Privacy policy
Omerta Cortex LLC. Effective 25 September 2026.
This policy explains what Omerta Cortex LLC, a Wyoming limited liability company, collects about you, why, who else sees it, where it is kept and what you can do about it. It covers the website at www.joinomerta.com, the way people apply to join, OMERTÁ Access (the app for members of the room, on iPhone and on the web), the trips and houses the club runs, and the experiences members host for one another. It replaces the policy that was here before.
We wrote it in plain language on purpose. Plain language does not make it less binding, and it does not shrink your rights.
1. Who is responsible
The controller of your personal data is Omerta Cortex LLC ("Omertá", "we", "us"). Our registered address is 1309 Coffeen Avenue Ste 1200, Sheridan, WY 82801, United States.
For any question about this policy, or to exercise a right under it, write to contact@joinomerta.com. For a request to delete or erase your data, write to jeff@joinomerta.com. We reply within 30 days.
Omerta Cortex LLC is not established in the European Union or the United Kingdom and has not, at the date of this policy, appointed a representative there under Article 27 of the GDPR or the UK GDPR. We are assessing whether one is required. Until then, contact us directly at the addresses above; your rights are the same either way.
2. Who this policy is for
Members of Omertá live in many places, among them Germany, the Netherlands, Lithuania, Italy, Greece, Norway, the United Kingdom, Switzerland, Indonesia, Japan, Hong Kong, Argentina, Australia and the United States, including California and Hawaii. This policy applies wherever you are. Section 11 sets out the rights you have under the GDPR and the UK GDPR, section 12 the rights you have in California and other US states, and section 13 what applies in the other countries listed.
3. The website, and applying to join
If you only visit www.joinomerta.com, we collect very little.
The website is built and hosted on Webflow and served through Cloudflare's content delivery network. Like any host, they log the IP address, browser type and pages visited for each request and keep those logs for a short period under their own retention rules. The site sets the cookies Webflow needs to run. As of the date of this policy it runs no analytics or advertising script; if we add one, we will update this policy and, where the law requires it, ask for your consent first. You can block cookies in your browser and the site still works.
Applying to join. Whether you come to us from the website, from an invitation or through a member, the application is a Typeform form. It asks for your name, your email address, your phone number, your net worth and your gender, and whatever else you choose to write. We use what you give us to decide whether to invite you and to reply to you. Each application is recorded in Notion, which is the team's live record of who has applied and where each application stands, and the team is told about it in Slack, with your name and the details you gave. Amazon Web Services runs the automation that moves an application through these steps and sends our application email.
Application calls are recorded. If we go further, you book a call with us through Cal.com and the call is held on Cal Video. The call is recorded and transcribed, and an AI service run by Amazon Web Services, Amazon Bedrock, writes a summary of the transcript for the team. The recording, the transcript and the summary are kept with your application in Notion. By joining the call you consent to its being recorded and transcribed. If you would rather not be recorded, tell us before the call by replying to the booking email or by writing to contact@joinomerta.com, and the call will not be recorded.
Invitations to apply. We write to some people we would like to meet and invite them to apply. Those invitations go out from apply.joinomerta.com through Amazon Web Services (Amazon SES). If you would rather not hear from us, reply and say so, or write to contact@joinomerta.com, and we stop writing.
How long we keep an application. We keep your application, and the recording, transcript and summary of any call, while the network is evaluating it. You can ask us to delete all of it at any time by writing to jeff@joinomerta.com, and we confirm by reply. If you are invited, what you gave us becomes part of your member record.
Separately, we email companies about sponsoring the rotation, through Brevo. Those emails go to people at businesses, whose work contact details we found in a commercial business contact database or on the company's own website, and they are about sponsorship, not membership. If you would rather not hear from us, use the link in the email or reply and say so, and we stop writing.
4. The app: what we collect and why
Membership is by invitation, so everything below concerns people who are already in the room.
Your phone number. You sign in with it. Supabase Auth sends a six digit code to that number through Twilio Verify, by WhatsApp or by SMS, and the number is matched against the roster to open your profile. Your number is shown to other members only while the "Show my WhatsApp" switch in Settings is on. That switch is off until you turn it on.
Your profile. Your name, the city you are in now, one line about you, what you bring the room, your contribution for the year, your interests, your photo, and your Instagram and WhatsApp handles if you add them. You type all of this yourself and you can change it in Edit profile at any time. Your photo is stored in a private bucket and the app fetches it with a signed link that expires within hours, so it is never at a public address.
What you do in the room. The experiences you host or join, the names you put up for membership, how you vote on them, the comments you leave, the three referrals you make a year (a name, a city, an Instagram handle and why they belong), and any feedback you send from the app. When the concierge opens, the requests you send it and the city you send them from.
What stays on your phone. An email address if you add one in Settings, your notification and privacy switches, whether you have seen the introduction, your sign-in session, and a copy of the roster so the app opens offline. None of this is sent to us. If you turn on location, your phone's position is read once, on the device, to pick the nearest room city. The coordinates are not sent anywhere.
Device and log data. Our providers keep the ordinary logs of any internet service: your IP address, the time of a request and what was requested. Sign-in attempts are logged with the time and the outcome. When the map is open, your phone fetches map tiles from Esri, so Esri sees your IP address and the area of the map you are looking at. The app loads one typeface from Google Fonts, so Google sees your IP address when the app starts. We do not run analytics, advertising or tracking code in the app, we do not use any identifier for advertising, and we do not build profiles.
5. Trips and experiences, outside the app
When you book a trip or a stay at a headquarters with Omertá, we collect what the booking needs: your name as it appears on your passport, your date of birth and passport details where a flight, boat, helicopter or hotel requires them, your dietary needs, an emergency contact, your travel insurance details, and anything about your health or fitness that you choose to tell us so that we can keep you safe on an activity such as surfing, freediving, skydiving or a boat trip. We ask for health information only where it matters for safety, we use it for nothing else, and we delete it when the trip is over.
Payment for a trip is made outside the app, to Omertá or to the operator we name, through the payment method we agree with you at the time. We do not store card numbers. Invoices for trips are issued through Mercury, our banking provider, so Mercury sees your name, your email address, the amount and how you paid. We keep the invoice and the record of payment for our accounts.
An experience hosted by a member is arranged between you and that member. What you tell the host, and any payment you make to the host, is between the two of you and outside this policy, except for the RSVP and the seat count that the app records.
6. The data inventory
Category · Source · Purpose · Legal basis (GDPR and UK GDPR) · Retention · Shared with
Phone number · You, at sign-in · Sign-in, matching you to the roster, keeping the account secure · Contract, Article 6(1)(b); legitimate interests, Article 6(1)(f), for security · While you are a member; cleared from the roster row when you leave; sign-in logs up to 12 months · Supabase; Twilio; WhatsApp (Meta) when the code is sent that way; other members while "Show my WhatsApp" is on
Profile: name, city, line, what you bring, contribution, interests, photo, year joined · You · Running the room; showing you to other members · Contract, Article 6(1)(b) · While you are a member; name, city and join date kept afterwards as an alumni record until you ask for erasure · Supabase; other signed-in members
Instagram and WhatsApp handles; map pin · You · Letting members reach you and find you, at your choice · Consent, Article 6(1)(a), given through the switches in Settings and withdrawable there · While the switch is on and you are a member · Other signed-in members
Experiences you host or join · You · Organising the club's calendar · Contract, Article 6(1)(b) · While you are a member; RSVPs deleted when you leave; past experiences you hosted stay in the calendar history under your alumni name · Supabase; other members
Nominations, votes, comments · You · Deciding who joins the room · Contract, Article 6(1)(b); legitimate interests, Article 6(1)(f), in running a members' club · Votes and comments deleted when you leave; a nomination you made stays, attributed to your alumni name · Supabase; other members (who put the name up, the counts, the comments)
Referrals: another person's name, city, Instagram handle, why they belong · You, about someone else · Meeting the people members put forward · Legitimate interests, Article 6(1)(f), ours and the referred person's; we tell the referred person where their name came from when we contact them · Until the referral is decided, then 12 months; deleted when you leave · Supabase; the Omertá team
Feedback you send from the app · You · Fixing and improving the app · Legitimate interests, Article 6(1)(f) · Up to two years · Supabase; WhatsApp (Meta), because the feedback sheet also opens a WhatsApp message to the team
Concierge requests, when the concierge opens · You · Doing what you asked · Contract, Article 6(1)(b) · Up to two years · Supabase; the Omertá team
Trip bookings: passport details, date of birth, dietary needs, emergency contact, insurance · You, when booking · Booking flights, boats, stays and activities · Contract, Article 6(1)(b); legal obligation, Article 6(1)(c), where a carrier or the law requires it · Until the trip ends, then deleted, except invoices and payment records, kept seven years for accounts · The operators and carriers for that trip; Mercury, for the invoice; the Omertá team
Health and fitness information you volunteer for an activity · You, when booking · Keeping you safe on the activity · Explicit consent, Article 9(2)(a); you can withdraw it, in which case we may not be able to take you on that activity · Deleted when the trip ends · The operator running that activity, where safety requires it
Application: name, email address, phone number, net worth, gender, and what you write · You, on the Typeform application · Deciding whether to invite you; replying to you · Steps before a contract, Article 6(1)(b); legitimate interests, Article 6(1)(f), in choosing who is invited · While the network is evaluating your application; deleted when you ask; merged into your member record if you are invited · Typeform; Notion; Slack; Amazon Web Services; the Omertá team
Application call: the booking, the recording, the transcript and an AI written summary · You, on the call · Meeting you before a decision; keeping a record of what was said · Consent, Article 6(1)(a), for the recording, which you can decline before the call; steps before a contract, Article 6(1)(b) · The same as your application · Cal.com (booking and Cal Video); Amazon Web Services (Amazon Bedrock, for the summary); Notion; Slack; the Omertá team
Invitations to apply: the name and email address of someone we would like to meet · Not you: an introduction or public information, and we say which when we write · Inviting people to apply · Legitimate interests, Article 6(1)(f); you can tell us to stop at any time · Until you tell us to stop, or your application is decided · Amazon Web Services (Amazon SES); the Omertá team
Device and log data: IP address, request times, sign-in attempts · Automatic · Security, running the service, diagnosing faults · Legitimate interests, Article 6(1)(f); legal obligation, Article 6(1)(c), for security · Sign-in logs up to 12 months; provider access logs under the provider's own short retention · Supabase; Vercel; Cloudflare; Esri (map tiles); Google (fonts)
Team notifications: your name and what you did (a referral, a proposed experience, leaving the room) · Automatic · Letting the team act on what happens in the room · Legitimate interests, Article 6(1)(f) · Up to two years in the team mailbox · Google Workspace; the Omertá team
Alumni record: name, city, join date, past experiences hosted, nominations made · Your record, after you leave · Knowing who has been a member; preventing a profile being claimed twice · Legitimate interests, Article 6(1)(f) · Until you ask for full erasure · Supabase; other members see the name on past experiences and nominations
Sponsor and partner contacts: the name, work email, job title and company of someone at a business · A commercial business contact database, the company's own website, or you · Partnership mail · Legitimate interests, Article 6(1)(f) · While the relationship lasts · Brevo (EU)
Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time (section 11). We do not use your data for any purpose that is not in this table without telling you first.
7. Who can see what
Other members, once signed in, can see your name, your city, your line, what you bring, your contribution, your interests, your photo and the year you joined. They can see your Instagram and WhatsApp handles only while the matching switch in Settings is on, and your pin on the map only while "Show me on the map" is on. On an experience they can see that you are going. On a nomination they can see who put the name up, the vote counts and the comments, with the names of the people who wrote them. They cannot see your phone number unless the WhatsApp switch is on, your email address, your sign-in history, your feedback, your referrals or your concierge requests. A member who has not yet signed in to the app is not shown to the room at all.
The Omertá team can see all of the above, plus your phone number, your referrals, your feedback and your concierge requests, what you give us when you book a trip, and, if you applied, your application and the record of your call. When a member sends a referral, proposes an experience or leaves the room, the team gets an email about it. Those emails go to the team only, never to members.
Members agree, in the terms of use, not to copy the roster or share what other members post outside the room. If you believe a member has misused your data, tell us and we will act on it.
Nobody else. We do not sell, rent or trade your information, we do not share it with data brokers, and we do not show ads.
8. Who processes it for us, and where
These companies hold or move your data so the club and the app can work. Each is bound by a contract that limits what it may do with your data to what we instruct.
Provider · What it does · Where your data is · Transfer mechanism for EU, UK and Swiss data
Supabase Pte. Ltd (Singapore), with Supabase Inc. (USA) as importer · The database, sign-in and photo storage for the app · Amazon Web Services, Oregon, United States (region us-west-2) · EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), Module Two; the UK Addendum; the Swiss addendum, all in Supabase's data processing agreement. Supabase is not on the Data Privacy Framework list
Twilio Inc. (USA) · Delivers the sign-in code by WhatsApp or SMS through Twilio Verify. Sees your phone number and the code · United States · EU-US Data Privacy Framework, the UK Extension and the Swiss-US DPF (participant page https://www.dataprivacyframework.gov/participant/5394)
Vercel Inc. (USA) · Hosts the web version of the app and runs the job that sends the team's notification emails · United States, with edge servers worldwide · EU-US DPF, UK Extension and Swiss-US DPF (https://vercel.com/kb/guide/is-vercel-certified-under-dpf)
Google LLC (USA) · Google Workspace holds the team's mailbox and working documents and sends the notification emails from jeff@joinomerta.com; Google Fonts serves one typeface to the app · United States and Google's data centres worldwide · EU-US DPF, UK Extension and Swiss-US DPF (https://policies.google.com/privacy/frameworks)
Webflow, Inc. (USA) · Builds and hosts www.joinomerta.com and its forms · United States · EU-US DPF, UK Extension and Swiss-US DPF (https://webflow.com/legal/eu-privacy-policy)
Cloudflare, Inc. (USA) · The content delivery network in front of the website, and the cdnjs library host the web version of the app loads the map library from · Cloudflare's network worldwide · EU-US DPF, UK Extension and Swiss-US DPF (https://www.dataprivacyframework.gov/participant/5666)
Notion Labs, Inc. (USA) · The team's workspace and the live record of applicants: each application, where it stands, the summary of the call and the decision. It also holds a copy of the roster for the team; it no longer writes to the app · United States · EU Standard Contractual Clauses (https://www.notion.com/help/gdpr-at-notion)
Esri (Environmental Systems Research Institute, Inc., USA) · Serves the map tiles that the Leaflet map library inside the app requests · United States · The request goes straight from your phone to Esri and carries only your IP address and the map area; Esri's own privacy statement governs it
Brevo (Sendinblue SAS, France) · Sends sponsorship mail to companies · European Union · No transfer outside the EU
Typeform S.L. (Spain) · The application form · Typeform's hosting on Amazon Web Services in the United States · Typeform is established in the EU; the transfer to its US hosting is covered by the Standard Contractual Clauses in its data processing agreement
Cal.com, Inc. (USA) · Booking of application calls, and Cal Video, which hosts, records and transcribes them · United States · Standard Contractual Clauses or the EU-US Data Privacy Framework, as Cal.com's privacy policy provides (https://cal.com/privacy)
Amazon Web Services, Inc. (USA) · Runs the automation behind applications, sends invitations and application email from apply.joinomerta.com (Amazon SES), and writes the summary of each application call (Amazon Bedrock) · United States · EU-US DPF, UK Extension and Swiss-US DPF, under the Amazon.com, Inc. certification (https://aws.amazon.com/compliance/eu-us-data-privacy-framework/)
Slack Technologies, LLC (USA), a Salesforce company · The team's alerts: a message to the team when someone applies, with the applicant's name and details · United States · EU-US DPF, UK Extension and Swiss-US DPF (https://slack.com/trust/compliance/gdpr)
Mercury Technologies, Inc. (USA) · Issues the invoices for trips and receives their payment. Mercury is a financial technology company, not a bank; its banking services are provided by its partner banks · United States · Standard Contractual Clauses, as Mercury's privacy policy provides (https://mercury.com/legal/privacy)
Apple Inc. (USA) · Distributes the app through the App Store and TestFlight, as an independent controller under Apple's privacy policy. If you install through TestFlight, Apple may pass us crash reports and the feedback you write there · United States · Apple's own policy and the Global Cross-Border Privacy Rules system
Meta Platforms (WhatsApp) · Carries the sign-in code when it is sent by WhatsApp, and receives what you send when you tap a member's WhatsApp link or send feedback that way, as an independent controller under WhatsApp's own terms · Meta's infrastructure · WhatsApp's own terms and privacy policy
The list of participants in the EU-US Data Privacy Framework is published by the US Department of Commerce at https://www.dataprivacyframework.gov/list. If a provider leaves the list, we fall back to the Standard Contractual Clauses.
Omerta Cortex LLC itself is in the United States. If you are in the EU, the UK or Switzerland, your data is therefore transferred to a country that the European Commission, the UK and Switzerland have not held adequate in general. We apply the safeguards above to every provider, we keep the data set small, and the transfer to us is necessary to run the membership you have asked for (Article 49(1)(b) of the GDPR and the UK GDPR). You can ask us for a copy of the clauses we rely on.
9. Cookies and local storage
The app sets no cookies. It keeps the following in your phone's local storage, and nowhere else: your sign-in session; a cached copy of your profile and of the roster so the app opens offline; your settings switches; whether you have seen the introduction; an outbox of anything you sent while offline; and, if you turned location on, the nearest room city. Nothing in local storage is read by anyone but the app on your phone, and "Leave the room" clears it.
The website sets the cookies Webflow needs to run. It sets no advertising or analytics cookies as of the date of this policy.
10. Security, and what happens if it fails
The database refuses any request that does not come from a signed in member, and each member can read only what this policy says members can see (row level security). The key inside the app carries no permissions of its own. The key that can change anything lives only on our servers. Photos sit in a private bucket behind signed links that expire. Everything travels over HTTPS. Sign-in requires a code sent to your own phone. Access to the raw data is limited to a small team, each with their own login. Supabase keeps encrypted backups for a short period so that a fault can be reversed. We store no card numbers.
No system is perfect, and we would rather tell you so. If a breach puts your data at risk, we will contain it, work out who is affected, and tell the supervisory authority within 72 hours where the GDPR or the UK GDPR applies and tell you without undue delay. Where Hawaii's chapter 487N or another US state law applies, we notify affected residents without unreasonable delay and the state's consumer protection office where that law requires it. We will tell you what happened, what we did about it and what you can do.
11. Your rights under the GDPR and the UK GDPR
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the following rights, and we honour them for every member wherever they live.
Access: a copy of the personal data we hold about you, and this policy's information about how we use it.
Rectification: correction of anything inaccurate. Most of your profile you can correct yourself in Edit profile.
Erasure: deletion of your data. "Leave the room" in Settings does most of this instantly; section 14 explains what remains and how to have that erased too.
Restriction: a pause on our use of your data while a dispute about it is settled.
Portability: your profile and what you posted, in a machine readable file, where we process it under contract or consent.
Objection: to any processing we base on legitimate interests. We stop unless we can show compelling grounds that override your interests.
Withdrawal of consent: at any time, for anything we do on the basis of consent, without affecting what was done before. The switches in Settings are the fastest way for the handles and the map pin.
No automated decisions: we make no decision about you by automated means alone, and we do not profile you. Nominations are decided by members voting, not by software.
To exercise a right, write to contact@joinomerta.com (or jeff@joinomerta.com for erasure) from the phone number or email address on file, or tell us from inside the app. We may ask you to confirm your identity through the app. We answer within 30 days, and within a month at most as the law requires, with up to two further months for a complex request, in which case we tell you why. There is no charge unless a request is manifestly unfounded or excessive.
Complaints. You can complain to a supervisory authority at any time. Because Omerta Cortex LLC has no establishment in the EU, there is no lead supervisory authority under the one stop shop; the authority in the country where you live or work is competent. Among members' countries these are the Autoriteit Persoonsgegevens (Netherlands), the State Data Protection Inspectorate, VDAI (Lithuania), the Garante per la protezione dei dati personali (Italy), the Hellenic Data Protection Authority (Greece), Datatilsynet (Norway), and in Germany the data protection authority of your federal state. In the United Kingdom it is the Information Commissioner's Office, https://ico.org.uk. In Switzerland it is the Federal Data Protection and Information Commissioner. We would rather hear from you first, but you do not have to.
12. California and other US states
This section applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA"). Omertá is a small club and may fall below the CCPA's thresholds; we give California members these rights regardless.
Categories of personal information collected in the last 12 months: identifiers (name, phone number, email address, Instagram and WhatsApp handles, account ID); personal information described in California Civil Code section 1798.80(e) (name, phone number, and the net worth you give on the application); characteristics of protected classifications under California or federal law (the gender you give on the application); internet or network activity (sign-in logs, requests to our servers); geolocation data at city level only, which you type yourself, never precise location; audio or visual information (your profile photo, any photo you attach to an experience, and the recording of your application call); and, if you volunteer it for a trip, health information, which is sensitive personal information under the CCPA. We collect no biometric information, no financial account numbers and no data from third party sources other than referrals made by other members and the introductions and public information behind an invitation to apply.
Sources: you, other members (referrals and nominations), the introductions and public information behind an invitation to apply, and our own systems (logs).
Business purposes: running the membership and the app, security, fixing faults, booking trips, and complying with the law.
Disclosed for a business purpose in the last 12 months: to the service providers in section 8, and profile fields to other members as section 7 describes.
Sold or shared: none. We do not sell personal information and we do not share it for cross context behavioural advertising, and we have not done so in the last 12 months. We have no actual knowledge of selling or sharing the personal information of anyone under 16. Do Not Sell or Share My Personal Information: there is nothing to opt out of, and we honour Global Privacy Control signals as a matter of course.
Sensitive personal information: we use health information you volunteer only to keep you safe on an activity, which is a purpose the CCPA permits without a right to limit. We do not use or disclose sensitive personal information for any other purpose.
Your rights: to know what we collect, use and disclose; to delete; to correct; to limit the use of sensitive personal information; to opt out of sale or sharing (not applicable); and not to be discriminated against for exercising any of them. We will not deny you membership, charge you differently or give you a different level of service because you exercised a right.
How to exercise them: email contact@joinomerta.com (or jeff@joinomerta.com to delete) from the phone number or email address on file, or use "Leave the room" in the app. We verify a request by matching it to the contact details on your member record, and may ask you to confirm through the app. An authorised agent may submit a request for you if they give us your signed permission and we can verify your identity; you may also ask us to confirm directly with you. We respond within 30 days, and never later than the 45 days the CCPA allows, telling you if we need the extra time the law permits.
Other states. Members in Hawaii are protected by Hawaii's breach notification law, chapter 487N of the Hawaii Revised Statutes; Hawaii has not enacted a comprehensive consumer privacy statute as of the date of this policy. Where a member lives in a state with a comprehensive privacy law (among them Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware and New Jersey), we give them the rights that law provides, in the same way and through the same contacts as above, including the right to appeal a refusal by writing to contact@joinomerta.com with "appeal" in the subject line.
13. Other countries
If you live in Switzerland, the Federal Act on Data Protection applies and the rights in section 11 are yours. If you live in Australia, we handle your data in line with the Australian Privacy Principles under the Privacy Act 1988, and you can complain to the Office of the Australian Information Commissioner. In Japan, the Act on the Protection of Personal Information; in Hong Kong, the Personal Data (Privacy) Ordinance; in Indonesia, Law No. 27 of 2022 on Personal Data Protection; in Argentina, Law 25.326. In each case you have the rights that law gives you, including access, correction and deletion, and the contacts in section 1 are how to use them. Where that law requires your consent for a transfer of your data to the United States, signing in and using the app after reading this policy is how you give it, and you can withdraw it by leaving the room.
14. How long we keep it, and leaving the room
The retention column of the table in section 6 governs. In short: your profile and what you do in the room stay while you are a member; feedback, concierge requests and team notifications for up to two years; sign-in logs for up to 12 months; trip records until the trip ends and invoices for seven years; applications, with any call recording, transcript and summary, while the network is evaluating them, or until the applicant asks us to delete them.
Settings has a "Leave the room" button. Tap it twice and the app deletes your account on the spot: your login, your phone number from the roster, your votes, your comments, your RSVPs, your referrals, your feedback, your concierge requests and your photos. Experiences you were hosting that had not happened yet are cancelled. Everything you typed on your profile is cleared, and the app clears its local storage on your phone.
Three things remain as an alumni record: your name, your city and the date you joined, so that the room knows who has been a member and so that nobody can claim your old profile. Past experiences you hosted and nominations you made stay in the room's history under that name. If you want all of that gone too, email jeff@joinomerta.com from the number or email address on file. We erase the alumni record within 30 days, remove your name from the history, and confirm by reply. Invoices we are required to keep for accounts are the one exception, and they are kept only for that purpose.
Backups roll off within 30 days of a deletion. A deletion that reached the backups before they rolled off is completed when they do.
15. Children
Membership is for adults aged 18 and over, and the app is not directed at children. The App Store rates OMERTÁ Access 13+, which is a content rating, not an invitation. We do not knowingly collect personal data from anyone under 16 in the EU or the UK, or under 13 anywhere else. If you believe we have, tell us at contact@joinomerta.com and we will delete it.
16. Changes
When this policy changes we update the date at the top. For a change that matters to you, such as a new purpose, a new category of data or a new processor that sees more than logs, we tell members in the app and, where we have an email address, by email, before the change takes effect. Earlier versions are available on request.
17. Contact
Omerta Cortex LLC, 1309 Coffeen Avenue Ste 1200, Sheridan, WY 82801, United States. contact@joinomerta.com. Deletion and erasure requests: jeff@joinomerta.com. We reply within 30 days.