1. Scope and operator
This policy applies to the hosted Orkestr service available through orkestr.de and its official connection pages. The hosted beta is operated by Orkestr. Contact: Ask the person who invited you..
Independent self-hosted installations are controlled by their respective operators. Unless a self-hosted operator connects that installation to an Orkestr-hosted service, the Orkestr hosted service does not receive data from that installation.
2. Information Orkestr processes
Orkestr processes information needed to provide user-requested workflows: account and contact details, chat messages, files, task outputs, timers, workspace records, connector status, managed-browser activity, security records, and technical service logs. Orkestr does not ask users to provide account passwords through chat.
3. Google user data Orkestr accesses
The public Google integration can request only the capabilities enabled for the deployment and required by the user-requested action. The currently enabled scopes are: openid, userinfo.email, userinfo.profile, https://www.googleapis.com/auth/gmail.readonly, https://www.googleapis.com/auth/gmail.send, https://www.googleapis.com/auth/gmail.compose, https://www.googleapis.com/auth/calendar.events.readonly, https://www.googleapis.com/auth/calendar.events.owned.
- Google identity: account identifier, email address, name, and available profile information used to identify the connected account.
- Authorization data: granted scopes, access token, refresh token when issued, token type, expiration time, and connection status.
- User-approved outgoing email: sender account, recipients, subject, body, and attachments that the user requests or approves for sending.
- Gmail drafts: recipients, subject, body, attachments, draft identifiers, and delivery status for drafts the user asks Orkestr to create or send.
- Selected Gmail content: message identifiers, sender and recipient headers, subject, date, labels, snippets, and message content retrieved for a user-requested search, read, summary, action, or notification rule.
- Selected Calendar data: calendar identifiers and event titles, descriptions, locations, attendees, start and end times, recurrence, status, and links needed for user-requested event listing or management.
- Operation metadata: identifiers and status returned by Google after a requested operation.
Orkestr accesses only the Google capabilities required by the user-requested action and granted by Google. It does not retrieve contacts, mailbox settings, or a complete mailbox or Calendar export. If Orkestr introduces a capability requiring additional Google scopes, it will update this policy and the in-product disclosure and obtain new consent before requesting that access.
4. How Orkestr uses Google user data
Orkestr uses Google identity data to display and manage the connected account, authorization data to maintain the connection, selected Gmail data to perform user-requested draft, read, notification, or message workflows, selected Calendar data to list or manage events, and operation metadata to report results. Orkestr requests access for a specific user-facing action; Google is the only consent screen that grants it. Google user data is not used for unrelated purposes.
5. Sharing and disclosure of Google user data
Orkestr does not sell Google user data. It does not provide Google user data to advertising platforms, data brokers, or information resellers, and does not use it for advertising, credit decisions, or to develop, improve, or train generalized or non-personalized AI or machine-learning models.
Data is disclosed only in these limited circumstances:
- Google: Orkestr sends the user-approved email and credentials required to authenticate the request to Google's OAuth and Gmail services.
- Configured AI provider: a configured AI provider may process only the specific Gmail or Calendar content needed for a user-requested workflow. That provider must be contractually prohibited from using Google Workspace data to develop, improve, or train generalized or non-personalized AI or machine-learning models. Notification rules default to bounded message metadata and snippets; full message content is retrieved only when the user asks for it. Google OAuth access and refresh tokens are never disclosed to an AI provider.
- User-selected communication provider: when the user works through WhatsApp, Meta's WhatsApp service carries the user's instructions and Orkestr's status or result messages.
- Infrastructure and security providers: hosting, storage, networking, monitoring, and security processors may handle encrypted or operational data only as needed to operate and protect the service.
- Support, security, and law: authorized human access or disclosure may occur only with the user's explicit support request, to investigate abuse or a security incident, or where required by applicable law.
Service providers are permitted to process data only for the service purpose for which it was disclosed and must protect it appropriately.
6. Storage and retention
Google OAuth credentials are stored in the connected user's isolated connector storage and retained until the user disconnects the account, the grant is revoked, the account is deleted, or the credentials expire and are no longer needed. A disconnect requests revocation from Google before deleting the local credential record.
Google content used in a requested workflow may remain in the user's Orkestr chat, draft, notification, or task history when it is part of the user-visible result. Orkestr does not maintain a separate complete copy of the user's Gmail mailbox or Calendar. Notification state stores bounded rule configuration, message identifiers used for deduplication, run status, and selected previews. Connection requests are one-time and expire. Encrypted credential records may remain temporarily in protected operational backups until those backups rotate.
7. Data protection mechanisms
- HTTPS/TLS protects Google authorization and service traffic in transit.
- Google OAuth access and refresh tokens are encrypted at rest with AES-256-GCM.
- Production encryption keys are stored separately from encrypted token records and are restricted to the Orkestr service account.
- Connector records are scoped by user and protected by authenticated access controls and private filesystem permissions.
- Orkestr requests the minimum approved Google scopes and blocks undeclared capabilities in both the user interface and server.
- Credentials are excluded from public responses, agent context, screenshots, source control, and operational event records.
No system can guarantee absolute security. Suspected unauthorized access is investigated and affected users and authorities are notified when required.
8. Google API Services User Data Policy
Orkestr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Workspace data is used only to provide the user-facing feature requested by the user. Orkestr and its service providers do not use Google Workspace data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
9. User controls, revocation, and deletion
Users can decline Google access and continue using Orkestr without Gmail. A connected account can be disconnected from Orkestr setup, which revokes the Google grant and removes locally stored credentials. Users can also revoke Orkestr from their Google Account permissions page.
Users may request access, correction, export, restriction, or deletion of their Orkestr data through the invitation chat, the data deletion page, or Ask the person who invited you.. Some minimal records may be retained where required for security, abuse prevention, dispute handling, or law.
10. Legal bases and international processing
Depending on the context, Orkestr processes data to provide the service requested by the user, based on the user's consent for optional connectors, for legitimate security and reliability interests, and to meet legal obligations. Providers may process data in countries outside the user's country; Orkestr relies on the provider's applicable contractual and legal transfer safeguards.
11. Changes and contact
Material changes to Google data access, use, or sharing will be reflected here and in the in-product disclosure before new access is requested. Questions or privacy requests can be sent to Ask the person who invited you..