Privacy

Local first, with explicit boundaries.

Effective September 23, 2026. Orson is provided by Rude Company LLC.

Local data

The Mac app is not yet available for download. The launch version is being built with an opt-in, local-only work timeline: app and idle intervals within your working hours, manual timers, pause and app exclusions. Optional screenshots and on-device text recognition will require separate consent. Orson encrypts user settings and timeline files on your Mac with a device-only Keychain key. No timeline data goes to Orson servers. Orson has no employer dashboard or hidden capture mode.

Optional AI features

When you explicitly use an AI feature, Orson passes the text needed for that request through the Orson service to TypeSafe. The Orson Worker does not write this text or AI responses to its database or application logs. TypeSafe processes requests under its own privacy terms. Plain-language action translation sends your action text and the names of apps you selected. Screenshot bytes and recognized text are not sent to the AI service. Advanced script templates require your review and approval before they can run.

Software updates

If you enable automatic update checks or choose Check for Updates, the native Sparkle updater fetches a signed update feed and downloads from downloads.meetorson.com. The request reveals your IP address and app version to the download host. Update checks do not transmit your local settings, action text, or timeline data.

Launch email

If you explicitly sign up for launch updates, Brevo will handle confirmation, marketing email, and unsubscribe requests. Buying a license does not subscribe you to marketing. The sign-up form and email program are not active yet.

Purchases and licenses

Stripe processes payment details. We receive purchase identifiers, status, and your checkout email. We store a hash of your signed registration code, activation-device hashes, remaining AI credits, and reset records. Resend processes the email needed to deliver registration and reset messages.

Device identifiers

Orson creates a random identifier in this Mac's device-only Keychain. It does not read the hardware serial number, hardware UUID, hostname, or account name. The service stores a cryptographic hash of the random identifier and a short, opaque Mac label derived from that hash. The label is pseudonymous, not anonymous: it identifies the same installation across activations while its Keychain item remains available.

Retention

License and transaction records are retained for customer support, fraud prevention, accounting, and legal obligations. Expired reset links may be periodically deleted. Timeline data will remain local. Encrypted app and idle observations will be kept for 30 days; raw screenshots and OCR for seven days, unless you delete them sooner. Edited timesheets remain until you delete them. Exports are created only when you request them.

Your choices

You can keep Orson disabled, avoid AI features, reset activations, and remove local settings. Contact privacy@meetorson.com for privacy requests.

Security

Registration and device certificates use Ed25519 signatures. The app contains only the public verification key. Local settings use AES-256-GCM with a device-only macOS Keychain key. If this key is lost, Orson cannot recover the encrypted files. Service secrets remain in Cloudflare Worker secret storage.