Privacy Policy.
Last updated August 28, 2026
Who we are
Orchestra Code ("Orchestra", "we", "us") is an AI code change platform available on the web and as a mobile app for iOS and Android. This policy explains what we collect, why, and the choices you have. It applies to the Orchestra Code mobile app and to orchestracode.com.
What we collect, and how
Account information. Collected when you create an account or sign in: your email address, a password you choose or the basic profile details (name, avatar) your sign-in provider returns, for example GitHub. We use a user identifier to keep accounts and workspaces separate. Used to authenticate you, run your workspace, and contact you about the service.
Your content. Collected when you start or continue a task: the prompts you type or dictate, and the code in the repositories you connect, which the agent clones onto the cloud machine for your account. Used to run the coding agent and to show you the chat, diff, preview, and pull request.
Images you attach. Collected only when you pick a photo for a task. We access your photo library at that moment and nowhere else. Used as part of that task.
Voice input. Collected when you hold the microphone button. Speech is transcribed by your device operating system speech service, and Orchestra receives only the resulting text, which becomes your prompt. We do not receive or store audio recordings.
Credentials you connect. Collected when you add an AI provider key or connect GitHub or Bitbucket. Stored encrypted, never displayed back, and used only to run your tasks against your own accounts.
Diagnostics. Collected automatically as your tasks run: timestamps, machine hours used, and error logs. Used for billing your plan allowance, security, and debugging.
Purchases. Collected from Apple, Google, or Stripe when you buy a subscription: the purchase status and plan. Used to unlock your plan. We never receive your full payment card details.
How we use your information
- To run AI coding agents and produce code changes, diffs, previews, and pull requests.
- To operate your account, workspaces, and subscriptions.
- To keep the service secure and to debug and improve reliability.
- To respond to your support requests.
We do not sell your personal data, and we do not use your code to train our own models.
Third-party AI providers
What is sent. When you start or continue a task, your prompt, your follow-up chat messages, any image you attached, and the files from the connected repository that the agent needs to read or change are sent to an AI provider. Nothing is sent to a provider until you start a task.
Who it is sent to. Only the provider you connect, and only that one: Anthropic (Claude), OpenAI (the API, or your ChatGPT subscription), or OpenRouter, which routes to the open-weight model you pick. Orchestra is bring your own key: the request runs on your own account with that provider and is billed to you at their price. We do not add an AI provider of our own on top, and we do not send your content to any AI service you have not connected.
Your permission. Before your first task, the app shows this disclosure and asks you to agree. You can read it again and withdraw your agreement at any time in Settings, under Data and AI processing. If you withdraw it, tasks stop running and nothing further is sent.
How they handle it. Each provider processes the request under its own terms. We only use providers whose terms commit to protection equivalent to this policy: processing the content to serve your request, not training their models on it by default, and applying encryption in transit and comparable security. Their terms are at anthropic.com, openai.com, and openrouter.ai. If you use your own key, the retention that applies is the one on your own provider account.
Git hosting
When you connect GitHub or Bitbucket, Orchestra acts on your behalf to clone repositories, create branches, push commits, and open pull requests. We use the access you grant only to perform the tasks you start.
Data sharing
We share data only with the service providers needed to run Orchestra: Fly.io (the cloud machines your code is checked out on), the AI provider you connected, the Git host you connected (GitHub or Bitbucket), and Apple, Google, or Stripe for purchases. Each acts under its own agreement, only to provide the service, and under terms we consider to give your data protection equivalent to this policy. We do not sell your personal data and we do not share it for advertising.
Data retention and deletion
We keep your account data and task history for as long as your account is active. You can delete your account at any time from Settings, which removes your account data. To request deletion or ask a privacy question, contact us at the email below.
Security
We use encryption in transit and at rest for sensitive data, including API keys. No system is perfectly secure, but we work to protect your information and limit access to it.
Children
Orchestra Code is not directed to children under 13, and we do not knowingly collect their data.
Changes to this policy
We may update this policy from time to time. We will revise the date at the top when we do.
Contact
Questions about this policy or your data? Email privacy@orchestracode.com.