Privacy Policy
How the Open Model Licensing Association ("OMLA," "we," "us," or "our") collects, uses, discloses, retains, and protects personal data, and the rights you have over it.
Version 3.0 — Effective 2026-07-18. This version reflects the OMLA v1 pivot: the site is now static HTML, a signed public registry, and two browser-only tools, with no accounts, no database, and no authentication provider. Earlier versions described a product with logins and dashboards that no longer exists.
Translations are provided for convenience; the English version governs.
In short. OMLA is a static website that publishes a license, a public registry, and two tools that run entirely in your browser. We collect essentially nothing about you automatically, and what little we do collect — an email you choose to send us, or a manifest you choose to publish — you gave us on purpose. We do not operate accounts, logins, or a database of any kind, we do not sell or share personal information, we do not run advertising trackers, and we never hold, move, or custody money. Some registry data is intentionally public because creators choose to publish it — including royalty splits and payment pointers. Questions or requests: contactus@omla-ai.org.
Contents
- Who we are & controller identity
- Scope of this policy
- What OMLA does not collect
- Data we collect
- Purposes & legal bases (GDPR Art. 13/14)
- Public-by-design registry data
- Disclosure & sub-processors
- International data transfers
- Data retention
- Your rights (GDPR / UK GDPR)
- California privacy rights (CCPA/CPRA)
- Other US state privacy rights
- Cookies & similar technologies
- Children's privacy
- Security
- Automated decision-making
- Changes to this policy
- Contact & complaints
1. Who we are & controller identity
The Open Model Licensing Association ("OMLA") is an open, community-governed initiative organizing as a nonprofit in the State of Washington, USA. OMLA's 501(c) tax-exempt status is in progress. OMLA operates the website at omla-ai.org and the public model registry published from it.
For personal data described in this policy, OMLA acts as the data controller (and, under the CCPA/CPRA, as a "business"). OMLA determines the purposes and means of the processing described below.
A postal address for legal notices will be published here when OMLA's Washington registration is complete. You can contact us about privacy and data protection at:
- General enquiries and legal / data-protection requests: contactus@omla-ai.org
If you are in the European Economic Area (EEA), the United Kingdom, or another jurisdiction that requires the appointment of a local representative or data-protection officer, and you wish to know whether one has been designated for your region, please contact contactus@omla-ai.org. Where a representative or data-protection officer is appointed, their details will be published here.
2. Scope of this policy
This policy applies to personal data we process about:
- visitors to omla-ai.org;
- people who submit a model manifest for publication in the registry;
- people identified in a model's declared lineage; and
- people who contact us by email.
This policy works alongside our Terms of Service. It does not cover third-party websites or services that may be linked from our site; those are governed by their own privacy policies.
OMLA does not operate a chatbot or any conversational AI feature on this site.
3. What OMLA does not collect
This site has no accounts, no login, and no payment processing. Because of that design, the following does not exist at OMLA, ever:
- No accounts. There are no user accounts, usernames, passwords, or sessions anywhere on this site.
- No usage data. OMLA runs no server-side application logic beyond serving static files. What models you run, how much, and for whom never reaches us.
- No payer identities. Reading the license, browsing the registry, or downloading a snapshot requires no account, no API key, and no registration. We do not know who OMLA's commercial licensees are.
- No payment data. Royalties, once the License is operative, are paid peer-to-peer over pointers creators publish themselves. OMLA receives no payment records, settlement confirmations, invoices, or transaction references, from either side.
- No revenue or cost figures. The royalty is self-assessed by the payer from its own books; those figures are never submitted to OMLA.
- No secret keys, ever. The signing-key and wallet-address tools on publish.html run entirely in your browser. Your private key is encrypted on your own device before it touches disk and is never transmitted anywhere — not to OMLA, not to anyone.
An honest caveat about web hosting. Fetching any page or snapshot file from omla-ai.org is still an ordinary web request: our hosting provider (DreamHost) automatically generates transient server access logs that may include your IP address, timestamp, requested URL, and user-agent string. These logs exist for security and reliability, are kept for a short operational period on the host's standard rotation, and are not used to identify or profile visitors. If you want to read the registry with minimal footprint, download a snapshot once and work offline — the files are signed, so you do not need to trust the transport.
We cannot hand over, sell, leak, or be compelled to produce data we do not have. That is the point of the design.
4. Data we collect
We collect only what we need to publish the license and operate the registry. The categories below describe what we collect, and section 5 maps each category to a purpose and legal basis.
4.1 Account & authentication data
There are no user accounts. OMLA does not operate logins, passwords, sessions, or any authentication system, so there is nothing to disclose in this category.
4.2 Model registration & public-key data
- Model manifests. If you publish a model, you email a signed manifest to contactus@omla-ai.org (see publish.html) — model name and description, a content hash (e.g., SHA-256) of the model weights, the license version, declared lineage, the declared royalty split, and the payee wallet address(es) and payment pointers you choose to publish.
- Your public signing key. The Ed25519 public key you sign your manifest with, and the signature itself. We never ask for, receive, or store your private key — the key-generation tool on publish.html generates and encrypts it entirely in your browser, and custody of it is solely your responsibility.
4.3 Wallet addresses and payment pointers that creators choose to publish
- Payee wallets and public payment pointers. When a creator publishes a model, they include a wallet address and one or more payment pointers (for example a Lightning address, a crypto address, a Stripe Payment Link, a PayPal.Me link, or an invoicing URL or email) so that commercial licensees can pay them directly. These pointers are provided by the creator for the express purpose of being published in the public registry and its mirrored snapshots. The publish.html tool can check a pointer's format for you, entirely in your browser, before you send it — but OMLA does not verify that a pointer belongs to you, does not transact against it, and never settles on your behalf. Treat every pointer you publish as permanently public; if you want privacy on a fiat rail, publish an invoicing URL rather than account details.
4.4 Issue & correction reports
- Emails about a listing. There is no complaint form and no automated registry-integrity pipeline in this version of the site. If you believe something is wrong with a published manifest — a hijacked wallet, misattributed lineage, or similar — you email us (see contact.html), and we process whatever you choose to include: your name, your email, and your description of the issue, the same way we would handle any other email.
4.5 Server logs & technical data
- Server access logs. Our website host (DreamHost) automatically generates logs that may include IP address, date/time, requested URL, HTTP status, referrer, and user-agent string. These support security, abuse prevention, and reliability.
- Local preference storage. A first-party
omla_langcookie (up to 365 days) that remembers your language choice, even though only English is currently published, and athemevalue in your browser's localStorage that remembers light/dark mode. On the registry page only, a small localStorage value records the last registry sequence number your browser has seen, purely as a client-side check against the registry ever appearing to roll back to an older state — it is a technical safeguard, not personal data, and nothing is sent to OMLA because of it. See section 13. We do not use advertising trackers, third-party analytics, cross-site profiling, or session-replay tools.
4.6 Special categories & payment-card data
We do not intentionally collect special-category data (such as health, biometric, or precise-geolocation data) and we do not collect payment-card numbers, because OMLA never processes payments. Please do not submit such data to us. If you include it in an email to us, we process it only as needed to handle your request.
5. Purposes & legal bases (GDPR Art. 13/14)
For people in the EEA and the UK, the General Data Protection Regulation (GDPR) and UK GDPR require us to tell you why we process your data and the legal basis for doing so. The table below maps each data category to its purpose and basis. Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms.
| Data category | Purpose | Legal basis |
|---|---|---|
| Model manifests, public keys & signatures (§4.2) | Publish a verifiable public registry entry | Consent (Art. 6(1)(a)) — you choose to submit it for publication; and legitimate interests (Art. 6(1)(f)) in a trustworthy registry |
| Published wallets & payment pointers (§4.3) | Publish a payee's chosen payment pointers so licensees can settle directly | Consent (Art. 6(1)(a)) — you choose to publish these. You can ask us to update or stop listing them. |
| Issue & correction emails (§4.4) | Investigate and respond to reports about a registry listing | Legitimate interests (Art. 6(1)(f)) in a trustworthy registry and in responding to inquiries |
| Server logs & technical data (§4.5) | Operate, secure, debug, and protect the site against fraud and abuse | Legitimate interests (Art. 6(1)(f)) in security and reliability |
| Local preference storage (§4.5) | Remember your language and theme choice, and detect registry rollback | Legitimate interests / strictly necessary preference and integrity functions (Art. 6(1)(f)) |
| Any data needed to comply with the law | Respond to lawful requests, subpoenas, and tax or regulatory obligations | Legal obligation (Art. 6(1)(c)) |
Where processing is necessary for us to publish something you asked us to publish, providing the relevant data is a condition of that publication; if you do not provide it, we cannot publish your manifest or wallet. Where we rely on consent, you may withdraw it at any time (see section 10) without affecting processing already carried out.
Some data we hold is collected indirectly (GDPR Art. 14) — for example, where a manifest or lineage declaration submitted by another person names you. The source of such data is the person who submitted the manifest or lineage reference.
6. Public-by-design registry data
OMLA operates a public registry. Public fields let anyone verify a model's provenance, signature, declared lineage, and license version — and, once the License is operative, compute the royalty distribution and pay it. The public fields include model names and descriptions, content hashes, public keys, license version, lineage references, royalty splits, payee wallet addresses, and payment pointers. Publishing the split and the pointers is what makes direct settlement possible without OMLA in the middle.
Because the registry is a signed, hash-chained sequence of snapshots, a manifest you submitted may remain part of historical snapshots even after you ask us to stop listing it in the current registry, so that other models' declared lineage against yours stays verifiable. Where the law gives you a right to erasure, that right is balanced against these registry-integrity interests and legal obligations (see sections 9 and 10).
Guideline: do not send us private information for a public registry field. Registry values — including payment pointers — are served in signed snapshots that anyone may download and mirror, so treat them as permanently public. If you want privacy on a fiat rail, publish an invoicing URL as your pointer instead of account details.
7. Disclosure & sub-processors
We do not sell or share your personal information, and we do not disclose it for advertising. We disclose personal data only in the limited circumstances below.
7.1 Intentionally public registry data
As described in section 6, registry data that creators choose to publish is publicly accessible by design. This is a deliberate feature of an open registry, not an incidental disclosure.
7.2 Service providers (sub-processors)
We keep this list short on purpose. Our only current sub-processor is:
| Sub-processor | Role | Location |
|---|---|---|
| DreamHost | Static website and mailbox hosting — the HTML pages, the registry snapshot files, the associated transient server access logs described in section 4.5, and the omla-ai.org mailboxes (contactus@ and lloyd@ — the addresses on contact.html) that receive the correspondence described in section 4 | United States |
We do not use a database, an authentication provider, an analytics platform, advertising trackers, or a chatbot. We do not use a transactional-email service — replies to your emails come from our own inboxes, by hand. If we ever add a sub-processor, we will update this section first.
7.3 Legal & protective disclosures
We may disclose personal data where we believe in good faith it is necessary to: comply with a law, regulation, subpoena, court order, or other lawful request; enforce our Terms of Service or the OMLA Public License; investigate fraud, security, or abuse; or protect the rights, safety, or property of OMLA, our users, or the public. This includes a specific, named case: if we become aware that a published model was used to generate, or was designed or insufficiently tested against generating, child sexual abuse material, we report the manifest and all information we hold about its submission to the National Center for Missing & Exploited Children's CyberTipline and/or law enforcement — as required by 18 U.S.C. § 2258A where it applies, and voluntarily in any event — as described in our Terms of Service §6.3.
7.4 Business changes
If OMLA reorganizes, merges with, or transfers its activities to another nonprofit or successor entity, registry and manifest data may be transferred as part of that change, subject to this policy or a successor policy with equivalent protections.
8. International data transfers
OMLA is based in the United States, and our one sub-processor (DreamHost) processes data in the United States. If you are located in the EEA, the UK, Switzerland, or another region with data-transfer restrictions, your personal data will be transferred to and processed in the United States.
Where applicable law requires a transfer mechanism, OMLA will use an available lawful mechanism appropriate to the relevant service and transfer, which may include the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (or UK IDTA), another recognized adequacy or contractual mechanism, and supplementary technical measures such as encryption in transit. Contact contactus@omla-ai.org to ask which mechanism applies to a particular transfer or to request available documentation.
9. Data retention
We keep personal data only as long as needed for the purposes in section 4, or as required by law. Indicative periods:
- Server access logs. Retained for a short operational period in line with our host's defaults and our security needs, then deleted or aggregated.
- Registry & manifest data. Retained for the integrity of the public registry and its signed, hash-chained sequence of snapshots. A published manifest may remain part of historical snapshots even after you ask us to stop listing it, so that other models' declared lineage against yours stays verifiable.
- Issue & correction emails. Retained for the duration of the matter plus a reasonable period to handle follow-up, recurrence, and legal obligations.
When we no longer need personal data, we delete it or irreversibly anonymize it, except where retention is required for registry integrity or by law.
10. Your rights (GDPR / UK GDPR)
If you are in the EEA, the UK, or another jurisdiction with comparable rights, you have the right to:
- Access — obtain confirmation of whether we process your data and a copy of it;
- Rectification — correct inaccurate or incomplete data;
- Erasure — ask us to delete your data ("right to be forgotten"), subject to the registry-integrity and legal limits in sections 6 and 9;
- Restriction — ask us to limit processing in certain circumstances;
- Data portability — receive the data you provided in a structured, commonly used, machine-readable format, and ask us to transmit it to another controller where technically feasible;
- Objection — object to processing based on legitimate interests; and
- Withdraw consent — where we rely on consent (for example, publishing a manifest, wallet, or payment pointers), withdraw it at any time, without affecting prior processing. Note that snapshots already downloaded and mirrored by third parties are outside our control.
How to exercise your rights. Email contactus@omla-ai.org with your request. We may need to verify your identity before acting. We aim to respond within one month, and we will tell you if we need an extension (up to a further two months) for complex requests, as the GDPR permits. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Limits. Some data is intentionally public and supports registry integrity (section 6). We may not be able to fully erase or remove such data where doing so would undermine the integrity of the registry or where we are legally required to keep it; in those cases we will explain what we can and cannot do.
Right to complain to a supervisory authority. You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement, or — in the UK — with the Information Commissioner's Office (ICO). We would, however, appreciate the chance to address your concerns first: please contact contactus@omla-ai.org.
11. California privacy rights (CCPA/CPRA)
This section applies to California residents and supplements the rest of this policy. It is our notice at or before the point of collection.
11.1 Categories of personal information collected
In the past 12 months we have collected the following categories of personal information, as defined by the CCPA/CPRA: identifiers (such as an email address you send us, and a public key or wallet address you choose to publish); and internet or other electronic network activity (transient server logs, including IP address and user-agent). We do not collect commercial information about licensees or payments — settlement happens entirely outside OMLA, and we have no account system to hold identifiers in the first place.
11.2 Sources, purposes, and recipients
We collect this information directly from you, automatically from your use of the site, and indirectly from others (for example, a lineage declaration that names you). We use it for the purposes described in sections 3, 4, and 5. We disclose it only as described in section 7 — to our one sub-processor and as legally required.
11.3 We do not sell or share personal information
OMLA does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months. We do not use or disclose sensitive personal information for purposes that would trigger a right to limit; we collect only what is described above.
11.4 Your California rights
- Right to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients;
- Right to delete personal information we have collected, subject to legal and registry-integrity exceptions;
- Right to correct inaccurate personal information;
- Right to opt out of the sale or sharing of personal information — although, as stated, we do not sell or share;
- Right to limit the use of sensitive personal information — we do not use sensitive personal information beyond what is permitted without a right to limit; and
- Right to non-discrimination — we will not deny you service, charge you a different price, or provide a different quality of service because you exercised your rights.
11.5 How to exercise California rights
Submit a request by emailing contactus@omla-ai.org. We will verify your request as reasonably as we can given that we hold no account records to match it against. You may use an authorized agent to submit a request on your behalf; we may ask the agent for proof of authorization and may ask you to confirm the agent's authority directly.
12. Other US state privacy rights
Residents of other US states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect — may have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. OMLA does not engage in targeted advertising, sell personal data, or carry out profiling that produces legal or similarly significant effects (see section 16). To exercise any applicable rights, or to appeal a decision on a request, contact contactus@omla-ai.org.
14. Children's privacy
OMLA is not intended for children, and the Terms of Service separately require users of the Service to be at least 16. For data-collection purposes, we do not knowingly collect personal data from children under 16 (in the EEA/UK) or under 13 (in the United States, per COPPA). If you believe a child has provided us with personal data, contact contactus@omla-ai.org and we will delete it promptly, consistent with our registry-integrity and legal obligations.
15. Security
We take reasonable technical measures to protect personal data and the integrity of the registry, including:
- Encryption in transit (TLS/HTTPS) for traffic to and from the site;
- A signed, hash-chained registry sequence — each published index links to the previous one and carries an Ed25519 signature from OMLA's registry key, so tampering or rollback is detectable (see registry.html); and
- Client-side key encryption. The signing-key tool on publish.html encrypts your private key in your own browser with AES-256-GCM, derived from your passphrase via PBKDF2-HMAC-SHA-256 (minimum 600,000 iterations), before it is ever written to disk. The unencrypted key is never transmitted anywhere.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach that is likely to affect you, we will notify affected people and, where required, the relevant supervisory authorities, within the timeframes the law requires.
16. Automated decision-making
OMLA makes no automated decisions about people. There is no registry-integrity status field, no automated flagging, and no algorithmic scoring on this site. The resolver (resolver.html) is deterministic arithmetic that a licensee runs on their own machine against public data; OMLA does not run it on anyone's behalf, and it processes no personal characteristics — only manifest and revenue figures the user supplies to their own copy of the code. To ask a question about how any part of the registry works, contact contactus@omla-ai.org.
17. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the version and effective date at the top of this page and, where appropriate, post a notice on the site. Your continued use of the site after an update takes effect means you accept the revised policy. Prior versions are available on request.
Version history: 3.0 (effective 2026-07-18) — v1 pivot: static site, no accounts, no database. Earlier versions (May–July 2026) described the retired accounts-and-dashboards platform and are available on request.
18. Contact & complaints
For any privacy question, request, or complaint:
- All requests — general, legal, and data protection: contactus@omla-ai.org
If you are in the EEA or UK, you also have the right to lodge a complaint with your local data-protection supervisory authority (in the UK, the Information Commissioner's Office), as described in section 10. We would welcome the opportunity to resolve your concern first.
Translations of this policy are provided for convenience; the English version governs. Where applicable mandatory local law requires otherwise, that law prevails to the extent of any conflict.