Privacy Policy

Last updated July 18, 2026

This policy explains how Organic Intelligence, Inc. (“Orgo,” “we,” “us”) collects, uses, and protects information when you use our cloud computers, dashboard, APIs, and related services (the “Service”). We built Orgo to run agent workloads on real computers, and we treat the data those computers touch with care.
01

Information we collect

  • Account information. Your name and email, provided when you sign up. We use passwordless email sign-in, so we do not store passwords.
  • Billing information. Payments are processed by Stripe. We keep a customer reference and your plan and usage records, but we never see or store full card numbers.
  • Usage and telemetry. API calls, computer lifecycle events (create, start, stop, delete), resource consumption, timestamps, and diagnostic logs used to operate, secure, and bill the Service.
  • Content on your computers. The files, screenshots, and data your agents create or process inside your computers. This is your content, and we access it only as described in Your content and your computers.
  • Communications. Messages you send us, such as support requests.
  • Cookies and analytics. Essential cookies keep you signed in, and we use product analytics to understand how the Service is used and to improve it. We do not use advertising cookies.
02

How we use information

  • Provide, operate, and maintain the Service.
  • Authenticate you and keep your account secure.
  • Process billing and usage-based charges.
  • Detect, prevent, and investigate abuse, fraud, and security incidents.
  • Debug, troubleshoot, and improve reliability and performance.
  • Send you service, security, and account notices.
  • Meet our legal and accounting obligations.

We do not sell your personal information, and we do not use the content on your computers to train AI models.

03

Your content and your computers

You control what runs on your computers and what data they process. In the ordinary course of operating the Service, we do not monitor the contents of your computers. Automated systems act on operational signals such as resource usage and health, and on abuse signals.

We access the content inside your computers only when:

  • you ask us to, for example to resolve a support request;
  • it is necessary to operate, secure, or protect the integrity of the Service; or
  • we are required to by law.

When you stop or delete a computer, its disk state is scheduled for deletion on our regular deletion cycle. See Data retention.

04

How we share information

We share limited data with vendors that help us run the Service (“sub-processors”), under contracts that require appropriate safeguards:

  • Stripe — payment processing and billing.
  • Resend — authentication and transactional email.
  • PostHog — product analytics.
  • Cloud infrastructure providers — bare-metal servers and object storage, operated in the United States.
  • Anthropic and OpenAI — only when you use Orgo-managed AI access. If you bring your own provider API keys, you interact with those providers directly under their terms.

We may also share information to comply with the law, enforce our Terms of Service, or protect the rights, safety, and security of Orgo, our users, and the public. If Orgo is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction, and we will notify you of any change in control.

We do not sell personal information or share it with data brokers or advertisers.

05

Data retention

We keep account and billing records for as long as your account is active and as needed for legal, accounting, and security purposes. Computer disk state persists until you stop or delete the computer, after which it is purged on our regular deletion cycle. When you delete your account, we delete or de-identify associated personal data within a reasonable period, typically within 30 days, except where longer retention is required by law.

06

Security

  • Every computer runs fully isolated in its own virtual machine.
  • Data is encrypted in transit (TLS) and at rest.
  • Access to production systems is restricted, authenticated, and logged.
  • We maintain administrative, technical, and organizational security controls designed to protect your data.
  • Our infrastructure is built and operated in the United States.

Enterprise customers who require a Data Processing Agreement (DPA) or additional security documentation can request one at spencer@orgo.ai. No system is perfectly secure, and we work continuously to protect your data; if you believe you have found a vulnerability, please report it to spencer@orgo.ai.

07

Your rights and choices

You can access, correct, export, or delete your data from your account settings or by contacting us. Depending on where you live, for example in the EEA, the UK, or California, you may have additional rights to access, correct, delete, port, restrict, or object to certain processing, and to not be discriminated against for exercising them. California residents: we do not sell or share personal information as those terms are defined under the CCPA.

To exercise any of these rights, contact spencer@orgo.ai. We will respond within the time required by applicable law.

08

International users

Orgo is based in and operates its infrastructure in the United States. If you access the Service from outside the United States, you understand that your information will be processed in the United States.

09

Children's privacy

The Service is not directed to children under 18, and we do not knowingly collect their personal information.

10

Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or an in-product notice, and the “Last updated” date above will change. Continued use of the Service after changes take effect means you accept the updated policy.

11

Contact

Organic Intelligence, Inc. is a Delaware corporation with its principal place of business in San Francisco, California, United States.
Questions about privacy: spencer@orgo.ai.