Privacy Policy
Last updated: July 21, 2026
1. Overview
OrcFlows ("OrcFlows," "we," "us," or "our") provides a workflow automation and AI agent platform that lets you build, run, and connect automated workflows to your own accounts on third-party services (such as Gmail, Slack, Notion, or GitHub) and to AI model providers (such as OpenAI or Anthropic). This Privacy Policy explains what information we collect when you use OrcFlows, why we collect it, and the choices you have.
This policy applies to OrcFlows and covers our web application, API, and related services (collectively, the "Service"). It does not cover third-party services you choose to connect to OrcFlows — those are governed by that provider's own privacy policy.
2. Information We Collect
Account information. When you sign up, we collect your email address and, if you register with a password, a securely hashed version of it. If you sign in with Google, we receive your name, email address, and profile picture from Google — we never see or store your Google password.
Workspace content. The workflows you build, the nodes and configuration within them, execution history and logs, and any inputs or outputs your workflows produce.
Secrets and credentials. API keys and other secrets you add to power your workflows and connectors are encrypted at rest (AES-256-GCM) before storage. Secret values cannot be retrieved once saved — only replaced.
Connected-account tokens. When you connect a third-party account (see Section 3), we store the resulting OAuth access and refresh tokens, encrypted at rest, so that your workflows can act on that account on your behalf.
Knowledge base content. Documents, text, and web pages you upload or crawl into a knowledge base, along with the vector embeddings generated from them (see Section 4).
Billing information. If you subscribe to a paid plan, payment is processed by Stripe. We receive your plan, billing status, and transaction metadata — OrcFlows never receives or stores your full card number.
Usage and log data. Standard technical data such as IP address, browser type, timestamps, and pages or API endpoints accessed, used for security, debugging, and (on Enterprise plans) audit logging.
3. Connected Accounts & Third-Party Services
OrcFlows lets you connect your accounts on a wide range of third-party services — Google (Gmail, Sheets, Calendar, Drive), Slack, Notion, LinkedIn, GitHub, GitLab, Dropbox, Microsoft, and many others — either via OAuth (you grant access through that provider's own consent screen) or by supplying an API key directly.
When you connect a Google account, we request only the scopes needed for the specific product you're connecting (for example, connecting Gmail requests Gmail access only, not Sheets, Calendar, or Drive). You can review and revoke access at any time from the Connectors page in the app, or directly from the third-party provider's own account settings (for Google, at myaccount.google.com/permissions).
Disconnecting an account deletes the corresponding stored tokens from our systems.
4. AI Providers & Knowledge Bases
Workflows and agents you build in OrcFlows can be configured to call AI model providers of your choosing — for example OpenAI, Anthropic, or a self-hosted/custom model endpoint. When a workflow runs, the inputs you've configured (which may include your own data) are sent to whichever provider that workflow specifies, subject to that provider's own data-handling terms. OrcFlows does not control, and is not responsible for, how a third-party model provider processes data you choose to send it.
Knowledge bases work similarly: content you upload or crawl is converted into vector embeddings using the embedding provider you select for that knowledge base (OpenAI, NVIDIA NIM, or a custom OpenAI-compatible endpoint you supply), and both the source content and resulting embeddings are stored so the knowledge base can be queried later.
5. How We Use Information
- To provide, operate, and maintain the Service, including running your workflows as configured.
- To authenticate you and secure your account and workspace.
- To process billing and manage subscriptions.
- To respond to support requests and communicate service-related notices.
- To monitor, debug, and improve the reliability and performance of the Service.
- To detect, prevent, and address fraud, abuse, or security issues.
- To comply with legal obligations.
We do not sell your personal information, and we do not use the content of your workflows, secrets, or knowledge bases to train our own models.
6. Security
We use industry-standard safeguards to protect your information, including encryption of stored secrets and OAuth tokens (AES-256-GCM), encryption in transit (TLS/HTTPS), and workspace-level data isolation between tenants. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Data Retention & Deletion
We retain your information for as long as your account is active or as needed to provide the Service. Deleting a connected account, secret, or knowledge-base document removes it from our active systems. You may request deletion of your account and associated data by contacting us at the address in Section 14; we will delete or anonymize your information within a reasonable period, except where retention is required by law (for example, billing records).
9. Your Rights & Choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Request deletion of your information.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent, where processing is based on consent.
To exercise any of these rights, contact us using the details in Section 14. You can also manage most of this directly in the app: connected accounts and secrets can be revoked or deleted from Connectors and Settings at any time.
11. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
12. International Data Transfers
We may process and store information in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) to protect information transferred internationally.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through an in-app notice before the change takes effect. The "Last updated" date above reflects the most recent revision.
14. Contact Us
If you have questions about this Privacy Policy or how we handle your information, contact us at contact@orcflows.com.