Your keys, in your keychain
API keys are stored in the OS keychain (Keychain Access on macOS, Credential Manager on Windows). ORA reads them at runtime; they never touch our servers because we don't have servers.
Your prompts, your files, your credentials — they live on your machine. ORA talks to providers using your own keys, with approval prompts before anything risky leaves your laptop.
We built ORA because we were tired of pretending a chat window was a workspace. Real workspaces are quiet, focused, and yours. They don't ship your thoughts to someone else's server by default.
So ORA is a desktop app — not a tab. It runs on your machine, it stores its state on your disk, and it speaks to AI providers using credentials you control. We do not see your prompts. We do not see your files. We do not proxy your traffic through us. We don't run a back-end you log into.
Privacy isn't a feature we layered on top. It's the shape of the thing.
Four guarantees
Architecture, not policy. Every guarantee maps to code we ship.
API keys are stored in the OS keychain (Keychain Access on macOS, Credential Manager on Windows). ORA reads them at runtime; they never touch our servers because we don't have servers.
File writes, network calls outside the chat, shell commands, and browser automations all stop at an approval prompt. Approve once, approve always, or deny — visible in the Approval Center.
Local file search only sees folders you explicitly approve. Revoke a folder and ORA wipes its embeddings on the next start. Sensitive paths (SSH, dotenv, keychains) are auto-redacted.
Switch on ORA Local AI and the whole workspace works without internet. Your laptop is the model — no ad tracking, no analytics, and nothing about your work leaves your device.
Three layers — each with a clear privacy boundary.
1. Client. The Tauri app on your desktop. Native binary, signed by us, sandboxed by your OS. Holds all your data: chat history, indexes, agent definitions, settings. Persists to your local app-data directory, which you can inspect or wipe.
2. Providers. Direct connections from your machine to Claude, OpenAI, Google, xAI, Perplexity, Mistral, DeepSeek, and ORA Local AI running on-device. Your prompts go to the providers you choose, signed by your keys. No proxy.
3. Update channel. When you allow it, ORA fetches updates from a signed release manifest hosted on our CDN. The fetch is the only network call ORA makes to us, and it carries no identifiers.
What goes where
If it isn't on this list, ORA doesn't collect it.
| Data | Where it lives | Who sees it |
|---|---|---|
| Your prompts & chats | Your machine | You + the providers you chose |
| API keys | OS keychain | You |
| File search embeddings | Your machine | You |
| Custom agents | Your machine | You (until you share them) |
| App settings | Your machine | You |
| Update checks | Our CDN | No personal data sent |
| Crash reports | Opt-in only | Us, anonymised |
| Email at purchase | Cloudflare KV (India + EU edge) | Us — to deliver licence + receipts |
| Name + phone (optional) | Cloudflare KV | Us — only with your consent |
| Marketing consent record | Cloudflare KV (audit-logged) | Us — proof of your choice |
| Razorpay payment ID | Razorpay + KV reference | You + Razorpay + us |
| Google Account — Gmail, Calendar, Drive, Contacts, Classroom (optional) | OAuth tokens in your OS keychain; limited inbox metadata in local app storage; mail, events, files, contacts, and course lists fetched from Google when used | You, Google, and — only for an AI action you start — the AI provider you choose |
| Connect form requests | heyora.in data folder | Us — to reply and qualify business/support requests |
| IP at consent time | Hashed (SHA-256 prefix) only | Us — never raw |
| Crash reports | Opt-in only | Us, anonymised |
Optional Google connection
Connecting each Google service is optional and separate from signing in to your ORA account. The same rules apply in ORA Desktop and ORA Mobile.
Read Gmail. When you choose Connect Gmail,
ORA requests gmail.readonly so it can display and search your
mailbox and perform summaries, drafts, or task extraction that you request.
Organize Gmail. Only when you enable mailbox
organization, ORA separately requests gmail.modify. After your
action or approval, ORA can create, apply, or remove labels; archive or trash
messages; mark them read or unread; star or unstar them; mark importance; or
report spam. ORA does not permanently delete messages.
Send Gmail. Only when you choose to send an
email from ORA, it separately requests gmail.send. ORA sends the
message you reviewed and approved; it does not automatically send email.
Read Calendar. When you open ORA's calendar
surface or connect Calendar, ORA requests calendar.readonly to
display your own events and answer scheduling questions you ask. Read-only:
ORA never creates, edits, or deletes events.
Read Drive. When you connect Google Drive in
the Connectors Hub, ORA requests drive.readonly to list, search,
and read your own files — including exporting Google Docs and Sheets as text —
so it can answer questions you ask about your documents. Read-only: ORA never
modifies or deletes Drive content.
Read Contacts. When you connect Contacts, ORA
requests contacts.readonly to resolve names and email addresses
you mention to your own contact entries. Read-only.
Read Classroom. When you connect Google
Classroom, ORA requests classroom.courses.readonly to show your
own course list in the education surface. Read-only.
Google shows a consent screen before each additional permission is enabled.
Credentials. ORA never receives or stores your Google password. OAuth access and refresh tokens are stored in the secure credential store of the device you connect — the operating-system keychain on desktop, and the platform keystore (Android Keystore / iOS Keychain) on mobile.
On your device. Gmail, Calendar, Drive, Contacts, and Classroom data is fetched directly from Google into the ORA app on your device (desktop or mobile). Limited inbox metadata — such as sender, subject, snippet, message ID, and unsubscribe information — may be cached in local app storage. ORA does not copy any Google user data to the heyora.in website, licensing backend, or Cloudflare KV.
AI actions. When you explicitly ask ORA to summarize, draft, or extract tasks, the content needed for that action is processed by the AI model you selected. A local model keeps it on your device; a cloud model sends it directly to that provider under its privacy terms. ORA does not sell Google user data, use it for advertising, or use it to train generalized AI or machine-learning models.
Local inbox metadata and any locally saved results remain on your device until refreshed or removed with ORA's local app data.
Disconnect anytime from Settings → Provider Connections. ORA attempts to revoke the active authorization at Google and removes the saved OAuth tokens from your OS keychain even if online revocation is unavailable. You can also revoke ORA from your Google Account permissions.
ORA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
For privacy questions or deletion requests, email [email protected].
DPDP Act 2023 · Your rights
India's Digital Personal Data Protection Act is the bar we hold ourselves to.
Transactional (always sent). Your purchase receipt, the licence email, refund confirmations. We need to send these to do business with you — DPDP categorises this as legitimate purpose.
Marketing (only with your consent). Product updates, launch news, occasional offers. The checkbox at checkout is off by default. Tick it if you want these. Untick anytime from your account at heyora.in/account.
Right to access. Sign in at heyora.in/account to see every device, licence, payment, and consent record we hold on you.
Right to correction. Reply to any email from us or write to [email protected] — we fix mistakes within 48 hours.
Right to withdraw consent. One click in your account. Effective immediately. No questions asked.
Right to erasure. Email [email protected] with subject "Delete my data". We delete within 30 days, log the action, confirm in writing.
Grievance redressal. If we mess up, [email protected] is the founder's inbox. Replied within 48 hours.
We don't believe AI belongs in someone else's cloud.
It belongs on your desk — running on your terms.
No account required. No ad tracking, no data sold. Telemetry stays off by default — and your prompts go only to the providers you choose.