OrdnaryPrivacy & Terms
OverviewPrivacy PolicyTerms of ServiceOrdnary Web ServicesTechnologiesFAQ
  • Introduction
  • Data Ordnary collects
  • Why Ordnary collects data
  • AI features and your data
  • Your privacy options
  • Sharing your data
  • Keeping your data secure
  • Exporting and deleting your data
  • Retaining your data
  • Compliance and cooperation with regulators
  • About this policy
  • Related privacy resources
  • Key terms

  • Data retention
  • Data transfer frameworks
  • Key terms
  • Partners
  • Updates

ORDNARY PRIVACY POLICY

Privacy Policy

Last updated 22 July 2026

This is what data we collect and why, how we use it, and how you can review and adjust it.

When you use our services, you trust us with your data. We understand this is a big responsibility, and we work hard to protect your data and put you in control of it.

This Privacy Policy is meant to help you understand what data we collect, why we collect it, and how you can update, manage, export, and delete it.

If European Union or United Kingdom data protection law applies to the processing of your data, see the European requirements section below for more information about your rights and how Ordnary complies with that legislation.

We build a range of services that let people index knowledge and automate their work, backed by a developer platform, cloud infrastructure, and payments.

Data Ordnary collects

We want you to understand the types of data we collect when you use our services. We collect data to provide better services to all our users, from basic things like the language you speak, to more complex things like which of your workflows in our automation tools run most often. The data Ordnary collects, and how it's used, depends on how you use our services and how you manage your privacy options.

When you're signed in, we collect data that we store in your Ordnary Account, which we treat as personal data. When you're not signed in, we store the data we collect with identifiers tied to the browser, app, or device you're using.

Things you create or provide to us

When you create an Ordnary Account, you provide us with personal data, such as your name and a password. You can also choose to add a phone number or payment information to your account.

We also collect the content you create, upload, or receive from others when using our services: documents and code you index in our knowledge-indexing tools, workflows you configure in our automation tools, and support messages you send us.

Data we collect as you use our services

Your apps, browsers, and devices

We collect information about the apps, browsers, and devices you use to access Ordnary services, which helps us do things like keep your session secure. This includes unique identifiers, browser type, operating system, IP address, crash reports, and the date, time, and referrer URL of your requests.

Your activity

We collect data about your activity in our services, which we use, for example, to show you the documents you view most in our knowledge-indexing tools. Activity data may include search terms, features used, and API or model requests.

Information from public sources and trusted partners

We may collect limited data from trusted partners, such as payment and fraud-prevention partners, to help us provide and secure our services.

Why Ordnary collects data

We use the data we collect across all our services for the purposes described below. For each purpose, we describe examples of what we do, what data is typically involved, and the legal basis we rely on.

Providing our services

We use your data to deliver our services. Examples of processing activities:

  • We process the documents you index in our knowledge-indexing tools so we can show search results.
  • We run the workflow steps you configure in our automation tools, including connecting to any external tools you authorize.
  • We use unique identifiers stored in your session to verify that you're the person entitled to access your Ordnary Account.
  • We process your payment information through Ordnary Pay when you subscribe to a paid plan.

Data typically involved: account information you provide (name, email address, password, payment information); content you create or submit (documents indexed in our knowledge-indexing tools, workflows configured in our automation tools); and data we collect as you use our services (device and browser information, IP address, activity).

Legal basis: to perform a contract with you, such as running a workflow you've configured or processing a payment you've authorized.

Maintaining and improving our services

We use data to make sure our services are working as intended and to improve them. Examples of processing activities:

  • We continuously monitor our systems to flag issues, and use activity data collected before an issue occurred to resolve it faster.
  • We track outages and problems you report to us to prioritize fixes.
  • Understanding which searches in our knowledge-indexing tools return no results helps us improve indexing quality.

Data typically involved: account information; content you create or submit; and data we collect as you use our services (device and browser information, activity, crash reports).

Legal basis: our legitimate interest in offering, maintaining, and improving the services to meet our users' needs, with appropriate safeguards for your privacy.

Developing new services and features

We use data collected in existing services to help us develop new services. Examples of processing activities:

  • Understanding how people organize documents in our knowledge-indexing tools informs new organization features.
  • Understanding which triggers and actions are most often combined in our automation tools helps us design new workflow templates.

Data typically involved: content you create or submit; and data we collect as you use our services (activity, features used).

Legal basis: our legitimate interest in developing new products and features that are useful to our users.

Providing personalized functionality

We use the information we collect to tailor our services to you. Examples of processing activities:

  • Our automation tools may suggest a workflow template based on triggers you've used before.
  • Our knowledge-indexing tools may surface documents related to what you're currently viewing.

Data typically involved: account information; content you create or submit; and data we collect as you use our services (activity, features used).

Legal basis: to perform a contract with you, or, where the feature is optional, with your consent.

Measuring performance

We use data for analytics and measurement to understand how our services are used. Examples of processing activities:

  • We analyze which features are used most often to inform product design.
  • We measure page load times and error rates across our sites to catch regressions.

Data typically involved: data we collect as you use our services (device and browser information, activity); and cookies and similar technologies, as described in our Cookie Policy.

Legal basis: our legitimate interest in understanding how people use our services in order to safeguard and improve them, or your consent for non-essential analytics cookies.

Communicating with you

We use data we collect, such as your email address, to communicate directly with you. Examples of processing activities:

  • We notify you of suspicious activity, such as an unrecognized sign-in to your Ordnary Account.
  • We let you know about planned changes or improvements to a service you use.
  • If you contact us, we keep a record of your request to help resolve it.

Data typically involved: account information (name, email address); and records of your support requests.

Legal basis: to perform a contract with you, our legitimate interest in keeping you informed, or, for marketing communications, your consent.

Protecting Ordnary, our users, and the public

We use information to help improve the safety and reliability of our services. Examples of processing activities:

  • We collect and analyze IP addresses and session data to protect against automated abuse.
  • We analyze content to help detect abuse, such as spam, malware, or illegal content.
  • We investigate suspected violations of our Terms of Service or our Acceptable Use Policy.

Data typically involved: data we collect as you use our services (device and browser information, IP address, activity); and content you create or submit.

Legal basis: our legitimate interest in protecting our services and users, or a legal obligation, for example to detect and combat child sexual abuse material.

Complying with applicable law

Legal obligations sometimes require us to process or retain information. Examples of processing activities:

  • We keep records of payments made to Ordnary for tax and accounting purposes.
  • We respond to lawful, enforceable requests from courts and government authorities, after review by our legal team.
  • Where required, we process information to confirm you meet the minimum age to use our services.

Data typically involved: account and payment information; and records of legal requests we receive.

Legal basis: a legal obligation.

AI features and your data

AI features in our services are powered by Google's Gemini models, accessed through Google Cloud Vertex AI. Ordnary does not train or operate its own AI models. How we handle prompts, input, and output is described in the AI Usage Policy. In short: we don't use content from paying API and Ordnary Web Services customers to train models unless you explicitly opt in, and for consumer services, your privacy options let you decide whether your content may be used to improve our product features.

Your privacy options

This section describes the main options you have for managing your privacy across our services.

Managing, reviewing, and updating your data

When you're signed in, you can always review and update your data by going to the service you're using. In Ordnary Accounts, you can review and manage the personal information stored in your account.

Cookie settings

You can also control what data Ordnary collects through your browser settings and our cookie notice; see our Cookie Policy for more detail.

Sharing your data

When you share data

Some of our services let you share data with other people, and you decide how. For example, you might share a document with specific teammates, or keep it private.

When Ordnary shares data

We don't share personal data with companies, organizations, or individuals outside of Ordnary, except in the following cases:

  • With your consent, for example when you choose to connect an external integration to our automation tools.
  • For external processing: we share data with subprocessors and trusted partners so they can process it on our behalf and in accordance with this Privacy Policy, such as hosting providers and Google Cloud for AI processing. See our Subprocessors page.
  • For legal reasons: if we reasonably believe disclosure is necessary to comply with applicable law or an enforceable government request, to enforce our Terms of Service, or to protect the rights, property, or safety of Ordnary, our users, or the public.
  • In connection with a business transfer: if Ordnary is involved in a merger, acquisition, or sale of assets, we continue to protect your data and notify affected users before it's transferred or made subject to a different privacy policy.

We don't sell your personal data.

Keeping your data secure

We build security into our services to protect your data. We work hard to protect Ordnary and our users from unauthorized access to, or alteration, disclosure, or destruction of, data we hold. Among other things, we:

  • use encryption to keep your data private in transit and at rest;
  • offer security features, such as multi-factor authentication, to help you protect your account;
  • review our data collection, storage, and processing practices, including physical security measures, to guard against unauthorized access; and
  • restrict access to personal data to Ordnary employees, contractors, and agents who need it, all of whom are bound by strict contractual confidentiality obligations.

See our Security Policy for more on how we secure our products and infrastructure.

Exporting and deleting your data

You can export a copy of the content in your Ordnary Account if you want to back it up or use it in a service outside of Ordnary. To delete data, you can remove content from specific services, or delete your entire Ordnary Account.

Retaining your data

We retain the data we collect for shorter or longer periods, depending on what the data is, how we use it, and how you configure your settings. Some data, such as content you create or upload, you can delete at any time. Other data, such as server logs, is automatically deleted or anonymized after a set period. We retain some data for longer where necessary for legitimate business or legal purposes, such as security, fraud prevention, or financial record-keeping.

Compliance and cooperation with regulators

We regularly review this Privacy Policy and make sure we process your data in a way that's consistent with it.

Data transfers

We host our services primarily in the European Union. Where data is transferred outside the EEA, for example to a subprocessor, or to Google Cloud regions used for Gemini processing, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with supplementary technical and organizational measures.

European requirements

If EU or UK data protection law applies to the processing of your data, we provide the options described in this policy so you can exercise your rights to access, update, delete, and restrict the processing of your data. You also have the right to object to the processing of your data, or to export your data to another service.

If you have questions or requests relating to your rights, contact us at privacy@ordnary.com. You may also contact your local data protection authority if you have concerns about your rights under local law.

Controller

Unless otherwise indicated in a service-specific privacy notice, Ordnary, Netherlands (KVK 95732888), is the controller for the processing of your data, except when Ordnary acts as a processor on behalf of business customers under the Data Processing Addendum.

Legal bases for processing data

We process your data for the purposes described in this policy on the basis of the following legal grounds:

  • we process your data to provide a service you've requested under a contract;
  • we process your data for our legitimate interests and those of third parties, applying appropriate safeguards that protect your privacy;
  • we process your data where necessary to protect the vital interests of you or another person;
  • we process your data where we have a legal obligation to do so; and
  • we ask for your consent to process your data for specific purposes, and you can withdraw your consent at any time.

About this policy

When this policy applies

This Privacy Policy applies to all services provided by Ordnary. It doesn't apply to services that have a separate privacy policy that doesn't incorporate this one, or to the data practices of other companies and organizations that advertise or integrate with our services.

Changes to this policy

We may change this Privacy Policy from time to time. We won't reduce your rights under this policy without your explicit consent. We always post the date the latest changes were made and provide access to archived versions. If we make material changes, we'll give more prominent notice, including, for certain services, an email notification.

Related privacy resources

The following pages provide additional information related to this policy:

  • Cookie Policy: how we use cookies and similar technologies.
  • Security Policy: how we secure our products and infrastructure, and how to report a vulnerability.
  • AI Usage Policy: how AI features in our products work and how your content is used.
  • Subprocessors: the third parties we work with to help deliver our services.

Key terms

Cookie

A small text file sent to your device when you visit a website. When you revisit the site, the cookie lets it recognize your browser.

Device

A device is a computer that can be used to access Ordnary services, such as a desktop, laptop, tablet, or smartphone.

IP address

Every device connected to the internet is assigned a number known as an IP address. These numbers are usually assigned in geographic blocks and can often be used to identify the general location from which a device is connecting.

Non-personal data

Data about users that is stored in a way that no longer identifies an individual user.

Ordnary Account

You access some of our services by signing up for an Ordnary Account and providing some personal data, typically your name, email address, and a password. This is used to verify your identity and protect your account from unauthorized access. You can edit or delete your account at any time in Ordnary Accounts.

Personal data

Information you provide us that personally identifies you, such as your name, email address, or billing information, or other data that can reasonably be linked to such information by Ordnary.

Referrer URL

A referrer URL carries information that a web browser sends to a destination website, typically when you click a link, and shows the URL of the last page the browser visited.

Sensitive personal data

A specific category of personal data relating to things like confidential medical data, race or ethnic origin, political or religious beliefs, or sexuality.

Server logs

Like most websites, our servers automatically record page requests made when you visit our sites. These server logs typically include your request, IP address, browser type, browser language, and the date and time of your request.

Unique identifiers

A string of characters that can uniquely identify a browser, app, or device. Unique identifiers can be used for various purposes, including security and fraud detection, and remembering your preferences.

Ordnary
  • Privacy Policy
  • Terms of Service
  • Technologies
  • FAQ