Identity & scope
This Privacy Policy is provided by Oreca Technologies Pvt. Ltd. (“Oreca”, “we”, “us”, or “our”). It applies to the Oreca desktop application, cloud web app, API access, and Spaces team workspaces.
The effective date of this policy will be announced. We will provide at least 30 days’ advance notice of material changes by email.
Information we collect
Account information, including your email address, name, and Firebase authentication UID.
Conversation information, including user messages, AI-generated responses, and session IDs.
Files uploaded to Knowledge Bases, including PDFs, CSVs, text, and audio.
Voice inputs processed by local Whisper speech-to-text, encrypted OAuth access and refresh tokens, agent execution logs, and memory data such as L1 facts and L2 timeline events.
If you opt in, aggregated usage telemetry such as response latency and error rates.
What we do not collect
Oreca does not collect continuous screen captures, keystroke logs, or clipboard contents. We do not index your entire file system, run persistent background processes after the app is closed, or sell, rent, or broker personal data to third parties.
Legal basis for processing
We process account and conversation data when necessary to provide the service you request. We rely on legitimate interest to maintain system health through usage telemetry and error logs. Voice audio, Brain or memory extraction, and cross-session search require separate, granular opt-in consent.
Oreca will appoint a Data Protection Officer for users residing in the EEA or UK.
Local-first architecture
In desktop mode, memory and chat history are stored exclusively in a local SQLite database at ~/.oreca/memory.db. You remain the sole data controller of that local database. Deleting it constitutes a complete exercise of the right to erasure under GDPR Article 17.
Knowledge Base documents are automatically deleted 30 days after removal.
Retention schedule
These are maximum retention periods. You may request earlier deletion at any time.
Third-party subprocessors
Oreca may use Google Cloud (Gemini), OpenAI or Anthropic as optional failover providers, Firebase/Google for identity, Tavily, Firecrawl and Arxiv for web and scholarly retrieval, user-registered MCP servers, and Stripe for payments. Oreca does not warrant the security of user-registered external processes.
Children’s data
The service is not directed at children under 13 in the United States or under 16 in the European Union. Accounts discovered to belong to children under 13 will be deleted within 48 hours of discovery.
International transfers
International transfers are conducted lawfully under the EU–US Data Privacy Framework or standard contractual clauses. For users in India, Oreca is committed to compliance with the Digital Personal Data Protection Act, 2023.
Security safeguards
Data in transit uses TLS 1.2 minimum, with TLS 1.3 preferred. OAuth tokens are encrypted at rest using Fernet (AES-128-CBC), and decrypted only in volatile memory when needed. Generated code runs in isolated microVM containers with restricted network access, read-only host access by default, and a 30-second execution timeout.
Access controls & incidents
Cloud queries are scoped by user_id, Space Knowledge Bases by space_id, and chat histories by session_id. Oreca staff have no routine internal access to conversation data. A response team is activated within two hours of a potential breach, and users will be notified within 72 hours of confirmation, subject to applicable law.
A note on this policy
This page is a plain-language presentation of Oreca’s internal legal framework and should be reviewed and finalized by qualified legal counsel before publication or reliance.