ORECABack to home

LEGAL / PRIVACY

Privacy, by design.

Oreca is built to give you useful intelligence without turning your computer into a surveillance device.

Oreca Technologies Pvt. Ltd.Effective date: To be announced
01

Identity & scope

This Privacy Policy is provided by Oreca Technologies Pvt. Ltd. (“Oreca”, “we”, “us”, or “our”). It applies to the Oreca desktop application, cloud web app, API access, and Spaces team workspaces.

The effective date of this policy will be announced. We will provide at least 30 days’ advance notice of material changes by email.

02

Information we collect

Account information, including your email address, name, and Firebase authentication UID.

Conversation information, including user messages, AI-generated responses, and session IDs.

Files uploaded to Knowledge Bases, including PDFs, CSVs, text, and audio.

Voice inputs processed by local Whisper speech-to-text, encrypted OAuth access and refresh tokens, agent execution logs, and memory data such as L1 facts and L2 timeline events.

If you opt in, aggregated usage telemetry such as response latency and error rates.

03

What we do not collect

Oreca does not collect continuous screen captures, keystroke logs, or clipboard contents. We do not index your entire file system, run persistent background processes after the app is closed, or sell, rent, or broker personal data to third parties.

04

Legal basis for processing

We process account and conversation data when necessary to provide the service you request. We rely on legitimate interest to maintain system health through usage telemetry and error logs. Voice audio, Brain or memory extraction, and cross-session search require separate, granular opt-in consent.

Oreca will appoint a Data Protection Officer for users residing in the EEA or UK.

05

Local-first architecture

In desktop mode, memory and chat history are stored exclusively in a local SQLite database at ~/.oreca/memory.db. You remain the sole data controller of that local database. Deleting it constitutes a complete exercise of the right to erasure under GDPR Article 17.

Knowledge Base documents are automatically deleted 30 days after removal.

06

Retention schedule

These are maximum retention periods. You may request earlier deletion at any time.

Data typeRetentionDeletion trigger
Account dataAccount duration + 90 daysManual deletion or account closure
Conversation dataUser-configurable; unlimited by defaultManual deletion or account closure
Cloud-uploaded documents30 days after removalRemoval or account closure
OAuth tokensUntil revokedUser revocation or account closure
Agent execution logs90 daysAccount deletion
Voice audio inputsNot retainedNever stored
Usage telemetry12 months, anonymizedRolling deletion
Sandbox code and outputSession duration onlySession end

Third-party subprocessors

Oreca may use Google Cloud (Gemini), OpenAI or Anthropic as optional failover providers, Firebase/Google for identity, Tavily, Firecrawl and Arxiv for web and scholarly retrieval, user-registered MCP servers, and Stripe for payments. Oreca does not warrant the security of user-registered external processes.

Children’s data

The service is not directed at children under 13 in the United States or under 16 in the European Union. Accounts discovered to belong to children under 13 will be deleted within 48 hours of discovery.

International transfers

International transfers are conducted lawfully under the EU–US Data Privacy Framework or standard contractual clauses. For users in India, Oreca is committed to compliance with the Digital Personal Data Protection Act, 2023.

Security safeguards

Data in transit uses TLS 1.2 minimum, with TLS 1.3 preferred. OAuth tokens are encrypted at rest using Fernet (AES-128-CBC), and decrypted only in volatile memory when needed. Generated code runs in isolated microVM containers with restricted network access, read-only host access by default, and a 30-second execution timeout.

Access controls & incidents

Cloud queries are scoped by user_id, Space Knowledge Bases by space_id, and chat histories by session_id. Oreca staff have no routine internal access to conversation data. A response team is activated within two hours of a potential breach, and users will be notified within 72 hours of confirmation, subject to applicable law.

A note on this policy

This page is a plain-language presentation of Oreca’s internal legal framework and should be reviewed and finalized by qualified legal counsel before publication or reliance.