Privacy Policy
Effective Date: June 10, 2026
Otimo Earth s.r.o ("Otimo Earth", "we", "us", "our"), a company registered in the Czech Republic under business ID 19558635 at Varšavská 715/36, Vinohrady (Praha 2), 120 00 Praha, operates the data changelog service Orloi ("Orloi" or the "Service"), which observes Airtable activity and stores a durable changelog in your Postgres database. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Orloi.
Orloi acts as a data processor for Airtable data transmitted through configured webhooks. Your Postgres database is the authoritative destination for stored changelog data. Orloi does not intentionally store a durable application-level copy of Customer Changelog Data outside the customer-configured Postgres database, except for limited operational metadata, logs, transient processing, security records, and backups described in this Policy.
Orloi may share account, authentication, security, administrative, support, and billing infrastructure with other products operated by Otimo Earth s.r.o., including Powersync. If you use the same email address across these services, the underlying Otimo identity account may be shared. Product-specific workspaces, engines, access permissions, and customer data are logically separated between services.
1. Information We Collect
1.1 Information You Provide
- Account Information: When you sign up or connect with Google, we collect your name and email address for identification and communication.
- API Credentials and Technical Metadata: To operate the changelog engine, we process and securely store technical metadata and authentication credentials. This includes Airtable OAuth tokens (access and refresh tokens), Airtable webhook secrets, and the connection string for your external Postgres database. Sensitive credentials are encrypted at rest using AES-256-GCM before storage, and access is strictly limited to systems required to operate the service.
- Database Destination: Your Postgres connection string is stored to enable writing changelog data to your database. Orloi writes exclusively to a dedicated
orloischema within your database.
1.2 Airtable Activity Data
Orloi observes Airtable activity through webhooks you configure. Depending on your setup, this may include:
- Record changes: Record IDs, record names, field values (current, previous, and unchanged states), field IDs, field names, field types, and table metadata.
- Schema changes: Table names, field definitions, field options, primary field IDs, and schema structure updates.
- Source metadata: Information about what triggered each change, including collaborator names, email addresses, user IDs, automation IDs, and the change source (API, form, automation, system, or client).
- Webhook payloads: Complete webhook payloads from Airtable, including cell values for all fields in configured tables.
The specific data Orloi collects depends on the tables, fields, and scope you configure. You can exclude specific tables and fields from collection.
Customer Data may include collaborator identifiers, activity metadata, and other personal data depending on how you configure Airtable and Orloi. Customers control what data is connected to the Service and are responsible for ensuring they have the right to process that data, including where the data relates to employees, contractors, collaborators, candidates, or other workers.
Webhook payloads and changelog events may be transiently processed by Orloi infrastructure to deliver the Service, including validation, routing, enrichment, error handling, and security monitoring. Orloi does not use transient processing as a separate long-term storage layer for Customer Changelog Data.
Orloi is not designed for processing special categories of personal data, criminal offence data, medical records, payment card data, government identification numbers, or similarly highly sensitive data. Customers should not intentionally configure the Service to process such data unless they have first confirmed that their intended use is legally permitted and covered by appropriate written safeguards.
1.3 Derived and AI-Generated Data
When AI features are enabled, Orloi may generate and store the following in your Postgres database:
- Compacted events: Human-readable summaries of raw changes.
- Metrics: Computed activity counts, trends, and comparisons.
- Reports: Daily and weekly operational summaries.
- Company and collaborator profiles: Operational profiles derived from activity patterns.
- Schema intelligence: Analysis of base structure and field importance.
- Alerts and signals: Anomaly detection and pattern observations.
- Automation mappings: Descriptions of Airtable automations.
- Process variants and detected process maps: Workflow pattern analysis.
These artifacts are stored in your Postgres database, not on Orloi infrastructure.
Orloi outputs are intended for operational and audit context. They are not intended to be used as the sole or determinative basis for employee performance evaluation, HR decision-making, disciplinary decisions, compensation decisions, promotion decisions, termination decisions, or similar decisions affecting individuals.
1.4 Information Collected Automatically
- Usage Logs: We record minimal logs (e.g., API request metadata, timestamps) to monitor and troubleshoot the changelog process.
- IP Address: Collected in server logs for security and fraud prevention.
- LLM Call Metadata: When AI features are used, we log provider, model, token counts, duration, and request IDs for reliability and cost tracking. Prompt content is not logged by default.
1.5 Cookies and Tracking
We do not use cookies for analytics or marketing purposes and do not integrate third-party analytics services such as Google Analytics.
2. How We Use Your Information
- Account Creation & Identification: To register and authenticate your account.
- Service Delivery: To establish and maintain the data flow from Airtable to your Postgres database, including reading webhook payloads and writing changelog data.
- Changelog Processing: To decompose webhook payloads into raw events, compact related changes into readable activity narratives, compute metrics, and generate derived artifacts.
- AI Feature Execution (Opt-In): To generate reports, profiles, summaries, and other AI-derived outputs only when you explicitly enable these features.
- Communications: To send transactional emails (for example, report delivery if email is configured), updates, and policy change notices.
- Customer Support: To respond to your inquiries.
3. Legal Bases for Processing (EU/UK Users)
- Contractual Necessity: Account creation, authentication, service delivery, and the core changelog functionality you configured.
- Legitimate Interests: Security, fraud prevention, service reliability, troubleshooting, and minimal operational logs, balanced against your privacy rights.
- Legal Obligation: Accounting, tax, and compliance records.
- Customer instruction / contractual necessity for enabled AI features; legitimate interests for limited operational metadata and service security. Optional AI features where the feature is explicitly configured and enabled by you.
4. Data Sharing & Third-Party Processors
We rely on third-party subprocessors to operate Orloi. We require each to adhere to strict confidentiality and security obligations.
For the current subprocessor list, including purposes, data categories, regions, DPA status, and privacy/security links, see Subprocessors.
We do not sell your personal data.
Where enabled features require subprocessors, including infrastructure, email, analytics, security, database, or AI providers, Orloi uses such subprocessors only to provide, secure, monitor, or improve the Service. AI features may send selected event content or summaries to AI providers when the customer enables those features.
4.1 Customer Postgres as Primary Data Store
A critical architectural distinction: Orloi writes changelog data — raw events, compacted events, metrics, reports, profiles, alerts, and derived artifacts — to your Postgres database as the durable destination. We do not use Orloi's own application database as the primary durable storage location for Customer Changelog Data. Your Postgres is the system of record for Orloi outputs, subject to the limited operational processing described in this Policy, the Retention Policy, and the Data Processing Agreement.
Customers are responsible for the security, access controls, backup configuration, retention settings, and user permissions of their own Postgres database. Orloi is responsible for the parts of the Service infrastructure that Orloi operates.
4.2 AI Processing Controls
- AI processing is limited to explicit AI functionality that you configure and enable.
- Before supported AI processing paths, Orloi applies deterministic redaction to reduce exposure of obvious high-risk values such as email addresses and phone numbers where technically feasible. Redaction is a risk-reduction measure and does not guarantee that all personal, confidential, or sensitive data is removed.
- AI inputs may still include names, record labels, schema names, field names, operational context, or other customer-controlled content depending on your configuration.
- AI prompts and responses are constrained to structured outputs for specific features.
- Data sent to AI providers is limited to compacted operational context, not broad raw base dumps.
- If an AI feature is not enabled, that feature path does not call AI providers.
5. International Data Transfers
Your data may be processed and stored in servers located in the European Union and the United States. Where transfers occur from the EU/EEA or the UK to other jurisdictions, we rely on Standard Contractual Clauses approved by the European Commission to ensure adequate safeguards.
Note: Because Orloi writes changelog data to your Postgres database, the storage location of that data is determined by your Postgres hosting provider, not by Orloi.
6. Data Retention & Deletion
For a more detailed retention schedule covering Orloi-managed application data, customer-controlled operational data, and vendor/platform data, see our Retention Policy.
- Active Accounts: We retain your account and credential data for as long as your account is active.
- Changelog Data: All raw events, compacted events, metrics, reports, and derived artifacts are stored in your Postgres database. Retention of this data is your responsibility because it resides in your infrastructure. We recommend managing raw-event retention with a cutoff appropriate to your needs (commonly 90 days for raw events).
- Webhook Payloads: Webhook payloads from Airtable are processed and decomposed into raw events. Payloads are not retained separately after processing.
- Backups: Internal backups of Orloi metadata (sync records, tasks, credentials) are encrypted and retained for up to 90 days for disaster recovery purposes.
- Legal Records: Account, billing, and compliance records may be retained where required by law.
- Deletion Requests: You may request account deletion from the account settings flow. We will email you a confirmation link before deletion starts. Once confirmed, the account deletion flow deletes your shared login and product data tied to that login across Orloi and Powersync, including subscriptions, connections, and engines, subject to legal retention requirements, backup expiry, and any active subscriptions that must be cancelled first. It will not delete data already written to your Postgres database, which you control directly. You may also contact martin.malinda@orloi.ai for help with deletion requests.
Customer Changelog Data retained in the customer-configured Postgres database is retained according to the customer's own database configuration and retention choices. Orloi may retain limited operational records, logs, audit records, billing records, and security records for as long as reasonably necessary for service operation, legal compliance, dispute resolution, and security.
7. Security Measures
We implement reasonable technical and organizational measures to protect your data, including:
- Encryption in Transit: HTTPS/TLS for all web traffic and database connections.
- Encryption at Rest: Credentials are encrypted at rest using AES-256-GCM. Encryption at rest is also used where supported by our hosting, database, and infrastructure providers.
- Access Controls: Admin access protected by two-factor authentication (2FA).
- Development Best Practices: Version control, structured release practices, dependency review, automated checks, and security-focused implementation practices.
- Restricted Logging: Logs stored securely on Fly.io and Netlify with access limited to essential personnel.
- Least-Privilege Architecture: Systems and personnel are granted only the minimum access required to operate the service.
- Webhook Verification: Airtable webhook payloads are verified using HMAC-SHA256 signatures.
8. Your Rights
If you reside in the EU, UK, or California, you have the following rights regarding your personal data:
- Access: Request copies of your data.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Delete your data.
- Portability: Receive your data in a structured format.
- Objection: Object to processing based on legitimate interests.
To exercise these rights, contact our Data Protection Contact at martin.malinda@orloi.ai. We will respond within applicable legal timeframes.
Where Orloi processes Customer Data as a processor, the relevant customer is normally responsible for handling data subject requests. Orloi will assist the customer/controller as required by applicable data protection law and the applicable agreement. Where Orloi processes Account Data or other data as a controller, individuals may contact Orloi directly to exercise their rights.
Note: Because Orloi stores changelog data in your Postgres database, you have direct access to and control over that data through your own database. Requests related to changelog data may be best addressed through your database access rather than through a formal data subject request to Orloi.
9. Children's Privacy
Orloi is not intended for individuals under the age of 16. We do not knowingly collect personal information from minors.
10. Changes to This Policy
We may update this Privacy Policy periodically. When we do, we will:
- Post the new policy on our site with an updated "Effective Date."
- Notify you by email of material changes.
11. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the relevant supervisory authority (e.g., the Czech Data Protection Authority) within 72 hours where legally required.
- Inform affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
- Provide a description of the nature of the breach, the categories and approximate number of data subjects and records affected, and measures taken to mitigate its effects.
If Orloi detects a security incident affecting Customer Data, Orloi will notify affected customers without undue delay, investigate the incident, take appropriate containment and remediation steps, and provide available information reasonably needed for the customer's own breach assessment. Where Orloi is legally responsible for regulatory notification, Orloi will make such notification in accordance with applicable law.
12. Governing Law & Dispute Resolution
This Privacy Policy and any disputes arising out of or relating to it are governed by the laws of the Czech Republic.
Any legal action or proceeding related to this Policy shall be brought exclusively in the courts of Prague, Czech Republic.
13. Contact Us
If you have questions or concerns about this Privacy Policy, please contact:
Data Protection Contact
Otimo Earth s.r.o
Email: martin.malinda@orloi.ai
Last updated: June 10, 2026