Legal

Privacy Policy

Last updated July 13, 2026.

What we don't do

  • Sell your data to big companies
  • Use your data to promote other products to you
  • Claim ownership of any content you generate (including AI-generated visuals, Orshot API generated images, PDFs, or videos)

What we do

  • Use anonymized platform usage data to improve Orshot's features and performance. We do not use customer-generated content (templates, uploaded assets, rendered outputs, or workspace data) for AI training or model development.
  • When you use Orshot through agent integrations (like our MCP server), basic account and usage information is shared with our team internally to improve reliability and the product — never for advertising.

What kind of data do we store

  • Your name, email and basic details to keep your account secure
  • Your preferences, so we can customize your profile as you want
  • Your subscription details

Template Ownership

Orshot retains ownership of all platform templates. Users are granted a usage license but cannot claim copyright over the templates themselves. Reselling unmodified templates is prohibited.

Things we don't control

We use some services to operate some features and improve overall experience. These services are not related to Orshot and are separate entities.

When you use Orshot, you indirectly accept the Policies of below services.

  • Supabase, used as database to store some of user data
  • Pirsch Analytics, to track app usage metrics
  • Stripe, used for enabling monthly subscriptions in the app
  • Railway, used for application hosting
  • Vercel, used for website hosting
  • Cloudflare R2, used for file and asset storage
  • Slack, used for internal operational notifications (agent-integration telemetry)

Who we share data with

We do not sell your data, rent it, or share it with third parties for advertising. We share, transfer, or disclose your data only in these cases:

  • With the service providers listed above (Supabase, Stripe, Railway, Vercel, Cloudflare R2, Pirsch Analytics, Slack), strictly to host and operate Orshot. Each provider processes data on our behalf under its own security and privacy commitments.
  • With destinations you explicitly configure. If you set up a workflow or integration that sends a rendered file to your own storage, spreadsheet, or another connected app, we transfer that file to the destination you chose.
  • If required by law, legal process, or to protect the rights, safety, or security of Orshot and its users.

We never disclose your data to anyone else, and no category of your data is shared with data brokers or advertising networks.

Google user data

Orshot offers optional integrations with Google Drive, Google Sheets, and Google Forms. If you connect a Google account, we access only the data needed to run the features you configure:

  • Google Drive: we list the folders and files you select so your workflows can use them as a content source, read files from folders you choose (including new files added to those folders, when you set up a folder trigger), and upload rendered outputs to folders you pick.
  • Google Sheets: we read rows from spreadsheets you select to feed your workflows, and write results (such as render URLs) back to those spreadsheets when you configure it.
  • Google Forms: we read form questions and new responses from forms you select to trigger your workflows.

Google user data is used solely to provide these user-facing features. Files read from Google Drive for rendering are stored temporarily in our Cloudflare R2 storage and deleted automatically within 3 days. We do not use Google user data for advertising, do not sell it, do not use it to train AI or machine learning models, and no human at Orshot reads it except with your permission for support, for security purposes, or where required by law. Google user data is shared, transferred, or disclosed only as described in the "Who we share data with" section above, and never with any other party.

You can disconnect a Google integration at any time from your workspace settings, which revokes Orshot's access with Google and deletes the stored access tokens. You can also revoke access yourself from your Google Account security settings.

Orshot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect your data

  • All data is encrypted in transit using TLS (HTTPS) between your browser, our servers, and every connected service.
  • OAuth access tokens for connected integrations (including Google) are encrypted at rest with authenticated encryption before being stored, and are decrypted only at the moment a workflow or integration you configured needs them.
  • Sensitive data is accessible only to the systems that need it to run your workflows. Production database access is restricted and protected by row-level security, so each workspace can only access its own data.
  • Temporary copies of files processed for rendering are deleted automatically on a short retention schedule (3 days for files fetched from connected sources).
  • When you disconnect an integration or delete your account, the associated tokens and stored data are deleted.

GDPR & Data Protection

Orshot complies with the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR). We process personal data lawfully, fairly, and transparently.

Legal Basis for Processing: We process your personal data based on: (a) your consent, (b) performance of a contract with you, (c) compliance with legal obligations, or (d) our legitimate interests in operating and improving our services.

Your Rights: Under GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate personal data
  • Request erasure of your personal data
  • Restrict or object to processing of your data
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with a supervisory authority

Data Controller: Orshot is the data controller for the personal data we collect. For any data protection queries or to exercise your rights, please contact us at hi@orshot.com.

Data Processing Agreement: For institutional or enterprise customers requiring a Data Processing Agreement (DPA), please visit our DPA page or contact us at hi@orshot.com.