Privacy Policy
Last updated: September 2026
1. Information we collect
We collect the information you provide directly: name, email, optional profile photo, timezone, preferred language, and all the content you create inside the platform (projects, tasks, comments, wikis, time entries).
2. How we use your information
We use your information to operate the service, authenticate you, send operational notifications (deadline reminders, assignments, configurable digests), and protect the platform from abuse. We do not use it for ad profiling and we do not share it with ad networks.
3. Storage and security
Your data is stored on our own servers, hosted in France (European Union). Passwords are hashed with bcrypt; refresh tokens are rotated with compromise detection. All connections use TLS 1.2+. Sensitive tokens (API keys, SCIM) are stored only as SHA-256 hashes.
4. Data sharing
We do not sell your personal information. We share it with third parties only when strictly necessary to operate the service:
- Hosting: Contabo GmbH, which operates the server everything above lives on, in France.
- Email: Resend receives your address and the contents of the email we send you — verification, invitations, password resets and notices.
- Error diagnostics: Sentry receives server errors together with the context of the request that failed, which includes your account identifier and your IP address. Processed in Germany.
- Push notifications: Firebase Cloud Messaging (Google) receives the device token and the notification payload.
- Optional integrations: Slack, GitHub, Microsoft Teams, Google Calendar — only when you or your organization admin enables them. What Google lets us see, and what we do with it, is section 5.
- SSO/SAML: your corporate Identity Provider, only if your organization configures SSO.
5. Google user data
Orkestra uses two Google services, and neither turns itself on: both start when you connect them.
Sign in with Google
The "Continue with Google" button asks for openid email profile. We receive your email address, whether Google holds it as verified, your name and the address of your photo. With that we recognise your account or create it: the email becomes your identifier, and the name and photo fill in your profile, which you can change afterwards. We ask for no ongoing access and store no credential from that permission, so once you are in there is no door left open into your Google account.
Google Calendar sync
How we access it. We ask for a single permission, calendar.app.created, which reaches only the calendars this application created. Your existing calendars and appointments are not kept safe by a promise of ours: they are unreachable for Orkestra. On connecting we create a calendar of our own in your account, named "Orkestra", and work only inside it.
How we use it. We write your tasks, your assigned subtasks and your activities there — the name, the date, the time and one reminder. Every fifteen minutes we read that same calendar to see whether you changed something, and from what we read we take two things and no others: when it is, and what it is called. An event Orkestra did not write is ignored rather than adopted. None of this is used for advertising, for profiling you, or to train artificial-intelligence models, ours or anyone else's.
What we store. The credential that lets us keep writing, the identifier of the calendar we created, and for each event we wrote its identifier and its start date, so we know which task it belongs to. All of it lives on the same server in France as the rest of your data. We store the contents of no event we did not write ourselves.
Who we share it with. Nobody. No data received from Google is sold, handed over or transferred to another service.
How you delete it. Disconnecting the calendar in Settings → Calendar deletes the credential and the links between events and tasks. The "Orkestra" calendar stays in your Google account, which is yours: you keep it or delete it. You can also withdraw the permission at myaccount.google.com/permissions. Deleting your Orkestra account removes all of the above.
Limited Use
Orkestra's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Your rights
You can access, correct, or delete your information at any time from your account settings. To exercise GDPR rights (access, portability, erasure, rectification) write to us at privacy@orkestra.team.
7. Retention
We retain your information while your account is active. When you delete your account, personal data is removed or anonymized as appropriate. Organization administrators may configure additional retention policies for tasks, comments and audit logs.
8. Contact
For privacy inquiries, write to us at privacy@orkestra.team.