Skip to content
← Back to Orchestrat
Legal

Privacy Policy

Last updated

@armanghev operates Orchestrat (“we,” “us”) and is responsible for the personal information described here. This policy covers orchestrat.dev, our waitlist, and the Orchestrat applications, CLI, and hosted services. It explains what we collect, why we use it, and the choices available to you.

1. Information we collect

  • Waitlist and correspondence. Your email address when you join the waitlist, and any information you choose to send when you contact us. The waitlist stores your email address and does not ask for your name, company, or payment details.
  • Account information. When you use the app, your authentication identifier, email address, name, avatar, and any profile details you provide. Signing in with GitHub supplies information from that provider to create or maintain your account.
  • Project content. Organization and project details, memberships, tasks, comments, documents, revision history, and attachments that you or your connected agents submit.
  • Coordination and technical data. Agent and session identifiers, runtime information, task claims, lifecycle events, timestamps, and reported errors. Our hosting services may process request information such as IP addresses, browser details, and diagnostic logs to deliver and protect the Service.

2. How we use information

We use this information to manage early-access invitations, create and authenticate accounts, provide shared project state, synchronize agent activity, respond to support requests, maintain reliability, prevent abuse, and meet legal obligations. Waitlist emails are used for Orchestrat early-access communications; you can ask us to remove your address at any time.

Where a legal basis is required, we rely on providing the service you request, our legitimate interests in operating and securing it, your consent where required, or compliance with legal obligations. Where we rely on consent, you may withdraw it without affecting earlier lawful processing.

3. Cookies, analytics, and local storage

If you accept optional analytics, the website uses Vercel Web Analytics to understand visits and improve the site. Analytics stays off until you accept. It processes page views, referrers, approximate location, and device and browser information as aggregate usage statistics. Vercel describes this analytics service as not using third-party cookies and using a temporary visitor hash rather than a persistent cross-site identifier. See Vercel’s analytics privacy documentation for details.

We store your analytics preference in your browser’s local storage under the key orchestrat:analytics-consent:v1. This stores only your choice, not an advertising identifier. Use “Cookie settings” in the footer to accept or reject optional analytics at any time. Rejecting stops future analytics events; it does not remove statistics already received. Your choice stays on this browser until you change it or clear site data. If browser storage is unavailable, the choice applies only to the current visit. The website and waitlist work whether you accept or reject analytics.

The web dashboard stores authentication session information locally in your browser so you can stay signed in. The macOS app and CLI use macOS Keychain for supported credentials. Authentication providers may use their own cookies during sign-in. You can clear browser storage or disconnect integrations, though doing so may sign you out or stop a connection. Orchestrat does not use advertising cookies or sell personal information for targeted advertising.

4. When information is shared

We use service providers for hosting, authentication, databases, storage, email delivery, and analytics. These include Vercel for the website and analytics, Supabase for authentication, Neon for the waitlist database, Resend for waitlist emails, and Cloudflare R2 for document and attachment storage where configured. These providers process information needed to perform their services.

Project content and activity are available to authorized project users and connected agents. Profile avatars may be accessible to anyone with their public image URL. When you connect a coding tool, it may retrieve project content and pass that context to its own provider. That provider’s terms and privacy policy govern its processing. Orchestrat does not run those models; review each tool’s permissions and data practices before connecting it.

We may also disclose information when reasonably necessary to comply with law, respond to a valid legal request, prevent fraud or harm, or protect rights and security. If the Service is transferred to a new operator, information may transfer with it, subject to applicable law and notice of any material change in how it is handled.

5. Retention and deletion

We retain information for as long as needed to provide the Service and for legitimate operational, security, and legal purposes. The appropriate period depends on the information, your use of the Service, and any obligations to retain it.

Archiving a project or document preserves its history; it does not erase it. Disconnecting an agent does not delete its past activity. Contact us to request removal from the waitlist, account closure, or deletion of personal information. Some records may need to be retained for legal or security reasons, and backups or storage cleanup may take additional time. We will explain any relevant limits when responding to your request.

6. Security and international processing

We use access controls and credential protections designed to safeguard information. No online service can guarantee complete security. Avoid submitting passwords, private keys, or unnecessary sensitive personal information in tasks, documents, or attachments.

We and our service providers may process information in countries other than where you live, which may have different privacy laws. Where applicable law requires protections for an international transfer, those requirements apply to our handling of the transfer.

7. Your choices and rights

Depending on your location and applicable law, you may have rights to access, correct, delete, or receive a copy of your personal information, or to object to or restrict certain processing. You may also have the right to complain to your local data protection authority. Contact us using the address below to make a request. We may need to verify your identity and authority before responding.

You can edit available profile settings, revoke connected agents, clear local browser data, or stop using the Service. The website does not currently change its behavior in response to a browser’s “Do Not Track” signal.

8. Children and policy updates

Orchestrat is intended for people using developer tools, not children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can investigate and address it.

We may update this policy as the Service changes. We will update the date on this page and give notice of material changes through the website, the app, or email as appropriate. Use of the Service is also subject to our Terms of Service.

9. Contact

For privacy questions or requests, contact @armanghev at arman@orchestrat.dev. Please do not include passwords, access tokens, or other secrets in your message.