Privacy
Orqara is being built around a local-first boundary: your machine remains the authority for local files and permissions, while hosted services stay as narrow as the feature requires.
The website and account service today
The current Orqara marketing and documentation site remains static. Orqara account authentication is now available to invited Early Access users through Clerk's hosted production Account Portal at accounts.orqara.com.
Public Arc downloads, billing, and the managed relay service are not yet generally available. Orqara does not currently run first-party advertising trackers or product analytics on the marketing site.
Account authentication
Clerk processes the identity and session data required to provide Orqara sign-in, account recovery, and account profile management. Depending on the sign-in method you choose, Google or GitHub may also process authentication data under their own terms.
- Email address and basic account profile information.
- Authentication method and session/security metadata.
- Social-provider identity information returned for the scopes required for sign-in.
Website infrastructure
The site is delivered through Cloudflare. As part of delivering and protecting the site, infrastructure providers may process ordinary network and request metadata such as IP address, TLS and HTTP information, request timing, and security events.
Infrastructure providers may also use essential security mechanisms needed to operate their services.
Arc's local boundary
Arc MCP is designed to remain the final authority for access to local workspaces and machine actions. Cloud account state or provider authorization must not silently increase those local permissions.
- Workspaces are explicitly authorized on the Mac.
- Read, write, Git, task, and broader machine permissions remain locally scoped.
- Provider routing and collaboration are separate from permission grants.
Planned Orqara Cloud data
Managed features are intended to retain only the state required to authenticate, route, revoke, bill, and operate the service.
- Account and opaque customer identifiers.
- Device identifiers and public keys.
- Provider, surface, and connector bindings.
- OAuth grants or tokens when a provider flow requires them.
- Subscription, revocation, liveness, and minimal security metadata.
Data the cloud is not designed to retain by default
- Repositories or workspace file contents.
- Diff contents or arbitrary command output.
- AI prompts or conversation content.
- Local Arc MCP configuration and local secrets.
- MCP request and response bodies merely for routine debugging.
Privacy contact and launch updates
Privacy questions can be sent to privacy@orqara.com.
This policy will continue to be expanded as Orqara enables device registration, release entitlements, billing, managed relay traffic, or other production data-collecting features. Future revisions will describe the relevant purposes of processing, processors, retention, and applicable user rights in more detail.