Privacy Policy
Effective Date: July 19, 2026
Last Updated: July 19, 2026
Ora Frontier is designed to make advanced artificial intelligence models usable on personal and enterprise hardware. This Privacy Policy explains how Ora Frontier, Inc., doing business as Ora Frontier ("Ora Frontier," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information when you access or use our websites, desktop applications, command-line interfaces, software development kits, application programming interfaces, workspaces, model catalog, account portal, remote-access features, support channels, and related products and services (collectively, the "Services").
This Privacy Policy also explains choices and rights that may be available to you. It does not apply to third-party products, websites, model repositories, or services that are governed by their own privacy notices.
1. Who we are and how to contact us
The data controller responsible for personal information covered by this Privacy Policy is:
Ora Frontier, Inc.
16192 Coastal Highway
Lewes, Delaware 19958, United States
Privacy inquiries: privacy@orafrontier.com
Legal notices: legal@orafrontier.com
If we appoint a data protection officer, European representative, or United Kingdom representative, their contact information will be posted here or in a supplemental regional notice.
2. Scope and roles
This Privacy Policy applies when Ora Frontier acts as a controller or business and determines why and how personal information is processed, including information associated with accounts, subscriptions, website visits, product telemetry, support, marketing, and our business operations.
When an organization uses the Services to process personal information contained in its prompts, files, workflows, agent tasks, application data, or other customer-controlled content, Ora Frontier may act as a processor, service provider, or contractor on behalf of that organization. In those circumstances, the organization's privacy notice and our Data Processing Addendum govern that processing. Requests concerning customer-controlled content should generally be directed to the organization that controls the account or workspace.
3. Privacy principles for a local-first product
Ora Frontier may support both local-only features and connected features. The following principles describe our intended approach:
- Local processing stays local unless a connected feature is used. When a feature is expressly identified as local-only, prompts, inputs, and outputs are processed on your device and are not transmitted to Ora Frontier merely to perform the inference task.
- Connected features require transmission. Account authentication, model downloads, license verification, cloud synchronization, remote agent invocation, team workspaces, support diagnostics, billing, and similar connected features necessarily transmit certain information to Ora Frontier or our service providers.
- No general-purpose model training without permission. We do not use Customer Content to train general-purpose artificial intelligence models unless the applicable customer or user affirmatively opts in or separately agrees in writing.
- Telemetry should be proportionate. We may collect device, compatibility, reliability, and performance information needed to operate and improve the Services. Where practical, we offer settings that allow users to limit optional analytics or diagnostic collection.
- We do not sell personal information. We do not sell personal information for money. We also do not share personal information for cross-context behavioral advertising as those terms are defined under California law, unless we first update this Policy and provide any legally required choices.
These principles are subject to the more detailed terms below and must be read together with feature-specific notices and settings.
4. Personal information we collect
The personal information we collect depends on which Services you use, how your account is configured, and whether you use local-only or connected functionality.
4.1 Information you provide directly
We may collect:
- Account and identity information, such as your name, email address, username, password credentials or authentication tokens, profile image, organization name, role, and account identifiers.
- Team and workspace information, such as workspace names, member names, business contact details, invitations, permissions, administrative settings, and audit events.
- Billing and transaction information, such as billing address, subscription tier, tax information, invoices, payment status, and limited payment-card metadata. Full payment-card numbers are generally processed by our payment processor rather than stored by Ora Frontier.
- Communications, such as support requests, bug reports, survey responses, feedback, product research responses, community posts, and correspondence with us.
- Customer Content, such as prompts, instructions, files, code, text, images, datasets, model configuration, agent tasks, outputs, logs, or other materials that you choose to submit through connected features.
- Integration information, such as tokens, account identifiers, configuration settings, and content made available through third-party integrations that you authorize.
- Event and application information, such as webinar registrations, job applications, partnership inquiries, or waitlist submissions.
Please do not submit sensitive personal information, regulated data, or confidential third-party information unless it is necessary, authorized, and permitted by your agreement with us.
4.2 Information collected automatically
When you access or use the Services, we may automatically collect:
- Device and hardware information, such as operating system, application version, device type, processor architecture, CPU, GPU, neural-processing hardware, memory, storage availability, driver versions, display information, and hardware compatibility characteristics.
- Network and log information, such as IP address, approximate location derived from IP, browser type, timestamps, referring URLs, pages or screens viewed, request identifiers, and security logs.
- Product usage information, such as feature interactions, commands invoked, model selected, model download status, inference start and completion events, latency, throughput, memory use, error codes, crash reports, and whether a task ran locally or through a connected feature.
- License and entitlement information, such as plan eligibility, model access rights, device activations, token usage, rate limits, and subscription status.
- Cookie and similar technology information, such as identifiers stored through cookies, pixels, local storage, software development kits, and comparable technologies.
We seek to avoid collecting the substance of local-only prompts and outputs through routine telemetry. Diagnostic bundles, logs, screenshots, or recordings that you deliberately submit may nevertheless contain content, file paths, user names, or other personal information. Review diagnostic materials before sharing them with us.
4.3 Information from third parties
We may receive personal information from:
- identity and authentication providers;
- payment processors and app marketplaces;
- enterprise customers or workspace administrators;
- integration partners that you connect to the Services;
- model publishers, repositories, or licensing providers;
- analytics, security, fraud-prevention, and infrastructure vendors;
- referral partners, event organizers, and marketing partners; and
- public sources, where permitted by law.
The information received depends on the third party, your settings, and the permissions you grant.
5. How local and connected features handle data
5.1 Local-only inference
For a feature expressly described as local-only, model execution occurs on the user's device. Ora Frontier may still communicate with our systems to authenticate the account, verify an entitlement, download or update a model, check for software updates, retrieve configuration, or record limited operational events. Unless you activate a feature that transmits content, enable content-inclusive diagnostics, or separately provide content to us, Ora Frontier does not receive the substance of prompts or outputs solely because local inference occurred.
Local processing does not eliminate all privacy risk. Other software on your device, operating-system services, backups, browser extensions, connected integrations, malware, other users, or your own logging configuration may access local content. You are responsible for securing your device and environment.
5.2 Model downloads and catalog access
When you browse or download models from the Ora Frontier catalog, we may process account identifiers, device compatibility data, selected model, download status, license acceptance, and related events. Model publishers or hosting providers may receive information as described in their own notices when their infrastructure is used.
5.3 Remote access, agent invocation, and synchronization
Features that let you invoke an agent away from your computer, synchronize settings or sessions, share workspaces, manage devices, or route tasks remotely require data to travel across networks and may require temporary storage. Depending on the feature, this may include task instructions, authentication data, status information, outputs, files, logs, or metadata. We use that information to execute the requested feature, secure the connection, troubleshoot issues, and enforce applicable limits.
5.4 Support and diagnostics
If you request support, you may choose to provide logs, diagnostic bundles, screen recordings, files, or other information. Support materials may contain Customer Content or personal information. We use them to investigate and resolve the issue, improve reliability, and prevent misuse. Where available, use redaction or content-exclusion options before uploading diagnostics.
5.5 Enterprise administration
If your account belongs to an organization, authorized administrators may be able to manage your account, view usage and security events, configure retention, control model access, enable integrations, and access content associated with the organization. The organization is responsible for providing appropriate notice to its users.
6. How we use personal information
We may use personal information to:
- provide, maintain, authenticate, and secure the Services;
- create and administer accounts, subscriptions, teams, and workspaces;
- deliver software, model files, updates, documentation, and support;
- determine hardware compatibility and optimize performance;
- process payments, invoices, taxes, refunds, and account credits;
- enable local, synchronized, remote, and collaborative features;
- monitor reliability, diagnose errors, prevent fraud, and respond to security incidents;
- enforce our Terms of Service, model licenses, usage limits, and acceptable-use rules;
- communicate about service changes, security issues, billing, support, and account administration;
- analyze and improve product usability, performance, and feature adoption;
- develop new products and features using aggregated, de-identified, or appropriately authorized data;
- conduct research, surveys, events, and marketing;
- comply with law, respond to lawful process, and protect rights, safety, and property; and
- carry out corporate transactions such as financing, merger, acquisition, reorganization, or sale of assets.
We may create aggregated or de-identified information and use it for any lawful purpose. We will not attempt to re-identify data that we maintain as de-identified, except to test whether our de-identification processes are effective or as otherwise permitted by law.
7. Legal bases for processing in the EEA, UK, and Switzerland
Where the GDPR, UK GDPR, or comparable law applies, we rely on one or more of the following legal bases:
- Contract: processing necessary to provide the Services, administer accounts, deliver models, process payments, and fulfill our agreements.
- Legitimate interests: securing and improving the Services, preventing fraud, maintaining business records, communicating with business contacts, and understanding product use, where those interests are not overridden by your rights.
- Consent: optional analytics, certain marketing communications, or other processing where consent is required. You may withdraw consent at any time without affecting prior processing.
- Legal obligation: tax, accounting, sanctions, law-enforcement, regulatory, and other compliance obligations.
- Protection of vital interests or public task: only where applicable in unusual circumstances.
Where we process special-category data, we will identify an additional lawful condition where required. Ora Frontier is not intended for processing special-category data unless expressly supported by the applicable plan and documentation.
8. Artificial intelligence, models, inputs, and outputs
8.1 Customer Content and training
Customer Content includes inputs, prompts, files, data, instructions, outputs, and related materials submitted through the Services. We process Customer Content to provide the feature requested, maintain security, comply with instructions, and satisfy our legal obligations.
We do not use Customer Content to train general-purpose models unless the customer or user affirmatively opts in or separately agrees in writing. We may use feedback, ratings, or examples that a user intentionally submits for improvement, subject to the notice presented at collection.
8.2 Third-party models
The Services may provide access to models developed or licensed by third parties. Those models may have separate licenses, acceptable-use terms, attribution requirements, restrictions, or privacy practices. The applicable model card, license, or notice controls where it conflicts with this Privacy Policy regarding the model publisher's independent processing.
8.3 Automated processing
We may use automated systems to detect abuse, diagnose errors, recommend compatible models, prioritize support, prevent fraud, or personalize product functionality. We do not intend to make decisions producing legal or similarly significant effects about individuals solely through automated processing unless we provide a specific notice and any rights required by law.
8.4 Accuracy and sensitive use
AI outputs may be inaccurate, incomplete, biased, offensive, non-unique, or unsuitable for a particular purpose. Do not rely on the Services as the sole basis for decisions involving health, safety, employment, credit, housing, education, insurance, legal rights, critical infrastructure, or other high-impact matters.
9. Cookies and similar technologies
We and our vendors may use cookies and similar technologies to:
- keep you signed in and remember preferences;
- secure accounts and prevent abuse;
- understand website and product performance;
- measure campaigns and referrals; and
- provide support functionality.
Where required, we request consent before using non-essential cookies. You can manage cookies through our consent tool and browser settings. Blocking certain cookies may prevent parts of the Services from functioning.
We respond to legally required opt-out preference signals, such as Global Privacy Control, where applicable. Because industry standards continue to evolve, we may not respond to browser "Do Not Track" signals that are not legally binding or standardized.
10. How we disclose personal information
We may disclose personal information to:
10.1 Service providers and subprocessors
Vendors that provide hosting, content delivery, authentication, payments, customer support, analytics, security, error monitoring, communications, model distribution, and other operational services. They may process information only for the purposes described in their agreements with us.
10.2 Model and integration providers
Third parties whose models, repositories, APIs, plugins, or integrations you choose to use. Information disclosed depends on the feature and permissions involved.
10.3 Workspace administrators and other users
Administrators and authorized members of your organization may receive account, usage, security, and content information according to workspace settings and permissions. Information you share publicly or collaboratively may be visible to the intended recipients.
10.4 Professional advisers and business partners
Lawyers, accountants, auditors, insurers, banks, financing sources, and other advisers or partners who need information to perform services for us or evaluate a transaction.
10.5 Authorities and protection of rights
Government authorities, regulators, courts, law enforcement, or other parties when we believe disclosure is required by law or reasonably necessary to protect rights, safety, security, users, or the public; investigate fraud or misuse; or enforce our agreements.
10.6 Corporate transactions
A buyer, investor, lender, successor, or other participant in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections where practicable.
We do not disclose Customer Content to advertising networks for targeted advertising.
11. Sale, sharing, and targeted advertising
Ora Frontier does not sell personal information for monetary consideration. We do not share personal information for cross-context behavioral advertising or process personal information for targeted advertising as those terms are defined by applicable U.S. state privacy laws.
If our practices change, we will update this Privacy Policy, provide any required notice, and offer applicable opt-out rights before the change takes effect.
12. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, comply with legal and accounting obligations, resolve disputes, enforce agreements, maintain security, and prevent abuse.
Retention depends on the data and context. For example:
- account and workspace information is generally retained while the account is active and for a reasonable period afterward;
- billing, tax, and transaction records may be retained for the period required by financial and tax laws;
- security logs and device records may be retained for a period proportionate to security, fraud-prevention, and reliability needs;
- support records may be retained to resolve issues, improve support, and document commitments;
- Customer Content transmitted through connected features is retained according to the feature, plan, workspace settings, documentation, and applicable agreement; and
- backup copies may persist for a limited period until overwritten or deleted through normal backup cycles.
We may retain information longer when required by law, subject to a legal hold, necessary to protect safety or security, or requested by the customer controlling the data. We may retain aggregated or de-identified information indefinitely.
13. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. Depending on the Services and plan, safeguards may include encryption in transit and at rest, access controls, least-privilege practices, logging, secure software development, vulnerability management, incident response, and vendor review.
No system is completely secure. You are responsible for protecting your credentials, devices, local model files, integrations, access tokens, and recovery methods. Notify us promptly at security@orafrontier.com if you believe an account or the Services have been compromised.
14. International data transfers
Ora Frontier and our service providers may process personal information in the United States and other countries that may not provide the same legal protections as your home jurisdiction.
Where required, we use recognized transfer mechanisms, such as the European Commission's Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum or other approved UK mechanism, adequacy decisions, or another lawful safeguard. You may contact us for information about applicable transfer safeguards.
15. Your choices and controls
Depending on the Services, you may be able to:
- update profile and account information;
- manage team members and workspace permissions;
- control optional analytics or diagnostics;
- choose whether to submit content-inclusive support materials;
- disconnect integrations;
- manage marketing preferences;
- control cookies through our consent tool;
- export or delete certain account data; and
- close your account.
Service and security messages are not promotional and may continue while you maintain an account. Waitlist marketing preferences can be updated through the unsubscribe link in our emails or by contacting privacy@orafrontier.com.
16. Privacy rights
Depending on where you live, you may have the right to:
- know or access the personal information we process;
- correct inaccurate personal information;
- delete personal information;
- receive a portable copy of certain information;
- restrict or object to processing;
- withdraw consent;
- opt out of sale, sharing, targeted advertising, or certain profiling;
- appeal a denied request; and
- lodge a complaint with a supervisory authority.
To exercise a right, contact privacy@orafrontier.com. We may verify your identity and authority before acting. You may use an authorized agent where permitted by law. We will not discriminate against you for exercising a privacy right.
Some rights are subject to exceptions. For customer-controlled content, we may direct you to the organization that controls the relevant workspace.
16.1 EEA, UK, and Switzerland
You may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may complain to your local data-protection authority. UK residents may complain to the Information Commissioner's Office.
16.2 U.S. state privacy rights
Residents of California, Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, Virginia, and other states with applicable comprehensive privacy laws may have rights described above, subject to legal thresholds and exceptions.
16.3 California notice at collection
During the preceding twelve months, we may have collected the following categories of personal information: identifiers; customer records; commercial information; internet or electronic-network activity; geolocation derived from IP; professional or employment information; audio, visual, or similar information submitted for support; inferences; and sensitive personal information such as account credentials or precise contents of communications where submitted through connected features.
We collect and use these categories for the purposes described in Sections 6 and 8. We disclose them to the categories of recipients described in Section 10. We do not sell or share them for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics about individuals beyond purposes permitted by law.
17. Children's privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Users must be at least 18 years old or the age of legal majority in their jurisdiction to create an account, unless an authorized educational or enterprise program expressly permits otherwise under a separate agreement.
If you believe a child has provided personal information in violation of this section, contact privacy@orafrontier.com so we can investigate and take appropriate action.
18. Third-party services and links
The Services may link to or interoperate with third-party websites, repositories, models, plugins, applications, or services. We are not responsible for third-party privacy or security practices. Review their terms and privacy notices before providing information or enabling an integration.
19. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in the Services, law, technology, or our practices. We will update the "Last Updated" date and provide additional notice when required by law. Material changes will apply prospectively unless otherwise permitted by law.
20. Contact us
Questions, complaints, and privacy requests may be sent to:
Ora Frontier, Inc.
Attn: Privacy
16192 Coastal Highway
Lewes, Delaware 19958, United States
Email: privacy@orafrontier.com
For security vulnerabilities, contact security@orafrontier.com rather than submitting sensitive vulnerability details through ordinary support channels.
See also our Terms of Service.