ORPECA LEGAL
Privacy Policy
Effective July 12, 2026
Orpeca is designed so that your trusted devices—not our service—hold the keys needed to read your documents.
1. Scope
This policy explains how the operator of Orpeca (“we,” “us,” or “our”) handles information when you use the mobile application, website, account service, encrypted sync, sharing, recovery, billing, and support features. It does not replace the privacy terms of Apple or another service you choose to use.
2. Information that stays on your device
Document contents, filenames, OCR text, extracted fields, classifications, search queries, folder and Packet contents, and the keys that decrypt them are processed and stored on trusted devices. When encrypted sync or sharing is enabled, our storage receives ciphertext and limited operational metadata, not the plaintext needed to understand your documents.
Automated extraction, classification, suggested folders, Packet readiness, search interpretation, and other generated results are produced to help you organize information. They may be inaccurate or incomplete. They are not used by us to make decisions about you.
3. Information we collect
- Account information: email address, password hash, verification and recovery status, account identifiers, and plan.
- Trusted-device and sharing information: device names, public keys, signed authorization records, invitations, roles, revocations, and opaque scope identifiers.
- Encrypted-storage metadata: ciphertext object identifiers, sizes, checksums, generations, quotas, and timestamps.
- Billing information: Apple product, transaction, subscription status, and account-binding identifiers. Apple handles payment-card details; we do not receive them.
- Service and security information: IP address, request timing, error and abuse-prevention records, and essential reliability counts. Optional detailed performance analytics are collected only when enabled in the app.
- Communications: information you send when asking for support, reporting a problem, or exercising a privacy right.
Our analytics rules forbid document content, filenames, OCR text, extracted values, prompts, search text, encryption keys, and decrypted metadata.
4. How we use information
We use the information above to:
- create and secure accounts and trusted-device relationships;
- coordinate encrypted sync, browser approval, and sharing;
- verify subscriptions and enforce plan limits;
- deliver verification, recovery, security, and invitation messages;
- operate, troubleshoot, protect, and improve the service; and
- comply with law and respond to valid legal requests.
We do not sell personal information or use it for third-party advertising or cross-app tracking.
5. Service providers
Our current infrastructure may use Render for application hosting, Neon for PostgreSQL, Cloudflare R2 for encrypted object storage and edge security, and Resend for service email. Apple processes App Store purchases and, when you enroll it, protects the Apple Recovery Key through iCloud Keychain. Providers receive only the information needed for their role and are required to provide privacy and security protections consistent with this policy. Their infrastructure may process information in countries other than yours.
6. Sharing and recovery
When you invite someone to a shared sub-vault, we process the recipient email, role, encrypted key envelopes, opaque identifiers, and access state. Recipients may save or export copies; once a person has obtained a copy outside Orpeca, you are responsible for that sharing decision.
iCloud Keychain recovery protects an encryption recovery key, not a readable copy of your documents. Encrypted document recovery also depends on an available encrypted backup. We cannot recover document keys from your password or bypass trusted-device security.
7. Retention and deletion
We retain account and service records while your account is active and as reasonably needed for security, dispute resolution, legal duties, and service operation. Encrypted objects and associated metadata are scheduled for deletion when the owning account or scope is deleted, subject to short operational backup and garbage-collection windows. Security and transaction records may be retained where legally required.
You can delete local data in Settings, delete service analytics from the Account analytics page, and initiate complete account deletion in Account settings. Deleting the app alone does not delete an online account or cancel an Apple subscription.
8. Your choices and rights
Depending on where you live, you may request access, correction, deletion, portability, restriction, or objection. You may disable optional detailed analytics in the app, revoke browser and sharing access, or delete your account. Contact us at privacy@orpeca.com. We may verify your identity before completing a request.
9. Security, children, and changes
We use encryption, access controls, signed device requests, and operational safeguards, but no system can promise absolute security or availability. The service is not directed to children under 13. If you believe a child provided account information without appropriate consent, contact us.
We may update this policy as the product or law changes. We will post the revised effective date and provide additional notice when a change materially affects your rights or how information is used.
10. Contact
Privacy questions: privacy@orpeca.com
General support: support@orpeca.com
See also our Terms and Conditions.