← OraCool homePrivacy & data
Implementation notice · September 2026OraCool is operated through the deployment owner’s hosting, database and configured service providers. This notice describes the app’s current handling of data; it is not a guarantee about a third party’s retention practices.
Conversations and account data
Signed-in conversation history is saved on the server and mirrored to the operator’s Supabase database when configured. The browser also keeps local account/session and chat state. Clearing browser storage does not delete server history. Saved chats, case evidence, subscriptions and administrative audit records have separate retention paths.
AI and microphone use
Messages and submitted files may be sent to configured AI providers to fulfill your request. Voice uses browser recognition or short recordings sent to a transcription provider. OraCool’s transcription endpoint does not save the audio clips. Browser and AI provider terms determine their own processing and retention. Stop/mute releases microphone access; hidden or locked pages pause hands-free listening.
Email communications
Email communications require Enterprise or admin access, verified recipients and consent. Destination addresses and prepared message bodies are encrypted in the communications store using the operator’s encryption key. Recipient masks, ownership, verification times and send status are also stored. If you dictate an address or message in chat, that text is part of your saved conversation. Telephone calling and SMS are not available on OraCool.
The configured email provider (SendGrid) receives email destinations, subject and message content. Provider records and billing logs are governed by their terms. Outbound activity is not proof of delivery.
Verified recipients expire after 30 days. Removing a recipient prevents new sends using unconfirmed drafts but does not cancel an already-dispatched message. Email is limited to consensual transactional communication, not bulk marketing.
Connections and security
Mailbox and social connections require separate authorization; signing up with an email address does not grant inbox access. Email provider credentials are kept server-side. The encryption key must be protected and preserved across deployments. Administrator accounts can view platform diagnostics and operational records; Enterprise subscribers do not receive these administrator powers.
Deletion and limits
Use the app’s chat, recipient and case deletion controls where available. Contact the deployment operator for other account/data requests and retention details. Backups, logs and provider-held records may have separate lifecycles. Do not submit passwords, one-time security codes or highly sensitive information in chat.
OraCool is not an emergency service. Market tools are informational; trading is paper-only.
Open OraCool →