Orchi Privacy Policy
Effective date: October 1, 2026
Orchi is a personal assistant and concierge service provided by Fosh Holdings LLC ("Fosh Holdings," "Orchi," "we," "us," or "our"). This Privacy Policy explains how Orchi handles personal information when you use the Orchi mobile application, related websites, support channels, and connected services (collectively, the "Service").
1. Information Orchi handles
Account and profile information
We handle information used to create and maintain your account, such as your account identifier, email address, preferred name, home region, time zone, language, and settings. We also store the name, voice, personality, response-length, and proactivity settings you choose for your personalized assistant.
Conversations, transcripts, and persistent memory
When you type or speak to Orchi, the Service processes your request and the response. Orchi stores text conversation records and transcripts associated with your account so that you can continue conversations and so the Service can operate. The current implementation does not intentionally store raw microphone audio as an Orchi account record. Voice audio is transmitted for real-time processing by our voice service provider, and resulting transcript text may be stored.
Orchi is designed to remember relevant facts, preferences, routines, relationships, constraints, corrections, approvals, and task outcomes. These memories and related Life Graph records may be derived from information you provide or from your interactions with the Service. You can review, correct, or remove individual memories through the Service. Removing a memory also removes its corresponding active Life Graph projection.
Tasks, approvals, recommendations, and activity
We handle the requests you ask Orchi to complete, planned actions, approval decisions, external handoffs, recommendations, reminders, commitments, task outcomes, and related audit and usage records. This can include names of people, destinations, timing, preferences, and other information contained in your request.
Voice and usage information
We handle voice-session identifiers, session timing, usage quantities, and related technical metadata needed to operate the Service, enforce plan limits, understand costs, and diagnose failures. As described above, transcript text may be retained with your conversation history, but raw microphone audio is not intentionally stored as an Orchi account record in the current implementation.
Location and travel information
If you grant foreground location permission and ask for location-dependent help, Orchi may use your current or recently available device location to calculate routes, travel time, nearby results, and departure reminders. Orchi does not request background location access in the current release. Saved commitments may include destinations, coordinates, addresses, route estimates, arrival buffers, and recently used route origins.
Calendar and reminders
If you grant calendar permission, Orchi can add calendar events when you ask. When you request or generate a Daily Brief, Orchi may read events for the current day—including event titles, times, locations, and notes—and send that selected information to Orchi's backend for the brief. If you grant notification access, Orchi can create local reminders and receive push notifications. Orchi stores notification preferences and an Expo push token associated with your account when remote notifications are enabled.
The current release does not request or read your device address book. Information about people may still be included if you provide it in a conversation, task, memory, calendar event, email, or file.
Gmail integration
If you choose to connect Gmail, Orchi requests Google account identity information and permission to read Gmail messages and send Gmail messages. Orchi uses these permissions to search messages when you ask, identify relevant confirmations, receipts, subscriptions, or time-sensitive items for enabled Radar features, and send messages only through the applicable approval flow.
We store the connected Google account identifier and label, granted scopes, connection status, and OAuth access and refresh tokens. Tokens are held in a server-only database area and are not included in the mobile application. You can disconnect Gmail in Orchi, which attempts to revoke the Google token and removes the stored connection and token records. You can also revoke access through your Google Account.
Vault files, photos, and documents
If you choose to use Vault, you may select a document or photo or take a new photo. Orchi stores the uploaded file in object storage and stores associated information such as its filename, type, size, source, title, summary, category, and analysis. To classify and summarize a Vault item, Orchi may provide a time-limited file link to its processing provider. You can open or delete individual Vault items. Account deletion is designed to remove the active Vault objects associated with the account before deleting the account.
Subscription and transaction information
Apple processes App Store purchases. Orchi does not receive your complete payment-card number. Orchi and RevenueCat receive and handle product identifiers, transaction and subscription status, entitlement status, expiration information, and related identifiers needed to provide Premium or Concierge access, restore purchases, and maintain account quotas. Orchi may also store records related to optional tips if offered in the Service.
Technical and service information
We handle device platform, application environment, authentication/session information, network requests, error information returned by Service components, and operational records needed to keep the Service functioning. Weather searches may send a place query or coordinates to Open-Meteo. Location-based place and route requests may be sent to Google Maps Platform services.
2. How we use information
We use personal information to:
- authenticate users and maintain accounts;
- provide conversations, voice interaction, persistent memory, Life Graph, tasks, recommendations, Daily Brief, Radar, Vault, travel assistance, reminders, and connected-service features;
- carry out or prepare actions you request and preserve approval boundaries for consequential actions;
- personalize responses and remember relevant context;
- provide plan access, storage quotas, purchase restoration, and subscription status;
- send requested reminders, service notifications, and proactive alerts according to your settings;
- operate, troubleshoot, secure, and improve the Service;
- prevent misuse and enforce our Terms of Service; and
- comply with law and protect users, Fosh Holdings, and others.
3. When information is disclosed
We disclose information only as needed for the uses described above, including to the following categories of recipients:
- Supabase, for authentication, database services, server functions, and related backend infrastructure;
- OpenAI, for real-time voice processing, text processing, research or response generation, and Vault-file classification where the feature requires it;
- Cloudflare R2, for Vault object storage;
- Google, when you connect Gmail or use Google identity, Gmail, Places, or Routes functionality;
- Apple, for App Store distribution, purchases, subscription management, and device services;
- RevenueCat, for purchase validation, entitlements, and subscription lifecycle management;
- Expo, for application update infrastructure and push-notification delivery;
- Open-Meteo, for weather and geocoding requests; and
- external websites or providers that you direct Orchi to open or use for a requested task.
These providers process information under their own terms and privacy practices as well as any applicable agreements with us.
We may also disclose information if reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate fraud or misuse, or complete a merger, financing, acquisition, reorganization, or sale of assets subject to appropriate notice and legal requirements.
The current Orchi implementation does not include an advertising SDK or a feature for cross-context behavioral advertising. This statement does not change the operational disclosures to service providers described above. We do not make a broader legal characterization of a "sale" or "sharing" without considering the law that applies to you and our then-current business practices.
4. Your choices and controls
Depending on the feature and your device, you can:
- use text without granting microphone access;
- grant or revoke microphone, camera, photo-library, calendar, reminder, location, and notification permissions in device settings;
- review, correct, and remove memories and Life Graph information;
- approve or decline consequential actions;
- change notification and proactive-assistance preferences;
- disconnect Gmail and revoke its permissions;
- open or delete individual Vault items;
- restore or manage App Store purchases; and
- permanently delete your Orchi account from within the app.
Deleting your Orchi account does not cancel an App Store subscription. Subscription management and account deletion are separate actions. You can manage an Apple subscription through your Apple account or the App Store subscription-management screen.
You may also request access, correction, or deletion where provided by applicable law by contacting us using the information below. We may need to verify your identity before completing a request.
5. Retention and deletion
We retain account information and user content while your account is active and as needed to provide the Service. Different categories may be kept for different periods depending on the feature, operational needs, legal requirements, dispute resolution, fraud prevention, and provider backup or recovery processes. We do not state a fixed retention period because the current implementation does not define one that applies uniformly to all data.
When you use in-app account deletion, Orchi is designed to delete active Vault objects, revoke a connected Google token where available, and permanently delete the authentication account. Deleting the authentication account cascades through associated active application records under the current database schema, including profiles, memories, conversations, tasks, integrations, and billing-account records. A deletion may fail safely rather than orphaning Vault objects if the object-storage service is unavailable or not configured.
Residual copies may remain temporarily in service-provider backup or recovery systems, and we may retain limited information where legally required or reasonably necessary for security, fraud prevention, or resolving disputes. We will not use retained information for unrelated purposes.
6. Security
Orchi uses technical and organizational measures appropriate to the current Service, including authenticated account access, database row-access policies, server-side provider credentials, time-limited Vault links, and approval controls for consequential actions. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
7. Children
The Service is not directed to children under 13, and we do not knowingly seek personal information from children under 13. If you believe a child has provided information to Orchi inappropriately, contact us so we can review and address the account.
8. United States privacy rights
Residents of some U.S. states may have rights to request access, correction, deletion, or a copy of personal information, and to appeal certain decisions. The rights available depend on the law that applies and may be subject to exceptions. Submit a request using the contact information below. We will not discriminate against you for exercising an applicable privacy right.
9. International processing
Orchi and its providers may process information in the United States and other places where they operate. Privacy laws in those locations may differ from those where you live. Before offering the Service in jurisdictions that require a specific transfer mechanism or local representative, Fosh Holdings will update this Policy and its operational arrangements as required.
10. Changes to this Policy
We may update this Policy as the Service changes. We will post the updated version and revise its effective date. If a change is material, we will provide additional notice when required by law.
11. Contact
Fosh Holdings LLC
[email protected]
1999 N University Dr, Ste 212
Coral Springs, FL 33071