Cookie Policy
The cookies and browser storage that OmniMessage uses. All of them are needed for the site to work.
OmniMessage is a GridStudio product.
Last updated: 5 October 2026
1.In short
OmniMessage uses a small number of cookies, and every one of them is strictly necessary: they keep you signed in and remember the choices you make. We use no analytics, advertising or social-media tracking cookies, which is why you do not see a cookie banner.
A cookie is a small text file that a website stores in your browser. Local storage is a similar place in the browser where a site can keep small pieces of data.
2.Cookies we set
| Name | Purpose | Duration | Provider | Category |
|---|---|---|---|---|
om_session | Keeps you signed in to the console. It holds a random, signed session token and nothing else, and scripts on the page cannot read it. | 30 days, renewed while you use the console; removed when you sign out | OmniMessage | Necessary |
om_oauth, om_oauth_post, om_oauth_pending | Set only while you sign in with Google, Apple or Facebook. They tie the provider’s answer to the browser that started the sign-in, so that nobody else can finish it. Their content is encrypted, and scripts on the page cannot read them. | Up to 15 minutes; removed when the sign-in finishes | OmniMessage | Necessary |
om_mode | Remembers whether the console shows live or test data. | 1 year | OmniMessage | Necessary |
NEXT_LOCALE | Remembers the language you chose for the site and the console. | 1 year | OmniMessage | Necessary |
om_admin_session | Used only by our own support staff, to return to their staff session after assisting a customer. It is never set for customers. | Up to 1 hour | OmniMessage | Necessary |
The session cookie is set with the SameSite=Lax and HttpOnly attributes and, in production, with Secure. Protection against cross-site request forgery relies on that attribute and on a header the console adds to its requests; there is no separate CSRF cookie.
3.Browser storage
| Key | Purpose | Duration |
|---|---|---|
omni-oauth | A random value that links the sign-in window of a channel provider to the console tab that opened it, so that the result cannot be handed to another site. | Only while you connect a channel; removed when the sign-in ends |
om-docs-lang | Remembers the programming language you last selected for code samples in the documentation. | Until you clear the site data |
4.Third parties
Our pages do not load third-party trackers. Two things you can choose to do in the console involve other companies, which use their own cookies on their own domains under their own policies:
- Payments: when you top up or buy a package you are taken to a checkout page hosted by Stripe.
- Connecting a channel: when you choose to continue with Facebook or TikTok, a window of that provider opens, and for WhatsApp the Facebook sign-in script is loaded from Meta. Nothing is loaded from these providers until you start connecting such a channel.
5.Your choices
Because these cookies are strictly necessary, they are not subject to consent. You can delete or block cookies in your browser settings; if you block them you cannot sign in, and the site will not remember your language or mode.
If we ever introduce cookies that are not strictly necessary, we will ask for your consent first and update this page.
6.Contact
Questions about cookies: support@omnimessage.co. The Privacy Policy explains how we handle personal data in general.
Questions about this document: support@omnimessage.co