Privacy
effective 2026-08-02
What we store
Account details, flow definitions, API key hashes and prefixes, run history (inputs, outputs, status, duration, tokens) and daily usage rollups. When you ask for an export we also hold the archive itself for 24 hours, then delete it. Self-hosted deployments store all of this on your infrastructure, not ours.
What we do not do
We do not train on your data. We do not sell it. We do not use third-party analytics on this site — it makes no external requests at all.
Why we store it
Run history exists so you can debug; usage rollups exist so you can bill. Both are yours to export or delete, from Account → Your data in the app. You do not need to ask us.
Exporting your data
One gzipped JSON archive holding everything we have for you: your organisation and account records, every flow with its definition, your full run history including inputs and outputs, your daily usage totals, your API key metadata and your flow audit trail. It contains no secrets — password hashes, API key hashes and session tokens are excluded and cannot be recovered from it. Large exports are built in the background; the download link lasts 24 hours, and you can ask for another whenever you like.
Retention
Run history is kept for 30 days on Free and 365 days on Pro, then deleted by a nightly sweep — inputs, outputs and all. Daily usage totals outlive that window: they are counts only, with no inputs, no outputs and no prompt text, and your invoices are reconstructed from them. Unpublishing a flow takes it off the air immediately; deleting one removes its definition from Orchent and its compiled graph from the engine that ran it.
Deleting your account
Account → Delete account, after you type your organisation's name and re-enter your password. Every API key stops authenticating and every published flow stops answering before anything else happens. Then your compiled flows are deleted from the engine, your subscription is cancelled outright so nothing is billed for an account that no longer exists, and every row we hold — account, users, keys, sessions, run history, usage totals, flows, audit entries and past exports — is deleted. It is irreversible, and there is nothing left behind but a dated log line recording that a deletion happened.
Access
Tenant isolation is enforced on every path. Cross-tenant requests return 404. Secrets are resolved server-side and never appear in stored definitions or history.
Export and deletion are self-serve under Account in the app — you never have to ask. Anything else — [email protected].