Privacy Policy

Last updated: 2 October 2026

Ome.gg is operated by Eastwood Media, a company incorporated in the Republic of South Africa ("we", "us", "our"). This Privacy Policy explains how we collect, use, share, and protect personal data when you access or use the website located at https://ome.gg and any associated services ("Service").

We've built Ome.gg to be anonymous by default: you can use the Service without providing your real name, and you can stop using it and delete your data at any time. This policy explains how that works and what choices you have.

This Privacy Policy forms part of our Terms of Service and should be read alongside our Community Guidelines and Cookie Policy.

1. Who we are and how to contact us

Data Controller: Eastwood Media, Republic of South Africa.

General privacy contact: [email protected]

Data Protection enquiries / requests under GDPR, UK GDPR, CCPA and similar laws: [email protected]

EU / UK data protection contact: For matters under the GDPR or UK GDPR, including any enquiry that would otherwise be directed to an Article 27 representative, contact us at [email protected].

You have the right to lodge a complaint with the supervisory authority in your country. In South Africa, that is the Information Regulator (South Africa) — inforegulator.org.za. EU users may complain to their local data protection authority.

2. What information we collect

2.1. Information you provide directly

  • Auto-generated handle and avatar. We generate these for you; no real name is required.
  • Email address (optional). Only if you choose to link an account to save your profile across sessions or devices.
  • Profile preferences. Gender, year of birth (for 18+ verification only — not stored as a date), interests/tags you select, language preference.
  • Public profile information (optional). If you link an email address, your account gets a public profile page at ome.gg/@yourhandle. You may add a display name, a short bio, and a location. This information is public by design: anyone with the link can read it without an account, and search engines may index and cache it. Your handle, avatar, chosen interests and join month appear there too. Only add what you're comfortable making public. You can hide the entire page at any time under Settings → Privacy, and you can clear any field.
  • Content you transmit. Text messages sent in random chat, in public chatrooms, and in DMs. Call audio and video (available between friends) is transmitted in real time and not recorded by default (see section 4).
  • Public chatroom messages. Messages you post in a public chatroom are visible to everyone in that room, including people who join later and people who read the room without joining. Unlike random chat, these messages are stored as the room's history so the conversation persists (see section 8).
  • Reports. When you report another User, we collect the report contents, the reason, and the related conversation context.
  • Support communications. Messages you send us via [email protected] or other channels.

2.2. Information we collect automatically

  • IP address. Used to derive approximate country (for matching and abuse prevention), enforce sanctions compliance, and detect abuse patterns. We do not derive precise location.
  • Device and connection data. Browser type, operating system, screen size, language settings, time zone, referring URL, pages visited, session duration. Used for service operation, security, and analytics.
  • Device fingerprint. A hashed signature derived from browser characteristics, used to detect ban evasion and abuse. We do not use this to identify you across other websites.
  • Cookies and similar technologies. See section 7.

2.3. Information about User Content (moderation)

  • Text content. Messages you send through random chat, public chatrooms, DMs and group chats are processed by automated moderation systems to detect prohibited content. Random-chat and public-chatroom messages are stored for 90 days, so a report can be reviewed with its context, and then deleted; messages flagged by moderation, and chats someone reported, are kept for 12 months. DMs and group chats are stored as your conversation history. See section 8 for every period.
  • Public profile text. Display name, bio and location are checked by the same automated moderation systems when you save them, and are reviewable by our moderators if reported.
  • Call content. Voice and video calls between friends are never recorded, transcribed or stored. We keep a record of the call itself (who called whom, when, and for how long) in the conversation (see section 4).
  • Match metadata. We log the fact that two Users were matched, the duration, and the filters applied. This is used for abuse investigation and service operation.

2.4. Information from third parties

  • Authentication providers. If we add social or magic-link login, we receive the email address and basic profile information from the provider.
  • Payment processors (future). If we add paid features, payment processors will share transaction confirmations with us (but never card numbers).
  • Ad partners. If you click on an ad, we may receive the click event but not your activity on the advertiser's site.

3. Why we use your information and our legal basis

For Users in the EU, EEA, UK, or other GDPR-equivalent jurisdictions, we are required to identify a legal basis for each processing activity. The table below summarizes purposes and bases:

PurposeLegal basis (GDPR Art. 6)
Provide the Service: matching, chat, DMs, friendsContract (Art. 6(1)(b))
Maintain account, send service notificationsContract (Art. 6(1)(b))
Moderate content via automated systemsLegitimate interests (Art. 6(1)(f)) — protecting Users from harm
Review reports, suspend/ban UsersLegitimate interests (Art. 6(1)(f)) — community safety
Detect and prevent abuse, fraud, ban evasionLegitimate interests (Art. 6(1)(f)) — platform integrity
Comply with legal obligations (e.g. NCMEC reporting, law enforcement requests)Legal obligation (Art. 6(1)(c))
Analyze service usage in aggregateLegitimate interests (Art. 6(1)(f)) — improving the Service
Advertising via third-party partners (non-essential cookies)Consent (Art. 6(1)(a))
Optional features (e.g. email account linkage)Consent (Art. 6(1)(a))

Where we rely on consent, you can withdraw it at any time (see section 9). Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

4. Voice and video calls — what happens to your audio

Calls are available only between Users who have accepted each other as friends. Random matching with a stranger uses your camera and microphone only in random video chat, which you enter deliberately from its own start screen; random text chat never does. Because live audio and video carry a higher privacy risk than text, we explain them separately.

  • Real-time transmission only. Audio and video are transmitted peer-to-peer via WebRTC between you and the friend you are on a call with. Our servers relay the call (via TURN) only when a direct peer connection is not possible.
  • No recording. We do not record, transcribe or store the audio or video of calls, and nothing of it is kept after the call ends. What we keep is the call record: who called whom, when, and how long it lasted.
  • Reports about calls. Because calls are never recorded, a report about a call is reviewed from the call record, the conversation around it and the accounts involved, not from the call itself.
  • You may not record other Users. As stated in our Terms of Service, you are prohibited from recording, screenshotting, or otherwise capturing another User's audio without their consent. We will act on reports of unauthorized recording.
  • Random video chat runs on a shared network. When you choose random video chat, your browser connects directly to a shared video-chat network used by Ome.gg and a number of partner chat sites, and you may be matched with visitors of those sites as well as Ome.gg. Video and audio flow peer-to-peer between you and the other person; as with any direct connection, their device can see your IP address. The network's signalling servers see your IP address, country, and the profile you enter for matching (gender, age, who you want to meet); they do not receive your Ome.gg account or handle. Text messages and reactions exchanged during a video chat travel directly between the two browsers and are not stored. You must be 18 or older to use random video chat.
  • Blocking in random video chat. To keep two people from being matched again, the network keeps a random identifier that your browser generates for video chat (it identifies nothing else, and clearing your site data resets it). When you block someone, or report them (a report always blocks), the network stores the other person's identifier for as long as the block lasts, which is indefinitely, and their IP address for 24 hours.
  • Reports in random video chat. If you report someone, or someone reports you, a single still frame of the reported video, both participants' IP addresses and countries are stored by the network's moderation team to review the report, and a ban issued there applies across the network. The frame is deleted 30 days after the report has been reviewed. Reports that were dismissed are deleted 90 days after review; reports that led to a ban are kept for 365 days after review, or for as long as the ban is still active; open reports are kept until reviewed. Temporary bans are removed 90 days after they expire.
  • Two-party-consent jurisdictions. In some jurisdictions (including California, Florida, Illinois, and several other US states), recording another User without consent may be a criminal offense. By using calls you confirm that your participation is lawful in your jurisdiction.

5. Automated decision-making and AI moderation

We use automated systems (including AI classifiers) to:

  • Block messages that contain CSAM, threats, doxxing, or other prohibited content before they are delivered to other Users.
  • Flag conversations for human review.
  • Detect and limit accounts engaging in abuse patterns.

These automated systems can result in decisions that significantly affect you, including suspension or termination of your account. Under GDPR Article 22, you have the right to:

  • Request human review of an automated decision that affects you. Contact [email protected] with details of the decision and your account.
  • Express your point of view and contest the decision.
  • Receive an explanation of how the decision was made, to the extent we can provide one without compromising the integrity of the moderation system.

Our automated moderation uses three providers. OpenAI's moderation API scores the text of messages for prohibited content. TypeSafe reviews the conversation attached to a report and estimates which rule, if any, it breaks. Google's Gemini model, reached through OpenRouter, writes a one-line summary of a report for our moderators. We share message content with these providers only for the purpose of moderation, under contractual data-protection terms. The report review and summaries only help our moderators order and read reports; they do not ban anyone by themselves.

6. Sharing your information

We share your information only as described below. We do not sell your personal information as defined by the California Consumer Privacy Act or similar laws.

6.0. Information you publish yourself

Two parts of the Service are public by design, and what you put in them is not shared by us so much as published by you:

  • Your public profile at ome.gg/@yourhandle is readable by anyone, including people without an account, and may be indexed and cached by search engines. Once a page has been indexed or copied, we cannot remove those third-party copies — deleting a field removes it from our Service only. Hide the page entirely under Settings → Privacy.
  • Public chatrooms show your handle, avatar and messages to everyone in the room, and recent history is readable by anyone before they join. Treat anything you post there as public.

6.1. Service providers (processors)

We share data with vendors who help us operate the Service. Each is contractually bound to use data only for the agreed purpose. Categories include:

CategoryExample providers (subject to change)
Hosting and infrastructureDigitalOcean, Cloudflare
Database and storageSelf-hosted on DigitalOcean
Email deliveryPostmark, SendGrid, or similar
Content moderationOpenAI (moderation API), TypeSafe (report review), Google Gemini through OpenRouter (report summaries)
GIF searchKLIPY (reaction clips in messages)
Age checksDidit (an ID document and selfie check, only when we offer one to someone appealing an age-related ban)
AnalyticsGoogle Analytics 4
Error monitoringSentry or similar
AdvertisingEzoic, Google AdSense, or direct ad partners (only with your consent for non-essential cookies)

A current list of sub-processors is available at ome.gg/sub-processors and is updated when material changes occur.

6.2. Other Users

  • Your handle, avatar, gender (if selected), and online status are visible to Users you are matched with or who have added you as a friend.
  • Messages you send to a matched User or friend are obviously visible to that User.
  • We do not share your email, IP address, or other technical data with other Users.

6.3. Law enforcement, courts, and regulators

We may disclose information when we believe in good faith that disclosure is:

  • Required by law, subpoena, court order, or government request;
  • Necessary to investigate or prevent fraud, security incidents, or other illegal activity;
  • Necessary to protect the rights, property, or safety of Eastwood Media, our Users, or the public.

6.4. NCMEC and child safety organizations

If we detect or receive a credible report of child sexual abuse material (CSAM), child exploitation, or grooming behavior on the Service, we will:

  • Preserve the content and associated User data;
  • Report to the National Center for Missing & Exploited Children (NCMEC) in the United States and to applicable authorities in other jurisdictions;
  • Cooperate with subsequent law enforcement investigations.

This is a mandatory disclosure category and overrides anonymity protections in this Policy.

6.5. Business transfers

If we are involved in a merger, acquisition, financing, asset sale, or bankruptcy, your information may be transferred to the successor entity. We will notify Users of any such transfer involving material changes to data handling.

6.6. Aggregated and de-identified data

We may create and share aggregated or de-identified data that cannot reasonably be linked back to you (for example, total active users by country).

7. Cookies and similar technologies

We use cookies and similar technologies to:

  • Essential operation: keep you signed in to your anonymous session, remember filters, maintain security.
  • Analytics: Google Analytics 4 runs on every page to show us, in aggregate, how the Service is used (pages visited, device type, approximate location derived from your IP address). It sets its own cookies (_ga, _ga_*).
  • Advertising: we don't show third-party ads today. If we add them, advertising cookies will be set only with your consent where the law requires it.

Our cookie notice tells you about these cookies on your first visit. You can block or delete cookies in your browser settings, and opt out of Google Analytics with Google's browser add-on (see the Cookie Policy). Disabling essential cookies may affect functionality.

A full list and detail of each cookie is in our Cookie Policy.

8. Data retention

We retain data only as long as necessary for the purposes described in this Policy. Specific retention periods:

Data typeRetention period
Account without an email (handle, avatar, settings)Until you delete it in Settings. Accounts are not deleted automatically for inactivity
Linked account (with email)Until you delete your account
Direct messages and group chats, with their photos and videosDeleting a conversation clears it from your view only; the other people keep their copy. A conversation is deleted for everyone 12 months after its last message, and a one-to-one conversation also when either account is deleted. A photo or video that was unsent or removed can no longer be opened from our servers, and is deleted with its conversation
Random chat text content90 days, then deleted. Messages flagged by moderation, and chats someone reported, are kept for 12 months for review
Public chatroom messages90 days as the room's history, then deleted. Messages flagged by moderation or removed by a moderator are kept for 12 months for review
Automated moderation scores (with a short excerpt of the message)12 months
Public profile fields (display name, bio, location)Until you clear them or delete your account. Copies cached or indexed by third parties are outside our control
Usernames you have released by renamingIndefinitely, so old profile links keep working and nobody else can claim your former handle
Call audio and videoNever recorded or stored. The call record (who, when, how long) is kept with the conversation
Random video chat: video, audio, text and reactionsNot retained; they travel peer-to-peer. A report captures one still frame of the reported video, kept by the network for 30 days after the report is reviewed
Random video chat: reports (frame, both IP addresses and countries)Until reviewed; then 90 days if dismissed, or 365 days if the report led to a ban (longer while the ban is active). Expired temporary bans are removed after 90 days
Random video chat: blocksThe blocked person's random video-chat identifier for as long as the block lasts (indefinitely); their IP address for 24 hours
Match metadata (who was matched, when, duration)12 months for abuse investigation
IP addresses and device fingerprintsWe do not store your full IP address. A network prefix of it, your browser type, your country and a one-way hash of the prefix and browser are kept with your account and its list of known devices until the account is deleted
Reports and moderation actionsThe report itself (who reported whom, when, why, and its automated review) is kept to recognise repeat abuse. The copy of the conversation attached to it is deleted after 12 months
Permanent ban records (fingerprint, IP subnet)Indefinitely, for ban enforcement
CSAM-related evidenceIndefinitely, as legally required, in a segregated preservation store accessible only to designated compliance personnel
Age check results (whether you are 18 or older, your year of birth, the date)With your account until it is deleted. We never receive the ID document or the selfie; Didit processes them under its own privacy terms
Support communicationsUntil you ask us to delete them

When data reaches the end of its retention period, we delete it or anonymize it so it can no longer be linked to you.

9. Your rights

The specific rights you have depend on where you live. We will respond to all valid requests within the time required by law (typically 30 days under GDPR, 45 days under CCPA).

To exercise any of these rights, email [email protected] with details of your request. We may ask for information to verify your identity, especially for anonymous accounts.

9.1. If you are in the EU, EEA, UK, or Switzerland (GDPR / UK GDPR)

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: request correction of inaccurate data.
  • Right to erasure ("right to be forgotten"): request deletion of your data. Note that some data (e.g. ban records, CSAM evidence) cannot be deleted due to legal obligations.
  • Right to restriction: request that we limit how we process your data in certain situations.
  • Right to data portability: request your data in a machine-readable format.
  • Right to object: object to processing based on our legitimate interests, including profiling.
  • Right to withdraw consent: withdraw consent at any time where processing is based on consent.
  • Right to human review of automated decisions: see section 5.
  • Right to lodge a complaint with your local data protection authority.

9.2. If you are in California (CCPA / CPRA)

  • Right to know what personal information we collect, the categories of sources, the business purposes, and the categories of third parties with whom we share.
  • Right to delete your personal information, subject to exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing of personal information. We do not sell personal information, but we may share for cross-context behavioral advertising if you have consented to advertising cookies. You can opt out via cookie settings or by emailing [email protected].
  • Right to limit use of sensitive personal information.
  • Right to non-discrimination for exercising these rights.

9.3. If you are in other US states (Colorado, Connecticut, Virginia, Utah, Texas, Oregon, etc.)

You have rights substantially similar to California residents, including the right to access, delete, correct, port, and opt out of targeted advertising and sale. The specific rights and procedures vary by state. Contact [email protected] for state-specific assistance.

9.4. If you are elsewhere

Many other jurisdictions have similar rights. Even where law does not specifically require it, we will honor reasonable access and deletion requests on a best-efforts basis.

9.5. Self-service options

You can do the following directly from in-app Settings without contacting us:

  • Delete your account and associated data
  • Delete individual DMs or conversations
  • Unfriend or block other Users
  • Edit your profile preferences
  • Manage cookie consent (via the cookie banner)
  • Adjust your privacy filters

10. International data transfers

We are based in South Africa, and our infrastructure providers may be located in the EU, the United States, the United Kingdom, and other jurisdictions. When we transfer personal data outside the EEA/UK to a country not subject to an adequacy decision, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • UK International Data Transfer Agreement or UK Addendum to SCCs for UK data;
  • Other safeguards as appropriate.

For details about specific transfers, contact [email protected].

11. Security

We take reasonable technical and organizational measures to protect your information, including:

  • TLS encryption for all data in transit;
  • Encryption at rest for stored data including DMs;
  • Access controls and least-privilege principles for our personnel;
  • Regular security reviews and dependency updates;
  • Hashed storage of device fingerprints;
  • Isolated infrastructure for sensitive evidence preservation.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to minimize risk.

Data breach notification. If we become aware of a personal data breach that is likely to result in risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours (as required under GDPR Article 33);
  • Notify affected Users without undue delay where the breach is likely to result in high risk to their rights and freedoms.

12. Children

The Service is strictly for Users aged 18 and over. We do not knowingly collect personal data from anyone under 18.

If we become aware that a User is under 18, we will:

  • Terminate the account immediately;
  • Delete any personal data we have collected from them, except where preservation is required for safety or legal reasons;
  • Cooperate with parents, guardians, and authorities investigating the matter.

If we close an account because its User appears to be under 18 and they tell us they are an adult, we may offer them an ID check through our provider Didit. Didit checks an identity document and a selfie; we receive only whether the person is 18 or older and their year of birth, never the document or the selfie. Taking the check is optional; without it the account stays closed.

If you are a parent or guardian and you believe your child has provided personal data to us, contact [email protected] immediately.

13. Do Not Track and Global Privacy Control

Our Service responds to the Global Privacy Control (GPC) signal where applicable. If you send a GPC signal, we will treat it as a request to opt out of any sale or sharing of personal information for advertising purposes.

The "Do Not Track" browser header is not a universal standard, and most websites do not honor it. We currently do not respond to DNT signals but do honor GPC.

14. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be:

  • Notified by updating the "Last updated" date above;
  • Where reasonably practicable, by in-app notice or by email to Users who have linked an email;
  • Effective 14 days after posting, except where immediate effect is required by law.

For material changes that would expand our use of previously collected personal data, we will obtain consent where required by applicable law.

15. Contact

Privacy questions, requests, or complaints:

Eastwood Media
Republic of South Africa

Supervisory authority (South Africa): Information Regulator (South Africa) — inforegulator.org.za

Privacy Policy | Ome.gg