Privacy Policy
Last updated: September 30, 2026
1. Who we are
Orqanova is operated by Vladimir Maslov, an independent developer based in the Republic of Moldova — a private individual, not a company. The service has no legal entity. In this document, “we” and “the operator” mean this developer. Contact for any data question: hello@orqanova.com.
2. Data we collect
Account
- email address (the only mandatory personal data) and its normalized form, used so one person cannot create several accounts through “plus-addresses”;
- password — only as a hash (PBKDF2-SHA256); we do not store it in plain text;
- interface language, workspace name (entered by you), and a referral code if you arrived through an invitation;
- one-time verification codes and email link tokens — stored only as hashes, with a limited lifetime.
We do not ask for your first or last name, phone number, date of birth, gender, country or avatar at sign-up.
Your content
Everything you upload or create in the service: photos (including photos of people), documents, brand memory texts, scripts and lines, constructor projects, generated frames, voice-overs, videos and finished reels. We extract text from uploaded documents, and for images you bring we build a text description with a model so they can be searched.
Payments
Payments are accepted in cryptocurrency only, through Cryptomus. We store the amount, status and service fields of the invoice, plus the payment system’s full notification — it may contain a wallet address and a transaction ID. We have no bank card data and cannot receive any. We also keep a ledger of credit debits and top-ups and a log of AI model usage (identifiers, model and amounts only, without generation content).
“Report a problem” submissions
Only when you press the button yourself, we save: your message, the screen address, the error text, the window size, your browser User-Agent, the browser log for the last 15 minutes (screen changes and failed requests only, without the contents of your fields) and a screenshot. The screenshot may contain anything that was open on your screen.
Technical logs
The server writes a request log: method, route template, response code, duration and internal identifiers. We do not write visitor IP addresses, User-Agent, email addresses, your prompts or generated texts to the logs, and we do not determine geolocation.
3. Cookies and local storage
The app sets no cookies of its own. Sign-in works with an access token kept in the browser’s local storage (localStorage). Technical interface data is stored there as well: the list of your constructor projects, IDs of tasks still running (so they survive a page refresh), the canvas background and favorite music tracks. All of this is needed for the app to work, and the token is removed when you sign out.
The landing page has no analytics or trackers. The only external resource is Google Fonts: when the page opens, your browser contacts Google servers, which receive the visitor’s IP address.
4. Who we share data with
To provide features, we send data to external services. Access keys to them are stored encrypted on our side.
- OpenRouter and OpenAI — texts and prompts, brand memory fragments, scripts, texts for memory search, reference images for image and video generation, images for automatic description;
- Groq or another OpenAI-compatible speech-recognition service — whole audio files (voice-overs, reel audio tracks);
- fal.ai — frames and photos (uploaded to fal.ai’s CDN) and audio for video generation and lip-sync;
- HeyGen — a video or frame with a face, plus audio, for lip-sync;
- ElevenLabs — line texts for speech synthesis. We do not clone your voice;
- Pexels and Jamendo — search queries (keywords) to find stock video and music;
- Resend — your email address and the email text (verification code, support reply);
- Cryptomus — only the amount, our order number and return addresses. Your email, name and account ID are not sent;
- Bright Data and ScrapeCreators — links and handles of other people’s accounts and videos, to obtain public data (see section 6). No data of our users is sent there;
- Yandex Object Storage (region ru-central1) — storage of backups and logs (see section 7);
- Google Fonts — landing page fonts (see section 3).
The application, database, job queue and file storage run on our own server, not in a third-party cloud. Backups and logs are stored in Yandex Object Storage (see below).
Backups and logs are stored in Yandex Object Storage, so your data may be transferred outside your country of residence.
5. Face photos and generative models
Yes. Photos of people that you upload (for example, a character reference photo) are sent to generative models — this is the basis of the character creation feature. Recipients of such a photo:
- OpenRouter — the photo is passed by link as a reference for image generation (models currently enabled in the service);
- fal.ai — the photo is physically uploaded to their CDN and passed as a reference or the first frame of a video;
- HeyGen — a frame with a face plus audio, for lip-sync;
- a description model via OpenRouter — a photo that you brought is sent in the request for an automatic text description. Images generated by the service itself are not sent for description.
Upload only photos of people whom you have the right and the depicted person’s consent to use (see the Terms of Service).
6. Data about competitors and other third parties
The service lets you add public accounts of competitors and your own, and study their publications. This is data about people who are not our users. How it works:
- collection starts only on an action by our user who specified the account; there is no background crawling without a request;
- data is obtained from a provider (Bright Data, and ScrapeCreators) and is publicly available data;
- for a profile we save: account handle, follower and post counts, an avatar link (we do not copy the file), the profile description text, and the verified flag;
- for publications: link, date, caption and hashtags, metrics (views, likes, comments, shares, saves), and a transcript of the speech in the video;
- comment texts together with commenter names are collected only on a separate, explicit command by the user (“What worked for the audience”);
- we do not copy other people’s video or audio: only temporary platform links are kept, which stop working after a few hours. We keep our own copy only of the cover image and of key frames extracted during video analysis;
- on-screen text, a transcript and an analytical breakdown (generated by a model) are also produced from a video;
- the data is visible only to the workspace that requested it;
- there is no automatic retention period: data lives until the user deletes the competitor or the analysis, or their own account. Deleting a competitor also deletes related files in storage.
If you are the owner of an account, or a comment is yours, and you want us to delete such data, write to hello@orqanova.com naming the account or link — details on the Data Deletion page. We respond to such requests within 30 days.
7. Where and for how long we keep data
- Database and files (photos, reels, voice-overs, screenshots from reports): on our server. There is no automatic deletion period — data is kept until you delete it. Deleting an account removes database records immediately; media files and backups may remain and are deleted on request (see section 9).
- Technical logs: 30 days, then deleted automatically. Stored in Yandex Object Storage. They contain internal user and workspace identifiers, but no email addresses or content.
- Database backups are made every 3 hours and kept in Yandex Object Storage for 30 days.
- Media file backups are kept in Yandex Object Storage without a time limit.
- Financial records (credit ledger, payments, AI usage log) are kept after account deletion, detached from you — see section 9. We keep them as long as needed for accounting and for investigating disputed charges; there is no fixed period.
8. Security and staff access
- passwords and verification codes are stored as hashes; access keys to external services are stored encrypted;
- files are accessed through temporary signed links; the storage is not public;
- sign-in, sign-up, account deletion and invoice creation are rate-limited;
- staff sign-in to the admin panel requires a password and a one-time code sent by email.
The service is run by one person. The operator’s admin panel can technically view the contents of workspaces (for example, brand memory and reports with screenshots), but content is accessed only for support and investigating incidents. Part of this access (viewing brand memory, money movements) is recorded in an operator action log; viewing reports with screenshots is not yet recorded there.
9. Data deletion
You can delete your account yourself: the service sends a confirmation code to the account’s email address, and after you enter it everything is deleted immediately, with no grace period. Deleted with the account: workspaces and everything in them — brands, brand memory and its search vectors, characters, locations, constructor projects, campaigns and runs, the wallet, data about competitors and tracked accounts, and the access token. You can also request deletion by email — we respond within 30 days; see Data Deletion.
What remains after account deletion:
- financial history: credit ledger entries, payments (including the payment system’s notification with a wallet address and transaction ID), and the AI usage log — detached from your account;
- “Report a problem” submissions: text, User-Agent, browser log and screenshot are kept, detached from the account;
- records of operator actions;
- technical logs — up to 30 days, database backups — up to 30 days, media backups — see section 7;
- media files in storage: database records are deleted immediately, but uploaded media files (photos, reels, voice-overs) may remain in file storage and are deleted on request through Data Deletion; database backups are rotated within 30 days, media backups have no time limit and are also deleted on request.
The service has no self-service export of your data. On request by email to hello@orqanova.com we will provide a copy of your data within 30 days.
10. Age
The service is intended for people aged 18 and over. It is not intended for anyone under 18, and we do not knowingly collect data of children. The service does not verify age at sign-up; if we learn that an account belongs to a person under 18, we will delete it.
11. Connecting social networks
You can connect social network accounts for publishing. The account is connected through the platform’s own consent window. The access credential is held by our publishing partner, Post for Me, not by us; we store the account identifier and the expiry of the access. You can disconnect publishing or remove the account in the “Publishing” section of the app, and the permission is then revoked on the platform side as well.
12. Changes and contact
We may update this policy; the current version is always on this page, with the last-updated date at the top. Questions about data: hello@orqanova.com.