Privacy Policy
Draft · last generated 2026-07-25 · not yet reviewed by counsel
1. No product telemetry
We do not operate analytics, tracking, or telemetry inside the Software. We have no visibility into how you use it, what data you load, or what your org chart looks like.
2. Organizational data — we don't receive it
People, titles, reporting lines, compensation, demographic codes, and notes you enter into the Software are stored locally in your browser's IndexedDB and/or in .orgpack files you save to a location you choose, via the File System Access API. This data is never transmitted to our servers by the Software's default operation.
3. Data that does reach us
Two categories of data reach OrgTool's servers, and only when you take an explicit action:
- Account & billing data — if you sign in via a cloud magic-link account, or purchase a paid plan, we (or our payment processor) receive your email address, name, and billing/subscription metadata (tier, seat count). We do not receive organizational data through this path.
- AI analysis content — if you explicitly enable AI features and configure your own Anthropic API key, a context block from your current scenario (people, titles, department structure, and, if you separately enable it, sensitive fields) is sent directly from your browser to Anthropic's API for that one request. It is not sent to, or stored by, OrgTool's own servers.
4. Third parties
Our payment processor (for billing data) and, only when you opt in, Anthropic (for AI analysis content you explicitly send) are the only third parties in this picture. [PLACEHOLDER — counsel to confirm processor name(s) and add standard sub-processor list format.]
5. Your rights
[PLACEHOLDER — GDPR/CCPA-style rights language to be drafted by counsel once the entity's data-processing footprint (limited to account/billing data) is confirmed.]
Contact
privacy@orgtool.io