Privacy Policy
This policy explains what data Orivo collects, how it is used, and what rights you have regarding your personal information.
1. What We Collect
When you create an account, we collect your email address and display name from Google OAuth. When you use Orivo, we may also collect your IP address, browser user agent, and page view data for analytics. If you subscribe to a paid plan, Lemon Squeezy (our payment processor) collects your payment information — we only store the purchase and subscription IDs, not your card details.
2. How We Use Your Data
Your data is used for: (a) authentication and account management, (b) providing cloud project storage and synchronization, (c) processing subscriptions and billing through Lemon Squeezy, (d) sending transactional emails such as subscription reminders, (e) internal analytics to understand how the service is used, and (f) responding to support requests.
3. Third-Party Services
Orivo uses the following third-party services that may process your data: Google (OAuth authentication — email and profile info), Lemon Squeezy (payment processing — purchase and subscription data), and Resend (transactional email delivery — email address). Each service operates under its own privacy policy. We do not sell, rent, or share your personal data with any other third parties.
4. Cookies and Local Storage
Orivo uses a session cookie (httpOnly, secure) for authentication. We also use a temporary cookie during the Google OAuth flow. The product stores editor settings, theme preferences, and some cached client-side UI state in your browser's localStorage. Account projects and billing state are stored server-side against your signed-in profile.
5. Data Retention
Account data, projects, and snapshots are stored as long as your account exists. Subscription and billing references are retained for record-keeping. Analytics data (page views) may be periodically cleared. Expired sessions are automatically cleaned up. If you delete your account, all associated data (projects, snapshots, subscriptions, support requests) is permanently removed.
6. Your Rights
You have the right to: (a) access the personal data we hold about you, (b) request correction of inaccurate data, (c) request deletion of your account and all associated data, (d) export your projects from the workspace at any time, and (e) withdraw consent for data processing by deleting your account. To exercise any of these rights, contact us at the email below.
7. Data Security
We protect your data using: HTTPS for all connections, httpOnly secure session cookies, hashed session tokens (SHA-256), server-side input validation, rate limiting on sensitive endpoints, and security headers (HSTS, X-Content-Type-Options, X-Frame-Options). Project data is stored in a PostgreSQL database on our server.
8. Children
Orivo is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
9. Changes to This Policy
We may update this privacy policy from time to time. If we make material changes, we will notify registered users by email. The date of the last update is shown at the bottom of this page.
Contact: For privacy-related inquiries, data access, or deletion requests, email us at [email protected].
Last updated: April 1, 2026