Legal

Privacy policy

Last updated

What we collect, why, who else handles it, and the choices you have. In plain words, because you should be able to read it.

The short version

  • Your business data belongs to your organization. We use it only to run Orcabase for you.
  • We never sell your information, and we don’t train AI models on your data.
  • The Data Agent sends AI models small samples of results (at most 30 rows), never passwords or keys.
  • You can export your data, or ask us to delete it, at any time.

This summary helps you find your way; the full text below is what applies.

01

Who we are

Orcabase is made by Tinilab Limited Company (“Tinilab”, “we”, “us”), of 39 Le Hien Mai, Phuong Cat Lai, Ho Chi Minh City, Vietnam. This policy covers our website at tini.so, the Orcabase app at app.tini.so, and our API and AI connectors (together, “Orcabase”).

Questions about your privacy, or a request about your data? Email hello@tinilab.com.

Orcabase handles two kinds of information, and our role is different for each:

  • Information about you, like your name and email address. We decide how it’s used, so we’re responsible for it.
  • Your organization’s business data: the databases, spreadsheets and apps you connect, and what you build from them. Your organization owns it and decides what goes into Orcabase. We handle it only to run Orcabase for you, as your organization instructs through the product and under our Terms of service.

02

What we collect

When you visit the website

Which pages you open, the page that sent you, and your browser, device type and rough location (country or city, worked out from your IP address). We use this to see which pages help people and which don’t.

When you use the app

  • Your account. You sign in with Google, which shares your name and email address with us. We never see or store your Google password.
  • Your organization and team. Its name, who belongs to it, each person’s role, and the invites you send.
  • What you connect. Connection details for your data sources, including database passwords, service account keys and AI provider keys. These are encrypted before they’re stored and never sent back to your browser.
  • What you build. Queries, dashboards, notebooks, data models, metrics and their history, and your chats with the Data Agent.
  • Query results. Connected databases are queried live, where they are. We keep the latest result of each saved query (at most 5,000 rows) so dashboards open quickly.
  • Hosted data. If you use data hosting, syncs or file uploads, we store that data for you in a warehouse we run.
  • AI usage. For every call to an AI model: which model, who asked, in which chat, how many tokens went in and out, and the cost.
  • How the app is used. The screens you open and the actions you take, linked to your email address and organization, so we can see which features work and help you when something goes wrong.
  • Technical logs. IP addresses, request times and errors, which keep Orcabase secure and help us fix problems.

When you contact us

What you choose to tell us, and our reply.

03

How we use it

We use it toWhy we’re allowed to
Run Orcabase: sign you in, connect your data, answer your questions and show your dashboardsTo provide the service you signed up for
Keep Orcabase secure: stop abuse, investigate problems, keep organizations apartOur legitimate interest in a safe service, and yours
Improve Orcabase: learn which features work and which confuse peopleOur legitimate interest in making Orcabase better
Talk to you about your account, changes to Orcabase and these policiesTo provide the service, and our legitimate interest
Bill your organization and keep records the law asks forTo provide the service, and legal obligations

We never sell your information, and we never use your organization’s business data to advertise to you or anyone else.

We don’t train AI models on your data. Whether an AI provider may keep or learn from the requests it receives is set by that provider’s terms; see How the Data Agent handles your data.

04

How the Data Agent handles your data

When you ask the Data Agent a question, parts of the conversation are sent to an AI model:

  • Your question and the chat so far.
  • The names of your data sources, tables and columns, and the definitions of your models and metrics.
  • Small samples of query results: never more than 30 rows or 16,000 characters of any one result.

Passwords, keys and other credentials are never sent to a model, and neither is data from any other organization.

Each request passes through an AI gateway (OpenRouter or Vercel AI Gateway) to the company that runs the model (for example Anthropic, OpenAI or Google). If your organization uses its own AI key, your own agreement with that gateway applies, including any data settings you choose there. If it uses Orcabase AI, requests go through our own gateway account. Either way, that provider’s terms decide how long requests are kept and whether they may be used for training.

The same applies when you connect Orcabase to Claude or ChatGPT: what your assistant receives from Orcabase is then governed by your agreement with that assistant’s maker. More detail is in AI privacy and usage.

05

Who else handles it

We use a few trusted companies to run Orcabase. Each gets only what it needs for its job, and is bound to protect it.

CompanyWhat they do for OrcabaseWhen
GoogleSign-inAlways
VercelHosts the website and the app’s pagesAlways
Cloud hosting providersRun our servers, databases and backupsAlways
CloudflareSecures connections to our serversAlways
OpenPanelWebsite and product analyticsAlways
OpenRouter or Vercel AI Gateway, and the model’s makerRun the AI models behind the Data AgentWhen you use the agent
FivetranSyncs data from apps you connect through itOnly if you connect one

Beyond these, we share information only:

  • With the people in your organization, as your organization’s settings and sharing choices allow.
  • With anyone who opens a public dashboard link you create. Turning the link off stops access at once.
  • When the law requires it, or to protect people’s safety or Orcabase’s security.
  • If Tinilab is merged or sold, with the new owner, who must keep honoring this policy. We’ll tell you first.

06

Cookies and similar tech

We keep this short, because we keep it small:

  • Sign-in. The app stores a session so you stay signed in. It’s required for the app to work.
  • Analytics. OpenPanel stores a random ID in your browser so repeat visits count as one visitor. It doesn’t follow you to other websites, and signing out of the app clears it.

We don’t use advertising cookies or cross-site tracking.

07

How long we keep it

  • Your account and your organization’s content are kept for as long as your organization uses Orcabase.
  • When an organization leaves, we keep its content for 30 days so it can change its mind or take a copy, then delete it. Copies in our backups are overwritten within a further 30 days.
  • When someone is removed from an organization, they lose access within 15 minutes. What they built stays with the organization.
  • Technical logs are kept for up to 90 days, unless we need them longer to investigate a security problem.
  • Billing records are kept for as long as tax and accounting laws require.

08

How we protect it

  • Everything travels over HTTPS, and passwords and keys are encrypted at rest with AES-256-GCM.
  • Every request checks that you belong to the organization whose data you’re asking for.
  • API tokens are stored only as a one-way fingerprint.
  • The Data Agent and AI assistants can create things, but never edit or delete them.

No system is perfectly secure, but we work hard to keep yours safe. If we ever learn of a breach that affects your information, we’ll tell you without undue delay. The details are on our Security page.

09

Your rights and choices

Wherever you live, you can ask us to:

  • Tell you what information we hold about you, and give you a copy.
  • Correct anything that’s wrong.
  • Delete your information, or stop or limit how we use it.
  • Give you your information in a format you can take elsewhere.

Your organization’s business data is always exportable: connected databases never leave your hands, hosted Postgres servers come with connection strings, and we’ll export anything else on request. If you’re asking about data that belongs to an organization, we’ll pass the request to its admins, who decide.

Email hello@tinilab.com and we’ll reply within 30 days. If you’re in the EU, UK or another place with data protection laws, you can also complain to your local data protection authority, though we’d like the chance to put things right first.

10

Where your data lives

We and the companies above may process information in countries other than yours, including the United States. When we move information across borders, we use the safeguards the law requires, such as standard contractual clauses.

11

Children

Orcabase is a tool for businesses, not for children. You must be at least 16 to use it, and we don’t knowingly collect information from anyone younger. If you think a child has given us information, tell us and we’ll delete it.

12

Changes to this policy

If we change this policy, we’ll update the date at the top. If a change matters, we’ll tell you in the app or by email before it takes effect.

Questions about this page? Email hello@tinilab.com

Tinilab Limited Company, 39 Le Hien Mai, Phuong Cat Lai, Ho Chi Minh City, Vietnam

Terms of service