Feature · Privacy

Analytics that can't see your work. Here's exactly what leaves, and what never does.

Most apps bury tracking in a privacy policy nobody reads. Orty does the opposite: its analytics are occurrence-only and content-blind by construction — the system records that events happened, never what they contained.

This page exists so you never have to take our word for any of it.

Default state: content-blind

  • No lead content anywhere — no usage stats, prompts, drafts, screenshots, or keys ever reach analytics or crash reporting.
  • AI calls stay per-request — lead rating and drafting go via Cloud Run to Orty's managed AI engine (GLM-5.3-Flash), or to your own provider on Signal. Both fire only when you trigger them, and neither is stored long-term.
  • Workspace stays per-account — CRM, drafts, insights, goals, diagnostics: encrypted per Whop account (Supabase) + local browser cache, exportable as one zip.

The two systems that do run

Product analytics (PostHog, server-side) is always on and records occurrence-only events — think counters: a rating completed, an error hit, a feature used. Crash reporting (Sentry) captures application errors with personal data scrubbed before anything leaves the server. Neither ever sees your leads, drafts, prompts, screenshots, or API keys. The legacy opt-in telemetry upload path is dormant by design and cannot be enabled.

Verify, don't trust

  • Check the network yourself — any packet sniffer confirms the only AI endpoints are your configured providers — and only while you act — plus PostHog/Sentry telemetry that carries no content.
  • Read the source of claims — the full policy lives at /privacy, dated and versioned like everything else here.

Frequently asked questions

Why include analytics at all?
Occurrence-only counters are how an indie developer learns which features earn their place — without ever seeing a customer's actual work. Content-blindness is structural, not a setting you must remember to enable.
Does the AI provider store the screenshots I rate?
Rating sends the screenshot via Cloud Run to Orty's managed AI engine (or your own provider on Signal), governed by that provider's API terms. Orty doesn't keep a server-side copy beyond the request — your workspace copy lives encrypted per Whop account until you delete it.
Is the website tracking me?
Only Plausible — a cookieless, GDPR-friendly counter that can't identify individuals. That choice is why you see no consent banner here: there's nothing to consent to.