⣀⣠⣤⣤⣀⣀
     ⢠⣶⠟⠛⠉⠉⠉⠛⠻⢿⣶⣤⡀
    ⢠⡿⠁          ⣍⠻⢿⣦⡀
  ⢠⡿⠁           ⠈⢧⣄⠛⢿⣶⣄⣠⡾⣧⡀
 ⢀⣿⠃            ⠘⣿⣷⣦⡉⠻⣫⣾⡽⣷
 ⣿⠇   ⣀⣀⡀     ⣀⣀⡀  ⠸⣿⠻⣿⣾⡿⠃ ⠹⣿⣷⡀
⣸⣿⠟⠛⠉         ⠉⠛⠻⣿⣇      ⠈⠛⠛⠒
⢠⣿⠃ ⢀⣀⣠⣤⣤⣤⣤⣤⣤⣤⣤⣤⣤⣀⡀ ⠘⣿⡆
orstrum
docs whitepaper github sign in
docs whitepaper github sign in

Legal

Privacy Policy

Effective July 19, 2026 · Orstrum, Inc.

Orstrum ("we," "us," or "our") is operated by Orstrum, Inc. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information when you use the Orstrum cloud service at orstrum.com and any associated CLI tools.

1. Information We Collect

Account data. When you create an account — via GitHub OAuth or email/password — we collect your email address and, if provided through OAuth, your GitHub username and public profile information.

Graph data. When you run orstrum push, we store the derived structural data from your codebase: file paths, import/export edges, exported symbol names, and AI-generated purpose summaries. We do not store your raw source code.

Usage data. We collect server logs, API call counts, and aggregate usage metrics (e.g., number of graph nodes, API requests per day) for billing, rate-limiting, and service improvement. Rate limiting is keyed on your IP address, which is held briefly in a Redis store and expires automatically.

API keys. When you create an API key for the CLI, we store a SHA-256 hash of it, its label, and its creation, last-used, and revocation timestamps. The raw key is shown once and is never stored, so we cannot recover it for you.

Cookies. We set the Supabase session cookies (sb-<project-ref>-auth-token and its refresh counterpart) required for authentication. See our Cookie Policy for details.

2. How We Use Your Information

  • To create and manage your account and workspace.
  • To store and serve your code graph via the hosted MCP endpoint.
  • To process subscription payments and send receipts.
  • To send transactional emails (e.g., password reset, security alerts).
  • To improve the product using aggregated, anonymized usage data.

We do not sell your personal data or graph data to third parties.

3. Data Storage and Security

Your data is stored in a Supabase-managed PostgreSQL database. Row-level security (RLS) policies enforce workspace isolation — no user can access another workspace's data through our API. Infrastructure is hosted on Vercel (edge/serverless) and Supabase (database).

4. Third-Party Processors

  • Supabase — database, authentication, and storage.
  • Vercel — web hosting and edge functions.
  • GitHub — OAuth sign-in (only if you use "Sign in with GitHub").
  • Stripe — payment processing for paid plans.
  • Anthropic — the LLM behind hosted impact analysis (see below).
  • Upstash — Redis store backing rate limiting; holds request counters keyed by IP address or workspace ID for a short, self-expiring window.
  • Google Workspace — outbound transactional email (password resets, invites, security alerts).

Each processor is bound by its own privacy policy and, where applicable, a Data Processing Agreement (DPA).

What goes to Anthropic. When you call the orstrum_analyze_impact tool, we send the file paths and purpose summaries relevant to that query to the Anthropic API to generate the analysis. No other feature sends your data to an LLM provider, and your raw source code is never sent — we do not hold it. Anthropic does not train models on data submitted through its API.

5. Data Retention

We retain your data for as long as your account is active. If you ask us to close your account, we delete your workspace, graph data, and personal information within 30 days, except where we are required to retain records for legal or billing purposes (up to 7 years for financial records).

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate information.
  • Request deletion of your account and associated data.
  • Request a machine-readable copy of your graph data.
  • Object to certain processing or lodge a complaint with a supervisory authority.

To exercise any of these rights, email us at tyler@aforah.com from the address on your account. We respond within 30 days. Note that the graph on your own machine is the authoritative copy — the local SQLite database written by the CLI is yours to export at any time without involving us.

7. Children

Orstrum is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you believe we have done so, contact us and we will delete the information promptly.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the effective date. Continued use of the service after changes constitutes acceptance of the updated policy.

9. Contact

Questions about this policy? Email tyler@aforah.com.

orstrum context graph

The structured graph your AI was missing.

Product

  • docs
  • whitepaper
  • github
  • cloud

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy
© 2026 Orstrum, Inc. All rights reserved. orstrum cloud