Privacy Policy
Last updated 2026-07-07
1. Scope
This policy describes what data Orgsemble collects when you use the service, where it is stored, and how it is used. It is written to match what the product actually does today; when the product changes, this page changes with it.
2. What we collect
- Account data. Your name, email address, and a hashed password (passwords are stored only as one-way hashes, never in plain text). If you sign in through a configured identity provider, we store the identity that provider asserts.
- Content you create. Organizations, charts, and the people data you place on them (names, titles, emails, photos), projects, sites, surveys and survey responses, compliance checklists, and files you import.
- Operational data. An audit log of actions inside your organization, session data needed to keep you signed in, API tokens (stored only as hashes), and basic request records used for rate limiting.
- Credentials you supply for integrations. Directory-sync credentials and any AI provider API keys you connect are stored encrypted and used only to perform the integration you configured.
3. Where your data lives
Your data is stored in a PostgreSQL database operated for the service. Uploaded images are re-served through the service's own origin rather than fetched by your browser from third-party hosts.
4. How we use data
Data is used to operate the service: rendering your charts and records, enforcing the roles and permissions you set, matching a signed-in member to their seat on a chart by email, running the schedules and notifications you configure, and keeping the audit log your organization's admins can review. We do not sell your data and we do not use your content for advertising.
5. Email
The service does not send email today. Your email address is used for sign-in, for matching you to your seat on a chart, and for display to the people you collaborate with. It is not used for marketing. If email sending is introduced (for example invitations or password reset), this policy will be updated first.
6. Cookies and local storage
The service sets a session cookie to keep you signed in, and stores your theme preference in your browser's local storage. There are no third-party analytics scripts, advertising pixels, or cross-site trackers; the application only talks to its own origin.
7. Third-party connections you configure
Two kinds of outbound connections exist, and both happen only when you configure them. Directory sync reads people data from the external system you connect (for example a corporate directory) using credentials you supply. AI connections send the text you ask an AI feature to process to your own AI provider account, under your key and that provider's terms. The service holds no AI provider key of its own.
8. Sharing and disclosure
Your content is visible to the people you share it with: members of your organizations according to their roles, per-chart grants, and anyone holding a share link you created, at the level that link grants. We disclose data to others only when required by law or to protect the service, and we will tell you when we are permitted to.
9. Retention and deletion
Content stays until you delete it or your organization's admins do. Deleting a chart, project, or organization removes it from the product; to request deletion of your entire account and its data, contact hello@orgsemble.com. Backups, where kept, age out on a fixed schedule after deletion.
10. Security
Passwords and API tokens are stored as hashes; integration credentials are stored encrypted; every read and change is checked against your role and permissions; and admin-relevant actions are recorded in the audit log. No system is perfectly secure. To report a vulnerability, see /.well-known/security.txt.
11. Your rights
You can view and correct your account data in the product, export your charts and reports, and request a copy or the deletion of your data at hello@orgsemble.com. Depending on where you live you may have additional legal rights; requests are honored regardless of jurisdiction where we reasonably can.
12. Changes to this policy
The date at the top of this page is the date of the current version. For material changes we will post notice in the product before the change takes effect.
13. Contact
Privacy questions and requests: hello@orgsemble.com.