# Privacy Policy

How Orkata collects, uses, shares, protects, retains, and deletes personal data when people use our website, dashboard, chatbots, and related services.

Effective date: September 3, 2026

This Privacy Policy explains how Orkata ("Orkata", "we", "us", or "our") handles personal data in connection with `orkata.co`, the Orkata dashboard, public chatbot pages, embedded chat widgets, actions, billing, support, and related services (collectively, the **Service**).

For account, workspace, billing, security, support, and product-analytics data, Orkata determines why and how the data is processed. When a person uses a chatbot created by an Orkata customer, that customer determines the chatbot's purpose, knowledge, questions, actions, and intended audience. The customer is generally the Personal Data Controller for that visitor data, and Orkata processes it on the customer's behalf while also processing limited data for security, abuse prevention, service reliability, billing, and legal compliance.

## 1. Data we collect

### Account, onboarding, and workspace data

When you sign in with Google, we receive and store the information needed to create and secure your account, including your email address, name when provided, authentication provider, account identifiers, and login timestamps. Google handles the authentication process under its own terms and privacy policy.

During onboarding, we store the answers you submit, such as role, organization name, industry, team size, intended use case, expected outcome, knowledge-source type, success definition, and how you discovered Orkata. We also store workspace names and identifiers, membership, roles, permissions, member email addresses, and an activity record of important workspace and access changes.

### Agent configuration and customer content

We store information customers add to build and operate AI agents, including:

- Agent names, instructions, selected models, temperature, publication access, widget settings, initial messages, suggested messages, profile images, and widget icons
- Uploaded PDF, Markdown, and text files
- Extracted file text, Text sources, Q&A content, and public website content selected for import
- Source names, URLs, file metadata, training and discovery jobs, searchable chunks, embeddings, and retrieval metadata
- Action names, trigger instructions, field definitions, webhook URLs, request templates, credentials or headers stored server-side, and other action configuration
- Administrative retrieval tests, evaluation cases, source and action snapshots, model outputs, scores, findings, and related diagnostic information

Customers should only upload, import, or configure content they are authorized to use. Public-facing settings may be visible to anyone who can open the published agent or embed, subject to the access mode selected by the customer.

### Conversation, feedback, and visitor data

Orkata stores chat sessions and messages so agent owners and authorized workspace members can review conversations. This can include:

- Visitor messages, assistant responses, and information voluntarily included in a conversation
- Random session and message identifiers and response versions created through regeneration
- The model used, response, action, and attachment credit usage, configured action name and identifier when invoked, timestamps, confidence information, action UI state, and references to retrieved source snippets
- Visitor feedback, including thumbs-up or thumbs-down ratings, selected reasons, and optional comments
- Approximate country, region, city, and timezone derived locally from the request IP address when the GeoIP database is available
- Browser language and the hostname of the referring page
- When an agent owner identifies visitors, the visitor identifier, name, email, phone number, and metadata; Orkata records whether the profile came from a verified server-signed token or the compatible unverified browser identity flow, plus any unverified page context supplied by the host website
- For a customer-enabled Telegram channel, Telegram chat, user, message, file, and update identifiers; profile fields such as display name, username, and language when Telegram provides them; visitor messages, captions, supported visitor and Helpdesk agent file attachments and extracted or generated attachment summaries; Helpdesk contact details supplied in chat; and agent replies

The request IP address is used for delivery, security, rate limiting, and approximate location lookup. Orkata stores the resulting approximate location with the conversation, not the raw IP address in the conversation record. Infrastructure and security logs may still process or retain IP addresses separately.

When an agent owner connects a Telegram bot, Orkata stores the bot identity, connection status, webhook processing records, and an encrypted bot token needed to receive and answer messages. Telegram also processes messages and account data under its own terms and privacy practices. Disconnecting the channel removes the stored bot connection but does not automatically delete existing Orkata conversation logs.

Visitors should not submit passwords, payment credentials, government identifiers, health information, or other sensitive data unless the agent owner has clearly requested it for a legitimate purpose and provides an appropriate notice and lawful basis.

### Form and action data

When a visitor submits an Orkata Collect data action, Orkata receives the submitted values to validate and send them to the public HTTPS webhook configured by the agent owner. Orkata does not store those field values as Leads. Values gathered conversationally remain part of the visitor's conversation messages. We store a limited receipt containing the action, session and collection instance identifiers, submission status, count, and timestamps to prevent or track duplicate submissions.

When an agent invokes a configured action, we store a limited credit-usage record containing the agent, conversation and request identifiers, selected model, action identifier, action type and configured name, credit amount, status, and timestamps. This record does not store the action's input values, API response, Form field values, or the destination reached through a Custom Button.

HTTP Request actions can send information collected or inferred during a conversation to an API chosen by the agent owner. The API response can be returned to the AI model to complete the request. Custom Buttons can send visitors to external websites, email addresses, or telephone links. Those destinations are controlled by their respective operators.

### Billing and transaction data

For paid plans and Extra-credit purchases, we process plan or purchase selection, invoice and payment references, transaction amount and currency, payment status, renewal dates, credit grants or reversals, and provider responses. We send the account name and email, order reference, amount, and purchase details to Midtrans when checkout is enabled.

Payment credentials and payment-method details are collected through Midtrans rather than stored directly by Orkata. We may retain transaction responses and webhook events for billing, reconciliation, fraud prevention, accounting, refunds, chargebacks, and dispute handling.

### Support and operational communications

If you contact us, we process your email address, message, attachments, account, workspace, invoice, or agent identifiers, and any other information you provide. We also store transactional email delivery jobs and status information.

### Technical, browser, attribution, and product-analytics data

Our servers and infrastructure may process IP addresses, request timestamps, routes, response status, user-agent information, error details, and similar technical data to deliver and secure the Service. Public chat and form endpoints use client addresses for short-term rate limiting and abuse prevention.

Orkata uses the following browser storage and cookies:

- Essential authentication and security cookies used by Google sign-in and Auth.js
- An `orkata_workspace` cookie that remembers the active workspace for up to one year
- An `orkata_first_touch` cookie that remembers the first landing path without its query string, referring origin, and separately stored UTM campaign fields for up to 90 days; it is removed after onboarding completes
- Browser local storage for limited product functions, such as remembering a public chat session, local chat history, a signed visitor identity token or compatible legacy visitor profile on sites that enable identification, model-comparison settings, and website-discovery progress
- PostHog browser storage or cookies used for product analytics, subject to the PostHog SDK configuration and browser controls

When PostHog is enabled, Orkata sends selected page views and product events, safe route names, UTM campaign fields, opaque visitor or session identifiers, authenticated internal user identifiers, workspace identifiers and roles, plan or model labels, durations, counts, and success or failure status. Autocapture and session recording are disabled, Do Not Track is respected, authenticated profiles are created only after identification, and analytics URLs exclude query strings and redact public-chat and invoice identifiers. We do not send customer prompts, messages, responses, source text, form values, names, or email addresses as analytics event properties.

We do not use advertising cookies, sell personal data, or use third-party behavioral advertising trackers.

## 2. How we use data

We use personal data and customer content to:

- Authenticate users, complete onboarding, and administer accounts and workspaces
- Create, configure, publish, and operate agents and visitor chat experiences
- Extract, divide, embed, index, retrieve, and update knowledge content
- Generate AI responses and perform administrative retrieval or response-quality tests
- Store and display chat logs, feedback, approximate visitor analytics, response details, and usage records
- Run customer-configured buttons, forms, webhooks, and API actions
- Enforce plan, storage, credit, workspace, role, and rate limits
- Process plans, payments, renewals, invoices, Extra credits, refunds, and transactional emails
- Attribute sign-ups to campaigns and understand acquisition and product use
- Provide support and investigate technical or billing issues
- Detect abuse, secure the Service, maintain logs, and prevent fraud
- Comply with law, enforce our Terms, and protect users and third parties
- Improve reliability, usability, retrieval quality, and product performance

Depending on the context, our grounds for processing may include performing a contract, taking steps requested before entering a contract, complying with legal obligations, consent where required, and legitimate interests such as operating, securing, measuring, and improving the Service while considering the rights of affected people.

## 3. AI processing and model training

Orkata does **not** use customer knowledge sources, uploaded files, imported website content, Q&A content, Text sources, visitor messages, or chat logs to train Orkata-owned foundation models.

We use external AI services to provide requested features:

- Knowledge text is sent through OpenRouter or the configured embedding provider to create numerical embeddings used for retrieval.
- During a chat, the conversation, agent instructions, available action descriptions, and selected knowledge snippets may be sent through OpenRouter to the selected downstream model provider.
- When administrative evaluation, judging, or confidence tools are used, relevant instructions, source excerpts, action descriptions, test questions, tool traces, and model outputs may be sent to an AI provider for that task.
- HTTP Request inputs and API results may be available to the selected AI model when needed to complete the action. Fields gathered by a conversational Collect data action are provided through chat and processed by the selected AI model. Form field values submitted through a rendered form are sent to the configured webhook and are not used as chat input merely because the form was submitted.

External AI providers have their own processing, security, location, and retention practices. Available models may be operated by providers such as OpenAI, Anthropic, Google, xAI, Meta, DeepSeek, Z.ai, MiniMax, or Moonshot AI. The provider used depends on the model selected by the customer and the routing available through OpenRouter. Customers with strict regulatory or retention requirements should evaluate the selected model and contact us before submitting regulated or highly sensitive data.

## 4. How we disclose data

We disclose personal data only when necessary:

- **To service providers** that support authentication, AI processing, analytics, payments, transactional email, operational communications, hosting, storage, networking, and security. Key providers currently include Google, OpenRouter and selected AI model providers, PostHog, Midtrans, and Resend.
- **As directed by customers**, including to agent owners, authorized workspace members, and webhook or API services configured by them.
- **For legal or business purposes**, including to professional advisers, authorities, or parties involved in a business transaction when reasonably necessary.

We do not sell personal data or use it for third-party behavioral advertising.

## 5. International processing

Orkata and its providers may process data in countries other than the country where the user or visitor is located. Where applicable law requires safeguards, an adequacy assessment, consent, notice, or another transfer mechanism, we will take steps appropriate to the transfer and provider. Because model selection can change the downstream AI provider, customers should contact us if they require specific processing locations or contractual transfer terms.

## 6. Data retention and deletion

We retain data for as long as needed to provide the Service, maintain account and billing records, resolve disputes, secure the Service, and meet legal obligations. Retention differs by category:

- The first-touch attribution cookie expires after no more than 90 days and is removed when onboarding completes. The active-workspace cookie expires after no more than one year.
- Active agent sources and chat logs do not currently expire automatically. Owners and authorized members can delete them using the controls described below.
- Product-analytics events are retained according to the configured PostHog project and applicable provider terms.
- Security, infrastructure, backup, email, billing, payment, tax, fraud, and dispute records may be retained after account or agent deletion for the period reasonably needed or required by Indonesian or other applicable law.

Available controls include:

- Deleting a source removes its stored source record, file when applicable, searchable chunks, and indexed knowledge. Text from an earlier answer can remain in chat history until conversations are deleted.
- Deleting conversations removes chat sessions, visitor metadata, messages, response details, and feedback for that agent while keeping the agent, sources, and actions.
- Deleting an action removes its configuration and associated Form submission receipts.
- Deleting an agent removes the agent, publication configuration, sources, stored files, indexed data, training and discovery jobs, actions, Form submission receipts, conversations, messages, feedback, and administrative test data. Limited usage, billing, security, audit, backup, and legal records may remain as described above.
- A workspace owner can delete an empty workspace after deleting its agents. Workspace deletion removes its memberships, workspace access records, invitations, and workspace activity records but does not delete the owner's user account, subscriptions, or billing records.
- Account-level, billing-record, or broader statutory requests can be sent to `support@orkata.co`.

Information may remain temporarily in backups or restricted legal and security records where immediate deletion is not technically possible or retention is required or permitted by law. When retained for those purposes, we limit further use accordingly.

## 7. Security

We use reasonable administrative, technical, and organizational measures designed to protect data. These include access controls, server-side credentials, HTTPS requirements for sensitive integrations, request validation, rate limits, restricted private-network access for crawler and action requests, scoped workspace permissions, and deletion controls.

No online service is completely secure. Customers are responsible for securing their Google account, limiting workspace access, carefully configuring actions and webhook credentials, and avoiding unnecessary sensitive data. If we identify a personal-data incident that requires notice, we will notify affected parties and authorities within the period required by applicable law.

## 8. Your choices and rights

Depending on applicable law and the processing context, you may have rights to request information about processing, access or obtain a copy of personal data, correct inaccurate data, withdraw consent, object to or restrict certain processing, request deletion or destruction, request portability, and challenge certain automated decisions.

To make a request, email `support@orkata.co`. We may need to verify your identity and authority before acting. We aim to acknowledge a complete request within three business days and provide a response or status update within 30 calendar days, or sooner when applicable law requires. Some requests can be limited where data must be retained for legal obligations, security, fraud prevention, contractual claims, or the rights of others.

If your request concerns an agent operated by an Orkata customer, contact that owner first because the owner determines the purpose of the visitor-data processing. We will reasonably assist the owner or respond directly where Orkata is responsible for the relevant processing.

Browser Do Not Track is respected by Orkata's PostHog configuration. You can also clear Orkata cookies or local storage using your browser, although doing so may sign you out or clear local chat state.

## 9. Children

Orkata accounts are intended for people who are at least 18 years old or otherwise have legal capacity to enter a binding agreement. The Service is not designed for customers to intentionally collect children's personal data without an appropriate lawful basis, notice, safeguards, and required parental or guardian authorization. Contact us if you believe a child has submitted personal data improperly.

## 10. Third-party sites and customer integrations

Public agents can contain customer-provided links, buttons, forms, and API integrations. We do not control the privacy practices, accuracy, or security of third-party sites or customer systems. Review the relevant operator's privacy notice before submitting data.

Website import only accesses public pages selected or discovered from a customer-provided URL. The website operator may receive normal server request information when Orkata fetches those pages.

## 11. Changes to this Policy

We may update this Policy as the Service, providers, or legal requirements change. We will update the effective date and provide additional notice when a change is material and applicable law requires it. Changes apply prospectively from their effective date, subject to rights that cannot be waived.

## 12. Contact and complaints

For privacy questions, rights requests, complaints, or formal notices, contact:

**Orkata**  
Email: `support@orkata.co`  
Website: `https://orkata.co`  
Jurisdiction: Republic of Indonesia

Include your account email, the relevant workspace, agent, session, or invoice reference when safe to do so, a description of the issue, and the resolution requested. Do not send passwords, payment credentials, or copies of sensitive identity documents unless we specifically request them through an appropriate channel. We will verify the request, record its handling, and communicate the outcome or expected resolution time.

This Policy should be read together with the [Terms and Conditions](/terms).
