// Legal

Privacy Policy

Last Updated: September 16, 2026

1. Information We Collect

We collect information that you provide directly to us, such as when you create an account, connect your Git repository, or contact our support team.

2. How We Use Your Data

The primary purpose of data collection is to power our AI orchestration engine. We process your repository metadata to build the Context Map necessary for automated tasks.

3. Security

We implement industry-standard security measures to protect your data, including encryption at rest and in transit.

4. Telemetry from the IDE extension

The Orkestra AI extension for VS Code, Cursor, Windsurf and compatible IDEs sends usage telemetry only when both of these are true: your IDE's telemetry.telemetryLevel is set to all, and the extension's orkestra.ai.shareTelemetry setting is on. Turning either one off stops all telemetry immediately — the IDE setting wins over ours.

That setting previously shipped off and had no effect in code; from the next published version it ships on, and the extension's changelog says so.

What we collect while telemetry is on:

  • Daily usage — which account used the extension on a given day, the extension version, the IDE name and the operating system.
  • Workflow steps — which steps of the automated workflow and of the first-run setup ran and how they ended, other product events (signing in, hitting a plan limit, an error on a call to our API), and a random identifier for the installation, drawn on your machine. That identifier is not derived from your name, your e-mail or your hardware; it is generated at random and kept in your IDE's secret storage.
  • Failures — the error message and the execution log of the run that failed. Before it leaves your machine we remove the executed command line and redact fields whose name looks like a credential; the remaining text can still contain file paths, the task title and whatever the agent printed to its output.
  • Internal diagnostics — only for accounts our server explicitly authorizes: a hashed workspace identifier, the project folder name, the repository name when the folder has a git remote, the address (without query string) of the requests the extension makes, the platform and the Node version.

What we never collect: the contents of your files, or your provider API keys. The extension does not read your files in order to send them anywhere.