Privacy Policy

How Ormind collects, uses, and protects your data — in plain language.

Last updated: August 30, 2026

1. Who we are

Ormind is an AI platform that answers your questions by researching, generating, and running code, and delivers results as interactive documents you can refine and share. It is available on the web at chat.ormind.ai and as a mobile app.

Ormind is the data controller for the personal data described in this policy. You can reach us at contact@ormind.ai.

2. Data we collect

Account information

When you sign up or sign in, our authentication provider (Auth0, an Okta company) shares with us your email address, name, and profile picture (when available from your chosen sign-in method). We do not receive or store your password.

Content you provide

  • Conversations — the messages you exchange with the AI, and the AI's answers.
  • Files — documents, images, and data you upload or drop into a workspace.
  • Workspace content — pages, notes, deliverables, and journal entries created in shared workspaces.
  • API keys you add — see section 5.

Technical and usage data

  • Server logs — standard technical logs (such as IP address, timestamps, and requested pages) kept for security and troubleshooting.
  • Product analytics — a first-party log of key product events (for example: sign-up, document created, document shared). This stays on our own servers; we do not use third-party advertising trackers.
  • Device tokens — if you enable push notifications, the device token needed to deliver them.

3. How we use your data

  • To provide the service: answer your questions, run your requests, store your conversations and files so you can come back to them.
  • To operate shared workspaces: show members the content and activity they are entitled to see.
  • To secure the service: detect abuse, enforce rate limits, investigate incidents.
  • To improve the product: understand which features are used, through our own analytics.
  • To communicate with you: transactional emails such as workspace invitations and notifications you asked for.

We do not sell your personal data, and we do not use your content for advertising.

4. Third-party AI processing

The short version: when you send a message, the content needed to answer it — your message, relevant conversation history, and any files you attach — is transmitted to the AI model provider you selected, so that their model can generate the answer. Ormind asks for your explicit consent before the first time this happens.

Ormind connects to large language models operated by third parties. Depending on the model you pick, your content may be processed by providers such as:

ProviderModelsPrivacy policy
AnthropicClaudeanthropic.com/privacy
OpenAIGPTopenai.com/policies/privacy-policy
GoogleGeminipolicies.google.com/privacy
Mistral AIMistralmistral.ai/terms
Groqhosted open modelsgroq.com/privacy-policy
DeepSeekDeepSeekdeepseek.com
Z.aiGLMz.ai

The exact list of available models is shown in the model picker inside the product. We access these providers through their API (business) endpoints; the major providers state in their API terms that content submitted through the API is not used to train their models. Each provider processes data under its own terms and privacy policy, linked above.

If you decline consent, you can still browse your existing workspaces and files, but messages cannot be sent to third-party models.

5. Your own API keys (BYOK)

You may add your own API keys for supported model providers ("bring your own key"). These keys are:

  • encrypted at rest on our servers;
  • never displayed back — the interface shows only the last four characters;
  • used solely to call the corresponding provider on your behalf, and deleted when you remove them or delete your account.

6. Code execution

Some answers involve generating and running code. That code runs in isolated containers on our own servers, separated per user. Files produced by these runs are stored in your session or workspace like any other content you create.

7. Shared workspaces & public links

  • Workspace members — content in a shared workspace is visible to its members according to their role. Actions in a workspace are recorded in the workspace journal, attributed to the member who performed them.
  • Invitations — when you invite someone, we send them an email with your name and the workspace name.
  • Public links — if you create a public link to a document, anyone with the link can view that document. You can revoke a public link at any time.

8. Service providers

We rely on a small number of processors to run Ormind:

  • Auth0 (Okta) — authentication and account sign-in.
  • AI model providers — listed in section 4.
  • Stripe — payment processing for paid plans. Card details go directly to Stripe; we never see or store your full card number.
  • Brevo — delivery of transactional emails (invitations, notifications).
  • Apple / Google — delivery of push notifications to your device (APNs, Firebase Cloud Messaging).
  • Hosting providers — the servers our infrastructure runs on.

9. Notifications & email

We send transactional messages — workspace invitations, activity you subscribed to, and delivery of results you asked for — by push notification (if enabled on your device) and email. You can disable push notifications in your device settings at any time. We do not send marketing emails without your consent.

10. Data retention

We keep your data for as long as your account is active, so your conversations, files, and workspaces remain available to you. Server logs and analytics events are kept only as long as needed for security and product operation.

11. Deleting your account

You can delete your account directly in the app (Settings → Delete account) or by emailing contact@ormind.ai. Deletion removes your account, your conversations, your files, and your stored API keys. Content you contributed to workspaces shared with other people may remain visible to those members, no longer linked to an active account.

12. Security

  • All traffic is encrypted in transit (HTTPS).
  • Authentication is delegated to Auth0; we never handle your password.
  • API keys you add are encrypted at rest.
  • Code execution is isolated in per-user containers.
  • Access to workspace content is enforced by per-member access control on every request.

13. Your rights

Depending on where you live (including under the GDPR if you are in the European Economic Area), you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data;
  • delete your data (see section 11);
  • export your content — workspaces can be exported from within the product;
  • object to or restrict certain processing.

To exercise any of these rights, contact contact@ormind.ai. You also have the right to lodge a complaint with your local data protection authority.

14. Children

Ormind is not directed at children. You must be at least 18 years old, or have the consent of a parent or guardian, to use the service. We do not knowingly collect personal data from children under 13; if you believe a child has provided us data, contact us and we will delete it.

15. Changes to this policy

We may update this policy as the product evolves. Material changes will be announced on this page (and by email or in-app notice when appropriate). The "Last updated" date at the top always reflects the current version.

Questions about your data?

We answer privacy questions directly — no forms, no runaround.

contact@ormind.ai