Privacy Policy — the Ori app
Ori is a self-development app that turns a goal into a roadmap and daily sessions, and plans them around your day. This page says what data the app keeps, why, and how to get it removed. It is written for the closed test phase; it will be revised before a public launch. The website's waitlist has its own page.
Who is responsible
Ori is operated by its founder, Damian K., Czech Republic. Contact: oriapp.eu@gmail.com.
What we store
- Account: your email address and a hashed password, handled by Supabase Auth. We never see your password. If you sign in with Google, Ori receives only your name, email address and profile picture.
- Your content: the goals, milestones, sessions, habits, tasks and feedback you enter in the app.
- What Ori remembers: for each goal, a short summary (at most 800 characters) of what you told Ori when setting it up — why it matters to you, your constraints and your level. It is shown to you on the goal's Roadmap, where you can edit or delete it, and it is sent with that goal's AI requests.
- AI usage log: for each AI request, which feature made it, the model used, token counts, cost, timing and whether it succeeded. The log does not contain the text of your goals or answers.
- Google Calendar (only if you connect it): see Google user data below.
Who processes it for us
- Supabase (EU region) stores the database and handles sign-in.
- Anthropic receives the text of your goals, their summary and your feedback to generate your roadmap and sessions. Anthropic does not use API data to train its models. Nothing received from Google Calendar is sent to Anthropic.
- YouTube Data API receives only search keywords for session resources, never anything about you.
- Render and Vercel host the backend and the web app.
We do not sell data, show ads, or share your data with anyone else.
Google user data
Connecting Google Calendar is optional. When you connect it, Ori asks Google for three permissions and uses each for one thing only:
- See the list of your calendars (
calendar.calendarlist.readonly) — so you can choose which calendars Ori should respect. - View events on your calendars (
calendar.events.readonly) — Ori reads the times of events on the calendars you chose, so it never plans a session over something you already have. Event titles are shown only to you, in your own schedule; in the history Ori keeps of past days, an event is recorded only as a busy time, without its title. - Create and change events on calendars you own (
calendar.events.owned) — while your calendar is connected, Ori adds your planned sessions to it as events marked “[Ori]”, and updates or removes those events when your plan changes. Ori never changes or deletes an event it did not create.
To stay connected, Ori stores the access token Google issues, and which calendars you chose, in its database. Calendar data is not sold, not used for advertising, not used to train AI models, not sent to AI services, and not shared with anyone.
Ori's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Calendar in the app at any time (Profile → Integrations). Disconnecting revokes Ori's access at Google and deletes the stored token; you can choose to remove upcoming [Ori] events at the same time. You can also revoke access at myaccount.google.com/permissions.
Retention and deletion
Your data stays as long as your account exists. During the test phase the database may be reset between rounds; testers are told beforehand.
You can delete your account and everything linked to it yourself, in the app: Profile → Privacy & Security → Delete my account. Deleting also revokes Ori's access to your Google Calendar. If you cannot sign in, email oriapp.eu@gmail.com from the address you signed up with; deletion is then done within 14 days.
Your rights
Under the GDPR you can ask for a copy of your data, a correction, or deletion. You can download a copy yourself in the app (Profile → Privacy & Security → Export my data), or use the email above.