Legal
Privacy
policy
Last updated 21 September 2026. This policy covers this website today and states how the product is being built to handle data.
What this website collects
When you send the Get access form, we receive the details you enter: your name, work email, company, role, platform size, topic and message. We use them only to reply to you and to run the design partner program. The form goes through a delivery service configured on the deployment, and the request is not stored anywhere else by this website.
The hosting provider keeps standard server logs, such as IP address, browser type and the pages requested, for security and reliability. This website sets no analytics cookies and runs no advertising trackers. The demo on the homepage sends your question to our server, which answers it from three fictional sample help articles. Your IP address is used only to rate limit that endpoint, and the questions are not stored. If a model provider is configured for the demo, the question and those sample passages are sent to it to compose the wording; no other data goes with them.
How the product will handle data
The product is not yet live for customers. When it is, each vendor workspace will hold its own documentation, conversation logs and audit log, isolated from every other workspace. Personal data will be redacted from analytics views, and full content will stay in the vendor’s isolated log for a retention period the vendor sets. Customer documents and conversations will never be used to train models. Deleting a document will remove its chunks from the index within minutes.
End users of a vendor’s software interact with the assistant under that vendor’s own privacy terms. Orrin acts as a processor for the vendor, and a data processing addendum is available on request once the first production workspace opens.
Retention
Access requests are kept as long as needed to reply and to run the design partner program, and deleted on request.
Your rights
You can ask what we hold about you, ask for it to be corrected or deleted, and object to its use. Use the access form with the Support topic.
Subprocessors
This website is hosted on Vercel. Delivery of access requests uses the service configured on the deployment. The product’s runtime providers will be published on the Security page before any customer data is processed.
Changes
Changes to this policy are dated at the top of this page.