1. Who we are
Orchestra is an AI operating system for companies. The public product includes Orchestra Cloud (the customer front door at runwithorchestra.com), Orchestra OS (identity, operating workspaces, connectors, and execution), and Orchestra Creative Studio (creative and publishing). This policy covers information processed across those surfaces when you use Orchestra.
This is a product privacy notice. It is not a claim of ISO, SOC, GDPR certification, or any other audit we have not completed.
2. Account information
When you create an account we collect the information you submit, which currently includes email address, password, company name, and selected plan (for example Starter or Growth). Identity for Orchestra is issued by Orchestra OS. Cloud proxies registration and hands you off to OS; Cloud is not a second identity provider.
We also store session and handoff tokens needed to keep you signed in to the correct tenant after signup or sign-in. Passwords are processed by Orchestra OS Identity, not stored as a second password database on Cloud.
3. Company and business information you supply
Customers can add companies and operating context. That may include company name, website URL, notes, positioning, offers, materials you paste or upload, objectives, and instructions about what Orchestra should do. We use this information to activate and operate the company inside Orchestra (for example building a business brain, operating plan, and department work).
4. Website and business discovery data
If you provide a website or other public business identifiers, Orchestra may retrieve publicly available pages and related public information to understand the company. That can include page content, titles, metadata, and other information those sites already publish. We use it to operate the product you requested — not to build an unrelated marketing list about people who never used Orchestra.
Discovery is limited by what is publicly reachable and by the connectors you authorize. We do not claim we index the entire internet or that discovery is complete.
5. Connected third-party services
Orchestra can connect to third-party services you authorize so it can publish, message, or otherwise act on your behalf. Depending on what you connect, this may include Meta (Facebook / Instagram), email identity / outbound mail, payment processors used for Orchestra billing, hosting and infrastructure, and other connectors shown in your workspace when they are available.
What we receive from a provider is determined by that provider’s APIs and the scopes you grant. We use connected-account data to perform the customer-authorized actions you request in Orchestra, to keep the connection working, and to show status in the product (for example whether a token is valid).
6. OAuth authorization and tokens
Some connections use OAuth. When you complete an OAuth flow, the provider issues access and/or refresh tokens (and related identifiers such as page IDs). Orchestra stores those credentials so it can call the provider on your behalf until you disconnect or the provider revokes them.
Tokens are operational secrets. We do not treat a stored token as a public marketing asset. A stored token does not by itself mean a channel is live or that a post was published.
7. LinkedIn connection and data (where applicable)
If you connect LinkedIn (or a LinkedIn-related integration when that connector is available in your workspace), Orchestra may receive profile, organization, or messaging data allowed by the scopes you grant, plus OAuth tokens. We use that data only for the LinkedIn actions you authorize in Orchestra. If LinkedIn is not connected for your account, we do not pull LinkedIn private account data for that account.
8. Use of data to perform customer-authorized actions
Orchestra exists to turn goals into coordinated work. With your authorization we may use account, company, discovery, and connector data to draft and send communications, publish creative, update CRM-style records, follow official submission or contact routes, run operating loops, and record evidence of what happened (for example a message identifier or a live permalink when one exists).
We do not treat auto-replies, bounces, or internal drafts as customer results. We do not invent revenue, replies, or publications.
9. AI processing
Orchestra uses AI models and related services to understand company material, generate drafts, classify inbound messages, plan work, and produce creative where the product supports it. Content you provide and content retrieved from authorized sources may be sent to those processors so the feature can run.
Model providers process data according to their own terms. We do not claim that prompts or outputs stay exclusively on Orchestra-owned hardware, and we do not claim human review of every AI output.
10. Service providers
We use vendors to run the product. That currently includes hosting and deployment (including Vercel for public Cloud and related Orchestra surfaces), Orchestra OS and Creative Studio infrastructure, identity and session handling, payment processing when you purchase a paid plan, and AI / media providers used by production features. Third-party platforms you connect (such as Meta or LinkedIn) are also processors for the data that flows through those APIs.
Providers change as the product changes. This policy does not list every subprocessors’ legal name, because that list is not a published certification register.
11. How we use information
- Create and authenticate accounts and tenants
- Activate and operate companies you add
- Perform customer-authorized actions on connected services
- Bill paid plans and handle related payment events when Checkout is used
- Provide support when you contact us
- Maintain security, debug failures, and keep the service running
- Improve Orchestra based on how the product is actually used
We do not sell your personal information. We do not use connected social accounts to advertise Orchestra to your audience unless you ask Orchestra to publish for that brand.
12. Data retention
We retain account, company, connector, and operational records for as long as the account is active and as long as needed to provide the service, resolve disputes, and meet legal or billing obligations we actually have. When you disconnect a third-party account we stop using that connection for new actions; residual logs or evidence already written (for example a recorded permalink) may remain as operational history unless you request deletion and we can fulfill it.
We do not publish a certified retention schedule with fixed day counts for every data type.
13. Security
We use standard hosting, HTTPS, and access controls appropriate to a production web product. We do not claim that Orchestra is immune to unauthorized access, that we are certified against a named security standard, or that tokens and content can never leak. You should disconnect unused integrations and use a unique password.
14. Your choices and revoking connected accounts
- You can update company information you supplied inside the product.
- You can disconnect or revoke third-party connections in Orchestra where the product exposes that control, and/or revoke Orchestra’s access from the provider’s own security or apps settings (for example Meta or LinkedIn).
- Revoking OAuth at the provider typically invalidates tokens; Orchestra may then show the connection as requiring re-authorization rather than remaining live.
- You can stop using paid features by cancelling through the billing path you used.
15. Deletion and contact requests
To request access, correction, or deletion of personal information we hold about you, or to ask us to disconnect remaining integrations, email hello@orchestra.cloud or use the Contact page. Describe the account email and what you want done. We will handle requests we can fulfill in the systems we actually operate. Some records may need to be retained for billing, security, or legal reasons.
We do not operate a published automated self-serve deletion portal at this time.
16. Cookies and similar technology
Orchestra uses cookies and similar storage as needed for sessions, sign-in handoff, and basic operation of the site. We do not currently run a separate advertised third-party advertising pixel program on the marketing site. Hosting providers may log technical data such as IP address, user agent, and request paths as part of serving the site.
17. Children
Orchestra is a business product. It is not directed at children, and we do not knowingly create accounts for children.
18. International processing
Orchestra is hosted on internet infrastructure that may process data in more than one country (including where Vercel and other providers operate). If you use Orchestra from outside those locations, your information is transferred as needed to provide the service. We do not claim a specific Binding Corporate Rules or adequacy-framework certification in this policy.
19. Policy updates
We may update this policy when the product or our practices change. The effective date at the top will change when we do. Continued use of Orchestra after an update means the revised policy applies to that use. Material changes will be reflected on this public page; we do not promise a separate mailed notice for every edit.
20. Contact
Orchestra — Privacy
Email: hello@orchestra.cloud
Web: /contact
