LEGAL
Privacy Policy
Last updated 8 September 2026. Draft pending attorney review.
Draft — not legal advice — pending attorney review. Bracketed items are placeholders.
1. Who is responsible
The data controller is [OPERATOR LEGAL NAME, address]. Privacy questions and requests: [privacy email]. This policy covers the Orela website and chat service. Because Orela is an adult service, we treat the fact that you use it, and what you talk about, as sensitive and handle it accordingly.
2. What we collect
Account data: if you sign in by email we store your email address; if you sign in with Discord we receive the identifiers Discord sends (id, display name, email if shared, avatar). We do not receive your Discord password.
Guest identifier: without an account, a signed random identifier is stored in a cookie (orela-guest) so your balance and chats can be found again on this browser.
Conversations and settings: the messages you and the companions exchange, your per-character preferences (name, tone, intensity), your global taste settings, and relationship-progress values are stored on our servers, linked to your account or guest identifier.
Wallet: your crystal balance and a ledger of every credit and debit (trial, purchase, chat round, refund).
Payments: card payments are processed by a licensed payment processor; we receive a confirmation, amount, currency and a transaction reference, never your full card number. For cryptocurrency payments we record the wallet address, transaction id and amount.
Technical data: IP address (stored only as a one-way hash for abuse prevention), browser type, language, timestamps and error logs.
3. How we use it
To run the service: keep you signed in, show your balance, load your conversations, and generate replies. To generate a reply, the recent conversation, your settings and the character's instructions are sent to our model provider (currently xAI's Grok models accessed through an API relay). The provider processes that text to produce the reply; we do not allow it to use your conversations to train its models where the provider offers that control.
To bill you: credit purchases, deduct chat rounds, refund failed rounds, detect fraud and chargebacks.
To keep the service safe and lawful: enforce age rules, run content filters, investigate reports, block abuse, respond to lawful requests.
To improve Orela: we may analyse de-identified, aggregated usage (for example how long conversations last). We do not sell personal information and do not use it for third-party advertising.
4. Who we share it with
Service providers acting on our instructions: the model provider (reply generation), database hosting (Neon, Postgres), web hosting and CDN (currently Vercel; a virtual server behind Cloudflare after launch), transactional email (Resend, for sign-in codes), and payment processors. Each receives only what it needs for its task.
Authorities: when required by law, court order, or to report suspected child sexual abuse material. Successors: if the service is transferred to a new operator, your data may be transferred with it under the same protections. We do not share conversations with anyone else.
5. Cookies
orela-age — records that you confirmed you are 18+; about 180 days. orela-guest — signed guest identifier; about 180 days. orela-locale — your language choice; 1 year. orela-otp — short-lived cookie holding a hashed sign-in code; 10 minutes. Auth.js session cookies — keep you signed in; default 30 days. All are first-party and either essential or set at your request. We do not use third-party advertising or tracking cookies. Clearing cookies signs you out and, for guests, disconnects the browser from its guest data.
6. How long we keep it
Conversations, settings and relationship data: for as long as your account exists, or until you delete them. Guest data with no activity for 180 days may be deleted. Wallet ledger and payment records: up to 7 years where tax, accounting or anti-money-laundering rules require. Sign-in codes: 10 minutes. Server and error logs: about 30 days. Abuse and moderation records: up to 2 years, or longer if needed for an investigation. Deleted data may persist in encrypted backups for up to 30 days.
7. Your rights
Depending on where you live (including the EU/EEA, the United Kingdom and U.S. states such as California) you may have the right to access, correct, delete or export your data, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority. You can delete conversations per character from the app, sign out, revoke Orela in Discord's authorized apps, and clear this site's cookies. For account deletion or an export, email [privacy email] from the address on the account; we respond within 30 days. We do not discriminate against you for exercising these rights.
8. Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. Access to production systems is limited to the operator. Sign-in codes are stored only as hashes and expire quickly. No system is perfectly secure: please do not put real names, addresses, payment details or other people's private information into a chat.
9. International transfers
Our providers process data in the United States and the European Union. Where data leaves your region we rely on the provider's standard contractual clauses or equivalent safeguards.
10. Children
Orela is for adults only. We do not knowingly collect information from anyone under 18. If we learn that a minor has used the service we close access and delete the data. If you believe this has happened, contact [privacy email].
11. Changes
We may update this policy. The date above shows the current version, and material changes will be announced on the site.