Privacy Policy

Effective: 1 October 2026.

ORDAX is a capability platform that connects an authorized client to devices and scopes the user explicitly connects.

Data processed

How data is used

Data is used to authenticate connections, enforce grants, route tool calls to the selected device, return requested results, maintain reliability and provide security/audit controls. ORDAX does not request the full conversation history of an external AI client.

Infrastructure

The remote Control Plane uses Cloudflare services for compute and storage. Account authentication currently uses Supabase Auth. Local project/device data remains on the user's device unless an authorized tool invocation requires selected data or an artifact to transit the Control Plane to fulfill the request.

Sharing and sale

ORDAX does not sell personal data. Data is shared with infrastructure providers only as needed to operate the service or when required by law.

Retention

These retention periods apply to the ORDAX Product/MCP service. Files that remain only on the user's computer are not copied to the Control Plane unless an authorized tool request needs selected content or an artifact to fulfill that request.

User control

Users can stop the local Runtime, revoke device/scope grants, disconnect a provider connector and remove installed software. Access is designed to fail closed when authentication or grants are missing. Retained Product metadata can also be addressed through the support channel.

Security

Device credentials are scoped separately from user authentication. Remote actions are checked against explicit device, scope and action grants plus local policy where applicable. Do not place secrets in prompts or project files unless necessary for the task.

Questions about this policy can be raised through the support page.