Privacy Policy
Effective September 9, 2026
Who we are and what this policy covers
Orpheon (Uptick Technologies Inc., "Orpheon", "we", "us") provides an IT and people-operations automation console that organizations ("Customers") use to connect the software they already run and to automate work across it. This policy describes how we collect, use, and share personal information through our website at orpheon.ai and our application at app.orpheon.ai (together, the "Services").
Much of the information Orpheon handles belongs to a Customer and comes from systems the Customer chooses to connect ("Customer Data"). For Customer Data, the Customer decides what is connected and what the Services do with it; Orpheon processes it only on the Customer's instructions and under the Customer's agreement with us, including any data processing agreement. If you are an employee or user of a Customer, your organization's administrator controls that data and is the right first contact for questions about it.
Information we collect
Account information. When you sign in, we receive your name, work email address, and the organization you belong to from your organization's single sign-on provider. We do not store passwords; authentication is handled by the identity provider your organization uses.
Customer Data. When a Customer's administrator connects a third-party service — for example a Google Workspace directory, a ticketing system, or a chat workspace — the Services access the data those connections are granted, such as user and group directories, tickets and their contents, files and file metadata, calendar sharing settings, and licenses. The Services access only what the connection's permissions allow and use it only to perform the automations and views the Customer configures.
Usage and log data. When you use the Services we automatically record technical information such as your IP address, browser and device type, the pages and features you use, timestamps, and request identifiers. We use this to operate, secure, and troubleshoot the Services and to maintain an audit trail of administrative actions.
Cookies. We use cookies that are strictly necessary to keep you signed in and to protect your session. We do not use advertising cookies or third-party tracking for marketing.
Support communications. If you contact us, we keep the messages and any information you choose to include so we can respond.
How we use information
We use information to provide, operate, and improve the Services; to run the automations Customers configure; to authenticate users and secure accounts; to keep audit records of administrative actions; to respond to support requests; to send operational communications about the Services; and to comply with law. Where a legal basis is required, we rely on performance of our contract with the Customer, our legitimate interests in operating and securing the Services, your consent where we ask for it, and compliance with legal obligations.
We do not sell personal information, and we do not use Customer Data for advertising.
Automated processing and AI
Some features use large language models to summarize, classify, or draft content — for example to summarize a ticket or explain what an automation does. To do this we send the relevant content to a third-party model provider under terms that prohibit the provider from using it to train models. We do not use Customer Data or your personal information to train machine-learning models, and we do not permit our providers to do so.
Automations that change data in a connected system run only as configured and authorized by the Customer's administrators, and administrative actions are recorded in the Customer's audit log.
How we share information
Service providers. We use a small number of providers that process information on our behalf: cloud infrastructure (Amazon Web Services, United States), durable workflow orchestration (Temporal Cloud, whose workflow history can carry the session material an automation captures from a connected service), identity and single sign-on (WorkOS), a language-model provider (OpenAI, via its API), browser automation infrastructure (Browserbase), and providers for support and product analytics. They may process information only to provide their services to us and under contractual confidentiality and security obligations.
Connected services. When a Customer connects a third-party service, the Services exchange information with that service as the Customer directs. That exchange is governed by the Customer's relationship with the third party and by the third party's own terms and privacy policy.
Legal and safety. We may disclose information when we believe it is necessary to comply with law or legal process, to protect the rights, property, or safety of Orpheon, our Customers, or others, or to investigate fraud or security incidents.
Business transfers. If Orpheon is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
Aggregated information. We may share aggregated or de-identified information that does not identify any person or Customer.
Google API Services User Data Policy
Orpheon's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When a Customer connects Google Workspace, Orpheon accesses Google user data only within the scopes the Customer's administrator grants — such as the user and group directory, license assignments, and calendar or file sharing settings — and uses it solely to provide and improve the user-facing features the administrator configures, such as provisioning accounts, managing group membership, and transferring resources during offboarding. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except with the Customer's consent, for security or abuse investigation, to comply with law, or for internal operations where the data has been aggregated or de-identified.
Retention and deletion
We retain account information and Customer Data for as long as the Customer's subscription is active and as needed to provide the Services. When a Customer's agreement ends, we delete or return Customer Data in accordance with that agreement, except where we must retain it to comply with law or to resolve disputes. Usage and log data is retained for a limited period for security and operational purposes and then deleted or de-identified.
Security
We protect information with technical and organizational safeguards appropriate to its sensitivity, including encryption in transit and at rest, envelope encryption of credentials for connected services, least-privilege access scopes, network isolation of the systems that hold credentials, and audit logging of administrative actions. No system is perfectly secure, and we cannot guarantee that information will never be accessed or disclosed in violation of this policy.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. To exercise these rights, contact us at legal@orpheon.ai. Where your information is Customer Data, we will refer your request to, or act on the instructions of, the Customer that controls it.
You may disconnect a connected service at any time from the Services, which stops further access to that service's data.
International transfers
The Services are operated from the United States, and information may be processed there and in other countries where our providers operate. Where required, we rely on appropriate transfer mechanisms, such as standard contractual clauses, for transfers of personal information from other jurisdictions.
Children
The Services are intended for use by organizations and their personnel and are not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. We will post the updated policy on this page with a new effective date and, for material changes, notify Customers through the Services or by email.
Contact us
Questions about this policy or our privacy practices can be sent to legal@orpheon.ai or to Uptick Technologies Inc., 420 E 54th St, New York, NY 10022.