Retention Policy

Last updated June 15, 2026

Orloi retains personal data only for as long as needed to provide the service, maintain security and reliability, meet legal obligations, and support customer-controlled operational records.

Scope

This policy covers personal data processed by Orloi application systems, customer-connected integrations, vendor platforms, operational logs, and customer-controlled storage used by the changelog engine.

Data Categories

Orloi processes three broad categories of data:

  1. Orloi-managed application data, such as account records, connection configuration, encrypted credentials, and service state.
  2. Customer-controlled operational data, such as changelog records, derived summaries, metrics, and operational outputs written to customer-controlled storage.
  3. Vendor/platform data, such as billing records, email delivery metadata, infrastructure logs, and diagnostic data handled by subprocessors.

Orloi-Managed Application Data

Orloi-managed application data is generally retained while the relevant account, sync, or connection remains active. When a customer deletes an account, sync, or connection, Orloi deletes or disables the related application records according to the relevant lifecycle, subject to legal, security, fraud-prevention, billing, backup, and dispute-resolution exceptions.

Session cookies and temporary cache records expire automatically according to their configured lifetime or are cleared on logout where applicable.

Customer-Controlled Operational Data

Customer-controlled operational data is retained in infrastructure controlled by the customer. Orloi may write changelog data, derived summaries, collaborator/activity profiles, metrics, and AI-generated operational outputs into the customer database. The customer controls retention, deletion, backups, and restoration of that database unless a separate managed-deletion workflow is agreed.

Connection deletion stops future ingestion from the connected source and removes the relevant Orloi-managed connection records. It does not automatically delete data already written into customer-controlled storage.

Vendor/Platform Data

Vendor/platform data is retained according to vendor settings, platform retention periods, contract terms, and applicable legal requirements. Orloi reviews vendor retention as part of its vendor review process.

Exceptions

Data may be retained for longer where required for legal, accounting, fraud-prevention, dispute-resolution, security, abuse-prevention, or backup integrity purposes.

Review

This policy is reviewed periodically and when material processing, vendor, or infrastructure changes occur.