ORIN
Sign in

Privacy Policy

Effective Jul 28, 2026 · forms part of your agreement with us

ORIN holds a trading journal. That is more revealing than most software gets to be about a person, so this policy is specific rather than general: it lists every category of data we hold, what each one is for, how long it stays, and who else can see it.

Three things are true and unusual enough to state before the detail. We set no advertising trackers, and the one analytics tool we use does not run until you say yes. We do not sell or share personal information, and never have. And we hold no third-party credentials of yours — ORIN pays for its own market data, so there is nothing of yours to keep.

01Who is responsible for your data

Autusus LLC, c/o ZenBusiness Inc., 5511 Parkcrest Drive, Suite 103, Austin, TX 78731, United States (“ORIN”, “we”) is the controller of the personal data described here. Requests, questions and complaints go to privacy@tryorin.xyz.

Data Protection Officer. We have not appointed one. Our processing does not meet the Article 37 GDPR thresholds — we carry out no large-scale systematic monitoring of individuals and process no special-category data. Privacy requests are handled directly by the operator.

EU and UK representatives. We are established outside the European Union and the United Kingdom and have not yet appointed representatives under Article 27 of the GDPR or of the UK GDPR. If we begin offering the Service to data subjects in those territories on an established basis, we will appoint representatives and name them here before doing so.

This policy covers the ORIN website and application. It does not cover third-party sites we link to, which have their own policies.

02What we collect

The table below is the complete set. Each row names the California statutory category alongside the plain description, so the CCPA disclosure and this policy are one document rather than two that can drift.

WhatExamplesCCPA categoryWhere it comes from
IdentifiersEmail address, display name, account ID.§ 1798.140(v)(1)(A) — identifiersYou, at signup.
Authentication credentialsA salted hash of your password, session tokens. We never see or store your password itself.§ 1798.140(ae)(1)(D) — sensitive personal informationYou, via our authentication provider.
Commercial informationPlan, billing period, subscription status, renewal date, payment history, Stripe customer identifier.§ 1798.140(v)(1)(D) — commercial informationYou and Stripe. We never receive your card number.
Risk settings you enterSelf-declared account size, risk percentage, daily loss cap, strategy rules, default timeframe.§ 1798.140(v)(1)(B) — Cal. Civ. Code § 1798.80(e) personal informationYou, in Settings. These are figures you type, not connected accounts.
Analysis recordsSymbols analysed, timeframes, grades, computed evidence, price levels, risk plans, the candles the read was computed on.§ 1798.140(v)(1)(K) — inferences drawn from other informationGenerated by the Service when you run an analysis.
Journal and decisionsTrades you record, entry, stop, size, dollar risk, outcome, adherence, and any notes you write.§ 1798.140(v)(1)(K) — inferences; and § 1798.80(e)You, plus outcomes resolved from market data.
Watchlists and alertsInstruments you follow, trigger levels, alert status.§ 1798.140(v)(1)(D) — commercial informationYou.
Event logTimestamped records of analyses created, decisions made, outcomes resolved. This is the dataset the calibration figures are computed from.§ 1798.140(v)(1)(K) — inferencesGenerated by the Service as you use it.
Uploaded imagesChart screenshots you choose to upload.§ 1798.140(v)(1)(J) — audio, electronic, visual informationYou. Today these are read in your browser and not uploaded to us.
Technical and log dataIP address, user agent, timestamps, request paths, error traces — generated by our hosting and database providers.§ 1798.140(v)(1)(F) — internet or network activityAutomatically, when you use the Service.
CorrespondenceEmails you send us and our replies.§ 1798.140(v)(1)(A) — identifiersYou.

We hold no API keys or credentials of yours for any third-party service. ORIN pays for its own market data and calls the provider itself, so there is nothing of yours to store — no column in our database, no field in our write path, and nothing kept in your browser.

What we do not collect. We do not collect payment card numbers, bank details, government identifiers, precise geolocation, biometric data, contacts, browsing history on other sites, or any special-category data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation). We do not buy personal data from data brokers and we do not enrich your profile from third-party sources.

Sensitive personal information. The only category of California “sensitive personal information” we handle is your account log-in credential. We use it solely to authenticate you. We do not use or disclose it to infer characteristics about you, so the right to limit its use under Civil Code § 1798.121 does not arise; you may nevertheless ask us about it at any time.

03Why we process it, and on what legal basis

If you are in the European Economic Area, the United Kingdom or Switzerland, the GDPR requires us to identify a lawful basis for each purpose. These are ours.

PurposeData usedLegal basis (GDPR Art. 6)
Creating and running your account; letting you sign in from any device.Identifiers, credentials.Performance of a contract — Art. 6(1)(b).
Delivering the analysis product: running reads, storing your journal, watchlist and settings.Risk settings, analysis records, journal, watchlists.Performance of a contract — Art. 6(1)(b).
Taking payment, renewing subscriptions, issuing receipts, handling failed payments.Identifiers, commercial information.Performance of a contract — Art. 6(1)(b); legal obligation for tax records — Art. 6(1)(c).
Enforcing usage allowances and preventing abuse of a metered, paid-for reasoning model.Identifiers, usage counts, technical data.Legitimate interests — Art. 6(1)(f): keeping the service economically viable and available to paying users.
Security: detecting unauthorised access, investigating incidents, keeping backups.Technical and log data, identifiers.Legitimate interests — Art. 6(1)(f): protecting the service and its users. Legal obligation where breach notification applies — Art. 6(1)(c).
Computing published calibration statistics in aggregate, de-identified form.Event log, analysis records, resolved outcomes.Legitimate interests — Art. 6(1)(f): publishing an honest record of how the product performs, which is the product’s central claim. See the balancing note below.
Diagnosing faults and improving the Service.Technical and log data, error traces.Legitimate interests — Art. 6(1)(f).
Service emails you cannot opt out of: confirmations, password resets, receipts, material changes to these documents, security notices.Identifiers.Performance of a contract — Art. 6(1)(b).
Optional emails: weekly performance report, outcome and alert notifications.Identifiers, journal, alerts.Consent — Art. 6(1)(a). Withdraw at any time in Settings, without affecting anything else.
Complying with law and responding to lawful requests; establishing or defending legal claims.Any of the above, as strictly necessary.Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f).

Balancing note on calibration. ORIN publishes how its own grades have actually resolved, including when that reads badly. Producing those figures requires the outcome of trades recorded by real users. We consider this a legitimate interest because the statistics are computed only in aggregate, are never published below a minimum sample size, cannot be traced back to an individual, and are the basis on which anyone can judge whether the product works. You may object to this processing at any time — see clause 8 — and we will exclude your records from the aggregate.

04Automated processing and profiling

ORIN is an automated system. It grades market instruments, computes price levels and produces written analysis without a human in the loop.

That automation is directed at a financial instrument, not at you. It does not evaluate your creditworthiness, employability, reliability, behaviour, location, or personal characteristics; it does not decide anything about you; and it produces no legal or similarly significant effect concerning you within the meaning of Article 22 of the GDPR. Nothing the Service computes changes your access to credit, insurance, employment, housing or any service.

The Service does compute statistics about your own decisions — for example how often you followed a grade versus overrode it, and how those choices resolved. Those figures are shown to you, are not used to make decisions about you, and are not shared with anyone.

We do not use personal data to build advertising profiles, and we do not sell or share it for cross-context behavioural advertising.

05Who else sees it

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA. We have never done so. We have no advertising partners and no data brokers. We use one analytics provider, Microsoft Clarity, which runs only with your consent and whose data Microsoft states is neither sold nor used for advertising targeting.

We disclose personal data to service providers who process it on our behalf, under contract, only on our instructions, and only for the purposes below. The complete current list — including what each one does, where it processes and the transfer mechanism relied on — is at Sub-processors, and we update it there when it changes.

Summarised, they are: our hosting provider, our database and authentication provider, our payment processor, our market-data vendor, and the provider of the language model that writes the analysis prose.

We may also disclose personal data:

  • To comply with law — in response to a subpoena, court order or other lawful request. We review each request, disclose only what is strictly required, and will notify you unless legally prohibited.
  • To establish or defend legal claims, or to enforce these documents.
  • To prevent harm — where we reasonably believe disclosure is necessary to prevent fraud, imminent physical harm, or a security incident.
  • In a corporate transaction — a merger, acquisition, financing or sale of assets. Any acquirer remains bound by this policy for data collected before the transaction, and we will notify you before your data becomes subject to a different policy.

Disclosures in the preceding 12 months. In the 12 months before the effective date of this policy, we disclosed identifiers, commercial information, analysis records and technical data to the categories of service provider listed above, each for a business purpose. We sold or shared no personal information.

06International transfers

We are established in the United States and our infrastructure providers operate globally. If you are in the EEA, the UK or Switzerland, your personal data will be transferred to and processed in the United States and potentially other countries whose laws differ from your own.

Where we make such a transfer, we rely on one or more of:

  • the European Commission’s Standard Contractual Clauses (Decision 2021/914), supplemented by the UK International Data Transfer Addendum and the Swiss equivalent;
  • an adequacy decision, where one covers the recipient country or certification framework;
  • for a provider certified under the EU–US Data Privacy Framework and its UK extension, that certification;
  • where no other mechanism is available, your explicit consent or the necessity of the transfer for the performance of our contract with you (Art. 49).

We carry out a transfer risk assessment for each provider and apply supplementary measures — encryption in transit and at rest, access limited to what the provider needs — where the assessment calls for them. You may request a copy of the relevant safeguards from privacy@tryorin.xyz.

You can reduce the transfer surface yourself: we let you choose the region your database sits in where our provider offers one, and we will honour a request to host an account in a specific region where technically possible.

07How long we keep it

We keep personal data only as long as we need it, and we can say exactly how long.

DataRetentionWhy
Account, profile and settingsFor the life of the account, then deleted within 30 days of closure.Needed to provide the Service; the 30 days lets you reverse an accidental closure.
Analyses, journal, watchlists, alertsUntil you delete them, or 30 days after account closure.This is your trading record. We do not prune it on a timer — losing a year-old journal entry would defeat the purpose of keeping one.
Event logDeleted with the account. Aggregate statistics already computed from it are irreversibly de-identified and are not deleted.Once aggregated below the point of re-identification, the statistics are no longer personal data. Deleting them would corrupt a published record.
Billing and tax recordsSeven years from the transaction.Tax and accounting law. This is a legal obligation and survives an erasure request.
Security and access logsUp to 90 days, longer where an investigation is open.Incident detection and investigation.
CorrespondenceUp to 24 months from the last message.Continuity of support and defence of claims.
BackupsRolling, overwritten within 35 days.Disaster recovery. Deleted records persist in backups until the cycle overwrites them; they are not restored to live systems.

08Your rights

Whoever and wherever you are, you can export everything we hold about you from Settings, at any time, in machine-readable JSON, without asking us and without limit. That is a product feature rather than a request process because a right that requires a formal request and a 30-day wait is a right most people never exercise.

If the GDPR or UK GDPR applies to you

You have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify data that is inaccurate or incomplete;
  • erase your data (“right to be forgotten”), subject to our need to retain records the law requires us to keep;
  • restrict processing while a dispute about accuracy or legitimate interests is resolved;
  • portability — receive your data in a structured, commonly used, machine-readable format and transmit it elsewhere;
  • object to processing based on legitimate interests, including the calibration processing described in clause 3;
  • withdraw consent at any time, where processing is based on consent, without affecting processing carried out before withdrawal;
  • complain to your supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the authority for your country of residence. We would rather you came to us first, but you are not required to.

If you are a California resident

Under the CCPA as amended by the CPRA, you have the right to:

  • know what personal information we have collected, the sources, the purposes, the categories disclosed, and the specific pieces of information;
  • delete personal information we collected from you, subject to statutory exceptions;
  • correct inaccurate personal information;
  • opt out of the sale or sharing of personal information. We do neither, so there is nothing to opt out of — but we honour Global Privacy Control signals regardless, and a “Do Not Sell or Share My Personal Information” request sent to us will be recorded and confirmed;
  • limit the use of sensitive personal information. We use it only to authenticate you, which is an exempt purpose, so the right does not arise here;
  • non-discrimination — we will not deny you service, charge you a different price, or give you a lesser experience for exercising any of these rights. We operate no financial incentive programme in exchange for personal information.

Authorised agents. You may use an authorised agent. We will ask for written proof of authorisation and may ask you to verify your identity directly.

Shine the Light. California Civil Code § 1798.83 lets residents request details of personal information shared with third parties for their direct marketing purposes. We share none, and this remains true each year.

If you live in another US state with a privacy law

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and other states with comprehensive privacy statutes have broadly equivalent rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling with legal effects. We extend the rights described above to you regardless of which state you are in, and we do not carry out targeted advertising, sale or that kind of profiling in the first place. Where your state provides an appeal from a refused request, you may appeal to privacy@tryorin.xyz and, if still dissatisfied, to your state Attorney General.

How to exercise a right

Export and delete are available directly in Settings. For anything else, email privacy@tryorin.xyz from the address on your account. We will:

  • acknowledge within 10 business days;
  • respond substantively within 30 days (GDPR) or 45 days (US state laws), extendable once where the request is complex, with notice to you;
  • verify your identity proportionately to the sensitivity of the request — usually by confirming control of the account email, never by asking for a government ID for a routine request;
  • charge nothing, unless a request is manifestly unfounded or repetitive, in which case we will say so first.
In plain English

You can download everything we hold and delete your account yourself, today, without emailing anyone. For anything else, write to us and we will answer within a month.

This summary is for readability. The numbered clause above it is what binds.

09Security

Concretely, and not as a list of adjectives:

  • All traffic is encrypted in transit (TLS). Data is encrypted at rest by our database provider.
  • Passwords are never stored or transmitted in plain text. Authentication is handled by a specialist provider; we never see your password.
  • Every database table enforces row-level security, so a request can only ever return rows belonging to the authenticated user. This is enforced by the database itself rather than by application code, which means a bug in our code cannot expose another user’s records.
  • The key that authorises payment-plan changes is held server-side only and is never present in anything your browser downloads.
  • Access to production data is limited to the operator and used only to run and repair the Service.
  • The event log is append-only: it cannot be silently rewritten, including by us.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay where the breach is likely to result in a high risk to your rights.

Report a vulnerability to security@tryorin.xyz. We will not pursue legal action against good-faith security research that respects user privacy, avoids service degradation, and gives us reasonable time to fix the issue before disclosure.

10Cookies and local storage

We set no advertising cookies and no cross-site trackers. Everything we store to run the product is strictly necessary to deliver a service you have asked for, which is the exemption in Article 5(3) of the ePrivacy Directive and the equivalent under PECR, and we do not ask permission for those.

Analytics is the exception, and it is opt-in. We use Microsoft Clarity to see where the interface confuses people. It does not qualify for that exemption, so it is not loaded at all until you accept it — no script, no request to Microsoft, no cookie. You can withdraw at any time in Settings → Data & privacy, and the signed-in desk is masked so Clarity never receives your journal, positions, account size or analyses.

The full item-by-item list — what is stored, why, and how long it lasts — is in the Cookie & Local Storage Policy.

Do Not Track and Global Privacy Control. There is no consensus standard for DNT, so we do not respond to it. We do honour Global Privacy Control signals, which under California law are treated as a valid opt-out of sale and sharing. A browser sending GPC is treated as having declined analytics: Clarity is never loaded, the consent prompt is not shown, and the signal overrides a stored acceptance.

11Children

The Service is for adults. We do not knowingly collect personal data from anyone under 18, and the Terms of Service require you to be 18 or older. If you believe a minor has given us personal data, contact privacy@tryorin.xyz and we will delete it and close the account. We do not knowingly sell or share the personal information of consumers under 16 — and we do not sell or share anyone’s.

12Changes to this policy

We may update this policy. The effective date at the top always reflects the current version. Where a change materially affects how we use data you have already given us, we will give at least 30 days’ notice by email before it takes effect, and — where the law requires consent for the new use — we will ask for it rather than assume it from continued use.

13Contact

Autusus LLC, c/o ZenBusiness Inc., 5511 Parkcrest Drive, Suite 103, Austin, TX 78731, United States.

If you are unhappy with our response you may complain to your supervisory authority (EEA/UK) or your state Attorney General (US). We would prefer you gave us the chance to fix it first.

Questions about this document go to legal@tryorin.xyz. The other documents in this set are listed here.