Last updated · May 8, 2026

Privacy Policy

Orckera ("we", "us", "our") provides AI-driven risk intelligence for construction projects. This policy explains what data we collect, how we use it, who else processes it, and the rights you have over it.

1. Information we collect

We collect three categories of information.

1.1 Account information

When you sign in with Microsoft (or, in future, another supported identity provider), we receive your name, email address, and provider-issued user identifier. This information is used to authenticate you and associate your activity with your Orckera tenant.

1.2 Connected service data

When you authorize Orckera to connect to a third-party service (currently Microsoft 365 Outlook and Dropbox), we ingest the data you have explicitly scoped to a project. This includes:

  • Email messages within the folder or label you select, including headers, body content, and attachments
  • Files within the Dropbox folder you select, including their content and metadata
  • Metadata such as authors, recipients, timestamps, file paths, and revision history

We never access content outside the scope you authorize. You can disconnect any integration at any time, after which ingestion stops immediately.

1.3 Derived information

From the connected service data, we generate derived data: extracted entities (people, subcontractors, activities), commitments, schedule references, expectation tracking, and risk items. This derived information is regenerable from your raw data and configuration.

2. How we use your information

  • To deliver the Service: ingesting, processing, classifying, and surfacing risk intelligence about your construction projects
  • To improve your tenant's accuracy through your feedback (corrections, confirmations) — this never crosses tenant boundaries
  • To monitor service health, detect abuse, and operate the platform
  • To communicate service-related notices (we will not send marketing emails without separate opt-in)

We do not use your data to train AI models. Your data is processed only to deliver risk intelligence to your account. It is never aggregated with other customers' data for training, fine-tuning, or research. This applies to all sub-processors we use for AI features (see Section 4) — we contractually require equivalent guarantees from them.

3. Sensitive content handling

Construction project communications regularly contain attorney-client privileged material, claim-related correspondence, personnel matters, and pricing-sensitive documents. We classify each artifact at ingestion and quarantine privileged or claim-sensitive content from cross-artifact derivations. You can mark or override classifications at any time. Synthesis outputs inherit the sensitivity of their inputs, and privileged material is excluded from any feature that aggregates content across multiple artifacts.

4. Sub-processors

We use the following sub-processors to operate the Service:

  • OpenAI — large language model processing for entity extraction, classification, and synthesis. OpenAI does not train on API data by default.
  • Mistral AI — OCR for document and image content.
  • Cloudflare — object storage (R2) for raw artifacts; DNS and CDN.
  • Hetzner — compute and database hosting.
  • Sentry — error monitoring (may include incidental snippets of data in stack traces).

We will provide reasonable advance notice of changes to our sub-processor list when those changes materially affect the processing of your data.

5. Data security

  • OAuth access and refresh tokens are encrypted at rest using AES-256-GCM with per-tenant isolation
  • Data is isolated per customer using row-level security and per-tenant access boundaries
  • Transport encryption (TLS 1.2+) for all data in motion
  • Encrypted backups; documented restore procedures
  • Access to production systems is limited to personnel who require it for operations

6. Data retention and deletion

We retain your data for as long as your account is active. When you disconnect a connector, we soft-delete artifacts ingested by that connector and purge the underlying object storage within 30 days unless legal hold or audit requires otherwise.

You can request export or full deletion of your data by emailing [email protected]. We will respond within 30 days.

7. Your rights

Depending on your jurisdiction, you may have rights including:

  • Access to the personal information we hold about you
  • Correction of inaccurate information
  • Deletion of your information
  • Portability of your information in a structured format
  • Objection to or restriction of processing
  • Withdrawal of consent (achieved by disconnecting integrations or closing your account)

To exercise these rights, contact [email protected].

8. International data transfers

Your data may be processed in regions where our sub-processors operate, which may include the United States and the European Union. Where transfers occur outside your region, we rely on appropriate safeguards including contractual clauses and equivalent data protection arrangements.

9. Cookies

We use a single first-party session cookie (HttpOnly, Secure, SameSite=Lax) to keep you signed in. We do not use third-party advertising cookies, tracking pixels, or cross-site analytics.

10. Changes to this policy

We may update this policy. Material changes will be communicated by email to active account owners at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

11. Contact

Questions about this policy or about how we process your data:

[email protected]