Privacy Policy
Version 2026-06-11 · Effective June 11, 2026 · Last updated June 11, 2026
1. Overview
This Privacy Policy explains how Orenna Holdings, PBC ("Orenna", "we", "us") collects, uses, and shares information when you use Orenna Restoration Intelligence and related sites, applications, and APIs (the "Service"). It is part of our Terms of Service. Our guiding commitments: we do not sell your data, we do not use your content to train foundation models, and we retain the content of AI requests only as long as needed and within the limits you configure.
2. Information we collect
Account information. When you sign up, our identity provider supplies your email address and basic profile (such as your name) and an account identifier. Organization administrators may provide additional member information.
Customer Content. Information you put into the Service: project details, area-of-interest geometry, uploaded documents, site characterization inputs, scenarios, chat messages, and similar materials.
Usage and device data. Logs and metadata generated as you use the Service — request timestamps, feature usage, approximate IP-derived location, and error and performance data — used to operate, secure, and improve the Service.
Payment information. If you purchase a paid plan, our payment processor collects and processes your payment details. We do not store full card numbers; we receive limited billing metadata (such as plan, status, and the last digits of a card) needed to manage your subscription.
Cookies. In authenticated mode we use a secure, http-only session cookie to keep you signed in. We do not use third-party advertising cookies.
3. How we use information
We use information to:
- provide, maintain, and secure the Service and your account;
- generate the estimates, summaries, and draft materials you request, including
by sending the necessary inputs to AI model providers (see below);
- process payments and manage subscriptions;
- provide support, communicate about the Service, and enforce our Terms;
- monitor, debug, and improve reliability, quality, and security; and
- comply with legal obligations.
We do not use Customer Content to train our own or any third party's foundation models, and we do not sell personal information.
4. AI processing
To produce outputs, the Service sends relevant inputs — which may include Customer Content — to AI model providers acting as our sub-processors. By default we operate under arrangements where your inputs and outputs are not used to train the providers' models. We retain a record of AI calls for security, billing, and debugging; the content of those calls (request and response bodies) is stripped after your organization's retention window (default 30 days) and can be reduced further:
- Zero-retention mode (ZDR): your organization can choose to store AI call
content as hash-only from the first write, so request and response bodies are never persisted by us.
- Bring-your-own keys: if you supply your own provider API keys, calls are
made under your provider account and our stored record of those calls is hash-only.
You can manage these settings under Settings → Privacy.
5. Geospatial and reference data
The Service queries third-party geospatial and public-agency data services to characterize a site. To do so it may send area-of-interest geometry to those services to retrieve maps, layers, and reference data. Those services are operated by third parties and may have their own terms and privacy practices.
6. How we share information
We share information only as follows:
- Service providers / sub-processors who help us run the Service, under
contracts limiting their use of the data (see the list below).
- Within your organization, with administrators and members as governed by
roles and permissions you control.
- Legal and safety: to comply with law, enforce our Terms, or protect
rights, safety, and security.
- Business transfers: in connection with a merger, acquisition, financing,
or sale of assets, subject to this Policy.
We do not sell personal information or share it for cross-context behavioral advertising.
7. Sub-processors
We use the following categories of sub-processors; our current providers are listed on our Sub-processors page.
- Identity & access — authentication and session management (e.g. WorkOS).
- AI model providers — generating outputs from your inputs (e.g. Anthropic;
OpenAI when you choose it or use your own key).
- Cloud hosting & database — running the application and storing your data
(e.g. Railway).
- Web hosting / CDN — serving the web application (e.g. Vercel).
- Object storage — durable file storage (e.g. Amazon Web Services S3).
- Payments — subscription billing (e.g. Stripe).
- Geospatial & public data services — returning map and reference data for a
queried area of interest (e.g. Esri/ArcGIS Online and public agency services).
8. Data retention
We keep account and organization data for as long as your account is active and as needed to provide the Service. The content of AI requests is retained only within your configured window (default 30 days) and then stripped to hashes; records created before a retention change are handled as described at Settings → Privacy. We may retain limited information as required for legal, security, accounting, or dispute-resolution purposes.
9. Security
We protect information with measures including encryption in transit, scoped access controls and role-based permissions, per-tenant isolation, and audit logging. No method of transmission or storage is completely secure, but we work to protect your information and to respond to incidents. See our security overview (SECURITY.md) for more.
10. Your rights and choices
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Within the Service you can:
- view and export a copy of your data (Settings → Privacy);
- configure AI-content retention and zero-retention mode;
- supply your own provider keys; and
- update your profile or close your account.
To exercise rights not available in-product — including deletion of your account data — contact us at privacy@orenna.io. We will respond as required by applicable law and may need to verify your identity.
11. International transfers
We are based in the United States and may process information there and in other countries where we or our sub-processors operate. Where required, we use appropriate safeguards for cross-border transfers.
12. Children
The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect personal information from children.
13. Changes to this Policy
We may update this Policy. When changes are material, we will update the version and, where appropriate, ask you to review and accept the updated terms before continuing to use the Service.
14. Contact
Questions or privacy requests: privacy@orenna.io · Orenna Holdings, PBC, 2996 107th Ave., Oakland, CA 94605.