Orren is a Mac app with a cloud service behind it. Your work is stored on your own Mac, and a copy of your records is also held on Orren's servers so that Orren can answer questions about your business. This policy says exactly what travels, where it goes, what we do with it, and how you get it back or get rid of it. It is written by Conquermental LLC ("Orren", "we"), the company that makes Orren.
Who this policy covers
- Customers. People who install Orren and hold a licence.
- The people in your records. Your leads, clients, and the people who message you on connected platforms. Orren processes their information on your behalf and on your instructions. If you are one of those people and have a question about your data, please contact the Orren customer you dealt with; our Data Processing Addendum sets out how we handle it for them.
- Website visitors. Covered in The website below.
What stays on your Mac
- The authoritative copy of everything you create. Canvases, notes, captures, leads, conversations, calls, payments and files. Orren reads and writes them locally and keeps working with no network at all.
- Dictation and meeting audio. Speech is transcribed on your Mac by Apple's speech engine. Recordings and transcripts of your own dictations and of calls you record are written to your Mac and are not uploaded as audio. The text of a dictation is treated like any other capture (see What is sent to Orren's servers).
- Credentials you supply. Any API keys you enter, your Orren sign-in session, and the tokens for Google (YouTube and Calendar) and Calendly are held in your Mac's Keychain and are not transmitted to Orren's servers. Instagram and Notion are different, and are described below.
- Anything you mark guarded or private. A capture marked guarded stays on your Mac. A lead you hide is removed from Orren's servers and from every derived record the next time the app syncs.
What is sent to Orren's servers
So that Orren can answer questions about your whole business rather than about whatever happens to be on screen, the app synchronises a copy of your records to Orren's own infrastructure:
- Documents built from your records: captures, notes, chat history, leads and their conversations, calls, payments, tracked links and connected video metadata, together with the relationships between them.
- The questions you ask Orren, and the context assembled to answer them.
- Media you ask Orren to transcribe or analyse, such as a video file, for the duration of that job.
- Diagnostics, described under Diagnostics and crash reports.
Where it is held
- Application and API tier. Google Cloud Run, region us-central1 (United States). Holds requests in transit.
- Records and retrieval. Google Cloud SQL for PostgreSQL, us-central1. Holds your synchronised documents, relationships and connector state.
- Model calls. Google Vertex AI. Receives the content of a question and the context sent with it, and media you ask to be transcribed or analysed. Models from Google and, through Vertex AI, from Anthropic may be used.
- Sign-in email. Resend, which delivers the six-digit sign-in code to your address.
- Payments. Stripe, which processes your licence purchase. We never see or store your card number.
Each customer's records are isolated at the database level by row-level security, so one customer's queries cannot reach another's rows. Our full list of providers, and what each one holds, is kept at Subprocessors.
AI features
Orren calls AI providers on your behalf, using Orren's own accounts. When you ask Orren a question, the question and the context assembled to answer it are sent to a model on Google Vertex AI under Orren's agreement with Google. Google's terms for Vertex AI do not permit it to use customer content to train its models. Orren does not use your content to train models either; see Corrections you choose to share.
AI output can be wrong. Orren shows where an answer came from where it can, and nothing an AI writes is sent to another person unless you built an automation that sends it (see Automations in the Acceptable Use Policy).
Corrections you choose to share
There is a switch in Settings, Help improve Orren, and it is off by default. When it is on, and only then, the corrections you make (a call filed as the wrong kind, a capture judged wrongly, a dictation you reworded) are queued and sent to Orren with names and numbers removed, so the pattern of the correction can be used to make Orren better at the same task. Settings shows exactly what was last sent. Turn the switch off and nothing further leaves; your corrections still teach your own copy.
Google user data
If you connect a YouTube channel, Orren asks Google for read-only access using these scopes:
youtube.readonly: your channel and the videos on it, meaning titles, thumbnails, publication dates and view counts.yt-analytics.readonly: reporting about your own channel's performance.
If you connect Google Calendar, Orren asks for access to read your calendars and, only when you ask it to, to write a booking to them.
Orren's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- It is used only to show you your videos and calendar inside Orren and to attribute clicks, leads and revenue to them.
- It is not sold, not shared with third parties, and not used for advertising.
- It is not used to train any machine-learning model.
- No human at Orren reads it, except where you have asked us to help with a specific problem, or where the law requires it.
- The YouTube scopes are read-only. Orren cannot post, edit, delete or comment on your channel.
- Your Google tokens are held in your Mac's Keychain, not on Orren's servers. Channel and video metadata you sync is held with your other records.
You can revoke Orren's access at any time at myaccount.google.com/permissions, or by disconnecting inside the app. Revoking stops any further access immediately; records already synchronised are removed under Keeping and deleting.
Platforms you connect
When you connect Instagram or another platform, data moves between Orren and that platform using the access you granted. What each platform does with it is governed by that platform's own terms, not by ours.
Connecting Instagram authorises Orren to read and send messages, read and reply to comments, and read your account and media insights, for the Instagram professional account you connect and no other.
- The access token is held on Orren's servers, not on your Mac. Instagram messages are sent by Orren's server on your behalf, so the token never travels to your computer. It is stored in Orren's database, used only to serve your own account, and refreshed automatically before it expires. One Instagram account can be connected to one Orren account at a time.
- What Instagram sends us. Instagram notifies Orren's servers when someone messages you, comments on your posts, taps a button Orren sent, reacts to a message, or reads one. Those notifications, which include the sender's Instagram-scoped ID and the content of the message or comment, are stored so the app can retrieve them, and are then copied to your Mac.
- Who the other person is. For someone who messages or comments, Orren may read the public profile Instagram exposes to us (name, username and profile picture) so the conversation is identifiable to you rather than a number.
- Automations. If you build an automation, messages and public comment replies are sent from your account by Orren's servers, in response to the triggers you configure. Nothing is sent that you have not set up. Instagram permits a business to send messages only within a window after the other person last contacted you; Orren enforces that window.
- Disconnecting. Removing Orren in Instagram's Apps and websites settings, or disconnecting inside Orren, ends that access. Orren deletes the stored token. Records already synchronised are removed under Keeping and deleting, and the steps are spelled out in Data Deletion Instructions.
Orren does not post to your account, and does not request permission to.
Notion
If you connect Notion, Orren reads the pages you share with it and copies them to your Mac as reference material. The connection is read-only. The Notion token is held on Orren's servers so the sync can run without your Mac being open; disconnecting deletes it.
Calendly
If you connect Calendly, Orren reads your bookings and the invitees on them with the token you pasted, which stays in your Mac's Keychain. Orren does not write to Calendly.
Stripe, as a source of your revenue
Separately from paying for Orren, you may connect your own Stripe account so that Orren can match payments to leads. Orren reads payment events (amount, date, the customer email Stripe holds) through a connection you authorise, and holds the Stripe account reference on its servers. Orren never moves money and cannot charge your customers.
Other AI tools you connect to Orren
Orren can act as a source of knowledge for another AI assistant you use, through its MCP endpoint. That connection is authorised by your licence and reads your records the same way the app does. What the other assistant does with what it reads is governed by that assistant's provider, not by us. You can stop it at any time by removing the connection in that tool.
When someone opens a tracked link
A tracked link is a short address Orren mints for one recipient. When the person you sent it to opens it, Orren's server records that the link was opened, and then sends them straight on to the destination.
What is recorded: which link and which recipient it was minted for, the time, the device class (mobile, desktop, tablet), the browser and operating system family, the site the click came from, and an approximate location — country, region and city.
What is not recorded, at all:
- Their IP address. It is read once, in memory, to work out the approximate location, and then discarded. No table in Orren has a column for it.
- Their full browser user-agent. Only the family, such as "Safari" or "Instagram in-app".
- Any cookie, pixel, device fingerprint or cross-site identifier. Orren sets none, because it does not need one: the address itself is unique to the recipient.
The location is worked out inside Orren's own servers using a database bundled with them (DB-IP Lite, CC BY 4.0). Nothing about the visitor is sent to that company or to any other third party. The result is approximate, is a city at best, and is never a street address.
Orren does not record automated fetches as opens. A link is checked by the messaging platform itself moments after it is sent; those are recorded separately and excluded from every count.
Diagnostics and crash reports
To know whether Orren works, the app sends its author a small operational report on launch and about once an hour: the app version and macOS version, a machine identifier, counters (how many launches, how many questions answered, how many failed), and error codes with the name of the subsystem that raised them. If the app crashes or hangs, the crash report macOS wrote is sent on the next launch. None of this contains what you typed, said, or stored. Settings shows the last report sent.
If you file feedback or a support ticket from inside the app, it carries what you wrote, the screenshots and recordings you chose to attach, the last few things you did (as verbs, such as "opened a board"), and the same diagnostics. That report goes to Orren so we can fix the problem, and is kept until it is resolved.
Sign-in and licence
Your Orren account is your email address. Signing in sends a six-digit code to that address; the session that results is kept in your Mac's Keychain. Your licence is checked against Orren's servers when the app launches and periodically after. We keep your email, your licence status, and the machine identifiers of the Macs you have activated.
Keeping and deleting
- Export, always. Everything you create can be exported at any time from Settings, as plain files, including after a licence lapses.
- Deleting in the app. Deleting something in the app removes it from Orren's servers on the next sync, and from Orren's brain, so it can no longer be used to answer a question. Hiding a lead does the same for everything derived from that person.
- Deleting your account. Ask at the address below and your synchronised records, connector tokens and account are deleted from Orren's servers within 30 days. Your local copy on your Mac is yours and is untouched by that request. Step-by-step instructions are in Data Deletion Instructions.
- After a licence ends. AI features pause. Your records stay on our servers so that reactivating restores them; ask us at any time and we delete them as above.
- Diagnostics and crash reports are kept only as long as they are useful for finding and fixing problems, and are pruned periodically. Payment records are kept as long as tax and accounting law require.
- Backups. Automated database backups are kept for seven days and are overwritten on that cycle.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, or delete personal information we hold about you, and to object to certain processing. You can exercise all of them by writing to the address below; we answer within 30 days. We do not sell personal information and do not share it for cross-context behavioural advertising. If you are in the European Economic Area or the United Kingdom, our processing of your account data rests on the contract between us; our processing of the people in your records is done on your instructions as a processor, under the Data Processing Addendum. If you are unsatisfied with our answer, you may complain to your local data protection authority.
Where data travels
Orren's servers are in the United States. If you use Orren from elsewhere, your data is transferred to and processed in the United States. For customers in the EEA, the UK and Switzerland we rely on the standard contractual clauses incorporated in the Data Processing Addendum.
Children
Orren is a business tool and is not directed at anyone under 18. We do not knowingly collect information from children.
Security
Data travels over TLS. Customer records are separated by database-level row-level security. Connector tokens are held in the database and are never returned to the app or shown in any interface. Access to production systems is limited to the people who run Orren. The app is signed and notarised by Apple. More is in our Security Policy, including how to report a vulnerability.
Waitlist and early access
When you join the waitlist, we store your email address, the sign-in method you used, whether that address was verified, the date you joined, the waitlist you selected, and a record of your consent to early-access and launch updates. We use these details to manage the waitlist and contact you about your invitation and important launch updates.
If you continue with Apple or Google, we verify the sign-in response and use the email address the provider shares with us. Apple may share a private relay address instead of your personal address. Signing in for the waitlist does not give Orren access to your mailbox, contacts or connected-platform data. Email-only submissions are stored without provider verification.
Waitlist records are held in a private Google Cloud Storage bucket. Cloudflare handles website and signup requests on their way to our services. Social sign-in uses a short-lived, secure cookie to complete authentication; it expires after ten minutes and is cleared after a successful sign-in.
We keep your waitlist record while we manage early access and launch communications, unless you ask us to remove it. To leave the waitlist or request deletion, write to privacy@tryorren.com. Joining the waitlist does not start a product trial, create a paid subscription or charge you.
The website
Our website may use a privacy-respecting analytics tool to count visits and see which pages people read. It does not identify you and does not follow you to other sites. If we add cookies that require consent, the site will ask first.
What we do not do
- We do not sell your data, and we have no advertising business to sell it to.
- We do not use your content to train models.
- We do not store the payment card details you use to buy a licence; Stripe handles those.
- We do not read your records, except where you have asked us to help with a specific problem, or where the law requires it.
Changes
When this policy changes, the date at the top changes, and the app asks you to accept the new version before you continue. The version you accepted, and when, is recorded on your Mac.
Contact
Privacy questions, export requests and deletion requests: privacy@tryorren.com. Conquermental LLC, [COMPANY ADDRESS].
