1. Scope and operator
This policy applies to the hosted Orkestr service available through orkestr.de and its official connection pages. The hosted beta is operated by Orkestr. Contact: oguzcanunver@gmail.com.
Independent self-hosted installations are controlled by their respective operators. Unless a self-hosted operator connects that installation to an Orkestr-hosted service, the Orkestr hosted service does not receive data from that installation.
2. Information Orkestr processes
Orkestr processes information needed to provide user-requested workflows: account and contact details, chat messages, files, task outputs, timers, workspace records, connector status, managed-browser activity, security records, and technical service logs. Orkestr does not ask users to provide account passwords through chat.
Commercial Project Discovery and Workflow Audit inquiries are stored separately from each other and from personal-beta waitlist records. The short Project Discovery form requires a project category, desired outcome, contact name, work email, and contact consent. A visitor may optionally add the current situation, company, role, expected users or volume, system or source categories, constraints, success criteria, and timeframe. The specialized Workflow Audit form collects the workflow-specific information described on that form. If a visitor opens a configured scheduling link, the selected scheduling provider processes the booking information under its own privacy notice.
The public site records a limited set of first-party interaction events such as page path, CTA name, project-category selection, form start, optional-detail expansion, validation outcome, submission outcome, and scheduling click. These analytics events do not contain form field values, project or process descriptions, credentials, or cross-site tracking identifiers.
3. Google user data Orkestr accesses
The current public Google integration requests only basic Google identity permissions and Gmail send access: openid, userinfo.email, userinfo.profile, https://www.googleapis.com/auth/gmail.send.
- Google identity: account identifier, email address, name, and available profile information used to identify the connected account.
- Authorization data: granted scopes, access token, refresh token when issued, token type, expiration time, and connection status.
- User-approved outgoing email: sender account, recipients, subject, body, and attachments that the user requests or approves for sending.
- Operation metadata: identifiers and status returned by Google after a requested operation.
Orkestr's current public Gmail integration cannot and does not read the user's inbox, existing messages, drafts, labels, contacts, mailbox settings, or email history. If Orkestr introduces a capability requiring additional Google scopes, it will update this policy and the in-product disclosure and obtain new consent before requesting that access.
4. How Orkestr uses Google user data
Orkestr uses Google identity data to display and manage the connected account, authorization data to maintain the connection, outgoing-email content to perform a send explicitly requested or approved by the user, and delivery metadata to report the result. Google user data is not used for unrelated purposes.
5. Sharing and disclosure of Google user data
Orkestr does not sell Google user data. It does not provide Google user data to advertising platforms, data brokers, or information resellers, and does not use it for advertising, credit decisions, or to develop, improve, or train generalized or non-personalized AI or machine-learning models.
Data is disclosed only in these limited circumstances:
- Google: Orkestr sends the user-approved email and credentials required to authenticate the request to Google's OAuth and Gmail services.
- Configured AI provider: a configured AI provider may process email content supplied or approved by the user when the user asks the agent to prepare or perform that workflow. That provider must be contractually prohibited from using Google Workspace data to develop, improve, or train generalized or non-personalized AI or machine-learning models. Google OAuth access and refresh tokens are never disclosed to an AI provider. The current integration does not retrieve existing Gmail content for AI processing.
- User-selected communication provider: when the user works through WhatsApp, Meta's WhatsApp service carries the user's instructions and Orkestr's status or result messages.
- Infrastructure and security providers: hosting, storage, networking, monitoring, and security processors may handle encrypted or operational data only as needed to operate and protect the service.
- Support, security, and law: authorized human access or disclosure may occur only with the user's explicit support request, to investigate abuse or a security incident, or where required by applicable law.
Service providers are permitted to process data only for the service purpose for which it was disclosed and must protect it appropriately.
6. Storage and retention
Google OAuth credentials are stored in the connected user's isolated connector storage and retained until the user disconnects the account, the grant is revoked, the account is deleted, or the credentials expire and are no longer needed. A disconnect requests revocation from Google before deleting the local credential record.
Outgoing-email content may remain in the user's Orkestr chat or task history when it forms part of the user-visible workflow. It is not maintained as a separate copy of the user's Gmail mailbox. Connection requests are one-time and expire. Encrypted credential records may remain temporarily in protected operational backups until those backups rotate.
Project Discovery and Workflow Audit submissions are retained in the private deployment only for assessment, follow-up, security, and recordkeeping, and are deleted on a valid request unless a minimal record must be retained for dispute handling, abuse prevention, or law. The operator should configure and document a deployment-specific retention period before production collection.
7. Data protection mechanisms
- HTTPS/TLS protects Google authorization and service traffic in transit.
- Google OAuth access and refresh tokens are encrypted at rest with AES-256-GCM.
- Production encryption keys are stored separately from encrypted token records and are restricted to the Orkestr service account.
- Connector records are scoped by user and protected by authenticated access controls and private filesystem permissions.
- Orkestr requests the minimum approved Google scopes and blocks undeclared capabilities in both the user interface and server.
- Credentials are excluded from public responses, agent context, screenshots, source control, and operational event records.
No system can guarantee absolute security. Suspected unauthorized access is investigated and affected users and authorities are notified when required.
8. Google API Services User Data Policy
Orkestr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace data is used only to provide the user-facing feature requested by the user. Orkestr and its service providers do not use Google Workspace data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
9. User controls, revocation, and deletion
Users can decline Google access and continue using Orkestr without Gmail. A connected account can be disconnected from Orkestr setup, which revokes the Google grant and removes locally stored credentials. Users can also revoke Orkestr from their Google Account permissions page.
Users may request access, correction, export, restriction, or deletion of their Orkestr data through the invitation chat, the data deletion page, or oguzcanunver@gmail.com. Some minimal records may be retained where required for security, abuse prevention, dispute handling, or law.
Project Discovery and Workflow Audit contacts may use the same contact to withdraw consent or request deletion of their commercial inquiry record. Withdrawing a commercial inquiry does not affect a separate personal-beta account.
10. Legal bases and international processing
Depending on the context, Orkestr processes data to provide the service requested by the user, to assess and respond to a Project Discovery or Workflow Audit inquiry based on the contact's consent, for legitimate security and reliability interests, and to meet legal obligations. Providers may process data in countries outside the user's country; Orkestr relies on the provider's applicable contractual and legal transfer safeguards.
11. Changes and contact
Material changes to Google data access, use, or sharing will be reflected here and in the in-product disclosure before new access is requested. Questions or privacy requests can be sent to oguzcanunver@gmail.com.