Last updated: September 14, 2026. Applies to www.orionbiotechai.com and the ORION application.
| Data | When | Why |
|---|---|---|
| Email address, password (hashed) | Account signup/login | Authentication — handled by Supabase Auth; ORION never sees or stores your raw password |
| Company/ticker/indication search queries | Every analysis you run | To generate your report — your query text is sent to Anthropic's Claude API to write the narrative sections |
| Watchlist entries and saved reports | While using the app | Core research functionality (Watchtower and evidence records). Signed-in watchlists are stored server-side; a signed-out watchlist may remain only in that browser. |
| Portfolio name, ticker, company, shares, market value, cost basis, as-of date, and notes | Only when you create a portfolio or upload positions | Portfolio catalyst and risk dashboards. ORION does not connect to or import data from your broker; values are stored as supplied by you and are not inferred when omitted. |
| Organization membership, invitation email, role changes, and administrative audit events | Only inside an explicitly provisioned organization pilot | Pilot seat management, role-based access control, invitations, and administrative audit records. This is not a generally available self-serve feature. |
| Notification destination and delivery status | Only when a delivery channel is enabled by the backend and you explicitly configure it | Sending requested alerts. Email and Slack channel creation are currently disabled until their separate operational capabilities are verified. |
| Subscription tier, billing status | For an existing server-recorded subscription, or after live checkout is activated and explicitly used | Conditional payment processing through Toss Payments; ORION does not receive or store your card number. |
| Voluntary review feedback: category, usefulness, comment, optional email and reply consent | Only when you submit the feedback form | Improving proposal reviews and responding if requested. No document text or account identifiers are automatically attached. A daily keyed hash of the request IP address is stored to limit abuse; the feedback table does not store the raw IP. |
| API keys you generate | If you use the API | Authenticating your own programmatic requests |
We do not require your name, phone number, physical address, or government ID to create an ORION account. ORION collects portfolio information only when you deliberately upload it; it does not connect to your broker or infer missing position values. Company analysis output is generated from the same research workflow for users running the same query and is not personalized financial advice, while the portfolio dashboard organizes the positions and values you supplied.
Account and editable watchlist data are retained while the account is active. Reports, source snapshots, change events, and evidence-record versions are append-only product records: corrections are recorded as later versions rather than silently overwriting history. If you request account deletion, access is deactivated after review; records required for security, billing, or legal obligations may be retained only for those purposes. ORION has not yet published fixed deletion windows for every record class; those windows require privacy-counsel approval before a production retention policy is finalized.
For feedback submitted without an account, email orion.biotech.ai@gmail.com with the receipt shown after submission to request access, correction or deletion. Feedback is accessible to the ORION operator for review and is not published or counted as a customer. We have not set an automatic deletion period for feedback.
You can submit an authenticated access, export, correction, objection, or account-deletion request through the Account data request form. A deletion request is reviewed before processing and does not itself cancel an active subscription. Depending on your jurisdiction, you may have additional rights under applicable law; licensed privacy counsel must review how those laws apply to ORION.
Authentication tokens are verified server-side on protected requests and paid tier state is read from the server rather than browser storage. If live Toss billing is activated, payment card data is handled by Toss Payments rather than ORION's servers. Service-role database credentials and third-party API keys remain server-side. Notification-channel encryption exists in backend code, but outbound email and Slack are not represented as operational until their separate capability flags are enabled and delivery is validated.
ORION is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect data from children.
If this policy changes materially, we will update the "Last updated" date above. Continued use of ORION after a change constitutes acceptance of the updated policy.
Questions about this policy or your data: orion.biotech.ai@gmail.com.