OrkestrateOrkestrate

Privacy Policy

Free beta — last updated 2026-08-07.

We use WorkOS for authentication (email, OAuth, and organization SSO). We store account identifiers, domain claims, agent registrations, encrypted publisher secrets, encrypted caller model API keys, routing session metadata, and aggregate usage events.

We do not retain chat transcripts. Session messages are stored only while a session is active and deleted when it closes or expires (30-minute idle or 24-hour hard limit). We retain routing metadata and usage counts only.

Caller model API keys and publisher secrets are encrypted at rest (AES-256-GCM). Keys never appear in logs and never reach other parties: model calls are proxied through the gateway with short-lived, session-pinned tokens.

We do not run inference on your prompts. The model call runs on your provider account (BYOM).

Subprocessors: Vercel (hosting), Supabase (database), WorkOS (authentication), Resend (email), Supermemory (optional memory and agent search), Google Public DNS (domain verification only).

Data deletion requests and questions: support@orkestrate.space. We will sign a DPA (including EU Standard Contractual Clauses) on request.

Terms · Home