Security
OMMAIS is a small, independent site run by one person. This page says plainly how it protects you, and what it does not claim. Every statement here was checked against the site's own code.
Certifications: none
ommais.com is not SOC 2 audited and holds no ISO 27001 or similar certification. Those are reports written by independent auditors, and this site has never been through one. It has not had a formal penetration test either. If your organisation requires any of these from a vendor, OMMAIS does not meet that requirement today.
The site runs on Cloudflare, which holds its own SOC 2 and ISO 27001 certifications for its infrastructure (see Cloudflare's compliance page). That covers Cloudflare's systems, not this site's code.
Your conversations never pass through this site
OMMAIS Chat runs in your browser. Your questions go straight from your browser to the model service you are using — by default LLM7.io's free service; your own models through Ollama, where nothing leaves your computer; or a provider you added your own key for. This site has no server that runs a model or receives a conversation, so there is nothing here to leak. Which service your prompts go to is shown in the chat's status bar.
Cloud model services have their own privacy terms, and LLM7.io's free service is not audited as far as we know. Do not paste passwords, card numbers, health records or other sensitive information into any cloud AI model — here or anywhere else.
Saved conversations are encrypted on your device
- If you save conversations, they are stored only in your own browser, encrypted with AES-256-GCM.
- With a passphrase, the key is derived from it with PBKDF2-SHA256 at 210,000 iterations. The passphrase is never stored or sent anywhere.
- Signed in with Google, the key is a random 256-bit secret the site gives only to your own signed-in account. The site holds the key and never the conversations; your device holds the conversations and does not keep the key.
- Deleting your account deletes that key, which makes any copy left on a device unreadable.
Accounts
- No passwords. You sign in with Google, so this site never sees or stores a password.
- Sessions are random tokens in cookies that page scripts cannot read
(
HttpOnly,Secure,SameSite=Lax). The site stores only a SHA-256 hash of each token. Sessions expire after 30 days, renewed while you keep using the site. - Anything that changes your account must come from the site's own pages; requests from other websites are refused.
- Not collected: IP addresses, browser user agents, or the access tokens your sign-in provider issues (used once to sign you in, never kept).
- You can sign out of every device, and delete your account, from your account page. Deletion removes your account, sessions, likes, notifications and chat key; your comments are blanked.
What the site keeps
- The chat's sign-up list: the email address you enter, when, your country (from Cloudflare) and the page that sent you — in its own database, never sold or shared.
- Accounts: your name and email from your sign-in provider, and what you post — comments, forum threads, likes, challenge results.
- Read counts: a number per post per day, for the "Popular this week" list — nothing about who read it.
- Online games: nothing. Game rooms pass moves between signed-in players and store none of them. Messages are capped in size and rate so a room cannot be flooded.
- Offline copies: if you install the app or open a game, your browser keeps copies of the site's public pages and games so they work offline. Nothing you type is among them.
The privacy page has the full detail.
Who else is involved
- Cloudflare — hosting, databases and the online game server. All traffic is HTTPS.
- Google — sign-in, and Google Analytics for aggregate traffic.
- LLM7.io — the default chat model, reached from your browser. Any other model service is one you choose yourself.
Reporting a security problem
If you find a vulnerability, please email eric.varney@yahoo.com with "Security" in the subject, and give a reasonable chance to fix it before making it public. There is no paid bug bounty, but reports are read, answered and credited if you would like. The same contact is published at /.well-known/security.txt.
Last reviewed 30 September 2026.