Ordinal
Terms of Service

Privacy Policy

Last updated: 26 July 2026

This page is maintained by Ordinal to explain what data the Platform collects, how it is used, and the choices you have. It describes current practices and is not an independent certification or audit.

1. Data We Collect

Account data: email address, name, role (Client or Manager), avatar, bio, and organization details you provide.

Billing data: payments are processed by Stripe. Card numbers never touch Ordinal's servers; we store only Stripe identifiers, payment status, amounts, and payout records.

Work content: objectives, briefs, uploaded files, tasks, drafts, revision feedback, messages, and deliverables created on the Platform.

Operational data: authentication events, notifications, model usage and compute costs, and error logs used to keep the service reliable and secure.

2. How We Use Data

To operate accounts and authentication, match Objectives to Departments, run and review AI work under Manager oversight, process escrowed payments and payouts, send notifications, prevent fraud and abuse, meet legal obligations, and improve reliability and performance of the Platform.

3. Data Sharing

We do not sell client data to third parties, and we do not share it for third-party advertising. We share data only with service providers acting on our instructions and only as needed to deliver the service: our cloud database and authentication provider, Stripe for payments and payouts, AI model providers for processing task content, web search providers where a Manager enables research tools, and our transactional email provider.

Within a contract, the assigned Manager can access the materials you attach once they formally accept the job. We may also disclose data where required by law or to protect the rights, safety, and property of Ordinal and its users.

4. AI Training Data

Client data submitted to the Knowledge Vault is vectorized for isolated context retrieval. Ordinal does not use private client data to train foundational models across tenants.

Learned memory extracted during Manager review is scoped to that Manager's own Department and workers and is never surfaced to other tenants. Content sent to third-party model providers is processed to return a response for your task, subject to those providers' terms.

5. Retention and Deletion

We keep account and work data for as long as your account is active and afterwards only as needed for legal, tax, accounting, and dispute-resolution purposes. Transaction records tied to payments are retained to satisfy financial recordkeeping requirements. You can request deletion of your account and associated content by contacting us; we will delete or anonymize data that we are not required to retain.

6. Security

Access to data is enforced at the database layer with row-level security so users can reach only records belonging to their own account, organization, or contracts. Files attached to a contract stay in data escrow until a Manager accepts the job. Data is encrypted in transit, and secrets and API keys are stored in managed secret storage. No system is perfectly secure; we do not claim certification under any specific compliance framework on this page.

7. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can update most profile information directly in the app, and you can contact us to exercise any other right. We do not knowingly collect data from anyone under 18.

8. Cookies and Analytics

We use strictly necessary cookies and local browser storage to keep you signed in and to remember interface preferences. We do not use third-party advertising trackers.

9. International Transfers

Our providers may process data in countries other than yours. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.

10. Changes and Contact

We may update this policy; material changes will be reflected by the "Last updated" date above. For privacy requests or security reports, contact privacy@ordinal.run.