Privacy Policy

Version 1.2, effective 2026-07-06.

1. What we collect

2. What we don't collect

3. How we use it

We do not use your data to train machine-learning models and we do not sell it to any party.

4. Where it lives

All customer data is stored in Amazon Web Services us-east-1 (N. Virginia, USA), in MongoDB Atlas (account metadata, workflow definitions, execution history) and Amazon S3 (Data Storage files). Payment data is held by Stripe in the United States. Email sending is performed by Resend in the United States. DNS and CDN edge are operated by Cloudflare globally.

5. Sub-processors

Orkidata relies on the following sub-processors to operate the service. Each is listed with the category of data it receives. This list is authoritative as of the effective date above; material additions will be announced at least 30 days in advance by email.

Sub-processor Purpose Data received Region
Amazon Web Services Cloud compute, object storage, content delivery, API gateway, and secrets management All customer data, workflow definitions, execution history, transactional logs us-east-1 (USA)
MongoDB Atlas Primary database for account metadata, workflow definitions, execution history, rate-limit counters Account data, workflow definitions, execution history, billing metadata AWS us-east-1 (USA)
Stripe Payment processing, subscription state, Customer Portal Name, email, billing address, card details (held by Stripe, not by us), subscription status USA
Resend Transactional email (confirmation, password reset, billing notices), recipient-verification emails, workflow send_email steps (Orkidata mode), reminders consent invitations, and Gmail re-authentication notices Email address, name, email content USA
Cloudflare Authoritative DNS and edge DNS/CDN for orkidata.com Request metadata (IP, URL, headers) transiting the edge Global anycast
Sentry Error tracking, performance monitoring, and system stability IP addresses, user IDs, and application error payloads (personally identifying fields are included for debugging; request bodies and credential headers are stripped before sending) USA

6. Google user data (Sign-In, Drive, Gmail)

If you connect a Google account, Orkidata accesses Google user data only through the narrow OAuth scopes you grant, and only to do what you configured:

Orkidata's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used strictly to execute the workflows you explicitly configured. It is never sold or rented, never shared for advertising purposes, and never used to train machine-learning or artificial-intelligence models.

7. Your recipients' data (controller and processor roles)

Some features process personal data about people who are not Orkidata users — the recipients you email. This includes email addresses and names entered in workflow steps, information recipients submit through the Reminders public intake form or QR code (such as names and appointment dates), the consent ledger (opt-ins, opt-outs, and unsubscribes), and the attestation audit logs referenced in the Terms of Service.

8. International transfers

Primary processing happens in the United States. If you access Orkidata from outside the US, your data will be transferred to and processed in the US under the sub-processors listed above. Where required, transfers are covered by the sub-processor's own Standard Contractual Clauses or equivalent legal mechanisms.

9. Retention

10. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. To exercise any of these, or to ask a question about this policy, email privacy@orkidata.com. We will respond within 30 days.

You can request deletion of your account at any time by emailing the address above. Deletion removes your account metadata, workflow definitions, execution history, and uploaded files. Backups older than 30 days may retain a copy until they are overwritten on the normal rotation schedule.

11. Cookies

Orkidata uses one cookie: a secure, HTTP-only session cookie that keeps you logged in. The browser also stores a small sessionStorage hint so in-tab navigation feels instant, this is cleared when you log out and is never shared with any third party.

12. Security

Passwords are stored using strong, industry-standard one-way hashing. Credentials you enter for database or API connectors are encrypted at rest with industry-standard authenticated encryption, and all traffic is encrypted in transit using TLS 1.2 or higher. Infrastructure secrets are held in a managed secrets store with least-privilege access, applied across all services. Security is a moving target; no system is perfectly safe, and you should follow good operational hygiene in what you upload.

13. Children

Orkidata is not intended for and is not directed at children under 18. If you believe a child has created an account, please email privacy@orkidata.com and we will delete it.

14. Changes to this policy

Material changes will be announced by email to the address on file and reflected here with an updated version number. Continued use of the service after the effective date of an update constitutes acceptance.

15. Contact

Privacy questions: privacy@orkidata.com.
General: hello@orkidata.com.