Security and privacy that pass your review
Before a new tool gets the go-ahead, data protection officers, IT security and works councils take a close look. That review is what omul is built to pass: EU hosting or self-hosting, no participant accounts, no third-party trackers — and open source that makes security verifiable instead of just claimed.
No credit card · Free self-hosting · Open source (AGPLv3)
Security at a glance
What reviewers find in omul
The six points that land on the table first in almost every security and privacy review — and how omul answers them.
Hosting in the EU or on your side
Run omul in an EU data center or entirely on your own infrastructure. You choose the jurisdiction — and the data does not leave it.
Data-minimal by default
The audience joins with a 6-digit code — anonymously, no email, no login, no device fingerprint. Where no personal data is collected, there is little to protect.
DPA on request
For the hosted option we provide a data processing agreement (DPA) — on request ahead of launch. With self-hosting you are the sole controller, with no processor involved.
Deletion under your control
You set retention and remove results deliberately. No secondary use, no sharing with third parties — what's deleted is gone.
No third-party trackers
No Google Analytics, no ad pixels, no hidden scripts. If any usage measurement happens at all, it's cookieless and self-hosted.
Verifiable, not a black box
The source code is open (AGPLv3). Security can be reviewed independently — by your team, by auditors, by the community.
Sub-processors
Few, transparent, available on request
The fewer parties involved, the smaller the attack surface and the simpler the review. That's why we keep the list of sub-processors as short as possible — and disclose it rather than hide it.
- With self-hosting there are no sub-processors — you run everything yourself.
- For the hosted option we limit ourselves to the essentials, essentially the EU hosting provider.
- You get the current list on request; the DPA lists it bindingly.
- New sub-processors are not added quietly — changes are documented.
Deletion concept
How data goes away again
A security concept is only complete once it's clear how data disappears again. With omul that path is short and stays in your hands.
- 1
You set retention
Polls and results stay exactly as long as you decide — no longer. No open-ended stockpiling in the background.
- 2
Delete when you want
Remove results and sessions deliberately and for good — no third-party trash can, no silent copy kept somewhere else.
- 3
No secondary use
Your data is never sold, used for advertising or shared with third parties. A detailed deletion concept is available on request.
Open source
Security you can read
Open source under the AGPLv3 is what makes omul checkable rather than merely trustworthy. Your security team doesn't have to trust our claims — it can review the code itself. No black box, no hidden data paths, no surprises in the next update.
Responsible disclosure
Found a vulnerability? Here's how to report it
Security is an ongoing process. If you discover a security issue, please report it responsibly through our security policy — not publicly in the issue tracker. We acknowledge receipt and keep you informed.
Frequently asked questions about security & privacy
Where is data hosted?
Wherever you want: in an EU data center or on your own infrastructure (self-hosting). You choose the jurisdiction, and the data does not leave it — full data sovereignty, no vendor lock-in.
Is there a DPA?
For the hosted option we provide a DPA — on request ahead of the official launch. With self-hosting you process the data yourself and remain the sole controller, so no processor is involved.
Which sub-processors do you use?
With self-hosting, none. For the hosted option we deliberately keep the list short — essentially the EU hosting provider. You get the current, binding list on request and in the DPA.
How is data deleted?
You set the retention period and remove results and sessions deliberately. Deleted data is not reused or shared with third parties. A detailed deletion concept is available on request.
Do you use trackers or analytics?
No third-party trackers, no Google Analytics, no ad pixels. If any usage measurement happens at all, it's cookieless and self-hosted — no data flows to ad networks.
How do I report a vulnerability?
Responsibly through our security policy on GitHub, not publicly in the issue tracker. Because omul is open source (AGPLv3), anyone can review the code — responsible disclosure is explicitly welcome.
Security that gets the green light
Check omul yourself — the code is open
Start a live poll in under a minute, or hand the code to your security team. No credit card, no setup.
No credit card · Free self-hosting · Open source (AGPLv3)