Data and privacy
What OrgBolt stores, who processes it, and how you get it back or delete it.
Security overview
What OrgBolt stores
OrgBolt stores the data it needs to run the product and nothing else. Specifically:
- Your account (email, display name, password hash, workspace memberships)
- Task transcripts — the chat messages between you and the AI, including AI-generated metadata
- Deploy records — which task deployed which metadata to which org, when, and the Salesforce deploy ID
- Salesforce OAuth tokens, encrypted at rest via Supabase Vault (pgsodium)
- Audit log entries — one row per significant action (login, task created, deploy attempted, member invited)
- Saved result sets — the record data from a data query, but only the ones you click Save on (see the Data Queries topic)
Who processes your data
Six sub-processors touch your data in the course of running OrgBolt. The full list is on the Privacy Policy page and the Security page at orgbolt.com/security.
- Supabase — the Postgres database and auth provider that holds everything
- Anthropic — the AI provider that runs Work and Deploy inference. On the API plan, Anthropic does not store or train on your data.
- Hetzner — the VPS host (Ashburn, Virginia) where OrgBolt's server runs
- Cloudflare — DNS, tunnel routing, and Turnstile bot protection
Export your data
Settings → Data Export produces a single JSON file containing every task, chat message, deploy record, and workspace setting that belongs to you. The export is generated on demand — not on a schedule — so it always reflects the current state of your account. This is GDPR Article 20 (right to portability). The export is available to everyone, EU or not.
Delete your account
Settings → Delete Account starts a 30-day soft delete. Your data is immediately hidden from the app and cannot be accessed. If you change your mind within 30 days, you can contact [email protected] to restore it. After 30 days a scheduled daily job permanently removes:
- Your profile and all tasks / chat messages / deploy records
- Salesforce OAuth tokens (revoked via Salesforce immediately on deletion request, not 30 days later)
- Workspace data where you were the sole owner
Audit log entries are retained for 7 years but anonymized — the user_id column is set to null. This is a compliance requirement, not a product decision: regulators can ask for a record that a deploy happened, but that record cannot contain personal data after account deletion.
If you own a workspace with other members, Salesforce's data is still their data — deletion cannot orphan a shared workspace. OrgBolt will prompt you to transfer ownership to another member first, then complete your account deletion.