Skip to content

Privacy Policy

Information you provide

You may provide prompts, files, project material, feedback, and other content so Orcheum can carry out requested work. Guest visitors may submit a limited first thought without creating an account. Members may store conversations, projects, and related workspace data.

Account information

If you create or sign in to an account, Orcheum stores the identity details needed to operate that account. Depending on how you sign in, that may include an email address, a display name, and a subject identifier from a sign-in provider such as Google, Apple, or GitHub. Sign-in with Google is identity only: it does not grant Orcheum access to Gmail or other Google product data.

Orcheum maintains a session so you remain signed in. Sessions are delivered with HttpOnly cookies. A separate CSRF cookie is used to protect cookie-authenticated requests.

Service usage information

To operate, debug, and protect the service, Orcheum records operational information such as request timing, feature use, errors, and similar service events. Provenance and system receipts are meant to record what actually ran — participants, status, and related metadata — rather than to invent them.

AI and model processing

When you ask Orcheum to do work, relevant content is sent to the models and tools Argus commissions for that request. Those providers process the material in order to return results. Orcheum does not treat a connector as a substitute for your request: a model is used because the orchestration needs it, not because a vendor name appeared in the prompt.

Third-party providers have their own terms and privacy practices. Orcheum does not control how an external model provider independently retains data after it receives a request.

Connectors and connected accounts

Some product features can use an external account you connect, such as a Google account for mailbox access. Connection is optional. Orcheum accesses a connected account only after you authorize it, and only for the capabilities you have granted.

Permissions are requested for the capabilities the product needs. For Gmail read features, that is Gmail read access plus the identity scopes needed to recognize the connected account. Orcheum does not request Gmail compose or send permission for those read features.

Google user data

If you connect Google for mailbox features, Orcheum may read message metadata and content needed to fulfill a request you make — for example searching messages and reading a selected message so Argus can reason over structured results.

Google user data obtained through a connected account is used to provide that requested functionality. Orcheum does not sell Google user data. It does not use Google user data for advertising. It does not use connected Google mailbox content to train a generalized Orcheum model.

Structured connector results may be passed to the models and tools needed for your request. Connector provenance records capability use, account identity, and safe external identifiers. It is not a place for OAuth tokens or unnecessary message bodies.

OAuth credentials and tokens

When you connect an external account, Orcheum stores the credentials required to act on your authorization. Those tokens are kept server-side, encrypted, and are not returned to the browser, included in provenance, or written into product source.

Orcheum refreshes access tokens on the server when the connected account still authorizes it. If authorization expires, is revoked, or lacks a required permission, the product treats that as a failed or incomplete resource — it does not invent the missing data.

Security

Orcheum is designed so secrets stay on the server, public API errors do not expose connector internals, and one user cannot use another user’s connected account. No security practice described here is a certification, audit result, or guarantee against unauthorized access.

Retention

Account, conversation, and project data are kept while they are needed to provide the workspace. Guest allowances are short-lived by design. Orcheum has not published a single fixed retention schedule for all categories of data, and this policy does not invent one.

Connected-account tokens are kept while the connection remains. Message content retrieved to fulfill a request is used for that work; Orcheum does not treat the connector store as an archive of Gmail bodies.

Your controls

You can sign out. You can disconnect a connected Google account in the product, which stops Orcheum from using that connection and removes the stored connector credentials for that account under Orcheum’s disconnect lifecycle. You can also revoke access from your Google account permissions.

Orcheum does not currently publish a self-serve account-deletion control in the product. If you want an account closed, contact Orcheum through the website.

Updates

We may update this policy as the product changes. The effective date above will change when we do. Continued use of Orcheum after an update means the revised policy applies to that later use.

Contact

Orcheum has not published a dedicated privacy email address. Contact us through orcheum.com. Related terms are at orcheum.com/terms.