Privacy and your data
What Orneos stores, where it goes, what happens with AI features, and what we will not claim about backups.
The linked privacy notice, cookies and storage notice and website terms cover this public website and initial enquiries. This page describes application data paths; it does not extend those notices to workspace use. Before sharing project material in a pilot, agree access, purpose, provider use and retention under the arrangements applicable to that pilot.
What is stored
On the server: your company, teams, memberships, issues, projects, labels, Vault pages, comments, Intents and their revisions.
In your browser: a replica of your teams’ data, your queue of unsent changes, and small preferences. See Local data and storage.
With the identity provider: your account identity — email, name, authentication. Orneos never receives your password.
What we do not do
- Orneos does not use your workspace content to train models. Provider handling depends on the AI path and provider terms; this is not a promise about every third party you choose to send data to.
- We do not sell or share your data with third parties for their own purposes.
- We do not run analytics or advertising trackers on this website. The cookies notice is short because there is little to describe.
- AI data paths are disclosed per feature. Personal BYO drafting and server-provider AI use different credentials and funding controls.
Search queries
Spotlight uses local lookups and sends the query to Orneos for server-side Vault title/body search. Results are limited by team and space access. The Search page also sends your query and filters to Orneos when Company scope is selected, returning results within your authorized company access. Company is its default scope and needs a connection; Team scope queries local issue data. These searches use Orneos data, not a model provider; search is not an entirely on-device operation.
AI features
BYO Intent drafting sends request data directly from your browser under your provider account. Insights and enabled funded drafting use the server-configured provider and applicable consent/allowance controls. Provider handling and retention must be assessed for the path you use; having no browser key does not mean no AI request can be made.
Which content that is:
| Feature | Sent |
|---|---|
| Intent drafting | The assembled, export-filtered task context: task fields, confirmed Intent when available, project details, parent/sub-issues and relations, available discussion, and eligible Vault titles and links. Vault page bodies are not included. |
| Insights | Your question and the issue data needed to answer it |
Drafting excludes restricted/private Vault enrichment and references whose visibility cannot be established. This does not remove URLs already present in user-authored text. Review the task context before sending it to a provider.
A context bundle makes no model call. It can load missing discussion and exports available material to your clipboard; where you paste it is your decision. Restricted/private Vault enrichment is excluded.
Deletion
Deleting an issue, project or Vault page removes it for everyone in the team. It is not a soft delete and there is no trash.
For deleting an account or a company’s data, email support@orneos.com. Server-side deletion does not reach a copy already delivered to someone’s browser — see the revocation note in Security and isolation.
Export
Context bundles export task context and confirmed Intent. Vault Export downloads one page as Markdown. There is no self-service “download everything” button.
If you need your data out, ask and we will get it to you.
Backups and recovery
Read this before you rely on us
This documentation does not establish the deployed backup configuration or a tested, supported restore path. Confirm any backup and retention arrangement with us before relying on it.
We do not offer a recovery time objective, a recovery point objective, or a guarantee that a specific piece of lost work can be restored. Any pilot-specific backup or recovery arrangement has to be agreed separately, in writing.
Keep independent copies of anything you cannot afford to lose. See Known limits and the early-use notice.
Where it runs
Application and database are hosted with a cloud provider. BYO model calls go to your provider account; server-provider features use the configured service. If data residency is a requirement for you, raise it early — we have no residency commitments today.
Related
Something here wrong, missing or out of date? Tell us at support@orneos.com — corrections to these pages are welcome and we would rather hear it than have you work around it.