Legal
Privacy Policy
How Orkata collects, uses, shares, protects, and deletes personal data when people use our website, dashboard, chatbots, and related services.
Effective July 12, 2026
This Privacy Policy explains how Orkata (“Orkata”, “we”, “us”, or “our”) handles personal data in connection with orkata.co, the Orkata dashboard, public chatbot pages, embedded chat widgets, plugins, billing, support, and related services (collectively, the Service).
If you use a chatbot created by an Orkata customer, that customer determines the chatbot’s purpose, knowledge, questions, plugins, and intended audience. The customer is generally responsible for telling you why it collects your data. Orkata processes that visitor data to operate the Service on the customer’s behalf and may also process limited data for security, abuse prevention, and legal compliance.
1. Data we collect
Account data
When you sign in with Google, we receive and store the information needed to create and secure your account, including your email address, name when provided, authentication provider, account identifiers, and login timestamps. Google handles the authentication process under its own terms and privacy policy.
Chatbot configuration and customer content
We store information customers add to build and operate chatbots, including:
- Chatbot names, instructions, selected models, temperature, widget settings, initial messages, suggested messages, profile images, and widget icons
- Uploaded PDF, Markdown, and text files
- Extracted file text, Text sources, Q&A content, and public website content selected for import
- Source names, URLs, file metadata, training status, searchable chunks, embeddings, and retrieval metadata
- Plugin names, trigger instructions, field definitions, webhook URLs, request templates, and server-side configuration where applicable
- Retrieval tests, evaluation cases, quality results, and related diagnostic information
Customers should only upload or import content they are authorized to use. Profile images, widget icons, chatbot names, and other public-facing settings may be visible to anyone who opens the public chatbot or embed.
Conversation and visitor data
Orkata stores chat sessions and messages so chatbot owners can review conversations. This can include:
- Visitor messages and assistant responses
- Random session and message identifiers
- Response versions created through regeneration
- The model used, credit usage, timestamps, confidence information, plugin UI state, and references to retrieved source snippets
- Information a visitor voluntarily includes in a conversation
Chatbot owners can view their chatbot’s conversation history. Visitors should not submit passwords, payment credentials, government identifiers, health information, or other sensitive data unless the chatbot owner has clearly requested it for a legitimate purpose and provides an appropriate notice.
Form and plugin data
When a visitor submits an Orkata Form plugin, Orkata temporarily receives the submitted values to validate and send them to the public HTTPS webhook configured by the chatbot owner. Orkata does not store those field values as Leads. We store a limited receipt containing the plugin, session and form instance identifiers, submission status, count, and timestamps to prevent or track duplicate submissions.
HTTP Request plugins can send information collected or inferred during a conversation to an API chosen by the chatbot owner. The API response can be returned to the AI model to complete the request. Custom Buttons can send visitors to external websites, email addresses, or telephone links. Those destinations are controlled by their respective operators.
Billing and transaction data
For paid plans, we process plan selection, invoice and payment references, transaction amount and currency, payment status, renewal dates, and provider responses. We send the account name and email, order reference, amount, and selected plan details to Midtrans when checkout is enabled.
Payment credentials and payment-method details are collected through Midtrans rather than stored directly by Orkata. We may retain Midtrans transaction responses and webhook events for billing, reconciliation, fraud prevention, accounting, and dispute handling.
Support and communications
If you contact us, we process your email address, message, attachments, account or chatbot identifiers, and any other information you provide. We also store transactional email delivery jobs and status information for payment and renewal messages.
Technical and browser data
Our servers and infrastructure may process IP addresses, request timestamps, routes, response status, user-agent information, error details, and similar technical data to deliver and secure the Service. Public chat and form endpoints use client addresses for short-term rate limiting and abuse prevention.
Orkata uses essential authentication cookies. We also use browser local storage for limited product functions, such as remembering a public chat session, local chat history, model-comparison settings, and website-discovery progress. We do not currently use advertising cookies or third-party behavioral advertising trackers.
2. How we use data
We use personal data and customer content to:
- Authenticate users and administer accounts
- Create, configure, publish, and operate chatbots
- Extract, divide, embed, index, retrieve, and update knowledge content
- Generate AI responses and evaluate retrieval or response quality
- Store and display chat logs, response details, and usage records
- Run customer-configured buttons, forms, webhooks, and API actions
- Enforce plan, storage, credit, and rate limits
- Process payments, renewals, invoices, and transactional emails
- Provide support and investigate technical issues
- Detect abuse, secure the Service, maintain logs, and prevent fraud
- Comply with law, enforce our Terms, and protect users and third parties
- Improve reliability, usability, retrieval quality, and product performance
Depending on the context, our grounds for processing may include performing a contract, taking steps requested before entering a contract, complying with legal obligations, consent where required, and legitimate interests such as operating, securing, and improving the Service while considering the rights of affected people.
3. AI processing and model training
Orkata does not use customer knowledge sources, uploaded files, imported website content, Q&A content, Text sources, visitor messages, or chat logs to train Orkata-owned foundation models.
We do use external AI services to provide requested features:
- Knowledge text is sent through OpenRouter or the configured embedding provider to create numerical embeddings used for retrieval.
- During a chat, the conversation, chatbot instructions, available plugin descriptions, and selected knowledge snippets may be sent through OpenRouter to the selected downstream model provider.
- When retrieval evaluation, confidence, or quality tools are used, relevant questions, source excerpts, and model outputs may be sent to an AI provider for that task.
- HTTP Request inputs and API results may be available to the selected AI model when needed to complete the action. Form field values submitted through the rendered Form plugin are sent to the configured webhook and are not used as chat input merely because the form was submitted.
External AI providers have their own processing, security, location, and retention practices. Available models may be operated by providers such as OpenAI, Anthropic, Google, xAI, Meta, DeepSeek, Z.ai, MiniMax, or Moonshot AI. The provider used depends on the model selected by the customer and the routing available through OpenRouter. Customers with strict regulatory or retention requirements should evaluate the selected model and contact us before submitting regulated or highly sensitive data.
4. How we disclose data
We may disclose limited data to:
- Google, for account authentication and hosted font resources
- OpenRouter and downstream AI model providers, for responses, embeddings, evaluations, and related AI processing
- Midtrans, for checkout, payment confirmation, reconciliation, and fraud controls
- Resend, for transactional email delivery
- Hosting, database, storage, networking, security, and operational providers, as needed to run the Service
- Customer-configured webhook and API operators, when a visitor uses a Form or HTTP Request plugin
- The chatbot owner, including through chat logs, retrieved-source details, usage data, and form submission status
- Professional advisers, authorities, or other parties, when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or handle a business transaction
We do not sell personal data or use it for third-party behavioral advertising.
5. International processing
Orkata and its providers may process data in countries other than the country where the user or visitor is located. Where applicable law requires safeguards for an international transfer, we will take reasonable steps appropriate to the transfer and service provider. Because model selection can change the downstream AI provider, customers should contact us if they require specific processing locations or contractual transfer terms.
6. Data retention and deletion
We retain data for as long as needed to provide the Service, maintain account and billing records, resolve disputes, secure the Service, and meet legal obligations. Retention can differ by category and there is currently no automatic expiration period for active chatbot sources or chat logs.
Available controls include:
- Deleting a source removes its stored source record, file when applicable, searchable chunks, and indexed knowledge. Text from an earlier answer can remain in chat history until conversations are deleted.
- Deleting conversations removes chat sessions and messages for that chatbot while keeping the chatbot, sources, and plugins.
- Deleting a plugin removes its configuration and associated Form submission receipts.
- Deleting an agent removes the agent, its sources and indexed data, plugins, conversations, and messages.
- Account-level, billing-record, or broader statutory requests can be sent to
support@orkata.co.
Some information may remain for a limited period in backups, security logs, billing records, email records, or legal records where deletion is not technically immediate or retention is required or permitted by law. When retained for those purposes, we limit further use accordingly.
7. Security
We use reasonable administrative, technical, and organizational measures designed to protect data. These include access controls, server-side credentials, HTTPS requirements for sensitive integrations, request validation, rate limits, restricted private-network access for crawlers and plugins, and scoped deletion controls.
No online service is completely secure. Customers are responsible for securing their Google account, limiting who can access the dashboard, carefully configuring plugins and webhook credentials, and avoiding unnecessary sensitive data. If we identify a personal-data incident that requires notice, we will notify affected parties and authorities as required by applicable law.
8. Your choices and rights
Depending on applicable law and the processing context, you may have rights to request information about processing, access or obtain a copy of personal data, correct inaccurate data, withdraw consent, object to or restrict certain processing, request deletion or destruction, request portability, and challenge certain automated decisions.
To make a request, email support@orkata.co. We may need to verify your identity and authority before acting. Some requests can be limited where data must be retained for legal obligations, security, fraud prevention, contractual claims, or the rights of others.
If your request concerns a chatbot operated by an Orkata customer, contact that chatbot owner first because the owner determines the purpose of the visitor-data processing. We will reasonably assist the owner or respond directly where Orkata is responsible for the relevant processing.
9. Children
Orkata accounts are intended for people who are at least 18 years old or otherwise have legal capacity to enter a binding agreement. The Service is not designed for customers to intentionally collect children’s personal data without an appropriate lawful basis, notice, and required parental or guardian authorization. Contact us if you believe a child has submitted personal data improperly.
10. Third-party sites and customer integrations
Public chatbots can contain customer-provided links, buttons, forms, and API integrations. We do not control the privacy practices, accuracy, or security of third-party sites or customer systems. Review the relevant operator’s privacy notice before submitting data.
Website import only accesses public pages selected or discovered from a customer-provided URL. The website operator may receive normal server request information when Orkata fetches those pages.
11. Changes to this Policy
We may update this Policy as the Service, providers, or legal requirements change. We will update the effective date and provide additional notice when a change is material and applicable law requires it. Continued use after an update means the revised Policy applies from its effective date, subject to rights that cannot be waived.
12. Contact
For privacy questions, requests, or concerns, contact:
Orkata
Email: support@orkata.co
Website: https://orkata.co
This Policy is intended to explain current product behavior. It should be reviewed alongside the Terms and Conditions.