Privacy Policy
Effective: 1 October 2026.
ORDAX is a capability platform that connects an authorized client to devices and scopes the user explicitly connects.
Data processed
- Account and authentication data: authentication identifiers required to verify the connected ORDAX account. Authentication is currently provided by Supabase Auth; passwords are handled by the identity provider and are not stored by the ORDAX Control Plane.
- Device and authorization data: device identifiers and names, project or Space scopes, grants, allowed actions and connection state needed to route authorized requests.
- Requested capability data: file contents, Git information, Computer Control results, adapter metadata, command results or artifacts only when an authorized tool is invoked for that data.
- Operational and audit data: action names, scope, request/status identifiers, authorization decisions, execution status and timestamps needed for security, reliability and abuse investigation.
How data is used
Data is used to authenticate connections, enforce grants, route tool calls to the selected device, return requested results, maintain reliability and provide security/audit controls. ORDAX does not request the full conversation history of an external AI client.
Infrastructure
The remote Control Plane uses Cloudflare services for compute and storage. Account authentication currently uses Supabase Auth. Local project/device data remains on the user's device unless an authorized tool invocation requires selected data or an artifact to transit the Control Plane to fulfill the request.
Sharing and sale
ORDAX does not sell personal data. Data is shared with infrastructure providers only as needed to operate the service or when required by law.
Retention
- OAuth credentials: ORDAX verifies bearer tokens for requests but does not persist the user's OAuth access token in the Control Plane. Authentication records held by the identity provider follow the account lifecycle and the provider's applicable policy.
- Temporary Product artifacts: signed download links expire after 1 hour. Artifact bytes and their Product metadata are retained for no more than 7 days, then the daily retention process deletes both the Cloudflare R2 object and its D1 record.
- Product action and audit history: completed action records, request metadata and audit entries are retained for no more than 30 days for reliability, security and abuse investigation.
- Device pairings: pairing secrets expire and expired pairing records are deleted by the next daily retention cycle.
- Device links and grants: active links and grants remain while the user keeps them active. Revoked or expired authorization metadata is retained for no more than 30 days after it becomes inactive, once no retained action history depends on it.
These retention periods apply to the ORDAX Product/MCP service. Files that remain only on the user's computer are not copied to the Control Plane unless an authorized tool request needs selected content or an artifact to fulfill that request.
User control
Users can stop the local Runtime, revoke device/scope grants, disconnect a provider connector and remove installed software. Access is designed to fail closed when authentication or grants are missing. Retained Product metadata can also be addressed through the support channel.
Security
Device credentials are scoped separately from user authentication. Remote actions are checked against explicit device, scope and action grants plus local policy where applicable. Do not place secrets in prompts or project files unless necessary for the task.
Questions about this policy can be raised through the support page.