Privacy Policy

Version 2026-06-11 · Effective June 11, 2026 · Last updated June 11, 2026

Draft — pending legal review. This document is a good-faith draft and has not yet been reviewed by counsel.

1. Overview

This Privacy Policy explains how Orenna Holdings, PBC ("Orenna", "we", "us") collects, uses, and shares information when you use Orenna Restoration Intelligence and related sites, applications, and APIs (the "Service"). It is part of our Terms of Service. Our guiding commitments: we do not sell your data, we do not use your content to train foundation models, and we retain the content of AI requests only as long as needed and within the limits you configure.

2. Information we collect

Account information. When you sign up, our identity provider supplies your email address and basic profile (such as your name) and an account identifier. Organization administrators may provide additional member information.

Customer Content. Information you put into the Service: project details, area-of-interest geometry, uploaded documents, site characterization inputs, scenarios, chat messages, and similar materials.

Usage and device data. Logs and metadata generated as you use the Service — request timestamps, feature usage, approximate IP-derived location, and error and performance data — used to operate, secure, and improve the Service.

Payment information. If you purchase a paid plan, our payment processor collects and processes your payment details. We do not store full card numbers; we receive limited billing metadata (such as plan, status, and the last digits of a card) needed to manage your subscription.

Cookies. In authenticated mode we use a secure, http-only session cookie to keep you signed in. We do not use third-party advertising cookies.

3. How we use information

We use information to:

  • provide, maintain, and secure the Service and your account;
  • generate the estimates, summaries, and draft materials you request, including

by sending the necessary inputs to AI model providers (see below);

  • process payments and manage subscriptions;
  • provide support, communicate about the Service, and enforce our Terms;
  • monitor, debug, and improve reliability, quality, and security; and
  • comply with legal obligations.

We do not use Customer Content to train our own or any third party's foundation models, and we do not sell personal information.

4. AI processing

To produce outputs, the Service sends relevant inputs — which may include Customer Content — to AI model providers acting as our sub-processors. By default we operate under arrangements where your inputs and outputs are not used to train the providers' models. We retain a record of AI calls for security, billing, and debugging; the content of those calls (request and response bodies) is stripped after your organization's retention window (default 30 days) and can be reduced further:

  • Zero-retention mode (ZDR): your organization can choose to store AI call

content as hash-only from the first write, so request and response bodies are never persisted by us.

  • Bring-your-own keys: if you supply your own provider API keys, calls are

made under your provider account and our stored record of those calls is hash-only.

You can manage these settings under Settings → Privacy.

5. Geospatial and reference data

The Service queries third-party geospatial and public-agency data services to characterize a site. To do so it may send area-of-interest geometry to those services to retrieve maps, layers, and reference data. Those services are operated by third parties and may have their own terms and privacy practices.

6. How we share information

We share information only as follows:

  • Service providers / sub-processors who help us run the Service, under

contracts limiting their use of the data (see the list below).

  • Within your organization, with administrators and members as governed by

roles and permissions you control.

  • Legal and safety: to comply with law, enforce our Terms, or protect

rights, safety, and security.

  • Business transfers: in connection with a merger, acquisition, financing,

or sale of assets, subject to this Policy.

We do not sell personal information or share it for cross-context behavioral advertising.

7. Sub-processors

We use the following categories of sub-processors; our current providers are listed on our Sub-processors page.

  • Identity & access — authentication and session management (e.g. WorkOS).
  • AI model providers — generating outputs from your inputs (e.g. Anthropic;

OpenAI when you choose it or use your own key).

  • Cloud hosting & database — running the application and storing your data

(e.g. Railway).

  • Web hosting / CDN — serving the web application (e.g. Vercel).
  • Object storage — durable file storage (e.g. Amazon Web Services S3).
  • Payments — subscription billing (e.g. Stripe).
  • Geospatial & public data services — returning map and reference data for a

queried area of interest (e.g. Esri/ArcGIS Online and public agency services).

8. Data retention

We keep account and organization data for as long as your account is active and as needed to provide the Service. The content of AI requests is retained only within your configured window (default 30 days) and then stripped to hashes; records created before a retention change are handled as described at Settings → Privacy. We may retain limited information as required for legal, security, accounting, or dispute-resolution purposes.

9. Security

We protect information with measures including encryption in transit, scoped access controls and role-based permissions, per-tenant isolation, and audit logging. No method of transmission or storage is completely secure, but we work to protect your information and to respond to incidents. See our security overview (SECURITY.md) for more.

10. Your rights and choices

Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Within the Service you can:

  • view and export a copy of your data (Settings → Privacy);
  • configure AI-content retention and zero-retention mode;
  • supply your own provider keys; and
  • update your profile or close your account.

To exercise rights not available in-product — including deletion of your account data — contact us at privacy@orenna.io. We will respond as required by applicable law and may need to verify your identity.

11. International transfers

We are based in the United States and may process information there and in other countries where we or our sub-processors operate. Where required, we use appropriate safeguards for cross-border transfers.

12. Children

The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect personal information from children.

13. Changes to this Policy

We may update this Policy. When changes are material, we will update the version and, where appropriate, ask you to review and accept the updated terms before continuing to use the Service.

14. Contact

Questions or privacy requests: privacy@orenna.io · Orenna Holdings, PBC, 2996 107th Ave., Oakland, CA 94605.