ORIN
Sign in

Privacy Policy

Effective Aug 29, 2026 · forms part of your agreement with us

ORIN holds a trading journal. That is more revealing than most software gets to be about a person, so this policy is specific rather than general: it lists every category of data we hold, what each one is for, how long it stays, and who else can see it.

Three things are true and unusual enough to state before the detail. We never sell personal information, to anyone, at any price. We run one advertising pixel — Reddit’s, so we can tell which ads work — and the two analytics tools we use are on when you arrive and off in one click. The same single switch stops all three, it sends no email address or phone number to anyone, and Global Privacy Control turns it off before you arrive. And we hold no third-party credentials of yours — ORIN pays for its own market data, so there is nothing of yours to keep.

01Who is responsible for your data

Autusus LLC, c/o ZenBusiness Inc., 5511 Parkcrest Drive, Suite 103, Austin, TX 78731, United States (“ORIN”, “we”) is the controller of the personal data described here. Requests, questions and complaints go to privacy@tryorin.xyz.

Data Protection Officer. We have not appointed one. Our processing does not meet the Article 37 GDPR thresholds — we carry out no large-scale systematic monitoring of individuals and process no special-category data. Privacy requests are handled directly by the operator.

EU and UK representatives. We are established outside the European Union and the United Kingdom and have not yet appointed representatives under Article 27 of the GDPR or of the UK GDPR. If we begin offering the Service to data subjects in those territories on an established basis, we will appoint representatives and name them here before doing so.

This policy covers the ORIN website and application. It does not cover third-party sites we link to, which have their own policies.

02What we collect

The table below is the complete set. Each row names the California statutory category alongside the plain description, so the CCPA disclosure and this policy are one document rather than two that can drift.

WhatExamplesCCPA categoryWhere it comes from
IdentifiersEmail address, display name, account ID.§ 1798.140(v)(1)(A) — identifiersYou, at signup.
Authentication credentialsA salted hash of your password, session tokens. We never see or store your password itself.§ 1798.140(ae)(1)(D) — sensitive personal informationYou, via our authentication provider.
Commercial informationPlan, billing period, subscription status, renewal date, payment history, Stripe customer identifier.§ 1798.140(v)(1)(D) — commercial informationYou and Stripe. We never receive your card number.
Risk settings you enterSelf-declared account size, risk percentage, daily loss cap, strategy rules, default timeframe.§ 1798.140(v)(1)(B) — Cal. Civ. Code § 1798.80(e) personal informationYou, in Settings. These are figures you type, not connected accounts.
Analysis recordsSymbols analysed, timeframes, grades, computed evidence, price levels, risk plans, the candles the read was computed on.§ 1798.140(v)(1)(K) — inferences drawn from other informationGenerated by the Service when you run an analysis.
Journal and decisionsTrades you record, entry, stop, size, dollar risk, outcome, adherence, and any notes you write.§ 1798.140(v)(1)(K) — inferences; and § 1798.80(e)You, plus outcomes resolved from market data.
Watchlists and alertsInstruments you follow, trigger levels, alert status.§ 1798.140(v)(1)(D) — commercial informationYou.
Event logTimestamped records of analyses created, decisions made, outcomes resolved, and feedback you leave on a read — including any note you type with it. This is the dataset the calibration figures are computed from.§ 1798.140(v)(1)(K) — inferencesGenerated by the Service as you use it.
Uploaded imagesChart images you choose to upload, in either of the two modes the Upload screen offers: a measured read, where only the ticker and timeframe are transcribed, or the Upload beta, where a vision model analyses the picture itself.§ 1798.140(v)(1)(J) — audio, electronic, visual informationYou. Downscaled in your browser and sent to our server and on to a vision-model provider for the duration of the read only; the image itself is not stored by us afterwards. Whatever you photograph is what is sent, so crop anything on the screen you did not mean to share.
Community contentMessages, reactions, reports and shared reads you post in the Insider members’ room, with your display name. Visible to other members while they stand; moderation records are retained for the appeal process.§ 1798.140(v)(1)(A), (J) — identifiers; electronic informationYou. Stored until you delete the post or close your account, subject to the moderation-record retention described in the Terms.
Technical and log dataIP address, user agent, timestamps, request paths, error traces — generated by our hosting and database providers.§ 1798.140(v)(1)(F) — internet or network activityAutomatically, when you use the Service.
CorrespondenceEmails you send us and our replies.§ 1798.140(v)(1)(A) — identifiersYou.

We hold no API keys or credentials of yours for any third-party service. ORIN pays for its own market data and calls the provider itself, so there is nothing of yours to store — no column in our database, no field in our write path, and nothing kept in your browser.

What we do not collect. We do not collect payment card numbers, bank details, government identifiers, precise geolocation, biometric data, contacts, browsing history on other sites, or any special-category data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation). We do not buy personal data from data brokers and we do not enrich your profile from third-party sources.

Sensitive personal information. The only category of California “sensitive personal information” we handle is your account log-in credential. We use it solely to authenticate you. We do not use or disclose it to infer characteristics about you, so the right to limit its use under Civil Code § 1798.121 does not arise; you may nevertheless ask us about it at any time.

03Why we process it, and on what legal basis

If you are in the European Economic Area, the United Kingdom or Switzerland, the GDPR requires us to identify a lawful basis for each purpose. These are ours.

PurposeData usedLegal basis (GDPR Art. 6)
Creating and running your account; letting you sign in from any device.Identifiers, credentials.Performance of a contract — Art. 6(1)(b).
Delivering the analysis product: running reads, storing your journal, watchlist and settings.Risk settings, analysis records, journal, watchlists.Performance of a contract — Art. 6(1)(b).
Taking payment, renewing subscriptions, issuing receipts, handling failed payments.Identifiers, commercial information.Performance of a contract — Art. 6(1)(b); legal obligation for tax records — Art. 6(1)(c).
Enforcing usage allowances and preventing abuse of a metered, paid-for reasoning model.Identifiers, usage counts, technical data.Legitimate interests — Art. 6(1)(f): keeping the service economically viable and available to paying users.
Security: detecting unauthorised access, investigating incidents, keeping backups.Technical and log data, identifiers.Legitimate interests — Art. 6(1)(f): protecting the service and its users. Legal obligation where breach notification applies — Art. 6(1)(c).
Computing published calibration statistics in aggregate, de-identified form.Event log, analysis records, resolved outcomes.Legitimate interests — Art. 6(1)(f): publishing an honest record of how the product performs, which is the product’s central claim. See the balancing note below.
Diagnosing faults and improving the Service.Technical and log data, error traces.Legitimate interests — Art. 6(1)(f).
Service emails you cannot opt out of: confirmations, password resets, receipts, material changes to these documents, security notices.Identifiers.Performance of a contract — Art. 6(1)(b).
In-app notifications: weekly performance report, outcome and alert notices, shown inside the product.Identifiers, journal, alerts.Consent — Art. 6(1)(a). Withdraw at any time in Settings, without affecting anything else. We do not currently send any of these by email.
Complying with law and responding to lawful requests; establishing or defending legal claims.Any of the above, as strictly necessary.Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f).

Balancing note on calibration. ORIN publishes how its own grades have actually resolved, including when that reads badly. Producing those figures requires the outcome of trades recorded by real users. We consider this a legitimate interest because the statistics are computed only in aggregate, are never published below a minimum sample size, cannot be traced back to an individual, and are the basis on which anyone can judge whether the product works. You may object to this processing at any time — see clause 8 — and we will exclude your records from the aggregate.

04Automated processing and profiling

ORIN is an automated system. It grades market instruments, computes price levels and produces written analysis without a human in the loop.

That automation is directed at a financial instrument, not at you. It does not evaluate your creditworthiness, employability, reliability, behaviour, location, or personal characteristics; it does not decide anything about you; and it produces no legal or similarly significant effect concerning you within the meaning of Article 22 of the GDPR. Nothing the Service computes changes your access to credit, insurance, employment, housing or any service.

The Service does compute statistics about your own decisions — for example how often you followed a grade versus overrode it, and how those choices resolved. Those figures are shown to you, are not used to make decisions about you, and are not shared with anyone.

We do not use personal data to build advertising profiles, and we do not sell it. We do share a page path and a hashed account id with Reddit so that advertising we have paid for can be measured — described in full under analytics and advertising below, and switchable off in one click.

05Who else sees it

We do not sell personal information. We never have, there is no price at which we would, and nothing here is given to a data broker. We do, since August 2026, share a limited amount of it for cross-context behavioural advertising, as that term is defined by the CCPA/CPRA: the Reddit Pixel tells Reddit when someone who saw one of our ads created an account or subscribed. What it shares is a page path and a one-way hash of your account id — never your email address, and never anything from inside the product. You can stop it in one click in Settings → Data & privacy, and a browser sending Global Privacy Control has already stopped it. We use two analytics providers alongside it — Microsoft Clarity, whose data Microsoft states is neither sold nor used for advertising targeting, and Vercel Web Analytics, which records aggregate counts against no persistent identifier.

We disclose personal data to service providers who process it on our behalf, under contract, only on our instructions, and only for the purposes below. The complete current list — including what each one does, where it processes and the transfer mechanism relied on — is at Sub-processors, and we update it there when it changes.

Summarised, they are: our hosting provider, our database and authentication provider, our payment processor, our market-data vendor, the provider of the language model that writes the analysis prose, and the live-chat provider that runs the chat widget on our public pages.

If you open the chat. Anything you type into the chat widget on our public pages, and any contact detail you give us there so we can reply, goes to Tidio and is held by them on our behalf. Nothing from inside the product reaches it: the widget does not load on the desk or during onboarding, so it is never on a page showing your analyses, journal, positions or account size.

We may also disclose personal data:

  • To comply with law — in response to a subpoena, court order or other lawful request. We review each request, disclose only what is strictly required, and will notify you unless legally prohibited.
  • To establish or defend legal claims, or to enforce these documents.
  • To prevent harm — where we reasonably believe disclosure is necessary to prevent fraud, imminent physical harm, or a security incident.
  • In a corporate transaction — a merger, acquisition, financing or sale of assets. Any acquirer remains bound by this policy for data collected before the transaction, and we will notify you before your data becomes subject to a different policy.

Disclosures in the preceding 12 months. In the 12 months before the effective date of this policy, we disclosed identifiers, commercial information, analysis records and technical data to the categories of service provider listed above, each for a business purpose. We sold or shared no personal information.

06International transfers

We are established in the United States and our infrastructure providers operate globally. If you are in the EEA, the UK or Switzerland, your personal data will be transferred to and processed in the United States and potentially other countries whose laws differ from your own.

Where we make such a transfer, we rely on one or more of:

  • the European Commission’s Standard Contractual Clauses (Decision 2021/914), supplemented by the UK International Data Transfer Addendum and the Swiss equivalent;
  • an adequacy decision, where one covers the recipient country or certification framework;
  • for a provider certified under the EU–US Data Privacy Framework and its UK extension, that certification;
  • where no other mechanism is available, your explicit consent or the necessity of the transfer for the performance of our contract with you (Art. 49).

We carry out a transfer risk assessment for each provider and apply supplementary measures — encryption in transit and at rest, access limited to what the provider needs — where the assessment calls for them. You may request a copy of the relevant safeguards from privacy@tryorin.xyz.

You can reduce the transfer surface yourself: we let you choose the region your database sits in where our provider offers one, and we will honour a request to host an account in a specific region where technically possible.

07How long we keep it

We keep personal data only as long as we need it, and we can say exactly how long.

DataRetentionWhy
Account, profile and settingsFor the life of the account, then deleted within 30 days of closure.Needed to provide the Service; the 30 days lets you reverse an accidental closure.
Analyses, journal, watchlists, alertsUntil you delete them, or 30 days after account closure.This is your trading record. We do not prune it on a timer — losing a year-old journal entry would defeat the purpose of keeping one.
Event logDeleted with the account. Aggregate statistics already computed from it are irreversibly de-identified and are not deleted.Once aggregated below the point of re-identification, the statistics are no longer personal data. Deleting them would corrupt a published record.
Billing and tax recordsSeven years from the transaction.Tax and accounting law. This is a legal obligation and survives an erasure request.
Security and access logsUp to 90 days, longer where an investigation is open.Incident detection and investigation.
CorrespondenceUp to 24 months from the last message.Continuity of support and defence of claims.
BackupsRolling, overwritten within 35 days.Disaster recovery. Deleted records persist in backups until the cycle overwrites them; they are not restored to live systems.

08Your rights

Whoever and wherever you are, you can export everything we hold about you from Settings, at any time, in machine-readable JSON, without asking us and without limit. That is a product feature rather than a request process because a right that requires a formal request and a 30-day wait is a right most people never exercise.

If the GDPR or UK GDPR applies to you

You have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify data that is inaccurate or incomplete;
  • erase your data (“right to be forgotten”), subject to our need to retain records the law requires us to keep;
  • restrict processing while a dispute about accuracy or legitimate interests is resolved;
  • portability — receive your data in a structured, commonly used, machine-readable format and transmit it elsewhere;
  • object to processing based on legitimate interests, including the calibration processing described in clause 3;
  • withdraw consent at any time, where processing is based on consent, without affecting processing carried out before withdrawal;
  • complain to your supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the authority for your country of residence. We would rather you came to us first, but you are not required to.

If you are a California resident

Under the CCPA as amended by the CPRA, you have the right to:

  • know what personal information we have collected, the sources, the purposes, the categories disclosed, and the specific pieces of information;
  • delete personal information we collected from you, subject to statutory exceptions;
  • correct inaccurate personal information;
  • opt out of the sale or sharing of personal information. We never sell. We do share for cross-context behavioural advertising through the Reddit Pixel, and you have an unconditional right to stop that. Three ways, all equivalent and all free: turn analytics off in Settings → Data & privacy — that is our “Do Not Sell or Share My Personal Information” control; send a Global Privacy Control signal from your browser, which we treat as a valid opt-out request and which takes effect before anything loads and overrides any earlier acceptance; or email privacy@tryorin.xyz and we will action it and confirm. We do not ask why, we do not ask you to create an account to do it, and nothing about the product changes afterwards;
  • limit the use of sensitive personal information. We use it only to authenticate you, which is an exempt purpose, so the right does not arise here;
  • non-discrimination — we will not deny you service, charge you a different price, or give you a lesser experience for exercising any of these rights. We operate no financial incentive programme in exchange for personal information.

Authorised agents. You may use an authorised agent. We will ask for written proof of authorisation and may ask you to verify your identity directly.

Shine the Light. California Civil Code § 1798.83 lets residents request details of personal information disclosed to third parties for those third parties’ own direct marketing purposes. We disclose none for that purpose. The Reddit Pixel is measurement of our own advertising and does not license anything to Reddit to market with, which is why it is a CPRA “share” and not a § 1798.83 disclosure — two different definitions that are easy to conflate.

If you live in another US state with a privacy law

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and other states with comprehensive privacy statutes have broadly equivalent rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling with legal effects. We extend the rights described above to you regardless of which state you are in. We make no sale and carry out no profiling with legal effects; we do carry out advertising measurement that several of these statutes treat as targeted advertising, and the same single switch — Settings → Data & privacy, or a Global Privacy Control signal — is your opt-out from it under every one of them. Where your state provides an appeal from a refused request, you may appeal to privacy@tryorin.xyz and, if still dissatisfied, to your state Attorney General.

How to exercise a right

Export and delete are available directly in Settings. For anything else, email privacy@tryorin.xyz from the address on your account. We will:

  • acknowledge within 10 business days;
  • respond substantively within 30 days (GDPR) or 45 days (US state laws), extendable once where the request is complex, with notice to you;
  • verify your identity proportionately to the sensitivity of the request — usually by confirming control of the account email, never by asking for a government ID for a routine request;
  • charge nothing, unless a request is manifestly unfounded or repetitive, in which case we will say so first.
In plain English

You can download everything we hold and delete your account yourself, today, without emailing anyone. For anything else, write to us and we will answer within a month.

This summary is for readability. The numbered clause above it is what binds.

09Security

Concretely, and not as a list of adjectives:

  • All traffic is encrypted in transit (TLS). Data is encrypted at rest by our database provider.
  • Passwords are never stored or transmitted in plain text. Authentication is handled by a specialist provider; we never see your password.
  • Every database table enforces row-level security, so a request can only ever return rows belonging to the authenticated user. This is enforced by the database itself rather than by application code, which means a bug in our code cannot expose another user’s records.
  • The key that authorises payment-plan changes is held server-side only and is never present in anything your browser downloads.
  • Access to production data is limited to the operator and used only to run and repair the Service.
  • The event log is append-only: it cannot be silently rewritten, including by us.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay where the breach is likely to result in a high risk to your rights.

Report a vulnerability to security@tryorin.xyz. We will not pursue legal action against good-faith security research that respects user privacy, avoids service degradation, and gives us reasonable time to fix the issue before disclosure.

10Cookies and local storage

We set no advertising cookies and no cross-site trackers. Everything we store to run the product is strictly necessary to deliver a service you have asked for, which is the exemption in Article 5(3) of the ePrivacy Directive and the equivalent under PECR, and we do not ask permission for those.

Analytics is the exception, and it is on by default. We use Microsoft Clarity to see where the interface confuses people, and Vercel Web Analytics to count how many people reach each step. Neither qualifies for that exemption, and we load both when you arrive rather than asking first — so a request reaches Microsoft and Vercel, and Clarity’s two cookies are set, before you have chosen. One click in Settings stops both and deletes the cookies. You can turn them off at any time in Settings → Data & privacy, and the signed-in desk is masked so Clarity never receives your journal, positions, account size or analyses.

Vercel Web Analytics — counting, not recording. Our host also provides a page-view and event counter, and we use it to see how many people reach each step of the product — for example, how many hit the daily limit and how many open the upgrade screen. It sets no cookie and stores nothing in your browser. Vercel identifies a visit by a hash computed from the request and discards it after 24 hours, so there is no profile, nothing that follows you to another website, and nothing that can be traced back to your account. What it stores per event is the page path, the referrer, your approximate location from your IP address, and your browser and device type. The events we send it carry counts and labels only — never your identity, your email, the instrument you were looking at, or anything from your journal.

Reddit Pixel — measuring advertising, and the one thing we share. We advertise ORIN on Reddit, and the Reddit Pixel tells Reddit when someone who saw an ad went on to create an account or subscribe. Without it we would be paying for advertising with no way to know which of it works. It sets one cookie, _rdt_uuid, and it is the only thing on this site that qualifies as "sharing" personal information for cross-context behavioural advertising under California law — so it is named plainly rather than filed under analytics.

What Reddit receives is the page you were on, the fact that a signup or a subscription happened, and a one-way hash of your account id. It does not receive your email address, your phone number, any advertising device id, or anything at all from inside the product — not your journal, not your positions, not the instruments you look at. We chose the hash over the email address Reddit’s own setup guide suggests, because the whole authenticated desk is deliberately hidden from our analytics and handing an ad network the identifier we withhold from ourselves would make that pointless.

Turning analytics off in Settings → Data & privacy stops it and deletes its cookie, and a browser sending Global Privacy Control is treated as having opted out before anything loads. Under the CCPA that switch is your "Do Not Sell or Share My Personal Information" request, and we honour it as one.

The full item-by-item list — what is stored, why, and how long it lasts — is in the Cookie & Local Storage Policy.

Do Not Track and Global Privacy Control. There is no consensus standard for DNT, so we do not respond to it. We do honour Global Privacy Control signals, which under California law are treated as a valid opt-out of sale and sharing. A browser sending GPC is treated as having declined analytics: neither Clarity nor Vercel Web Analytics is loaded, no product event is recorded, and the signal overrides both the default and any stored acceptance.

11Children

The Service is for adults. We do not knowingly collect personal data from anyone under 18, and the Terms of Service require you to be 18 or older. If you believe a minor has given us personal data, contact privacy@tryorin.xyz and we will delete it and close the account. We do not knowingly sell or share the personal information of consumers under 16 — and we do not sell or share anyone’s.

12Changes to this policy

We may update this policy. The effective date at the top always reflects the current version. Where a change materially affects how we use data you have already given us, we will give at least 30 days’ notice by email before it takes effect, and — where the law requires consent for the new use — we will ask for it rather than assume it from continued use.

13Contact

Autusus LLC, c/o ZenBusiness Inc., 5511 Parkcrest Drive, Suite 103, Austin, TX 78731, United States.

If you are unhappy with our response you may complain to your supervisory authority (EEA/UK) or your state Attorney General (US). We would prefer you gave us the chance to fix it first.

Questions about this document go to legal@tryorin.xyz. The other documents in this set are listed here.