Legal
Privacy Policy
This Privacy Policy describes how Oriloq handles your personal data when you use our Mac application and website. Your voice and text content is processed transiently and ephemerally, only in memory, for the sole purpose of generating responses. It is never stored, logged, or used to train models.
1. Who we are
Oriloq is provided by NowwweB ("we", "us"). We distribute the Mac application directly from our website. Oriloq is a productivity tool that provides real-time transcription, translation, and AI-powered prompts. We process a minimal amount of personal data solely to provide these services, and we do not collect any voice or text content you process with Oriloq.
2. Data we collect
Depending on how you use Oriloq, we may collect the following categories of data:
- Contact and billing data such as your email address (used for checkout, receipts, and support).
- Chatbot feedback data: when you voluntarily rate a chatbot response (thumbs up or thumbs down), we collect your rating along with the exchanged messages. Messages are automatically stripped of personal data (phone numbers, credit card numbers, etc.) before storage. Your email address or name may be associated with the feedback if you are logged in.
- Device hardware identifiers: when you activate your Oriloq license on a Mac, we collect certain hardware identifiers (network interface address, serial number, system UUID, and your Mac's display name) to link your license to your devices. A one-way SHA-256 fingerprint is computed from these identifiers. This data is used solely to enforce the license device limit and is retained for up to 2 years.
Oriloq does not use cookies. Your voice and text content is processed transiently and ephemerally, only in memory, for the sole purpose of generating responses. It is never stored, logged, or used to train models.
Payment Information: Oriloq is sold directly by NowwweB. Payments are processed through PayPal (and its partners). We do not store your full card details, but we may receive limited payment information (such as transaction identifiers and subscription status) to provide paid access, manage subscriptions and refunds, and handle support. PayPal may collect and process payment information according to its own policies.
3. How we use your data
We use your data to:
- Provide and maintain the Oriloq applications and services.
- Process payments, subscriptions, and refunds (via PayPal).
- Respond to your requests and provide support.
- Maintain security and prevent fraud.
- Comply with legal obligations and enforce our terms.
- Improve the quality and relevance of our chatbot based on voluntary feedback you provide.
4. How we handle your content
Your voice and text content processed by the Oriloq Mac application is handled entirely on your device and is never sent to our servers. It is never stored, logged, or used to train models. When you use the support chatbot on our website, your questions are sent to OpenAI's API for processing. This processing is transient — OpenAI does not store the conversations. On our side, we only store chatbot exchanges if you voluntarily provide feedback (see section 6).
We do not collect analytics, diagnostics, or usage data about how you use Oriloq.
5. Anonymous download analytics
We collect anonymous, aggregated statistics about application downloads and update checks to help us understand how our software is adopted. These analytics do not use cookies, do not require consent banners, and do not identify individual users.
Specifically:
- Your IP address is used only to derive your approximate country and to compute an anonymous device hash, then immediately discarded. It is never stored.
- The anonymous device hash (a one-way SHA-256 fingerprint combining your IP and browser user agent) is used solely to estimate the number of unique devices. It cannot be reversed to identify you.
- No personal data (name, email, browsing history, etc.) is collected or associated with these analytics.
- Raw event data is automatically deleted after 7 days. Only anonymous, aggregated counts (downloads per day, per country, per version) are retained.
The legal basis for this processing is our legitimate interest (Article 6(1)(f) GDPR) in understanding software distribution patterns. Because no personal data is stored, this processing does not require consent under the ePrivacy Directive.
6. Chatbot feedback
Our website includes a support chatbot. When you interact with it, you may voluntarily rate a response as helpful or not helpful (thumbs up / thumbs down). If you choose to provide feedback, we collect:
- Your rating (positive or negative).
- The exchanged messages (your question and the chatbot's response), automatically anonymized to remove personal data such as phone numbers, credit card numbers, tax identifiers, and other sensitive information.
- Your email address or name, if you are logged in at the time of the interaction.
- The language used during the interaction.
This feedback is collected solely to improve the quality and relevance of our chatbot responses. The legal basis for this processing is our legitimate interest (Article 6(1)(f) GDPR) in improving our services. You can exercise your rights of access, rectification, and deletion over this data by contacting us at the address indicated below.
Providing feedback is entirely voluntary. You can use the chatbot without providing any rating.
Chatbot feedback data is retained for a maximum of 24 months from the date of collection, after which it is permanently deleted.
7. YouTuber Program (Google OAuth)
If you participate in our YouTuber Program, we request access to your Google account to verify channel ownership and subscriber count. We request the following permissions: read-only access to your YouTube channel data, your email address, and your display name.
We collect and store:
- Your YouTube channel ID and channel title, stored with your license data (retained for up to 2 years).
- Your email address, associated with your channel claim record to prevent duplicate claims (retained indefinitely).
We do not store your Google profile picture, access tokens, or refresh tokens. The legal basis for this processing is your consent (Article 6(1)(a) GDPR), which you provide by initiating the Google OAuth flow.
8. Legal basis for processing
Our legal bases for processing your personal data include:
- Performance of a contract to provide the service you requested.
- Legitimate interest to ensure security and improve performance.
- Compliance with legal obligations when required by applicable law.
9. Data sharing
We only share your personal data with:
- Service providers that help us operate Oriloq (for example cloud hosting, email delivery, or payment processing via PayPal), under contracts that require them to protect your data.
- Legal authorities when we are required to do so by applicable law or to protect our rights, users, or the public.
- Business transfers if we are involved in a merger, acquisition, or asset sale, in which case we will continue to protect your data and inform you of any material changes.
10. Data retention
We keep your personal data only for as long as necessary to provide the services, comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed, we delete it or anonymize it.
11. Your rights
Depending on your location, you may have rights over your personal data, such as:
- Accessing the personal data we hold about you.
- Correcting inaccurate or incomplete personal data.
- Requesting deletion of your personal data, where applicable.
- Objecting to or restricting certain types of processing.
- Exporting your data in a portable format where required by law.
To exercise these rights, contact us using the details below. We may need to verify your identity before responding.
If you feel that your rights have not been respected, you have the right to lodge a complaint with the competent supervisory authority (in France, the CNIL).
12. Security
We implement technical and organizational measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, or unauthorized access. However, no online service can be completely secure, and we encourage you to use strong passwords and keep your devices up to date.
13. International transfers
Your data may be processed and stored in countries other than the one where you live. When we transfer personal data internationally, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms, where required by law.
14. Children's privacy
Oriloq is not intended for children under the age of 13, and we do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us so we can take appropriate action.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make material changes, we will update the "Last updated" date and, when appropriate, notify you through the application or by email.
16. Contact us
If you have any questions about this Privacy Policy or how we handle your data, you can contact us at:
contact@oriloq.app
Last updated: