Skip to content
Orqra

Privacy

Your creative work stays local. Product analytics is optional.

This policy describes Orqra local-first and BYOK boundaries, the optional Desktop product analytics flow, and the limited website download signal.

Current privacy state

Local data
Core creative data stays on this device by default
Cloud sync
Not available
Website product analytics
Not configured in this build
Marketing cookies
None
Website account system
None
Model providers
User-configured BYOK providers

Local-first and BYOK boundaries

Projects, workflow graphs, Prompts, generated results, imported files, creative assets, notes, model API keys, Agent Sessions, Traces, and Artifact content stay on your device. When you run a model, the request and selected inputs go directly from your device to the Provider you configured, under that Provider's terms. Orqra Server handles only commercial, licensing, release, feedback, and the limited product analytics boundaries described below.

Optional Desktop product analytics

Desktop product analytics is off by default and starts only after you enable it in Privacy & Data. Events are limited to the event type, app version, build channel, platform, locale, edition, UTC calendar date, and closed completion outcomes. A random installation identifier is HMAC-hashed by Orqra Server before storage. The stored hash is pseudonymous, is not an account or device identity, and is never joined to commercial records.

Data that product analytics never includes

Product analytics never includes projects, Prompts, outputs, files, paths, API keys, model requests or bodies, Provider or model names, License data, email, device identity, error text, response bodies, feedback content, or creative content. Orqra does not use analytics events to reconstruct or inspect your work.

Retention and your control

The Desktop retry queue is kept for at most 7 days. Infrastructure may process limited network metadata, such as IP address and User-Agent, in access security logs for at most 7 days; those logs are not product analytics. Raw product events are kept for 30 days, and daily aggregates for 12 months. Turning analytics off immediately stops sending and clears the local queue, first-event markers, and random identifier without changing core features or requiring a restart.

Website download signal

Orqra does not use general page analytics, marketing pixels, marketing cookies, or browser identifiers. When this build is configured with Orqra Server, the structured product-statistics signal for a public release download redirect contains only UTC date, release version, channel, and platform. It does not retain referrer, query, IP address, User-Agent, or an installation identifier. Network infrastructure may still process limited transport metadata in short-lived access security logs as described above. The signal measures a redirect request rather than a completed download or installation.

Purpose, choice, and operator

Orqra operates this limited product analytics solely to improve first-use and workflow reliability. Desktop analytics relies on your explicit opt-in and remains off otherwise. The operator of Orqra determines how the limited analytics and commercial or contact data described in this policy is processed. Use the privacy contact below for privacy matters.

Your privacy rights

You may withdraw consent at any time by turning product analytics off. Depending on your region, you may also request access, correction, deletion, restriction, objection, portability, or complain to a competent data protection authority. Because product analytics is not linked to an account or email, Orqra may be unable to locate a specific event from an email address alone.

Service providers and international processing

Orqra may use hosting, database, security, and payment service providers acting under contractual and confidentiality safeguards. Processing locations may differ from your country; where required, Orqra uses appropriate transfer safeguards. Product analytics is not sold and is not shared for targeted advertising.

Commercial and license data

Orqra Server may store the purchase email, payment provider identifiers and status, product identifier, License status, device activation metadata, webhook records, and release metadata. It does not store your projects or creative content.

Transactional License email

After a verified purchase, Orqra uses Zoho ZeptoMail in its China data centre to send the License email. This necessarily processes the purchase email, locale, License Key, message body, delivery identifier, and delivery result. Open and click tracking, remote images, attachments, and marketing use are disabled. ZeptoMail may retain delivery logs for up to 60 days; Orqra does not enable message-content storage. Orqra keeps only the delivery status, a non-secret Provider request ID, stable error code, and timestamps.

Payments

Dodo Payments processes checkout and payment information under its own terms and privacy policy. Orqra receives only the commercial records needed to fulfil, support, refund, and audit a purchase.

Last updated:

Contact: privacy@orqra.com