Privacy Policy
Last updated: September 21, 2026
1. Scope and operator
This Privacy Policy explains how ORG2 Cloud and the ORG2 Remote mobile app (together, "ORG2") handle information. ORG2 is operated by Houyi He under the YORG-AI brand.
2. Information we collect
- Account and contact information: your name, email address, avatar, user identifier, and authentication session information when you sign in with email or GitHub.
- Organization and device information: organization memberships, repository scope identifiers, device and desktop identifiers, device labels, access level, and pairing or connection timestamps.
- Product interaction information: sign-in, pairing, connection, sync, session-access, and plan-entitlement activity needed to operate the service.
- User content: session metadata, prompts, messages, tool output, replay segments, comments, and photos or files that you choose to send or sync.
- Billing information: Stripe customer and subscription identifiers, plan, seat count, subscription status, billing period, and payment status. Stripe processes payment-method and full card details; ORG2 does not store full card numbers.
3. How we use information
We use this information to authenticate users; pair devices; sync, display, and replay sessions; support organization collaboration; process subscriptions; enforce plan entitlements; secure and maintain the service; respond to support or privacy requests; and comply with applicable legal obligations.
4. Voice, camera, and selected files
If you use dictation, Apple's Speech framework processes microphone audio and returns transcript text to ORG2. ORG2 does not write the raw microphone recording to its servers. Camera frames used to scan a pairing QR code are processed on the device; ORG2 uses the decoded pairing information to connect your devices. Photos, screenshots, or files are sent only when you choose to attach or sync them.
5. Service providers
ORG2 uses third-party providers to deliver specific parts of the service: GitHub and Supabase for authentication; Supabase for managed database and file storage; Vercel for web hosting and delivery; Cloudflare for website and relay infrastructure; Apple's Speech framework for dictation; and Stripe for checkout, subscriptions, and payment processing. These providers receive information only as needed for those functions and handle it under their own terms, privacy notices, and applicable obligations.
6. Sharing, sale, and tracking
We share information with the providers above, with members of an organization as described below, when you direct us to share it, or when disclosure is required to comply with law or protect users and the service. We do not sell personal information, use it for third-party advertising, or track you across other companies' apps and websites.
7. Session visibility and controls
A synced session is visible to members of the organization you sync it to, according to the per-session access level you choose (off, metadata only, or full replay) and its visibility (organization or restricted). Restricted sessions are visible only to you. You can disable sync, change session access, and revoke a paired device.
8. Retention and deletion
We keep account, organization, device-pairing, billing, and synced content information while needed to provide and secure the service. Plan replay windows control whether older replay content is visible; they are not deletion schedules. You can request account deletion in Account settings. Account deletion removes your ORG2 Cloud profile, memberships, and account-owned session records, and associated replay files are removed through scheduled cleanup. We may retain limited records when necessary for security, payment disputes, legal compliance, or backups, and delete or anonymize them when they are no longer needed for those purposes.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, receive a copy of, object to or restrict certain processing of, or delete your personal information. You may also withdraw consent where processing relies on consent. Use the controls described above or contact us to make a request. We may need to verify your identity before completing it.
10. Security and changes
We use administrative and technical safeguards intended to protect information, but no online service can guarantee absolute security. We may update this policy as ORG2 changes. The date above identifies the latest version.
11. Contact
For privacy questions or requests, contact Houyi He at houyihe21@gmail.com.