Skip to content
Back to home

Privacy

Privacy Policy

How the website and application handle data, files, voice, and integrations.

Effective August 14, 2026

1. Overview

Orkestrai is designed to operate locally. Workspaces, terminals, sessions, the canvas database, and voice models stay on your device by default. This Policy explains what the application and website may process.

2. Data processed locally

The application reads and writes data on the computer where it is installed. This data is not sent to Orkestrai by default.

  • Paths, files, and metadata from selected workspaces.
  • CLI session history and identifiers.
  • Nodes, edges, notes, tasks, portals, roles, routines, and preferences.
  • Temporary dictation audio, transcriptions, and synthesized audio when local voice is active.
  • Local CLI credentials only for flows that read provider status; they are not copied to an Orkestrai service.

3. Providers and third-party services

When you use a CLI, MCP, external voice backend, website in a Portal, or encrypted workspace sharing, transmitted data follows that feature and third party configuration. Orkestrai does not automatically intermediate provider conversations.

  • Prompts and files may be sent by the chosen CLI according to its provider settings.
  • An external voice backend receives audio or text only when selected in Settings.
  • Downloads and updates may access model distribution hosts, Node.js, and GitHub releases.
  • The collaboration relay receives encrypted frames and technical connection metadata, but cannot decrypt workspace content. The sanitized projection excludes files, notes, credentials, private URLs, and local paths. Raw terminal output is transmitted only after the host explicitly enables its separate Administrator-only permission for that device.

4. Website and Remote PWA data

The public website and Remote PWA do not require an account. Hosting infrastructure may log technical data required for security and delivery, such as IP address, user agent, time, and requested route.

  • We do not use advertising cookies on the public website.
  • Local preferences such as theme may be stored in the browser.
  • After a host invitation, the Remote PWA stores the device name and a non-extractable WebCrypto pairing key in IndexedDB so that device can reconnect. Forgetting the workspace removes that local record.
  • The invitation secret remains in the URL fragment, is removed before the connection starts, and is never sent in an HTTP request to the website or relay.
  • If analytics are added in the future, this Policy will be updated before use where required.

5. Storage and retention

Local data remains on your device until you remove workspaces, models, settings, or the application. The collaboration relay is stateless and keeps active rooms only in memory; bounded operational logs and website infrastructure logs, when present, are retained as necessary for security, diagnostics, and legal obligations.

6. Security

We apply reasonable safeguards, including workspace scoping, local bridge tokens, end-to-end encrypted collaboration, device approval, role-scoped commands, immediate revocation, validations before stopping processes, and integrity checks for voice downloads. No system is completely secure; keep your operating system, Orkestrai, and CLIs updated.

7. Your rights

Depending on your jurisdiction, you may request confirmation, access, correction, deletion, or information about personal data processed by official infrastructure. Most application data exists only on your device and can be managed directly by you.

8. Children

Orkestrai is a professional tool and is not intentionally directed to children. If you believe child data was improperly processed, use the official channels to request a review.

9. Changes to this Policy

We may revise this Policy when the product, infrastructure, or law changes. The updated effective date will be published on this page.

10. Contact

Privacy requests should be submitted through the official channels listed in the Orkestrai distribution. Do not post credentials, private files, or other sensitive data in public channels.