Data Deletion Instructions

Last updated July 25, 2026

This is the single, canonical deletion page for Loki, operated by Omni Capital ehf. (company ID 5712241860, Birkigrund 47, 200 Kópavogur, Iceland). It covers Loki account and workspace data, and data obtained from a connected platform: Meta (Facebook and Instagram), TikTok, Google (including Google Ads and YouTube API Services), and LinkedIn. It applies whether you are agency staff, a client team member with portal access, or someone whose data an agency entered into Loki on your behalf. You do not need a Loki login to use it.

1. How to request deletion

Email thor@omni-systems.ai with the subject line “Data Deletion Request” and include:

  1. The email address associated with your Loki account or portal access, or, for data obtained from a connected platform, the social account handle or profile URL concerned.
  2. The name of the agency workspace or the agency that connected the account, so we can locate the records.
  3. What you want deleted: your whole account, or specific data (for example one connected account’s stored token and metrics).

We acknowledge every request within 2 business days. We complete deletion of data obtained from a connected platform within 7 calendar days, and deletion of all other personal data within 30 days, sooner where we reasonably can. We confirm completion in writing. If we cannot delete some or all of the data, we will tell you which data, and why, in plain language, for example where accounting law requires us to keep an invoice record.

If you are a client of one of our agency customers and you are not sure whether Omni or your agency should handle the request, email us anyway. We will action it directly, or route it to the right agency ourselves, and tell you which we did.

2. If you came here from a social platform

If you arrived here from a social platform’s own settings after removing Loki’s access (for example Meta’s Apps and Websites screen, or TikTok’s connected apps screen), email us with the platform name and the account handle and we will delete the data Loki obtained for that connection. Removing access at the platform already stops Loki from reading anything further; emailing us makes the deletion of what Loki already holds explicit and gets you written confirmation.

3. What you can already do inside Loki

Some deletion actions are available directly in the product, without emailing us:

  • Client portal users: an agency admin, or a portal user holding the primary contact role for that client, can remove a client contact’s portal access. This fully and immediately deletes that person’s portal account, their stored password, and their access tokens.
  • Clients: an agency owner or admin can delete a client from the clients list. This permanently removes that client’s record together with its videos, comments, reports, portal messages, portal users, onboarding forms, and AI conversations. Files already uploaded to storage (video files, message attachments, logos, avatars) are not swept automatically by that action, so ask us using Section 1 if you want the stored files removed as well.
  • Your own agency account: agency staff can delete their own account from their profile dialog. Open the profile menu, choose Delete account, and type DELETE to confirm. This permanently removes your profile and your sign-in identity. Two accounts are blocked from self-deleting: a sole agency owner, who must transfer ownership first because deleting would leave the agency without an owner, and an Omni super-admin account. In both cases, email us using Section 1.
  • Agency team members: an agency owner or admin can remove a team member from Settings, Team. This immediately revokes that person’s access to the workspace, but it does not by itself delete the underlying account, so use the self-serve route above or the email request in Section 1 to have the account and its personal data fully deleted.
  • Google Drive: an agency admin can disconnect the agency Drive connection from Settings at any time, which deletes the stored authorization token.
  • Google Calendar: the Calendar connection is personal to each staff member, so only that member can disconnect it, from their own profile. An agency admin cannot disconnect it for them. Disconnecting deletes that member’s stored token.

The email request in Section 1 covers anything the controls above do not, including portal users and anyone without a Loki login, uploaded files, and a sole agency owner’s own account.

4. Deletion that happens without a request

No social platform connection is live in Loki today. Once a connection is available and an account is connected, the following deletions happen automatically, with no request needed:

  • The agency disconnects the account in Loki. The stored tokens and everything Loki retrieved for that connection are purged within 7 calendar days, and normally much sooner. This matches the turnaround for an emailed request on the same data.
  • You revoke Loki’s access at the platform. Loki stops processing immediately and purges within 30 calendar days. This applies to revoking Google Account permissions, to Meta deauthorization, and to TikTok removing the authorization, which Loki uses as the trigger to purge the cached TikTok profile, stats, and video list data. LinkedIn content, including the tokens themselves, is deleted immediately when the relevant member token or OAuth access token is terminated.
  • The Loki account or agency workspace is closed. The workspace’s database records are removed with it. Uploaded files held in storage are removed as part of the request process in Section 1, so tell us if you want those removed too.
  • Retention is no longer necessary for a legitimate business purpose, the product or feature is discontinued, the source platform requests deletion, or deletion is required by law. This does not apply to data that has already been aggregated or de-identified.
  • LinkedIn stored marketing data is permanently deleted within 10 days of a client ceasing service or requesting deletion, and stored marketing data that is member data is deleted immediately when the relevant authorization is terminated. Our 7-day request turnaround already sits inside that ceiling.
  • TikTok information obtained through TikTok Developer Services is deleted in all forms on termination or disconnection, within the same 7 calendar day window as the first bullet above.

5. What gets deleted

For a connected platform account: the stored OAuth access and refresh tokens, cached profile and account metadata, cached content and content metadata, cached metrics and insights, generated reports containing that account’s data, and records derived from any of it. For a Loki account: the account record and profile, portal credentials and access tokens where the person is a portal user, and the workspace content covered by the request. For uploaded files: video files, message attachments, logos, and profile pictures held in storage are removed by us as part of the request, because they are not deleted automatically when the record that referenced them goes. Until a logo or profile picture is removed this way, it stops being shown in the product but its file address keeps working, so tell us if an image is what you want gone.

Two things to be straight about. First, comments, messages, approvals, and idea sheet responses a person authored stay part of the client’s project record after that person’s account is deleted, with the display name shown against them. Tell us if you want that name removed too and we will remove it. Second, aggregated and de-identified statistics in reports your agency produced, which cannot be linked back to an individual or to a specific account, may be retained as part of that agency’s own records. Records we are legally required to keep, such as accounting and invoice records, are retained for the period the law sets and are not used for anything else.

6. Backups

Deleting data from Loki’s live systems is immediate for that data. Encrypted database backups rotate out on our database provider’s schedule, currently within 7 days, and a deleted record stops existing in backups once that rotation completes. We keep that retention at no more than 30 days. During that window the data is not accessible to the application, is not processed for any purpose, and is only ever used to restore the service after a failure.

7. Revoking access at the platform itself

Deleting data in Loki does not delete anything on the platform’s own side. To cut Loki’s access off at the source, or to remove data the platform itself holds about you, use the platform’s own controls:

  • Google: https://myaccount.google.com/permissions
  • Facebook: Settings and Privacy, then Settings, then Business Integrations
  • Instagram: Settings, then Website Permissions, then Apps and Websites
  • TikTok: Settings and Privacy, then Security and Permissions, then Manage App Permissions
  • LinkedIn: Settings, then Data Privacy, then Permitted Services

8. Questions and status

For anything not covered here, or to check the status of a request you already sent, email thor@omni-systems.ai. We will tell you where the request stands, what has been deleted, and the reason for anything we cannot delete. See also the retention schedule in our Privacy Policy and the deletion and return clause in our Terms of Service, Section 8(j).

Deletion requests: thor@omni-systems.ai, subject “Data Deletion Request”. Acknowledged within 2 business days. Platform data deleted within 7 calendar days; all other personal data within 30 days.

Related documents

Privacy Policy · Terms of Service