OMLA has been shut down. The OMLA license and registry were never published and not used. This site is preserved as a historical record only.

Privacy Policy

How the Open Model Licensing Association ("OMLA," "we," "us," or "our") collects, uses, discloses, retains, and protects personal data, and the rights you have over it.

Version 3.0 — Effective 2026-07-18. This version reflects the OMLA v1 pivot: the site is now static HTML, a signed public registry, and two browser-only tools, with no accounts, no database, and no authentication provider. Earlier versions described a product with logins and dashboards that no longer exists.

Translations are provided for convenience; the English version governs.

In short. OMLA is a static website that publishes a license, a public registry, and two tools that run entirely in your browser. We collect essentially nothing about you automatically, and what little we do collect — an email you choose to send us, or a manifest you choose to publish — you gave us on purpose. We do not operate accounts, logins, or a database of any kind, we do not sell or share personal information, we do not run advertising trackers, and we never hold, move, or custody money. Some registry data is intentionally public because creators choose to publish it — including royalty splits and payment pointers. Questions or requests: contactus@omla-ai.org.

Contents

  1. Who we are & controller identity
  2. Scope of this policy
  3. What OMLA does not collect
  4. Data we collect
  5. Purposes & legal bases (GDPR Art. 13/14)
  6. Public-by-design registry data
  7. Disclosure & sub-processors
  8. International data transfers
  9. Data retention
  10. Your rights (GDPR / UK GDPR)
  11. California privacy rights (CCPA/CPRA)
  12. Other US state privacy rights
  13. Cookies & similar technologies
  14. Children's privacy
  15. Security
  16. Automated decision-making
  17. Changes to this policy
  18. Contact & complaints

1. Who we are & controller identity

The Open Model Licensing Association ("OMLA") is an open, community-governed initiative organizing as a nonprofit in the State of Washington, USA. OMLA's 501(c) tax-exempt status is in progress. OMLA operates the website at omla-ai.org and the public model registry published from it.

For personal data described in this policy, OMLA acts as the data controller (and, under the CCPA/CPRA, as a "business"). OMLA determines the purposes and means of the processing described below.

A postal address for legal notices will be published here when OMLA's Washington registration is complete. You can contact us about privacy and data protection at:

If you are in the European Economic Area (EEA), the United Kingdom, or another jurisdiction that requires the appointment of a local representative or data-protection officer, and you wish to know whether one has been designated for your region, please contact contactus@omla-ai.org. Where a representative or data-protection officer is appointed, their details will be published here.

2. Scope of this policy

This policy applies to personal data we process about:

This policy works alongside our Terms of Service. It does not cover third-party websites or services that may be linked from our site; those are governed by their own privacy policies.

OMLA does not operate a chatbot or any conversational AI feature on this site.

3. What OMLA does not collect

This site has no accounts, no login, and no payment processing. Because of that design, the following does not exist at OMLA, ever:

An honest caveat about web hosting. Fetching any page or snapshot file from omla-ai.org is still an ordinary web request: our hosting provider (DreamHost) automatically generates transient server access logs that may include your IP address, timestamp, requested URL, and user-agent string. These logs exist for security and reliability, are kept for a short operational period on the host's standard rotation, and are not used to identify or profile visitors. If you want to read the registry with minimal footprint, download a snapshot once and work offline — the files are signed, so you do not need to trust the transport.

We cannot hand over, sell, leak, or be compelled to produce data we do not have. That is the point of the design.

4. Data we collect

We collect only what we need to publish the license and operate the registry. The categories below describe what we collect, and section 5 maps each category to a purpose and legal basis.

4.1 Account & authentication data

There are no user accounts. OMLA does not operate logins, passwords, sessions, or any authentication system, so there is nothing to disclose in this category.

4.2 Model registration & public-key data

4.3 Wallet addresses and payment pointers that creators choose to publish

4.4 Issue & correction reports

4.5 Server logs & technical data

4.6 Special categories & payment-card data

We do not intentionally collect special-category data (such as health, biometric, or precise-geolocation data) and we do not collect payment-card numbers, because OMLA never processes payments. Please do not submit such data to us. If you include it in an email to us, we process it only as needed to handle your request.

5. Purposes & legal bases (GDPR Art. 13/14)

For people in the EEA and the UK, the General Data Protection Regulation (GDPR) and UK GDPR require us to tell you why we process your data and the legal basis for doing so. The table below maps each data category to its purpose and basis. Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms.

Data categoryPurposeLegal basis
Model manifests, public keys & signatures (§4.2) Publish a verifiable public registry entry Consent (Art. 6(1)(a)) — you choose to submit it for publication; and legitimate interests (Art. 6(1)(f)) in a trustworthy registry
Published wallets & payment pointers (§4.3) Publish a payee's chosen payment pointers so licensees can settle directly Consent (Art. 6(1)(a)) — you choose to publish these. You can ask us to update or stop listing them.
Issue & correction emails (§4.4) Investigate and respond to reports about a registry listing Legitimate interests (Art. 6(1)(f)) in a trustworthy registry and in responding to inquiries
Server logs & technical data (§4.5) Operate, secure, debug, and protect the site against fraud and abuse Legitimate interests (Art. 6(1)(f)) in security and reliability
Local preference storage (§4.5) Remember your language and theme choice, and detect registry rollback Legitimate interests / strictly necessary preference and integrity functions (Art. 6(1)(f))
Any data needed to comply with the law Respond to lawful requests, subpoenas, and tax or regulatory obligations Legal obligation (Art. 6(1)(c))

Where processing is necessary for us to publish something you asked us to publish, providing the relevant data is a condition of that publication; if you do not provide it, we cannot publish your manifest or wallet. Where we rely on consent, you may withdraw it at any time (see section 10) without affecting processing already carried out.

Some data we hold is collected indirectly (GDPR Art. 14) — for example, where a manifest or lineage declaration submitted by another person names you. The source of such data is the person who submitted the manifest or lineage reference.

6. Public-by-design registry data

OMLA operates a public registry. Public fields let anyone verify a model's provenance, signature, declared lineage, and license version — and, once the License is operative, compute the royalty distribution and pay it. The public fields include model names and descriptions, content hashes, public keys, license version, lineage references, royalty splits, payee wallet addresses, and payment pointers. Publishing the split and the pointers is what makes direct settlement possible without OMLA in the middle.

Because the registry is a signed, hash-chained sequence of snapshots, a manifest you submitted may remain part of historical snapshots even after you ask us to stop listing it in the current registry, so that other models' declared lineage against yours stays verifiable. Where the law gives you a right to erasure, that right is balanced against these registry-integrity interests and legal obligations (see sections 9 and 10).

Guideline: do not send us private information for a public registry field. Registry values — including payment pointers — are served in signed snapshots that anyone may download and mirror, so treat them as permanently public. If you want privacy on a fiat rail, publish an invoicing URL as your pointer instead of account details.

7. Disclosure & sub-processors

We do not sell or share your personal information, and we do not disclose it for advertising. We disclose personal data only in the limited circumstances below.

7.1 Intentionally public registry data

As described in section 6, registry data that creators choose to publish is publicly accessible by design. This is a deliberate feature of an open registry, not an incidental disclosure.

7.2 Service providers (sub-processors)

We keep this list short on purpose. Our only current sub-processor is:

Sub-processorRoleLocation
DreamHost Static website and mailbox hosting — the HTML pages, the registry snapshot files, the associated transient server access logs described in section 4.5, and the omla-ai.org mailboxes (contactus@ and lloyd@ — the addresses on contact.html) that receive the correspondence described in section 4 United States

We do not use a database, an authentication provider, an analytics platform, advertising trackers, or a chatbot. We do not use a transactional-email service — replies to your emails come from our own inboxes, by hand. If we ever add a sub-processor, we will update this section first.

7.3 Legal & protective disclosures

We may disclose personal data where we believe in good faith it is necessary to: comply with a law, regulation, subpoena, court order, or other lawful request; enforce our Terms of Service or the OMLA Public License; investigate fraud, security, or abuse; or protect the rights, safety, or property of OMLA, our users, or the public. This includes a specific, named case: if we become aware that a published model was used to generate, or was designed or insufficiently tested against generating, child sexual abuse material, we report the manifest and all information we hold about its submission to the National Center for Missing & Exploited Children's CyberTipline and/or law enforcement — as required by 18 U.S.C. § 2258A where it applies, and voluntarily in any event — as described in our Terms of Service §6.3.

7.4 Business changes

If OMLA reorganizes, merges with, or transfers its activities to another nonprofit or successor entity, registry and manifest data may be transferred as part of that change, subject to this policy or a successor policy with equivalent protections.

8. International data transfers

OMLA is based in the United States, and our one sub-processor (DreamHost) processes data in the United States. If you are located in the EEA, the UK, Switzerland, or another region with data-transfer restrictions, your personal data will be transferred to and processed in the United States.

Where applicable law requires a transfer mechanism, OMLA will use an available lawful mechanism appropriate to the relevant service and transfer, which may include the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (or UK IDTA), another recognized adequacy or contractual mechanism, and supplementary technical measures such as encryption in transit. Contact contactus@omla-ai.org to ask which mechanism applies to a particular transfer or to request available documentation.

9. Data retention

We keep personal data only as long as needed for the purposes in section 4, or as required by law. Indicative periods:

When we no longer need personal data, we delete it or irreversibly anonymize it, except where retention is required for registry integrity or by law.

10. Your rights (GDPR / UK GDPR)

If you are in the EEA, the UK, or another jurisdiction with comparable rights, you have the right to:

How to exercise your rights. Email contactus@omla-ai.org with your request. We may need to verify your identity before acting. We aim to respond within one month, and we will tell you if we need an extension (up to a further two months) for complex requests, as the GDPR permits. Exercising your rights is free unless a request is manifestly unfounded or excessive.

Limits. Some data is intentionally public and supports registry integrity (section 6). We may not be able to fully erase or remove such data where doing so would undermine the integrity of the registry or where we are legally required to keep it; in those cases we will explain what we can and cannot do.

Right to complain to a supervisory authority. You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement, or — in the UK — with the Information Commissioner's Office (ICO). We would, however, appreciate the chance to address your concerns first: please contact contactus@omla-ai.org.

11. California privacy rights (CCPA/CPRA)

This section applies to California residents and supplements the rest of this policy. It is our notice at or before the point of collection.

11.1 Categories of personal information collected

In the past 12 months we have collected the following categories of personal information, as defined by the CCPA/CPRA: identifiers (such as an email address you send us, and a public key or wallet address you choose to publish); and internet or other electronic network activity (transient server logs, including IP address and user-agent). We do not collect commercial information about licensees or payments — settlement happens entirely outside OMLA, and we have no account system to hold identifiers in the first place.

11.2 Sources, purposes, and recipients

We collect this information directly from you, automatically from your use of the site, and indirectly from others (for example, a lineage declaration that names you). We use it for the purposes described in sections 3, 4, and 5. We disclose it only as described in section 7 — to our one sub-processor and as legally required.

11.3 We do not sell or share personal information

OMLA does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have not sold or shared personal information in the preceding 12 months. We do not use or disclose sensitive personal information for purposes that would trigger a right to limit; we collect only what is described above.

11.4 Your California rights

11.5 How to exercise California rights

Submit a request by emailing contactus@omla-ai.org. We will verify your request as reasonably as we can given that we hold no account records to match it against. You may use an authorized agent to submit a request on your behalf; we may ask the agent for proof of authorization and may ask you to confirm the agent's authority directly.

12. Other US state privacy rights

Residents of other US states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect — may have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. OMLA does not engage in targeted advertising, sell personal data, or carry out profiling that produces legal or similarly significant effects (see section 16). To exercise any applicable rights, or to appeal a decision on a request, contact contactus@omla-ai.org.

13. Cookies & similar technologies

OMLA uses a small, fixed set of cookies and local storage — all strictly necessary or preference-related, none of it advertising or tracking. There is no cookie banner because there is nothing to consent to beyond ordinary site preferences, but for full transparency, here is everything the site sets:

NameTypePurposeExpiry
omla_langFirst-party cookieRemembers your language choice (only English is currently published)365 days
themelocalStorageRemembers light/dark theme preferenceUntil you clear browser storage
omla.registry.highwater.*localStorage, registry.html onlyClient-side anti-rollback check: detects if the registry ever appears to revert to an older, already-superseded sequenceUntil you clear browser storage

None of these are shared with OMLA or any third party — they live entirely in your browser. We do not use advertising trackers, cross-site profiling, session-replay tools, or any authentication/session cookie, because there is no login to maintain a session for.

14. Children's privacy

OMLA is not intended for children, and the Terms of Service separately require users of the Service to be at least 16. For data-collection purposes, we do not knowingly collect personal data from children under 16 (in the EEA/UK) or under 13 (in the United States, per COPPA). If you believe a child has provided us with personal data, contact contactus@omla-ai.org and we will delete it promptly, consistent with our registry-integrity and legal obligations.

15. Security

We take reasonable technical measures to protect personal data and the integrity of the registry, including:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach that is likely to affect you, we will notify affected people and, where required, the relevant supervisory authorities, within the timeframes the law requires.

16. Automated decision-making

OMLA makes no automated decisions about people. There is no registry-integrity status field, no automated flagging, and no algorithmic scoring on this site. The resolver (resolver.html) is deterministic arithmetic that a licensee runs on their own machine against public data; OMLA does not run it on anyone's behalf, and it processes no personal characteristics — only manifest and revenue figures the user supplies to their own copy of the code. To ask a question about how any part of the registry works, contact contactus@omla-ai.org.

17. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the version and effective date at the top of this page and, where appropriate, post a notice on the site. Your continued use of the site after an update takes effect means you accept the revised policy. Prior versions are available on request.

Version history: 3.0 (effective 2026-07-18) — v1 pivot: static site, no accounts, no database. Earlier versions (May–July 2026) described the retired accounts-and-dashboards platform and are available on request.

18. Contact & complaints

For any privacy question, request, or complaint:

If you are in the EEA or UK, you also have the right to lodge a complaint with your local data-protection supervisory authority (in the UK, the Information Commissioner's Office), as described in section 10. We would welcome the opportunity to resolve your concern first.

Translations of this policy are provided for convenience; the English version governs. Where applicable mandatory local law requires otherwise, that law prevails to the extent of any conflict.