Privacy Policy

Last updated: July 15, 2026. Applies to www.orionbiotechai.com and the ORION application.

Note on this document. This is a factual description of what the product actually collects and does today, written directly from the source code rather than a generic template — but it has not been reviewed by a privacy attorney. Recommended before relying on this in a regulated market (GDPR/CCPA jurisdictions in particular): a licensed privacy-law review of this text and of ORION's actual data flows.

1. What we collect

DataWhenWhy
Email address, password (hashed)Account signup/loginAuthentication — handled by Supabase Auth; ORION never sees or stores your raw password
Company/ticker/indication search queriesEvery analysis you runTo generate your report — your query text is sent to Anthropic's Claude API to write the narrative sections
Watchlist entries, saved reports, prediction historyWhile using the appCore product functionality (Watchtower, Thesis Ledger, Track Record). Signed-in watchlists are stored server-side; a signed-out watchlist may remain only in that browser.
Portfolio name, ticker, company, shares, market value, cost basis, as-of date, and notesOnly when you create a portfolio or upload positionsPortfolio catalyst and risk dashboards. ORION does not connect to or import data from your broker; values are stored as supplied by you and are not inferred when omitted.
Organization membership, invitation email, role changes, and administrative audit eventsOnly inside an explicitly provisioned organization pilotPilot seat management, role-based access control, invitations, and administrative audit records. This is not a generally available self-serve feature.
Notification destination and delivery statusOnly when a delivery channel is enabled by the backend and you explicitly configure itSending requested alerts. Email and Slack channel creation are currently disabled until their separate operational capabilities are verified.
Subscription tier, billing statusFor an existing server-recorded subscription, or after live checkout is activated and explicitly usedConditional payment processing through Toss Payments; ORION does not receive or store your card number.
API keys you generateIf you use the APIAuthenticating your own programmatic requests

We do not require your name, phone number, physical address, or government ID to create an ORION account. ORION collects portfolio information only when you deliberately upload it; it does not connect to your broker or infer missing position values. Company analysis output is generated from the same research workflow for users running the same query and is not personalized financial advice, while the portfolio dashboard organizes the positions and values you supplied.

2. Who we share it with

We do not sell your data, and we do not run third-party advertising or analytics trackers on this site today. Data is shared only with the service providers required to run the product:

ProviderWhat they receivePurpose
SupabaseAccount email, hashed password, and signed-in app data such as watchlists, reports, predictions, source snapshots, change events, and data-rights requestsAuthentication and database hosting
Toss PaymentsBilling email and payment method directly provided during an authorized checkoutOnly when live billing is activated and the user explicitly starts checkout; unavailable during merchant review.
Anthropic (Claude API)The company/ticker/indication text of each search you runGenerating the AI-written narrative sections of your report
Vercel and RenderRequests to the web application and backend, including standard network and request metadataFrontend and backend application hosting
ResendYour verified account email and requested message contentOnly when a sending domain is verified, the backend explicitly enables email delivery, and you request an enabled email workflow. No newsletter, alert, or invitation delivery request is created by the current disabled UI.
SlackWatchtower alert content and the incoming-webhook URL you provideOnly when Slack delivery is separately operationally verified, enabled by the backend, and explicitly configured. It is currently unavailable.

ORION also queries public data sources (ClinicalTrials.gov, Yahoo Finance, Financial Modeling Prep, SEC EDGAR, FDA public disclosures) to build reports — these calls concern the company you searched for, not you personally, and do not send your account information to those sources.

We may disclose data if legally required to (subpoena, court order) or to investigate fraud/abuse of the service.

3. Cookies & local storage

ORION uses browser session storage for the Supabase sign-in session in the current tab. Local storage is used for on-device preferences, onboarding progress, a signed-out watchlist fallback, and a randomly generated first-party analytics identifier. That identifier is sent only to ORION's own backend with allowlisted product events; search text, report content, authentication tokens, and cross-site advertising identifiers are not included. Local storage is not trusted as proof of a paid tier. When you sign in, eligible watchlist items are synchronized to the account's server-side watchlist. No advertising or cross-site tracking cookies are set by this site.

4. Retention

Account and editable watchlist data are retained while the account is active. Reports, predictions, source snapshots, change events, and thesis versions are append-only product records: corrections are recorded as later versions rather than silently overwriting history. If you request account deletion, access is deactivated after review; records required for security, billing, legal obligations, or the integrity of an aggregate de-identified track record may be retained only for those purposes. ORION has not yet published fixed deletion windows for every record class; those windows require privacy-counsel approval before a production retention policy is finalized.

5. Your rights

You can submit an authenticated access, export, correction, objection, or account-deletion request through the Account data request form. A deletion request is reviewed before processing and does not itself cancel an active subscription. Depending on your jurisdiction, you may have additional rights under applicable law; licensed privacy counsel must review how those laws apply to ORION.

6. Security

Authentication tokens are verified server-side on protected requests and paid tier state is read from the server rather than browser storage. If live Toss billing is activated, payment card data is handled by Toss Payments rather than ORION's servers. Service-role database credentials and third-party API keys remain server-side. Notification-channel encryption exists in backend code, but outbound email and Slack are not represented as operational until their separate capability flags are enabled and delivery is validated.

7. Children's privacy

ORION is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect data from children.

8. Changes to this policy

If this policy changes materially, we will update the "Last updated" date above. Continued use of ORION after a change constitutes acceptance of the updated policy.

9. Contact

Questions about this policy or your data: orion.biotech.ai@gmail.com.