Your data stays tied to your Whop account.
Last updated: October 9, 2026
This policy is short on purpose. Orty is a privacy-first company, and the simplest way to honor that is to never collect your data in the first place.
The short version
Orty is now a web app: your leads and CRM are stored encrypted per your Whop account (Supabase + local browser cache) and you can export everything anytime. On Free and Pro, Orty runs the AI for you — when you rate a lead or draft an email, your content (screenshot, bio, portfolio, prompt) is sent through Orty's managed provider (GLM-5.3-Flash) to produce the result. If you don't want your content going through Orty's provider, the $5 Signal plan lets you bring your own AI key instead. Also leaving: a version check; always-on product analytics that record only that events happened (PostHog, server-side — never what happened); errors-only crash reports with personal data scrubbed (Sentry); and Whop OAuth to verify your subscription. Any key you bring is used per request and never stored server-side long-term. Checkout and auth are powered by Whop, and we never see or store your full card details.
1. What we store per Whop account
Orty web stores your CRM per Whop account (Supabase + local browser cache: IndexedDB). When you login with Whop, we create a user record tied to your whop_user_id and persist leads, longform audits, copilot sessions, and goals per that id. Your Whop email and user id are the only account identifiers we keep. On Free and Pro there is no key to store — Orty runs the AI. If you bring your own key (the $5 Signal plan), it is used per request and held in your browser session only, never stored server-side long-term. Sessions are signed, encrypted cookies that expire — an expired session prompts a clean re-login without losing in-page input. To stop credential-stuffing, the login and OAuth callback endpoints are per-IP rate-limited.
This site uses cookieless analytics only — Plausible and Vercel Analytics. Neither sets tracking cookies nor identifies you. Inside the web app, product analytics (PostHog, server-side) is always on but records occurrence-only events — e.g. that a rating completed, never the lead, prompt, screenshot, or key involved. Crash reporting (Sentry) captures errors only, with personal data scrubbed before anything leaves the server. The legacy opt-in telemetry upload path is dormant by design and cannot be enabled.
2. The app runs in your browser
Orty is now a web app at getorty.work (proxied to Cloud Run europe-west1). Your leads, emails, chat sessions, CRM, and goals are synced per Whop account (Supabase) with a local browser cache for offline.
The CRM is no longer a plain CSV on disk — it is per-user rows in Supabase with a local cache. You can still export the whole workspace as one zip anytime; any AI key you bring is never included. If you clear browser storage, the server copy restores on next login. Delete your Whop account and we delete the rows.
3. What leaves your browser or the server
These are the outbound connections Orty makes:
- Managed AI calls (default — Free and Pro) — triggered only when you press a button. The content you submit (a screenshot, bio, portfolio text, or prompt) is sent from Cloud Run to Orty's AI provider, Z.ai (GLM-5.3-Flash), using Orty's key, to produce the result. It is processed only to generate your report or draft and is not kept by Orty beyond the request. So on Free and Pro your content does pass through Orty's provider, under that provider's terms.
- Your own provider calls (Signal, $5/mo — optional) — if you don't want your content going through Orty's provider, the Signal plan lets you bring your own AI key. Calls then go to your provider with your key, used per request and never stored long-term. This is the option for people who want to choose — and be the only one holding — the provider their content reaches.
- A version check — Orty asks getorty.work/version.txt whether an update exists. No identifiers.
- Always-on product analytics (PostHog, server-side) — records occurrence-only events (e.g. a rating completed, a chat message sent). Never lead content, prompts, screenshots, keys, or emails.
- Errors-only crash reporting (Sentry) — captures application errors with personal data scrubbed, so repeatable bugs get fixed. No lead content, ever.
- Whop OAuth (PKCE S256) — login + Pro verification — login with Whop verifies your $19.99/mo Pro subscription (Whop product
prod_wBSzJmZU1f1sV). We store onlywhop_user_id+ email +is_proin your session; no device hash. A signed webhook (/webhooks/whop, HMAC-SHA256) flipsis_prolive on subscription events.
On Free and Pro the AI call goes from Cloud Run to Orty's managed provider (GLM-5.3-Flash), using Orty's key. On Signal it goes to the provider you chose, with your key. Either way the content you submit is processed only to produce your result and is not stored by Orty beyond the request.
Whop account required. No tracking pixels. If you never press Rate, Co-Pilot, or Long Form, the only traffic is version check + Whop auth.
4. Payment is powered by Whop
Checkout is powered by Whop. Orty never sees or stores your full card details — payment is processed entirely by Whop, which supports card, PayPal, crypto, and other methods. We receive only the information Whop passes along to deliver your order: your purchase email and an order confirmation.
That purchase email is used solely to deliver your order. It is not used for marketing, not sold, not shared.
5. Your leads are encrypted per Whop account
Your leads, drafts, chat sessions, and CRM are stored encrypted per whop_user_id in Supabase with a local browser cache. The only time content leaves your browser beyond that is when you run an AI feature (Rate, Co-Pilot, or Long Form). On Free and Pro that content is sent through Orty's managed provider (GLM-5.3-Flash) to produce the result; on Signal it goes to your own provider. Either way it is used per request and not stored long-term by Orty.
You can still export the whole workspace as one zip anytime. If you lose browser storage, login restores from the server copy. Delete your Whop subscription and we delete the rows on request.
6. Children's privacy
Orty is a professional tool intended for adults doing business outreach. It is not directed at children under 16, and we do not knowingly collect any data from children. Any data we do store (per §1, scoped to your Whop account) is deleted on account deletion — including any future data subject to the equivalent request from a minor.
7. Changes to this policy
If this policy ever changes in a way that reduces your privacy, we will say so loudly — not bury it in a quiet update. Material changes will be announced via Whop and reflected in the "last updated" date above. The posture (managed AI, or your own per-request key never stored long-term, analytics occurrence-only and content-blind, errors-only crash reports with PII scrubbed, every outbound connection documented in §3, RLS per whop_user_id) is structural.
8. Contact
For any privacy question, email hello@getorty.work. I'm the founder, and I read every message.