Privacy Policy

What Orastra collects, why, who else sees it, and what you can ask us to do about it. Written to be read — if anything here is unclear, that is a bug and we want to hear about it.

Last updated 2026-08-02 · Ramya Shripathi, trading as Orastra

1.Who we are

Orastra is operated by Ramya Shripathi, trading as Orastra, Shriram Spandhana, Off Wind Tunnel Road, Challaghatta, Bengaluru, Karnataka 560037, India. This policy explains what personal data we collect, why, who we share it with, and what rights you have.

Orastra handles two different kinds of personal data, and the distinction decides who is responsible for what. Data about YOU — the person who signs up — we decide the purposes for, so we are the controller. Data about YOUR CUSTOMERS — the people who call, message, or chat with your AI employee — we only handle on your instructions, so you are the controller and we are your processor.

If you have any question about this policy, or want to exercise a right described in section 8, contact hello@orastra.tech.

2.What we collect

We collect only what the product needs to work. Concretely:

Account dataYour name, email address, and hashed password (or your Google account identifier if you sign in with Google). Used to authenticate you and to contact you about the service.
Business profileYour business name, industry, website, description, timezone, languages, opening hours, contact phone, meeting link, and team email. This is what your AI employee tells your customers.
Knowledge baseThe facts, prices, policies and FAQs you add — typed in, imported, or extracted from your own website when you ask us to read it.
ConversationsMessages exchanged between your AI employee and your customers across web chat, the website widget, phone, SMS, WhatsApp and email — including call transcripts.
Customer recordsNames, email addresses, phone numbers and notes for the people your AI employee talks to, plus appointments and tasks created on your behalf.
Connected accountsAccess tokens for services you connect (Gmail, Google Calendar, Google Drive, Slack, CRM, helpdesks, Twilio, WhatsApp). Stored encrypted and never shown back to the browser.
Usage dataCounts and timestamps of actions your AI employee takes, used for your dashboard analytics and to calculate your bill.
Technical dataIP address and request metadata, used for rate limiting and abuse prevention, and error diagnostics when something breaks.

We do not collect special-category data (health, biometrics, religion, and similar) on purpose. If you put such information into your knowledge base or a customer does so in a conversation, it is processed as ordinary content — so please do not use the service for it unless you have your own lawful basis.

3.The website chat widget

If you install our chat widget on your own site, it loads from our servers and behaves as follows, which you should reflect in your own privacy notice:

  • It sets no cookies and no advertising identifiers on your visitors' devices.
  • It stores the current conversation in the browser's session storage so a visitor who navigates between your pages does not lose the thread. That is cleared when they close the tab.
  • Messages a visitor sends are transmitted to us and processed exactly like any other conversation on your account — you are the controller, we are your processor.
  • It records the visitor's IP address transiently for rate limiting. It is not stored against the conversation.
  • It only answers on the domains you explicitly allow.

4.Why we use it, and our lawful basis

To provide the servicePerformance of our contract with you. This covers running your AI employee, storing your knowledge base, and taking the actions you have permitted.
To bill youPerformance of our contract, and our legal obligation to keep accounting records.
To keep the service secureOur legitimate interest in preventing abuse, fraud and unauthorised access — this is why we rate limit, verify webhook signatures and log errors.
To improve the serviceOur legitimate interest. We use aggregate, non-identifying usage patterns; we do not read your conversations to develop features.
To send service emailsPerformance of our contract. Marketing email, if we ever send any, is consent-based and always unsubscribable.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

5.AI processing

Your AI employee is powered by Anthropic's Claude models. To answer a message, we send the model the conversation, the relevant parts of your knowledge base, and your business profile. We do not send your stored access tokens, your password, or other customers' data.

Anthropic processes this as our sub-processor under their commercial terms, which prohibit using submitted content to train their models.

Automated decisions your AI employee makes — booking an appointment, escalating to a person, sending a reply — are configurable by you, and every action class can be set to require your approval first. No decision producing legal or similarly significant effects is made about your customers without a human in the loop where you have configured one.

6.Who we share it with

We share personal data only with the following categories of sub-processor, only as needed to run the service:

Hosting & databaseSupabase (application database and authentication) and Vercel (application hosting and privacy-friendly, cookieless analytics).
AI model providerAnthropic, for generating replies as described above.
CommunicationsTwilio, where you use phone, SMS or WhatsApp-over-Twilio; Meta Platforms, where you connect WhatsApp directly.
Your connected toolsGoogle (Gmail, Calendar, Drive), Slack, your CRM, Zendesk or Intercom — only those you choose to connect, and only within the scopes you approve.
Integration brokerComposio, which brokers OAuth connections to some of the tools above.
Error monitoringSentry, for diagnosing faults. Reports are scrubbed before they leave our servers: credentials, tokens, message bodies, email addresses and phone numbers are redacted, and we do not record session replays.

We may also disclose data where we are legally required to, or to establish or defend legal claims. If we are ever involved in a merger or acquisition, personal data may transfer as part of that transaction, and we will tell you before it does.

Some of these providers are located outside your country. Where personal data is transferred internationally, we rely on the transfer mechanisms those providers offer, such as Standard Contractual Clauses.

7.How long we keep it

  • Account and business profile data: for as long as your account is open.
  • Conversations, customer records, appointments and knowledge: for as long as your account is open, or until you delete them — whichever comes first.
  • Connected-account tokens: until you disconnect that service, at which point the stored credentials are cleared.
  • Billing and accounting records: as long as tax law requires us to keep them, typically several years, even after your account closes.
  • Error reports: retained by our monitoring provider on a rolling window, currently 90 days.

When you close your account we delete or irreversibly anonymise your data within 30 days, except where we are required to keep it. You can ask us to delete it sooner at hello@orastra.tech.

8.How we protect it

Security measures we actually operate, rather than aspirations:

  • All traffic is served over HTTPS, with HSTS enforced in production.
  • Access to your workspace's data is enforced by the database itself through row-level security, not only by application code.
  • Connected-account credentials are stored encrypted and are never returned to the browser.
  • Inbound webhooks from Twilio and Meta are cryptographically signature-verified, so third parties cannot impersonate your customers.
  • The chat widget only answers on domains you have explicitly allowed.
  • Error reports are scrubbed of credentials and personal data before transmission.
  • Rate limiting is applied to authentication, chat and import endpoints.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority without undue delay, and in any case within 72 hours of becoming aware of it where the law requires.

9.Your rights

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access — get a copy of what we hold about you.
  • Rectification — correct anything inaccurate.
  • Erasure — have it deleted, subject to records we must keep.
  • Restriction and objection — limit or object to certain processing, including processing based on our legitimate interests.
  • Portability — receive your data in a machine-readable format.
  • Withdraw consent — where we relied on consent, at any time, without affecting prior processing.
  • Complain — to your local data protection authority.

To exercise any of these, email hello@orastra.tech. We will respond within one month. We may ask you to verify your identity first — not to obstruct you, but because handing someone else's data to an impersonator would be the exact harm these rights exist to prevent.

If you are one of our customers' customers and want your data removed, contact that business directly: they control it and we act on their instructions. Tell us and we will point you to them.

10.Children

Orastra is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact hello@orastra.tech and we will delete it.

11.Changes to this policy

We may update this policy as the product changes. The date at the top always reflects the current version. If a change materially affects your rights, we will tell you by email or in the app before it takes effect, rather than relying on you to notice.

12.Contact

Privacy questions and data-rights requests: hello@orastra.tech

Everything else: hello@orastra.tech

Postal: Ramya Shripathi, trading as Orastra, Shriram Spandhana, Off Wind Tunnel Road, Challaghatta, Bengaluru, Karnataka 560037, India