Privacy Policy

The short version

We collect what the product needs to work, nothing more. We do not sell your data, we do not run advertising, and we do not train AI models on your content.

What we collect

Account. Your email, name, and passkey public keys. Passkeys never give us a password; the private key stays on your device.

Your content. The maps, nodes, documents, and files you create. Orient keeps an append-only history of changes so undo, history, and audit work; every change records which person or which AI agent made it, and when.

Billing. Paid plans, when offered, are handled by Stripe. We see your subscription state and invoices; your card never touches our servers. A verified email is required for checkout.

Telemetry. Operational logs, traces, and product events — what was slow, what failed, which features are used — tied to your account id so we can debug your problems. Not sold, not shared for marketing.

Support. Tickets you (or your agents) file, with what you attach.

AI agents

An agent you enroll acts with its own credential, under the access you approve, and everything it does is attributed to it in the history. Agent actions are processed exactly like your own actions. We do not use your content or your agents’ activity to train models.

Where data lives

Your maps are stored on our servers in New Zealand, Australia, and Europe: each workspace lives on one of them, a new one on the server nearest its owner, and its change history is copied continuously to Cloudflare (R2) so it can be restored on another. Uploaded files are stored with Cloudflare (R2). Email, when we send it, goes through Amazon SES. Payments are Stripe. These providers process data for us under their own security terms; we do not give them your content for any other purpose.

Sharing

People and agents see what you share with them, at the access level you set — nothing else. Workspace admins on team plans can see membership and audit records for their workspace.

Retention and deletion

Your content is kept while your account exists. Deleting your account removes your content and personal data from the live service promptly and from backups on their rotation schedule. The in-app privacy section provides data export and erasure.

Exporting your data

Profile › Privacy › Export my data, or orient export create on the command line, makes one zip file of everything you can open in Orient: every map in every workspace you belong to, with every item, its notes, progress, dates, assignees and tags; each map’s recorded history of changes, with who made each change and when (for an item that moved or changed who may see it, from that moment on); your documents, diagrams and presentations; and the files uploaded to those workspaces, as the original files. A README in the file explains its layout. It does not contain anything you could not open yourself, map layout and personal view settings, chat with agents, support conversations, your personal calendar, or billing records; files restricted to other people are listed without their contents. An agent’s key exports only the areas that agent was given.

The export is assembled on our servers for you alone and stored in our file storage (Cloudflare R2) for 24 hours so you can download it through a link that works for a few minutes at a time. It is deleted after 24 hours, when you start a new export, or when you delete your account, whichever comes first.

Your rights

New Zealand’s Privacy Act 2020 gives you the right to access and correct your personal information; if you are in the EU or UK, the GDPR gives you similar and further rights. Write to [email protected] and we will act on it.

Changes and contact

We will announce material changes in the product. Privacy questions: [email protected]. Thoreon Limited, New Zealand.