1. Who we are and who this policy covers
Orchestror is a multi-tenant software platform for SEO and marketing agencies. Each agency operates its own instance of the product on its own subdomain (for example, youragency.orchestror.com). The platform coordinates AI agents to help agencies run SEO and marketing work for their own clients.
This policy applies to two audiences:
- Agency customers ("you"): the agencies and their staff who log in to Orchestror and operate the platform.
- End clients of the agency: the businesses whose websites, listings, and marketing an agency manages through Orchestror. Data about these businesses (and, in some cases, about their leads and contacts) may flow through the platform because an agency customer directed it to.
If you are an end client of an agency and you have questions about how your data is used, your first point of contact is the agency that manages your account. We describe below what our own systems do with that data.
Orchestror is operated by an individual doing business as Orchestror, based in the United States. See "Contact" below for our mailing address.
2. Information we collect
We collect the following categories of information. For each, we note the purpose it serves.
Account and authentication data. Access to an Orchestror instance is controlled at the instance level rather than through individual user accounts. We do not maintain a per-user profile, and we do not store an individual login name, email, or password for each staff member in the product database. A session token is issued after login and expires after seven days. Purpose: to control access to the instance.
Waitlist and contact data. If you request access through our marketing site, we collect the name and email you submit. Purpose: to respond to your request and to contact you about access.
Chat and operational content. When you use the platform, the prompts and messages you send to the AI agents, the tasks ("runs") you execute, and their inputs and outputs are stored in the instance database. This content is free-form and may contain any information you choose to enter, including personal information about your clients or their contacts. Purpose: to operate the features you use, to show your history, and to account for usage and cost.
Client business data. For each client site an agency configures, we store business details such as the legal name, phone number, address, service locations, and Business Profile identifiers. Purpose: to perform the SEO and marketing tasks you request.
Connected-account data. When you connect a third-party account (see "How we share information"), we access data from that account as needed to perform the actions you request. For Google connections this includes Search Console, Analytics, Business Profile, and Drive data for the properties you connect, plus the identity (email) of the connected Google account. Purpose: to perform the connected-service actions you direct.
Analytics data. Websites, keyword rankings, traffic figures, and review data pulled for the client sites you manage are stored as snapshots. Purpose: reporting and analysis.
First-party usage telemetry. We record limited, pseudonymous events about how the platform is used (for example, which page or action was used, and an associated site identifier). This telemetry does not identify an individual person and can be turned off in the app's preferences. Purpose: to understand and improve product use.
What we do not collect. We do not collect device IP addresses, user-agent strings, or device fingerprints in the product database. We do not load third-party analytics or tracking scripts (such as Sentry, PostHog, Mixpanel, Segment, or Hotjar) inside the product. The only external resource the product interface loads is Google Fonts. On our public marketing site we use Cloudflare Web Analytics (cookieless) and Google Analytics 4; that site is separate from the product.
3. Cookies and browser storage
The Orchestror product does not set HTTP cookies. Authentication uses a bearer token held in your browser's local storage, not a cookie. The product uses browser local storage and session storage to hold your session token and a small set of preferences (theme, active site, activity-tracking on/off, and onboarding state). Because there are no product cookies, no cookie consent banner is required for the product itself.
Our separate marketing site uses Cloudflare Web Analytics (cookieless) and Google Analytics 4. GA4 runs only on that marketing site, not inside the product. Depending on how a GA4 property is configured, it can involve advertising-related data sharing with Google; where that is a factor it is confined to the marketing site, and we work to keep advertising signals turned off on that property. Consult that site's notice for details.
4. How we use information
We use the information above to:
- provide, operate, and maintain the platform and the features you use;
- perform the specific SEO and marketing tasks you request, including through AI agents;
- generate content, images, reports, and recommendations at your direction;
- communicate with you about access, support, and service-related matters;
- understand and improve how the product is used; and
- comply with law and enforce our terms.
Our AI agents process your prompts and the content you provide in order to produce the outputs you request. See "Automated decision-making and AI" below.
5. Google API Services User Data Policy (Limited Use)
When you connect a Google account, Orchestror's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Scopes we request. When you connect Google, we request only these scopes, each tied to a visible feature in the product:
| Scope | What it is for |
|---|---|
webmasters.readonly | Read Search Console performance and index data for the properties you connect. |
analytics.readonly | Read Google Analytics 4 traffic data for the properties you connect. |
business.manage | Read and update the Google Business Profile locations you connect. Google does not offer a read-only variant of this scope. |
drive.file | Create and manage only the specific Drive files the app creates (the minimum Drive scope; we cannot see your other Drive files). |
openid, email | Identify the connected Google account. |
We do not request Gmail or Google Calendar scopes.
Limited Use. We limit our use of data received from these Google APIs to providing or improving user-facing features that are prominent in the product's interface. We do not transfer this data except in the following cases, which are reproduced verbatim from Google's policy:
- "To provide or improve your appropriate access or user-facing features that are visible and prominent in the requesting application's user interface and only with the user's consent"
- "For security purposes (for example, investigating abuse)"
- "To comply with applicable laws"
- "As part of a merger, acquisition, or sale of assets of the developer after obtaining explicit prior consent from the user"
No AI or ML training on Google data. We do not use data obtained through Google Workspace or Google APIs to develop, improve, or train generalized artificial intelligence or machine-learning models.
Human access. We do not allow humans to read data obtained from these Google APIs except with your affirmative agreement for specific data (for example, if you ask us to help troubleshoot), for security purposes, to comply with law, or as necessary to operate a feature you have requested.
Disconnecting. You can disconnect a Google connection from within the app. Doing so deletes the stored refresh token (and the local token file used for Drive) from your instance, and also revokes that token with Google directly, unless the same Google account connection is still in active use by another site on your instance, in which case only the local link for the site you disconnected is removed (the shared connection keeps working for the other site or sites still using it, and you can disconnect those separately, or revoke access directly at myaccount.google.com/permissions, at any time).
7. Automated decision-making and AI
Orchestror is, by design, a platform that uses AI agents to process data and generate outputs such as content, images, reports, and recommendations. We disclose this use plainly here.
The AI agents produce marketing and SEO outputs. They do not make decisions that produce legal or similarly significant effects about an individual consumer (such as decisions about credit, employment, housing, insurance, education, or essential services). For that reason, we do not currently offer a formal opt-out from automated decision-making of the kind California's Automated Decision-Making Technology (ADMT) regulations require for "significant decisions." If our use of AI ever expands to significant decisions about individuals, we will update this policy, provide the required pre-use notice, and offer the opt-out and access rights those rules require.
Many actions on the platform are gated by human review by default. For example, social posts are only published after explicit human approval, and WordPress content defaults to draft status until a person publishes it. Actions taken through integrations you connect (for example, updating a connected CRM) execute as you direct them and may not pass through the same human-approval gate. AI output can be inaccurate; you are responsible for reviewing it before you rely on or publish it. See our Terms of Service for more on AI output.
We do not use your data, or data obtained from your connected Google accounts, to train generalized AI or ML models.
8. Data retention
We keep information for as long as needed to provide the service and for our legitimate business and legal purposes. Because we are an early-stage product, several retention behaviors are honest to describe precisely:
- Chat threads can be deleted in the app, which permanently removes the thread and its messages.
- Usage telemetry, chat messages, runs, research jobs, video jobs, and analytics snapshots are currently retained in the instance database until deleted manually. We do not yet run an automated time-to-live job that purges these on a fixed schedule.
- Cached third-party responses stored on the instance disk expire on a per-endpoint basis (for example, some are refreshed after 24 hours).
- Deleting a client site removes its directory and every database record scoped to that site: chat history, run history, snapshots, schedules, workflows, and stored credentials for that site.
We describe retention globally rather than by individual data category today; we will move toward per-category retention as these controls mature. We are working to add configurable, automated retention periods for the categories listed above (chat messages, runs, research and video jobs, analytics snapshots). Until then, if you want data deleted, you can request it (see "California privacy rights" and "Contact"). We will describe our then-current retention practice when you ask.
9. Security
We take reasonable measures to protect data, and we describe our current posture honestly rather than promising protections we have not yet implemented.
What is protected today:
- Credentials stored in our dedicated encrypted credential store are encrypted at rest using Fernet (AES-based) symmetric encryption with a dedicated encryption key.
- All product responses are served over HTTPS with strict transport security, and the product sends security headers including a strict Content-Security-Policy,
X-Frame-Options,X-Content-Type-Options, and a strict referrer policy. - Access credentials are compared using a constant-time comparison to resist timing attacks.
- The platform is multi-tenant by separate deployment: each agency runs its own instance rather than sharing one database, which isolates tenants at the infrastructure level.
- Production instances additionally sit behind a network-level access gateway (Cloudflare Zero Trust) in front of the login surface.
Current limitations we want you to know about:
- Not all credentials are encrypted at rest yet. Some connected-account credentials are currently protected by system-level access controls rather than the Fernet-based encryption described above. We treat migrating these to the encrypted credential store as a priority engineering item.
- There is no per-user account model or administrator role system today — access to an instance is controlled at the instance level rather than per staff member. We are hardening this layer, including stronger credential handling and application-level rate limiting, as ongoing engineering work.
No method of storage or transmission is perfectly secure. We are actively hardening these areas and will update this section as we do.
10. Your California privacy rights (CCPA/CPRA)
We provide the following rights to California residents as a matter of practice, whether or not we currently meet the CCPA/CPRA revenue or volume thresholds.
You have the right to:
- Know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties that receive it;
- Delete personal information we hold about you, subject to legal exceptions;
- Correct inaccurate personal information;
- Opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising);
- Limit the use of sensitive personal information to what is necessary to provide the service; and
- Not be discriminated against for exercising these rights.
You may also designate an authorized agent to make a request on your behalf.
Categories of personal information. The categories we collect, our sources, the purposes, and the categories of third parties we disclose to are set out in "Information we collect" and "How we share information" above. In the terms of the statutory categories the CCPA uses, these map to identifiers, commercial information, internet or other electronic network activity, geolocation data, professional information, and the contents of communications. We do not sell or share any category for cross-context behavioral advertising in the product.
Sensitive personal information. Connected-account credentials and the free-form content you enter may include sensitive information. We use such information only to provide the features you request and do not use or disclose it for other purposes without your consent.
Global Privacy Control (GPC). We do not sell or share personal information for advertising in the product. If we ever do, we will honor GPC opt-out signals as a valid request to opt out of sharing.
How to exercise your rights. Because we do not yet offer a self-service privacy portal, submit requests by email to hello@orchestror.com. We will verify your request and respond within the timeframe required by law (generally within 45 days, with an extension where permitted). Note that some mechanisms (such as a full data export) are handled manually on request rather than as an automated feature.
11. Email and marketing communications (CAN-SPAM)
Transactional and operational emails (such as reports and run notifications) are sent only when an instance is configured to send them; email sending is not enabled by default on every instance.
If we send commercial or marketing email, we will: identify the sender accurately, use non-deceptive subject lines, identify the message as an advertisement where required, include a valid physical postal address in each such message, and provide a clear way to opt out that we honor promptly (within ten business days). We will not charge a fee to opt out, require you to give any information beyond an email address, or make you take any step other than replying to an email or visiting a single web page. Our physical mailing address for this purpose is 1453 W Flagler St STE B, Miami, FL 33135-2208, United States.
If your agency uses Orchestror to send campaigns to your own lists, you are the sender of those messages and are responsible for CAN-SPAM compliance, including one-click unsubscribe support where required.
12. Children's privacy (COPPA)
Orchestror is a business tool and is not directed to children. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it. If you believe a child has provided us information, email hello@orchestror.com.
13. International users and data transfers
Orchestror is a US-based service intended for US-based agencies and their clients. Several of our sub-processors are located in the United States; for others we are still confirming the hosting region, as noted in the sub-processor table above. This service is not directed to residents of the European Union, the United Kingdom, or Israel, and GDPR, UK GDPR, and the Israel Privacy Protection Law do not apply to it today, as long as we do not target or monitor individuals in those regions. If we expand to serve users in those regions, or otherwise begin targeting or monitoring people there, we will update this policy and implement the additional obligations those laws require before doing so.
14. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last Updated" date and, where appropriate, provide additional notice. We will not apply materially different practices to information we already collected without a lawful basis or, where required, your consent.
What changed in the July 18, 2026 update
- Documents the real product, not the earlier placeholder policy that only covered the waitlist form — now covers Google OAuth connections, client CRM data, WordPress publishing, third-party SEO data APIs, and AI content/image generation.
- Splits sub-processors into two tiers — providers Orchestror contracts with directly, versus optional integrations you connect with your own accounts.
- Adds a dedicated Google API Limited Use section, reproducing Google's four permitted-transfer exceptions verbatim, and states plainly that we do not train AI models on Google data.
- Adds California CCPA/CPRA rights, an Automated Decision-Making disclosure, a CAN-SPAM section, and a children's privacy clause.
- Security section is honest about current gaps rather than promising protections not yet implemented — some credentials are encrypted at rest, some are not yet.
- Disconnecting a Google account now revokes the token with Google directly (previously local-only), and deleting a site now cascades to every related database record (previously partial).
15. Contact
Privacy questions
For any privacy question or to exercise a right described above, email hello@orchestror.com.
Mailing address: 1453 W Flagler St STE B, Miami, FL 33135-2208, United States.