Orca ESB
Privacy
Placeholder · last updated September 2026
This is a short placeholder for the Orca ESB privacy policy. The marketing site does not run its own account database or analytics cookies. Sign-up and sign-in are handled by Clerk. Requesting Orca Cockpit access stores flags, a Project list, plan/credit stubs, and timestamps on that Clerk user record (`cockpitAccessRequested`, `cockpitWorkspaces`, `orcaCreditsCents`, provision status). First account visit queues a default Project.
If you save Cursor, Anypoint, Salesforce, GitHub, or Postman credentials on Settings, they are encrypted and stored on your Clerk user as private metadata. They are never written to public metadata. Orca Cockpit can read them with your signed-in session so you do not have to paste them into a VM. Vault writes are website-only.
The desktop app signs in on this site (Clerk) and exchanges a one-time PKCE code at /api/desktop/token. Session JWTs can then read your vault. When cloud Projects store more tenant inventory, this page will describe that retention too.
Beta · $50 first Project. Card checkout is not live, so there is no payment-processor card data to retain here. Operators may set `orcaCreditsCents` on your Clerk user.
Questions: sivaji@orcaesb.com or rajiv@orcaesb.com.