Legal

Privacy.

This policy explains what Orastack collects, why we use it, and the boundaries between account data, service telemetry, and the customer application data our realtime platform processes.

Private beta policy · Updated September 24, 2026

Scope

This policy applies to the Orastack website, console, APIs, SDK-connected realtime service, CLI, and support interactions. It does not govern the applications our customers build or the privacy choices those applications make.

Data we collect

Account data. We process contact details, organization membership, roles, project configuration, authentication records, and support communications.

Service data. We process API requests, connection metadata, scope identifiers, user identifiers supplied by customers, usage records, errors, delivery lifecycle telemetry, security events, and device or network information needed to operate the service.

Customer application data. Depending on customer use, event payloads, state values, signal data, and presence metadata may pass through or be retained by Orastack under the configured semantics and retention.

Billing data. Our payment provider processes payment methods. Orastack receives customer, subscription, invoice, and payment-status records rather than full card details.

How we use data

  • Provide, secure, monitor, support, and improve the service.
  • Authenticate operators and realtime clients and enforce scoped authorization.
  • Recover reliable events, synchronize state, route live traffic, and diagnose failures.
  • Meter usage, administer plans, prevent abuse, and reconcile billing.
  • Communicate about account, security, product, and legal changes.
  • Comply with law and protect Orastack, customers, users, and the public.

Customer roles

Customers determine what application data they send, which users receive it, and the lawful basis for that processing. For customer application data, Orastack acts as a service provider or processor on the customer's instructions. Customers remain responsible for their application's privacy notices and user requests.

Sharing

We do not sell customer application data. We may share data with infrastructure, authentication, database, email, payment, security, and support providers that help operate Orastack; with professional advisers; during a corporate transaction; or when legally required. Providers may include Cloudflare, Neon, Clerk, Render, Stripe, and Resend as the deployment evolves.

Retention

Retention depends on the data category and customer configuration. Reliable replay data expires under the applicable plan. Signals and presence are ephemeral. Operational traces are bounded separately from replay history. Account, security, usage, and billing records may remain longer where required for operations, fraud prevention, reconciliation, or law.

Security

We use project and environment isolation, default-deny grants, short-lived client tokens, non-recoverable server-key verification material, bounded payloads and queues, access controls, and monitoring. No service can guarantee absolute security. Please report suspected vulnerabilities to security@orastack.dev.

Your choices

Organization owners can manage team access, environments, credentials, retention, and project deletion through the service as those controls become available. To request access, correction, deletion, or another applicable privacy right, contact privacy@orastack.dev. We may need to verify the request and may retain records where legally required.

International use

Orastack may process data in the United States and other locations where our providers operate. Where required, we will use appropriate transfer mechanisms and offer additional contractual terms to eligible customers.

Children

Orastack is a developer infrastructure service for organizations and is not directed to children under 13. Customers are responsible for evaluating their own applications and users.

Changes

We may update this policy as the service and legal requirements evolve. We will update the date above and provide additional notice for material changes when appropriate.

Contact

Questions and privacy requests may be sent to privacy@orastack.dev.