Privacy Policy
Effective date: April 5, 2026 · Last updated: May 19, 2026
Who We Are
OrgBolt, LLC (“OrgBolt,” “we,” “us,” “our”) is an AI-powered Salesforce change management platform. We are based in the United States. For privacy inquiries, contact us at [email protected].
Data We Collect
| Category | Examples |
|---|---|
| Account data | Email address, display name, workspace name, password hash |
| Salesforce integration | OAuth tokens (encrypted at rest), org metadata, instance URL |
| AI conversation data | Chat messages, task descriptions, AI-generated outputs |
| Usage data | Actions performed (via audit log), token consumption |
| Technical data | IP address, browser type (via Cloudflare), cookies |
Legal Basis for Processing
Under GDPR Article 6, we process your data on the following bases:
- Contract performance — providing the OrgBolt service you signed up for
- Legitimate interest — security, fraud prevention, service improvement
- Consent — non-essential cookies (Cloudflare Turnstile), marketing communications
- Legal obligation — tax records, breach notification compliance
How We Use Your Data
- Provide, maintain, and improve the OrgBolt platform
- Process AI inference — chat messages are sent to Anthropic's Claude API for processing. On the API plan, Anthropic never trains on your data and deletes inputs and outputs within 30 days.
- Authenticate your identity and manage sessions
- Protect against bots and abuse (Cloudflare Turnstile)
- Comply with legal obligations
OrgBolt Support Access
You can grant OrgBolt support staff read-only access to your workspace at any time from Settings → Support Access. You choose the duration (1 day to 1 month); access auto-expires at the end of that window, and you can revoke it at any moment.
While accessing your workspace under a grant, OrgBolt staff can only read — they cannot send AI messages, deploy to your connected Salesforce orgs, modify tasks, change settings, or otherwise alter any data. Every write attempt is blocked at the request layer.
All grant creations, revocations, and staff sessions are recorded and visible to you in your workspace’s support access history (also under Settings → Support Access) — including which staff member opened each session, when it started, and when it ended. We never access your workspace without an active grant from you.
If an OrgBolt Staff member is added to your Workspace, AI requests sent during their membership are persisted in full for debugging purposes. When the last Staff member leaves, those snapshots are deleted in the same transaction.
Sub-Processors
We share data with the following service providers under their standard terms of service; each vendor's data-processing terms are available via their trust page:
| Vendor | Data Processed | Location |
|---|---|---|
| Supabase | All application data (Postgres, Auth) | US |
| Anthropic | AI chat messages (inference only, deleted within 30 days) | US |
| Hetzner | Infrastructure hosting | US (Ashburn, VA) |
| Cloudflare | DNS, tunnel, Turnstile tokens, cookieless web analytics (Insights) | Global CDN |
| GitHub | In-app feedback reports (your name, email, workspace name and the report text, filed as a private issue) | US |
| Pushover | Staff notification when a feedback report is filed (your name, email, workspace name and the first 300 characters of the report) | US |
Data Retention
| Data Type | Retention | Deletion Method |
|---|---|---|
| User profile (PII) | 30 days after deletion request | Automated hard delete |
| Salesforce OAuth tokens | Immediate on deletion request | Revoke + delete |
| AI chat messages | 30 days after deletion request | Automated hard delete |
| Audit logs | 7 years (anonymized) | user_id nulled |
| Billing/tax records | 7 years | Per IRS requirements |
Your Rights Under GDPR
If you are in the European Economic Area, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data (available via Settings → Delete Account)
- Data portability — receive your data in a structured format
- Restriction — limit how we process your data
- Object — object to processing based on legitimate interest
- Withdraw consent — for consent-based processing (e.g., cookies), at any time
To exercise these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Your Rights Under CCPA/CPRA
If you are a California resident, you have the right to:
- Know — what personal information we collect, use, and disclose
- Delete — request deletion of your personal information
- Opt-out of sale — see “Do Not Sell” below
- Non-discrimination — we will not discriminate against you for exercising these rights
Do Not Sell or Share My Personal Information
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months.
Cookies
| Cookie | Purpose | Type |
|---|---|---|
| sb-* | Authentication session (Supabase) | Strictly necessary |
| cf_clearance | Bot protection (Cloudflare Turnstile) | Functional (consent required) |
| _cf_bm | Bot management (Cloudflare) | Functional (consent required) |
You can manage your cookie preferences at any time. Rejecting non-essential cookies will prevent Cloudflare Turnstile from loading, which may affect form submissions.
We also use Cloudflare Web Analytics (Insights), a cookieless analytics service that collects aggregated traffic statistics (page views, referrers, country, browser). It does not use cookies or local storage and does not track users across sites. Because no cookie or persistent identifier is set, it loads on every page regardless of your consent choice and is not affected by the “Reject non-essential” button.
International Data Transfers
Your data is processed in the United States (Hetzner, Ashburn, Virginia). If you are located outside the US, your data will be transferred internationally. Our sub-processors operate under their standard terms of service, and each vendor's data-processing terms are available via their trust page (see the Sub-Processors table above).
Children's Privacy
OrgBolt is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected data from a child, contact us and we will delete it promptly.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of material changes by email or by posting a notice on our website. Your continued use of OrgBolt after changes constitutes acceptance of the updated policy.
Contact Us
For privacy-related inquiries: [email protected]