Legal

Privacy

The data boundary for the Ormas local-runner dispatch beta.

What stays local

Your repository contents, local filesystem path, OpenRouter or other provider key, environment variables, and raw local execution logs remain in the local runner boundary. Do not paste provider credentials into the Ormas portal or task brief.

The upstream provider you select processes model inputs under its own terms. Provider access is initiated locally with your key; Ormas does not store that key.

What Ormas stores

To operate a dispatch, Ormas stores the task brief and control-plane metadata such as your account, repository alias, base commit, verification command, allowed paths, budget, task state, safe runner metadata, metered token counts, verification outcome, receipt, and settlement. Repository aliases are labels and must not contain local paths or secrets.

Returned patches and limited diagnostic records may be retained long enough to deliver the result, investigate failures, prevent duplicate settlement, and operate the beta. Do not submit secrets or regulated data in a task brief.

Account and billing data

The portal may store your email, display name, avatar, authentication-provider identifier, sessions, hashed Ormas access keys, account preferences, promotional and paid balances, and payment/settlement records. Sign-in may use Google, an email magic link, or another enabled provider. We do not store a portal password.

Payment card data is handled by the payment processor and is not stored by Ormas.

Uses and sharing

We use this data to authenticate users, dispatch and verify tasks, prevent abuse, provide support, reconcile billing, and improve reliability. We do not sell personal information or share it for third-party behavioral advertising.

Service providers may process the minimum data needed for hosting, database, authentication email, payment, monitoring, and customer-selected model inference. Current categories include Vercel, Neon, Resend, Stripe, and the provider selected through your local host, such as OpenRouter and its downstream model provider.

Retention and rights

We retain account, task, security, and financial records only as long as needed for beta operations, legal obligations, dispute resolution, and fraud prevention. Retention can differ by record type; billing and idempotency records may outlast task artifacts.

Depending on your US state, you may request access, correction, or deletion of personal information, subject to security, billing, and legal exceptions. Ormas does not sell or share personal information for cross-context behavioral advertising.

To make a request, contact privacy@ormas.ai. We may verify your identity before completing it.

Territory, children, and contact

The beta uses hosting-derived country metadata to enforce its US-only policy. Ormas is not directed to anyone under 18.

Effective 2026-07-14. Ormas Beta is operated by Heron Cove LLC, United States. Privacy questions: privacy@ormas.ai.