EU, in the Sweden Central region. OMAI SOFTWARE LTD is an Israeli company and its support team works from Israel.
The providers involved
| Provider | What it does |
|---|---|
| Meta Platforms | The WhatsApp Business Platform (Cloud API) — receiving and delivering messages. |
| Microsoft Azure | Hosting, database, file storage, search, telemetry and the secret store. |
| Azure OpenAI (Microsoft) | Generating replies and building the search index of your business knowledge. |
| Twilio | Carrier phone numbers, message transport and one-time-code delivery for numbers rented through OMAI. |
| Grow (Meshulam) | Hosted checkout and recurring billing for Israeli card payments. |
| The optional Continue with Google sign-in, and OMAI’s own support mailbox. |
The controls that apply
- Web traffic is encrypted in transit over HTTPS (TLS 1.2 or 1.3), with HSTS enabled.
- The database and file storage are encrypted at rest using Azure platform-managed encryption.
- Your WhatsApp access token is stored in Azure Key Vault, reached through a managed identity; the database holds a reference to it.
- The stored payment token is encrypted with AES-256-GCM.
- Inbound webhooks from Meta are authenticated with an HMAC-SHA256 signature check, so unsigned or forged payloads are rejected.
- Every request is scoped to one organization, and membership is re-checked against the database on each request.
Message content is processed in plain form by the application and by the AI provider, so no scheme in which only you can read a conversation is in place. Who inside your business and inside OMAI can reach that content is covered in who can see your data.
What is not done with it
- Personal data is not sold.
- Message content is not used for advertising, and it is never sent to analytics or advertising providers.
- The AI provider does not use your content to train its foundation models.
- The website and dashboard run on strictly necessary cookies by default. Analytics, marketing, functional and session-recording technologies load only if you allow them in the consent banner, and you can change that choice at any point from Cookie preferences in the footer.
Downloading your own copy
Export the organization’s data
Step 1 Open Dashboard → Settings and scroll to the Account & privacy card.
You should see: You see Export your data with a short description of what the file contains.
Step 2 Select Export data (JSON).
- The action needs the Owner or Admin role. An agent or viewer who opens the address directly gets a server error rather than a clear refusal.
You should see: Your browser downloads a file named
omai-export-<your organization id>.json. It is generated while you wait, so a large account takes longer to start downloading.
The file contains the organization record, the business profile, opening hours, services, FAQs, policies, WhatsApp connections (without any token), contacts, conversations, messages, leads with their fields, knowledge sources, the subscription record and the assistant settings.
It does not contain invoices or billing charges, tax documents, the audit log, usage records, the files you uploaded to the knowledge base, message templates, legal acceptances, consent records, the team member list, or the extracted knowledge passages. A written request to support@omai-software.com is the route to anything on that list.
Which country is my data held in?
No. The application, database, file storage and secrets run on Microsoft Azure in the EU (Sweden Central). OMAI SOFTWARE LTD is registered in Israel and support is provided from Israel.
Does OMAI read my customers’ messages?
The application processes message content to run the inbox and produce replies, and the AI provider processes it to generate a reply. Access by people at OMAI is restricted to a separate operator role, and privileged actions are recorded in an audit log — see who can see your data.
Can I get an export automatically on a schedule?
No. The export is a manual download from the Account & privacy card, taken whenever you want a copy.
What happens to all of this if I stop using OMAI?
Disconnecting a number stops new messages arriving, but stored data stays until it is deleted. How long things are kept covers deletion and the records that are kept afterwards.
