Security & privacy

Security and privacy that pass your review

Before a new tool gets the go-ahead, data protection officers, IT security and works councils take a close look. That review is what omul is built to pass: EU hosting or self-hosting, no participant accounts, no third-party trackers — and open source that makes security verifiable instead of just claimed.

No credit card · Free self-hosting · Open source (AGPLv3)

Security at a glance

What reviewers find in omul

The six points that land on the table first in almost every security and privacy review — and how omul answers them.

  • Hosting in the EU or on your side

    Run omul in an EU data center or entirely on your own infrastructure. You choose the jurisdiction — and the data does not leave it.

  • Data-minimal by default

    The audience joins with a 6-digit code — anonymously, no email, no login, no device fingerprint. Where no personal data is collected, there is little to protect.

  • DPA on request

    For the hosted option we provide a data processing agreement (DPA) — on request ahead of launch. With self-hosting you are the sole controller, with no processor involved.

  • Deletion under your control

    You set retention and remove results deliberately. No secondary use, no sharing with third parties — what's deleted is gone.

  • No third-party trackers

    No Google Analytics, no ad pixels, no hidden scripts. If any usage measurement happens at all, it's cookieless and self-hosted.

  • Verifiable, not a black box

    The source code is open (AGPLv3). Security can be reviewed independently — by your team, by auditors, by the community.

Sub-processors

Few, transparent, available on request

The fewer parties involved, the smaller the attack surface and the simpler the review. That's why we keep the list of sub-processors as short as possible — and disclose it rather than hide it.

  • With self-hosting there are no sub-processors — you run everything yourself.
  • For the hosted option we limit ourselves to the essentials, essentially the EU hosting provider.
  • You get the current list on request; the DPA lists it bindingly.
  • New sub-processors are not added quietly — changes are documented.

Deletion concept

How data goes away again

A security concept is only complete once it's clear how data disappears again. With omul that path is short and stays in your hands.

  1. 1

    You set retention

    Polls and results stay exactly as long as you decide — no longer. No open-ended stockpiling in the background.

  2. 2

    Delete when you want

    Remove results and sessions deliberately and for good — no third-party trash can, no silent copy kept somewhere else.

  3. 3

    No secondary use

    Your data is never sold, used for advertising or shared with third parties. A detailed deletion concept is available on request.

Open source

Security you can read

Open source under the AGPLv3 is what makes omul checkable rather than merely trustworthy. Your security team doesn't have to trust our claims — it can review the code itself. No black box, no hidden data paths, no surprises in the next update.

Open source in detail

Responsible disclosure

Found a vulnerability? Here's how to report it

Security is an ongoing process. If you discover a security issue, please report it responsibly through our security policy — not publicly in the issue tracker. We acknowledge receipt and keep you informed.

Security policy on GitHub

Frequently asked questions about security & privacy

Where is data hosted?

Wherever you want: in an EU data center or on your own infrastructure (self-hosting). You choose the jurisdiction, and the data does not leave it — full data sovereignty, no vendor lock-in.

Is there a DPA?

For the hosted option we provide a DPA — on request ahead of the official launch. With self-hosting you process the data yourself and remain the sole controller, so no processor is involved.

Which sub-processors do you use?

With self-hosting, none. For the hosted option we deliberately keep the list short — essentially the EU hosting provider. You get the current, binding list on request and in the DPA.

How is data deleted?

You set the retention period and remove results and sessions deliberately. Deleted data is not reused or shared with third parties. A detailed deletion concept is available on request.

Do you use trackers or analytics?

No third-party trackers, no Google Analytics, no ad pixels. If any usage measurement happens at all, it's cookieless and self-hosted — no data flows to ad networks.

How do I report a vulnerability?

Responsibly through our security policy on GitHub, not publicly in the issue tracker. Because omul is open source (AGPLv3), anyone can review the code — responsible disclosure is explicitly welcome.

Security that gets the green light

Check omul yourself — the code is open

Start a live poll in under a minute, or hand the code to your security team. No credit card, no setup.

No credit card · Free self-hosting · Open source (AGPLv3)