Back to Home

Privacy Policy

This policy explains what OrgX collects, why it is used, who receives it, how long it is retained, and what controls users have across the OrgX app, ChatGPT app, MCP server, widgets, tools, and connected workspaces.

Last updated: June 2026

Encrypted

Data is protected in transit and at rest where supported by the underlying provider.

Transparent

Tool inputs, outputs, recipients, retention, and controls are documented here.

Controlled

Users can disconnect clients, revoke permissions, and request export or deletion.

1. Data We Collect

Account and workspace context: OrgX user, organization, workspace, initiative, workstream, milestone, task, decision, artifact, agent, plan-session, and settings records needed to complete user-requested work.

Tool inputs: prompts, search queries, entity IDs, workspace IDs, initiative names, task instructions, approval notes, rejection reasons, artifact URLs, GitHub pull request URLs, quality scores, activity updates, uploaded or linked artifact text, and other fields a user or connected client sends to OrgX.

Tool outputs: structured tool responses, generated summaries, decisions, artifacts, tasks, recommendations, cost estimates, agent receipts, status updates, widgets, and links returned to the requesting client.

Connection and security data: OAuth client registrations, authorization state, access tokens, refresh tokens, token expiry, granted scopes, MCP session IDs, session-bound workspace context, PKCE/OAuth metadata, request IDs, rate-limit state, audit events, and diagnostic logs.

Billing data: plan, subscription, invoice, and payment workflow metadata when a user starts billing or account-upgrade flows. Payment card details are handled by Stripe and are not stored by OrgX.

2. Purposes For Using Data

We use data to authenticate users and MCP clients, enforce OAuth scopes and workspace access, execute requested tools, return structured outputs, render widgets, maintain organizational memory, coordinate agent work, and support human approval flows.

We use operational data to prevent abuse, apply rate limits, debug incidents, secure the service, measure reliability, and maintain auditability for workspace actions.

We do not sell OrgX MCP data, ChatGPT app data, tool inputs, tool outputs, connector data, or workspace records for advertising.

We do not train foundation models on proprietary workspace data unless a user or workspace administrator explicitly opts in through a documented workflow.

3. Recipients And Sub-Processors

OrgX-operated application APIs and databases receive the data needed to store organizational memory, initiatives, tasks, decisions, artifacts, agent records, plan sessions, receipts, and workspace settings.

User-authorized MCP clients and ChatGPT app surfaces receive the tool descriptors, prompts, tool inputs they send, tool outputs returned by OrgX, and widget resources needed to display the requested app experience.

Infrastructure and service providers may process limited data for hosting, database, authentication, queueing, observability, email, billing, AI inference, product telemetry, release operations, and customer-authorized integrations. Current providers and use triggers are described on the sub-processors page.

Payment or billing services receive data only when a user starts an account upgrade, checkout, invoice, or billing workflow. OrgX does not silently purchase plans or share payment details with MCP clients.

4. Retention

Durable OrgX records such as decisions, tasks, initiatives, artifacts, agent receipts, plan sessions, and workspace settings remain until a user or workspace administrator deletes them, the workspace is deleted, or the workspace retention policy removes them.

OAuth client registrations, access tokens, refresh tokens, authorization state, and MCP session state are retained only as long as needed to maintain the connection, honor refresh behavior, enforce access controls, and support security review. Tokens expire according to their configured lifetime.

Operational telemetry and diagnostic logs are retained for the period needed to operate, debug, secure, and audit the service, then deleted or aggregated according to OrgX operational retention practices.

Reviewer and demo workspaces may be reset to a known baseline before app-review or sales-demo runs so tests remain reproducible.

5. User Controls

Users can disconnect the OrgX app or MCP server from ChatGPT, Claude, Cursor, Codex, or another MCP client, which stops that client from making further authenticated tool calls.

Users and workspace administrators can review, update, export, correct, or delete OrgX records through OrgX product workflows and authorized write-capable MCP tools.

Users can revoke connector permissions, rotate credentials, remove workspace members, request account or workspace deletion, and contact support for privacy or data-control requests.

Users should not put secrets, private keys, passwords, MFA codes, cookies, payment card numbers, government IDs, health records, or unrelated sensitive personal data into prompts, notes, metadata, artifact text, or URLs.

6. Security And Access Controls

OrgX uses TLS in transit, encryption at rest where supported by the underlying provider, scoped OAuth grants, workspace membership checks, tool access gates, audit logging, and rate limits.

Read-only and write-capable tools are explicitly annotated in MCP metadata. Workspace-scoped tools verify that the caller is authorized for the requested workspace before returning or mutating data.

Dynamic client registration is supported for MCP clients that require it. Secrets, access tokens, refresh tokens, and session identifiers should never be pasted into public logs, issues, prompts, or support requests.

7. Contact

For connector support, use GitHub Issues and include enough detail to reproduce the problem without sharing secrets. For privacy or data-control requests, include the OrgX workspace and account context needed to locate the data, but do not include tokens, passwords, cookies, or private keys.

OrgX — Proof for AI-Delivered Work