Skip to content

Privacy

What we do with your data, and what we don’t

Last updated 3 September 2026

Orblex is a CRM that reads the email and calendar you already have and turns it into records you can question. That means it handles some of the most sensitive material a business has: what your customers said to you. This page says exactly what happens to it.

Who we are

Orblex is operated by [legal entity name], [registered address]. For anything in this policy, including a request to export or delete your data, write to [privacy@yourdomain].

What we collect

Your account

  • Your name and email address.
  • A password, stored only as a one-way hash. We cannot read it, and neither can anyone who obtains the database.
  • Session records, so signing out on one device revokes that session.

Your CRM records

Whatever you put in: accounts, contacts, opportunities, tasks, notes, meetings and the activity timeline that connects them.

Mail and calendar, if you connect them

Connecting a Google account is optional and the product works without it. If you do connect one, we read and store:

  • Messages — subject, full body text, sender, recipients and timestamps for messages in the connected mailbox, so the record can show the conversation a fact came from.
  • Calendar events — title, time, description and participants, so meetings appear against the right account.
  • Your Google profile — name, email address and account id, to identify the connected mailbox.

We request read-only access to Gmail and Calendar. We also request permission to send mail, used only for a message you have read and explicitly approved; nothing is ever sent automatically. We never modify, label, archive or delete anything in your mailbox.

Google API Services — Limited Use

Orblex’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Google user data is used only to provide and improve the features you can see in the product — building the record, answering your questions about it, and preparing work for your approval.
  • We do not transfer it to others except as described under “Who else sees it”.
  • We do not use it for advertising, and we do not sell it.
  • No human at Orblex reads your messages, except where you explicitly ask us to for support, where it is necessary for security, or where the law requires it.
  • We do not use it to train generalised artificial-intelligence models.

What the AI does with it

When an AI provider is configured, the text of a message or meeting may be sent to that provider to extract structured facts, to answer a question you asked, or to produce the numerical embedding that makes search work. We send the minimum needed for the task rather than your whole database.

The provider is configured by whoever operates this deployment, from Anthropic, OpenAI or Google. Each processes the request under its own API terms, and none of them use API content to train their models by default. The result comes back, is stored on the record, and the request is not retained by us beyond a usage record — model, operation, token count and estimated cost — which contains no message content.

A deployment with no provider configured never sends your content anywhere. Search still works; the assistant returns the records it found rather than a written answer.

Who else sees it

We use a small number of processors, each doing one job:

  • Our hosting and database provider, to run the application and store your data.
  • An AI provider (Anthropic, OpenAI or Google), as described above, and only when one is configured.
  • Google, when you choose to connect Gmail or Calendar.

We do not sell your data, we do not share it with advertisers, and we do not use one customer’s data to serve another. Each workspace is isolated: every query is scoped to the workspace of the person making it, and that isolation is covered by automated tests.

How it is protected

  • Traffic is encrypted in transit with TLS.
  • Google access and refresh tokens are encrypted at rest with AES-GCM before they are written to the database.
  • Passwords are stored only as one-way hashes.
  • Session cookies are HTTP-only and marked Secure, so they cannot be read by scripts in the browser.
  • Access inside a workspace is limited by role, and sensitive actions are checked on the server rather than in the interface.

How long we keep it

Records are kept until you delete them. Deleting a record removes it from the product immediately and it is purged from backups on their normal rotation.

Disconnecting a mailbox stops all further syncing and deletes the stored tokens. Messages already synced remain on the records they were attached to unless you delete them.

Deleting a workspace deletes everything belonging to it — records, messages, meetings, memories, agent runs and connected-account credentials — by cascade, not by a cleanup job that might miss something.

Your rights

You can ask us to export your data, correct it, or delete it, and we will do so within thirty days. If you are in the UK, EU or another jurisdiction with equivalent rights, you also have the right to object to processing and to complain to your data-protection authority.

Children

Orblex is a tool for businesses. It is not intended for anyone under 16 and we do not knowingly collect their data.

Changes

If we change how we handle your data in a way that matters, we will say so here and email the owner of each workspace before the change takes effect. The date at the top of this page is the last time it changed.

Questions about any of this? Ask us — a person reads every message.