Privacy Policy
This policy describes personal information handled by the operator of OrcaRender at orcarender.com ("OrcaRender", "we", "us") when you use our website, studio, rendering APIs, or support channels. For privacy and deletion requests, contact support@orcarender.com.
1. Information we handle
- Account and access: email address, account identifiers, password hashes, authentication/session information, API credential records, and subscription or credit balances.
- Rendering content: prompts, uploaded or referenced images and videos, reference URLs, generated outputs, revisions, agent conversations, job settings, and execution or quality-review metadata.
- Billing and support: payment-provider identifiers, checkout and subscription status, usage receipts, transaction records, and information you send when contacting us. Payment card details are submitted to the payment processor, not to the rendering API.
- Operational information: request times, IP addresses and request metadata in service/access logs, error reports, device/browser information supplied in requests, and security or abuse-related records. Do not put passwords or API keys in prompts or URLs.
2. Purposes and legal bases
We use this information to authenticate accounts, execute and deliver requests, manage queues and storage, process billing, provide support, diagnose failures, secure the service, address abuse, and comply with legal obligations. We may use aggregate operational statistics to understand reliability and capacity; that is distinct from training a model on your content.
Where data-protection law requires a legal basis, we rely on performing our agreement with you, legitimate interests in operating and protecting the service subject to your rights, compliance with legal obligations, or consent where required. For content processed for a business customer, that customer determines its purposes; contact the customer as well if it submitted information about you. We handle our own account, billing, and security records separately.
3. Model training and content access
OrcaRender does not use customer prompts, input media, or outputs to train or fine-tune its own general-purpose models. Our rendering service performs inference. Customer content is not licensed to us for sale as a training dataset. Any separate training use would require a separate, explicit agreement.
Content may be processed by render hosts, automated planning/quality tools, and authorized personnel for delivery, support, troubleshooting, safety, or legal needs. Agent-assisted planning, opening-image generation, and revision features may send relevant instructions and reference content to external AI services, including OpenAI. Those services have their own processing and retention terms; this policy does not assert that every upstream service has zero retention.
4. Sharing and service providers
We share information as needed with compute/storage and hosting providers, payment processing services such as Stripe, transactional email services such as Mailgun, and AI services used by the requested feature. When you provide a media URL, our retrieval may disclose the requested URL and the service's network address to that source. A callback sends operation information to the endpoint you configure.
If you access OrcaRender through OpenRouter or another integrating application, that intermediary also receives and handles information under its own policies. We may disclose information when required by law, to investigate fraud or abuse, to protect people or the service, or in a business transfer subject to applicable protections. We do not sell customer rendering content or use it for targeted advertising.
5. Retention and deletion
See the Data Policy for the distinction between media, job records, logs, and backups. Integration/API result availability normally expires 24 hours after a job finishes unless a different retention period is configured for the integration. Studio projects do not have that blanket 24-hour expiration.
Prompts, job/agent histories, account records, usage receipts, and operational logs can remain after media expires. There is currently no single automatic fixed deletion deadline across those records and backups. We retain them for service operation, account history, security, billing, and legal needs and review deletion requests individually. Backup copies and files retained by dependent jobs may not disappear immediately after a deletion request.
6. Cookies, security, and locations
We use session and security cookies needed for login and request protection. You can control cookies in your browser, but disabling them may prevent account features from working. Our delivery provider Cloudflare supplies a performance-analytics script, including on these policy pages. The policies and contact links remain readable without JavaScript. We do not use customer rendering content for targeted advertising.
We use access controls, credential hashing where applicable, private asset authorization, and encrypted public connections. No service can guarantee complete security. Processing can involve remote render hosts and external service providers; no particular processing country or data-residency guarantee is included unless separately agreed. Ask us about locations and any required transfer arrangements before submitting location-restricted data.
7. Your choices and rights
You can manage available project/media deletion controls and revoke API credentials in the service. Contact support@orcarender.com for access, correction, account deletion, or other privacy requests. Include an account email or request identifier, never a password or API key. We may verify your identity and retain records where needed for legal obligations, security, or unresolved transactions.
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy, withdraw consent, or complain to a data-protection authority. We will handle applicable requests within the deadlines required by law. These rights are not limited by this policy.
8. Eligibility and updates
The service is intended for adults aged 18 or older who can enter an agreement. Do not submit children's personal information or sensitive regulated data without an appropriate, separately agreed arrangement. Contact us if you believe a child has supplied personal information.
We may update this policy as the service changes. We will update its effective date and provide additional notice where required. Material new uses requiring consent will not be authorized merely by silently changing this page.