Last updated · 2026-10-02

Privacy policy

What Oruka processes, why, and how to exercise your rights. This covers the website, accounts and hosted service, and explains Enterprise's scope.

Operator and service details must be completed before publishing this document.

English translation. Spanish is the reference version, subject to mandatory local language and consumer rights.

Identification and contact

Operator (individual)
To be completed by the operator
Address for legal notices
To be completed by the operator
Country of establishment
Colombia
Contact and privacy email
To be completed by the operator
Contact phone
To be completed by the operator

1. Controller and scope

The individual identified on this page, established in Colombia, controls personal data relating to Oruka visitors, users, contracting and support. This policy is based on Colombia's Law 1581 of 2012 and its regulations, including those compiled in Decree 1074 of 2015, without displacing other applicable laws.

A business using Oruka for its customers' data determines the purposes and acts as controller. In the hosted service, Oruka processes that data on its instructions. Enterprise operators administer their own installation; we receive only information provided for contracting or support and data relating to expressly enabled additional services.

2. Data we process

Account and contracting: email, profile information you provide, Google-verified email and profile picture if you choose Google sign-in, billing information, plan, transaction references and support requests. Local passwords are stored as salted hashes, not recoverable plaintext.

Service content: contacts, phone numbers, emails, notes, messages, files, knowledge documents, agent instructions and memory, tasks, automations, forms, campaigns, calendars and operation history. Voice features may process audio, transcripts and call history depending on the enabled integration; the business must provide notices and obtain required permissions.

Integrations and security: API keys, access tokens and granted scopes, connected account identifiers, technical logs, errors, usage and connection information processed by the server and its providers. Infrastructure may process IP addresses to deliver and protect the service; an internet connection is not represented as anonymous.

Optional analytics: public page visits with Google Analytics and general product screen names with PostHog, only when configured and authorized. Our integration does not send conversation text, form fields or customer identifiers. It does not record sessions.

3. Purposes and authorization

We process data to create and secure accounts, provide contracted features, respond to requests, execute authorized integrations, bill and manage payments, detect abuse and meet legal duties. Prior, express and informed authorization is required where Colombian law demands it unless a legal exception applies; you may request evidence of authorization.

Optional analytics depends on your specific choice and is not required to use the service. Cookie consent does not authorize marketing campaigns, call recording or processing your customers' data. Necessary access, billing and security messages differ from promotional communications, which require an applicable authorization or legal basis and an opt-out mechanism.

Where the GDPR or another law recognizes these grounds, performance of a contract, legal obligations, consent and, where justified following a balancing assessment, legitimate interests may support specific purposes. Legitimate interests are not invoked as a general exception to Colombia's authorization requirements.

4. Google data and permissions

Signing in and connecting Google are separate actions. When you choose Continue with Google, we request openid, email and profile. We retrieve your email address, its Google verification status and your profile picture when available to create or access your account and display your avatar. This sign-in does not authorize access to Gmail, Drive, Sheets, Calendar or Search Console and does not retain a refresh token for those features.

When you connect an account from Connections, Google displays the requested permissions and you decide whether to grant them. This connection requests access to Sheets, Calendar, Drive, Gmail sending and Search Console reading together, plus openid and email to identify the connected account. Granted permissions may cover more resources than you configure for a particular task; operations depend on the features you use and the instructions and automations you enable.

Google Sheets (spreadsheets): permits reading and modifying spreadsheets. Oruka's logging feature sends the spreadsheet identifier, worksheet name and values you configure, such as contact details, answers or task results, to append rows to the specified sheet. Sheets documents you import from Drive may also be converted to text for your knowledge base.

Google Calendar (calendar): permits accessing and managing calendars and events. Oruka retrieves availability and event details such as identifiers, titles, dates, times, time zones, descriptions, locations, attendee email addresses and meeting links. It uses them to display your calendar and create, update or cancel appointments according to the actions you authorize. Google receives appointment details and may send invitations to attendees.

Google Drive (drive.readonly and drive.file): read access permits accessing files available to the connected account; it is not technically restricted to the folder you select. Knowledge import lists files in the folder you configure, including identifiers, names, types and sizes, and reads or exports supported documents to import them into Oruka. The drive.file permission permits creating and managing files used by the application, such as assets you upload to the media library. We may also download these assets for an action you configure.

Gmail (gmail.send): permits sending email from the connected account. Oruka sends Gmail the recipient, subject, text or HTML body and reply-to address when provided, and receives the sent message identifier. This permission does not permit reading your inbox or importing your email history. Sent content is delivered to the recipients you specify.

Google Search Console (webmasters.readonly): permits retrieving properties accessible to the account and their search metrics. Oruka uses property addresses, queries, pages, clicks, impressions, click-through rates and positions to display the SEO panel, compare periods and produce analyses you request. This permission is read-only and does not permit changing properties or submitting or deleting sitemaps.

5. Google data use and AI processing

We use Google data for the disclosed features: account access, spreadsheet logging, appointment management, knowledge import, media library, email sending and SEO analysis. A connection can operate while you do not have the application open: refresh tokens allow the automations and actions you configure to run. Connecting an account does not itself import all its files or information.

If you import a Drive document into Knowledge, its text is sent to the configured embedding provider to create search vectors. When that knowledge is used in a conversation, relevant passages are sent to the model provider to generate an answer. Tool results and Google data you include in a task, such as appointment details or SEO metrics, may also become part of the context sent to the model. Depending on your configuration, providers include OpenAI, Anthropic, Google or providers through Vercel AI Gateway; the gateway also processes requests routed through it.

These transfers serve the AI features you enable. Oruka does not use Google data to train or improve general-purpose artificial intelligence models. Creating embeddings to search your own documents and generating responses are processing to provide the service, rather than training a general-purpose model. Providers processing Google data must observe the limited-use restrictions in this policy; use for training general-purpose models is not authorized.

A response using Google data may be shared with members of your business who can access the conversation, or with an external recipient if you configure the agent to reply through a channel, send an email or use another integration. Appointment attendees, email recipients and destination services receive the information needed for that action. Review the knowledge, tools, channels and recipients you enable before activating an automation.

6. Google data storage and protection

To maintain a connection, Oruka stores access and refresh tokens on the server, their expiry when supplied, granted permissions, the connected account's email address and the connection date. Refresh tokens obtain new access tokens when they expire. The interface displays connection status and the connected account without returning these tokens to the browser as part of the connection record.

Imported documents may be retained as extracted text, passages, embeddings and source file identifiers in the knowledge base. The media library retains metadata and Drive resource identifiers for retrieval when needed. Data used in a task and its results may also remain in conversations, operation records or settings. The selected Search Console property is retained for the SEO panel. These copies and derived data are subject to the same use restrictions as the original data.

Requests to Google APIs and token exchanges use HTTPS. The application uses session and access controls; the installation's shared connection is managed by its owner. Storage, processing countries, infrastructure protection measures and retention and backup cycles must correspond to the services identified in the operations record. We do not claim that every installation has the same storage encryption or a universal deletion period.

7. Limited use and recipients of Google data

Oruka's use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements, and applicable Google Workspace restrictions. These restrictions also apply to derived, aggregated or anonymized data.

We only use Google data to provide visible service features you authorize. Transfers are limited to infrastructure and processing providers necessary for those features, services and recipients of actions you authorize, security purposes, legal requirements or an acquisition or asset sale with your prior explicit consent. We do not sell this data, provide it to data brokers, use it for personalized or targeted advertising, or use it to determine creditworthiness or for lending purposes.

Oruka personnel may not read your Google data unless you expressly authorize access to specific data for assistance, it is necessary to investigate a security issue or abuse, it is legally required, or the data is aggregated and anonymized for permitted internal operations. Providers and contractors involved must follow the same restrictions. Google data is not included in this application's optional analytics events.

8. Disconnecting Google and requesting deletion

The installation owner can disconnect Google from Connections. This removes Oruka's saved tokens from active connection storage. To also revoke Google's authorization, open your Google Account's third-party connections, select Oruka and remove its access. These are separate controls: disconnecting in Oruka does not itself revoke authorization in Google. If the installation also uses a service account, its owner must remove that credential or its permissions to stop that independent access.

Disconnecting or revoking access stops future access through that connection but does not automatically delete previously imported documents, embeddings, conversation history or files or events created in Google. You can delete documents from Knowledge and assets from the media library. Copies held by Google and messages already delivered to recipients are managed in those services; disconnecting Oruka cannot recall them.

To request access, export or deletion of other Google data retained by Oruka, use the privacy email in the identification record and identify the connected account and affected data or features, without including passwords or tokens. Your privacy rights explains identity verification and response deadlines. Requests cover imported content and derived data; any mandatory retention or temporary persistence in backups will be explained when handling the request. Response deadlines do not guarantee instant deletion of every copy.

9. AI and model providers

Content needed to generate responses or search documents is transmitted to the selected provider, which may be OpenAI, Anthropic, Google or providers available through Vercel AI Gateway. Knowledge indexing may use OpenAI embedding models directly or through the gateway even when the conversation model is different.

Each API's retention and data-use terms depend on the provider, product, configuration and current contract. For data obtained from Google APIs, the limited-use restrictions and exclusion of general-purpose model training described in this policy take precedence. We do not promise zero retention; retention must be verified for each provider and configuration. Avoid supplying sensitive information or secrets that are not necessary.

Oruka can execute business-configured instructions and automations. It must not be used for solely automated decisions with legal or similarly significant effects without appropriate grounds and safeguards, including human review where required.

10. Recipients and integrations

Hosting, database, storage, email, AI and payment providers may be involved. Only services necessary for the relevant purpose should be enabled, under applicable contractual terms. This page's operations record identifies this installation's infrastructure.

Depending on connected features: Meta (WhatsApp, Instagram, Messenger and ads) processes messages and channel data; Google may provide sign-in, Gmail, Drive, Sheets, Calendar or Search Console; ElevenLabs provides voice; Stripe and Mercado Pago process payments; Shopify supports commerce; Resend or an SMTP provider delivers email; other OAuth, API or MCP services execute authorized actions. Installing Oruka does not activate all providers.

Payment details entered on processor-hosted pages go to that processor; Oruka receives references and payment status and does not need to store full card numbers. Google Analytics and PostHog receive the optional events described in Cookies and preferences when authorized.

We do not sell personal data or share it for cross-context behavioral advertising through this integration. Information may be disclosed to meet legal obligations, valid authority requests or establish, exercise or defend legal claims, limited to what is necessary.

11. International processing

The service operates from Colombia and integrations may process data in the United States and other countries. A provider's domicile alone does not establish where each item is processed. Consult the operations record and the connected service's terms.

International transfers and transmissions must satisfy applicable requirements, including Article 26 of Law 1581, available exceptions and transmission agreements where applicable. If the GDPR applies, adequacy decisions, standard contractual clauses or other valid safeguards may be required. We do not represent that all providers are automatically covered by the same mechanism. You may request information about destinations and safeguards applicable to your data.

12. Retention and deletion

Data is retained as necessary for disclosed purposes, the contractual relationship, requests and applicable legal duties. Billing and transaction evidence may be retained for applicable tax, accounting or limitation periods. Data must not be retained indefinitely merely because the software permits it.

The application does not enforce general automatic deletion of conversations or databases. Enterprise operators define and execute their policy. Hosted deletion and exports are handled on request under the rights procedure; legal retention restrictions will be explained. Backup cycles, deletion and retention arrangements appear in the operations record.

Analytics choices expire after 180 days or sooner when their version or configuration changes. The PostHog identifier used here lasts for the browser tab's session; Google Analytics cookies are configured for up to 180 days. Provider event retention is configured separately and documented in the operations record.

13. Security

The application includes session and access controls, password hashing and integration verification mechanisms. Encryption, backups, permissions, monitoring and incident response also depend on deployment and must be maintained according to risk. No system offers absolute security.

Report suspected incidents to the published contact. They will be investigated and applicable notification duties to authorities and affected people will be followed. Do not publish credentials or other people's data in public reports.

14. Children and sensitive data

Oruka is not directed to anyone under 18. Do not request or upload sensitive or children's data unless the feature, purpose and legal safeguards allow it. You are not required to authorize sensitive-data processing for optional purposes. Report suspected unauthorized processing through the privacy contact.

15. Your rights and changes

You may know, access, update and correct your data, request authorization evidence, learn how it is used, complain and request revocation or deletion where legally available. Your privacy rights explains how to apply and the response deadlines for Colombia and additional rights in other territories.

This policy takes effect on the displayed update date. Material changes will be communicated appropriately; authorization will be requested before new purposes requiring it are introduced. Acceptance of terms does not replace a data authorization that must be collected separately.

This installation's operations record

Hosting
Vercel — web application and agent execution; function region iad1 (United States).
Database
Neon — PostgreSQL; AWS us-east-1 region (United States).
File storage
Neon PostgreSQL for application files. The media library may use Google Drive when you connect a Google account. No S3 bucket is configured for this installation.
Processing countries
Colombia (service operations) and the United States (verified Vercel and Neon infrastructure). Google APIs and AI or other integration providers may process data in other countries depending on the service and configuration you enable.
Retention, deletion and backups
To be completed by the operator
Analytics event retention
Google Analytics and PostHog are not configured for this deployment; the application does not send optional analytics events to them. If enabled, retention will be disclosed and your choice will be requested before sending events.