OrdiriLog in

Privacy Policy

Effective date: August 2, 2026

Ordiri (“we,” “us,” “our”) provides a task management and automatic scheduling application. This policy explains what information we collect, how we use it, and the choices you have. Ordiri is currently in an alpha testing phase — a limited number of users have access via an access code, and the product is still under active development.

This policy is written to accurately describe Ordiri's actual technical practices. It has not been reviewed by a lawyer. Before relying on it for a public launch beyond alpha testing, have it reviewed by a qualified attorney familiar with your jurisdiction.

1. Information we collect

Account information. When you sign up, we collect your email address and, if you use Google or Microsoft sign-in, basic profile information they provide (such as your name and email).

Calendar data. If you connect a Google Calendar or Microsoft (Outlook) account, we access your calendar via that provider's official API, using an access grant (OAuth) that you explicitly approve. We store:

  • A read-only mirror of your real calendar events (titles, times, and busy/free status) so our scheduling engine can find open time and avoid conflicts.
  • The access and refresh tokens needed to maintain this connection, which are encrypted before being stored and are never visible in plain text in our database.

We only write new events to your real calendar when you explicitly approve a scheduled block (through the daily Kickoff/approval step) — we never modify or create real calendar events without your direct action.

Task and project data. Anything you create in Ordiri — tasks, projects, due dates, effort estimates, priorities — is stored so the app can function.

Usage and error data. We use an error-monitoring service (Sentry) to detect and fix bugs. This can include technical details about your device, browser, and the specific action that triggered an error, but does not include your calendar event contents or task data unless directly relevant to diagnosing a reported bug.

2. How we use your information

We use the information above to:

  • Operate the core product — the task manager and the automatic scheduling engine.
  • Send you transactional email (e.g., account-related notices) via our email provider, Resend.
  • Diagnose and fix technical problems.
  • Communicate with you if you've joined our waitlist, with your explicit consent to receive that email.

We do not sell your personal information. We do not use your calendar or task data to train any AI or machine learning model — Ordiri's scheduling engine is fully rule-based (deterministic), not AI-driven, and does not use your data for any purpose beyond operating the product for you.

3. Third-party services we rely on

To operate Ordiri, we use the following service providers, each of which processes data on our behalf under their own privacy and security practices:

ServicePurpose
SupabaseDatabase, authentication, and secure data storage
VercelApplication hosting
Google Calendar API / Microsoft Graph APICalendar read/write access, with your explicit permission
ResendTransactional email delivery
SentryError monitoring and diagnostics

We do not share your calendar contents or task data with any other third party, and we do not permit these providers to use your data for their own purposes.

4. Data storage and security

  • Calendar OAuth tokens are encrypted at the application layer before being stored — they are not stored in plain text at any point.
  • All data is transmitted over encrypted (HTTPS) connections.
  • Access to your data within our database is restricted at the row level, so your account's data is not accessible to other users.
  • No security measure is perfect. If we become aware of a data breach affecting your information, we will notify you.

5. Data retention

We retain your account and task data for as long as your account is active. If you disconnect a calendar account, we delete the associated tokens and stop syncing new data from that calendar; previously-synced historical records may be retained as part of your task history unless you request deletion.

6. Your rights

You can:

  • Access or export your task and project data at any time through the app.
  • Disconnect a calendar account at any time from Settings, which revokes our access and deletes the stored tokens.
  • Request full account deletion, including all associated task, project, and calendar-sync data, by contacting us (see below). We will process deletion requests within a reasonable time.

7. Children's privacy

Ordiri is not directed at, and is not knowingly used by, children under 13. If we learn that a child under 13 has provided us with personal information, we will delete it.

8. Changes to this policy

We may update this policy as the product evolves, particularly as it moves out of alpha testing. We will update the effective date above when changes are made, and will make reasonable efforts to notify active users of material changes.

9. Contact us

Questions about this policy, or requests regarding your data, can be sent to: alex@lutonmail.com