Skip to content
Orion
PricingEnterprise
Download
Use Cases
Daily WorkSchedulingYour RepresentativeCross-DeviceCreativity
Resources
Orion SafetySelf-AuditOrion SensorCommunicationNewsUsage & LimitsFirmware
PricingEnterprise
Sign InDownload

Privacy Policy

Last updated: March 4, 2026

This Privacy Policy explains how Zinley ("Zinley," "we," "us," or "our") collects, uses, and protects your information when you use Orion.

For questions about this policy, contact us at privacy@meetorion.app.

We believe you should know exactly what happens to your data and have full control over it. This policy covers all data processing activities related to your use of Orion's services across all plans (Free, Plus, Pro, Max, Enterprise, and any future tiers).

Information We Collect

We collect information necessary to provide and improve Orion's services. The following describes each category of data we collect and its purpose:

Account Information

Email address, name, and authentication credentials collected during registration. This information is required to provide account access and maintain account security.

Device and Platform Information

Device identifiers, operating system information, device capabilities, and connected platform details (messaging apps, integrations). This information enables Orion to function across your devices and connected platforms.

Inputs and Outputs

Your conversations, commands, and requests to Orion ("Inputs"), and the responses and actions Orion generates ("Outputs"). We process these to deliver the service and retain conversation history so Orion can maintain context across sessions. Your conversation content is never used for model training and is not viewable by any Zinley team member.

Usage Data

Feature usage, performance metrics, error logs, and interaction patterns. This data is used to improve the service and resolve technical issues.

Automatic Collection

We automatically collect device and connection information (IP address, device type, browser data), browsing patterns, and log files. This data supports service operation, security monitoring, and performance optimization.

Feedback and Reports

When you submit feedback, bug reports, or rate responses, we collect that information along with associated conversation context. Bug reports include your full conversation history to help us diagnose issues.

How We Use Your Information

We use your information for the following purposes:

Service Delivery

  • Process AI requests, make calls, access files, and run tasks on your behalf
  • Maintain persistent memory to learn your preferences and maintain continuity across sessions
  • Synchronize data and settings across your devices and connected platforms
  • Deliver Orion through desktop, mobile, CLI, and messaging apps
  • Maintain account security and authentication

Service Improvement

  • Analyze usage patterns to improve existing features
  • Monitor system performance and reliability
  • Develop new features
  • Log errors, performance metrics, and operational data to diagnose issues and improve the system

Safety and Compliance

  • Enforce our Terms of Service and Acceptable Use Policy
  • Prevent fraud, abuse, and security threats
  • Investigate policy violations and resolve disputes
  • Comply with legal obligations

Communications

  • Send important service updates and security notifications
  • Provide customer support and technical assistance
  • Respond to your inquiries and feedback

Your Data Is Never Used for Training

Zinley does not build AI models. We use third-party models from OpenAI, Anthropic, and Google, and we maintain zero data retention agreements with all of them. Your data is never used for model training. There is no opt-in, no opt-out, and no configuration required -- this applies to all users on all plans.

What This Means

  • Your inputs, outputs, and conversation history are never used to train any AI model
  • We have zero data retention agreements with all our AI model providers (OpenAI, Anthropic, Google)
  • Your conversation content is not viewable by any Zinley team member
  • We log only errors, performance metrics, and operational data for service operation -- not your raw conversation inputs or file contents
  • Data is retained only for the minimum period needed for service operation

Safety Exception

Content flagged by our automated safety systems may be reviewed by our trust and safety team to enforce our Acceptable Use Policy. This is strictly limited to safety enforcement.

Data Sharing and Disclosure

We do not sell your personal data. We may share information only in the following limited circumstances:

Service Providers

We engage third-party service providers to operate the platform, including AWS for infrastructure, OpenAI and Anthropic for AI models, and other technical providers. All service providers are contractually bound to protect your data and may only use it for the specific purposes outlined in our agreements. See our Security page for the full subprocessor list.

Affiliates

We may share data with our affiliates and related entities, who are bound by this Privacy Policy.

Third-Party Integrations

If you connect third-party applications to Orion, those services will receive the data necessary to provide the integration. Their use of your data is governed by their own privacy policies.

Legal Requirements

We may disclose information if required by law, court order, or government request, or to protect our rights, property, or safety, or that of our users or the public.

Business Transfers

If Zinley is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and your options regarding your data.

Data Security

We implement and maintain technical and organizational measures to protect your information. These measures include:

Encryption

  • AES-256 encryption for data at rest
  • TLS for all data in transit between your devices, our servers, and AI providers
  • Files are accessed locally on your device -- file content is not uploaded to our servers unless needed for a specific task (e.g., AI analysis). File hashes and embeddings may be synced for indexing.

Access Controls

  • Multi-factor authentication for all team members
  • Least-privilege access principles
  • Regular access reviews and audits
  • Secure key management systems

Monitoring

  • 24/7 security monitoring and threat detection
  • Regular security assessments and penetration testing
  • Incident response procedures

Data Retention

We retain your data only for as long as necessary to fulfill the purposes described in this policy. The following outlines our retention periods by data category:

  • Account Data: Retained while your account is active. Permanently deleted when you delete your account
  • Conversations and Messages: Retained to maintain context across sessions. When you delete a conversation, it is permanently and immediately deleted -- not moved to a trash folder or backup
  • Device and Platform Data: Retained while connected and for up to 30 days after disconnection
  • Persistent Memory: Retained while your account is active to personalize your experience. Permanently deleted when you delete your account or when you clear your memory in settings
  • Phone Call Data: Call audio is not recorded or stored. Call metadata (time, duration, outcome) is retained for up to 90 days for your records
  • Inputs and Outputs (default): Retained for up to 30 days for service operation, then deleted
  • Safety-Flagged Content: Inputs and outputs retained for up to 2 years; trust and safety scores for up to 7 years
  • Feedback and Bug Reports: Retained for up to 5 years to help improve service quality
  • Usage Analytics: Aggregated and anonymized data may be retained for up to 2 years

You may delete your account at any time through Settings. Upon account deletion, all associated data is permanently removed -- not moved to a backup or archive.

Telemetry and Diagnostics

We collect operational metrics to maintain service performance and reliability. The following describes what we collect and how to opt out:

Operational Metrics

We log latency, reliability, and usage pattern data to monitor service health. This does not include your device data, file paths, or conversation content. Data is encrypted in transit (TLS) and at rest (AES-256).

Error Reporting

We collect error logs and crash reports to identify and resolve technical issues. These are encrypted in transit and at rest and do not contain your personal content.

Opting Out

You can disable telemetry and error reporting in your account settings. Disabling these will not affect Orion's core functionality.

Your Rights

You have the following rights regarding your personal data:

Access and Portability

  • Access your personal data and understand how it is used
  • Export your data in a machine-readable format
  • Receive copies of your data for transfer to other services

Correction and Control

  • Update or correct your account information
  • Manage your connected devices and platforms
  • Control data sharing preferences
  • Withdraw consent for data processing at any time

Deletion and Restriction

  • Delete your account and all associated data
  • Request deletion of specific data categories
  • Restrict certain types of data processing
  • Object to data processing for specific purposes
  • Appeal any denied data rights request

To exercise any of these rights, contact us at privacy@meetorion.app. We will respond within 30 days of receiving your request.

International Data Transfers

Zinley is based in the United States, and our servers are primarily located in the US. If you access Orion from outside the United States, your data may be transferred to, stored, and processed in the US and other countries where our service providers operate.

We ensure that international data transfers comply with applicable laws and include appropriate safeguards:

  • Standard contractual clauses (SCCs) with service providers per GDPR Article 46
  • EU adequacy decisions where applicable
  • Additional security measures for sensitive data
  • Regular reviews of transfer mechanisms

Cookies and Tracking

We use cookies and similar technologies on our services. The following describes how and why they are used:

Essential Cookies

These are necessary for our services to function properly, including authentication, security, and core functionality.

Analytics Cookies

These help us understand how our services are used so we can improve them. You may opt out of analytics tracking in your account settings at any time.

Platform Identifiers

We use device and platform identifiers to enable cross-device and cross-platform functionality. This is essential for Orion to work seamlessly across your desktop, phone, and messaging apps, and can be managed through your settings.

Children's Privacy

Orion is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected personal information from a person under 18, we will promptly delete that information.

If you believe we have collected information from someone under 18, please contact us at privacy@meetorion.app.

Regional Privacy Laws

We comply with applicable privacy laws in all jurisdictions where we operate:

GDPR (European Union)

If you are in the EU, you have additional rights under the General Data Protection Regulation, including the right to object to processing, request data portability, and lodge complaints with supervisory authorities. Our EU representative is Zinley Ireland Limited, located in Dublin, Ireland.

CCPA (California)

California residents have rights under the California Consumer Privacy Act, including the right to know what personal information we collect, delete personal information, and opt out of the sale of personal information (note: we do not sell personal information).

LGPD (Brazil)

Brazilian residents have rights under the Lei Geral de Proteção de Dados, including the right to access, correct, and delete personal data, and to be informed about data sharing. We rely on standard contractual clauses for international transfers. Explicit consent is obtained where required.

South Korea (PIPA)

Users in South Korea have rights under the Personal Information Protection Act. We have appointed a domestic representative in accordance with Article 31-2 of PIPA to handle inquiries related to data protection.

Canada (PIPEDA)

Canadian residents have rights under the Personal Information Protection and Electronic Documents Act. We obtain explicit consent for the collection and use of personal information. Data may be transferred to the United States for processing.

Other Jurisdictions

We respect privacy rights in all jurisdictions where we operate and will comply with applicable local privacy laws and regulations.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will:

  • Update the "Last updated" date at the top of this policy
  • Notify you via email for material changes at least 30 days in advance
  • Provide prominent notice in our app for significant changes
  • Give you the opportunity to review changes before they take effect

We recommend reviewing this policy periodically. We will notify you of material changes in accordance with the procedures described above.

Contact Information

For questions, concerns, or requests regarding this Privacy Policy, please contact us:

Data Controller (US): Zinley, [Company Address], San Francisco, CA

Data Controller (EU/UK): Zinley Ireland Limited, Dublin, Ireland

Company Website: zinley.com

Privacy Team: privacy@meetorion.app

Data Protection Officer: dpo@meetorion.app

General Support: support@meetorion.app

We will respond to all inquiries within 30 days of receipt.

It learns your work.

Your words. Your world.

Product

DownloadPricingChangelog

Resources

NewsUse CasesUsage & LimitsAboutSecurity
Orion
© 2026 Zinley, Inc.
TermsPrivacyXDiscordReddit