1. Who we are and who the controller is
Oro Shin ("Oro", "we", "us", "our") is the company that operates Oro AI Agent (the "agent", the product) and the website at oroshin.site. Oro AI Agent is an autonomous AI agent that a business owner deploys to run their customer channels: it answers messages and comments, publishes posts, handles product catalogues, verifies payments, and reports back.
For the personal data described in this policy, Oro Shin is the data controller. You can reach us at support@oroshin.site. A regulator or a business customer who needs Oro Shin's registered company details can obtain them by emailing support@oroshin.site.
2. The scope of this policy
This policy applies to the Oro AI Agent app, the website, and the backend services that run the agent. It covers the personal data of you, our customer, and the data your business receives through the channels you connect to Oro AI Agent.
When Oro AI Agent processes messages, comments, and other content from the people who contact your business, it does so on your behalf. For that content, you are the controller and Oro Shin acts as your processor. This policy explains what the agent does with that data so you can meet your own obligations to the people you serve.
3. If you are a business in the EEA or the UK
Where you are established in the EEA or the UK and Oro AI Agent processes end-customer personal data on your behalf, Oro Shin acts as your processor for that data. In that role, Oro Shin commits that:
- we process end-customer personal data only on your documented instructions;
- we impose a duty of confidentiality on the people who may access it;
- we apply the security measures described in the Security section;
- we use only the sub-processors listed in this policy, and we will give you notice before adding a new one so that you may object;
- we assist you with requests from data subjects and with security incidents;
- on termination, we delete or return the data as described in the Retention and deletion section; and
- we make available to you the information needed to demonstrate compliance with these obligations.
To arrange a data processing agreement, email support@oroshin.site.
4. The data we collect
4.1 Account data
The details you use to create and sign in to your Oro account, and your subscription status. Subscriptions purchased on Android are handled by Google Play Billing.
4.2 Per-channel data from the platforms you connect
The agent only reaches a platform after you connect it, and only with the access token that connection produces. The channels Oro AI Agent supports are:
| Channel | What the agent does when you connect it |
|---|---|
| Facebook Messenger | DMs and post comments, auto-reply, product photos |
| DMs, comments, scheduled posts | |
| WhatsApp Cloud API, send and inbound | |
| Telegram | Bot API, send and inbound |
| LINE | Messaging API, reply and push |
| TikTok | Connector, content |
| YouTube | Connector |
| Google Business Profile | Reads reviews, drafts owner replies |
| GitHub | Your own GitHub account: list repos, create a repo, publish a site to GitHub Pages |
For each connected channel we access the account or page identifiers that channel exposes, the access token the connection produces, and the messages, comments, posts, or reviews needed to run the feature you enabled.
GitHub is a connector you link to your own account. Oro Shin's own GitHub is never involved, and no GitHub credential ever reaches the agent's sandbox. The agent uses your connection only to list your repositories, create a repository, and publish a site to GitHub Pages on your behalf.
4.3 Message and comment content the agent processes to reply
To answer on your behalf, the agent reads the messages and comments people send to your connected channels and generates the replies it sends back. This can include text, images, video, and audio that people include in their messages.
4.4 Catalogue and business data
The description of your business, the agent configuration, and the product catalogue you give the agent so that it can plan and execute work on its own.
4.5 Bring Your Own Key (BYOK) API keys
If you choose to bring your own key, we store the Anthropic, OpenAI, or Google AI Studio API key you supply so the agent can call your provider under your own account.
4.6 Technical and log data
Standard technical data generated when you use the app and website, such as your IP address, device type, access times, and records of the actions taken in your account. We use this to operate, secure, and debug the service.
5. How and why we use your data
- To run the agent: read messages and comments, generate and send replies, publish posts, manage catalogues, verify payments, and report back to you.
- To let the agent work in its isolated cloud computer, where it can browse the web, run code, read and write files, transcribe audio, process images and video, and publish websites.
- To create and manage your account and your subscription.
- To secure the service, prevent abuse, and diagnose problems.
- To meet our legal obligations and respond to lawful requests.
6. Legal bases under GDPR and UK GDPR
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract. To provide the service you signed up for, including running the agent across the channels you connect and managing your account and billing.
- Legitimate interests. To secure the service, prevent abuse, and keep the product working and supported, balanced against your rights.
- Consent. When you connect a third-party channel or supply your own API key, you actively grant that access. You can withdraw it by disconnecting the channel or removing the key. Withdrawing consent does not affect the lawfulness of any processing we carried out on the basis of your consent before you withdrew it.
- Legal obligation. To keep records we are required to retain and to comply with the law.
7. Automated decisions
Oro AI Agent replies to the people who contact your business, and publishes content, on its own. You, the business owner, set the persona, the auto-reply rules, the blocklist, and the escalation rules that govern how it acts; approval gates apply to publishing actions; and payment-slip analysis flags a transfer for you to review rather than settling an order.
Because you configure the agent, can require your approval before it acts, and remain the decision-maker, Oro Shin does not make solely automated decisions that produce legal effects, or similarly significant effects, concerning an end customer.
If an end customer wants to reach a human, they can contact the business they were messaging, or contact us at support@oroshin.site.
8. AI processing
When you have not brought your own key, the agent sends the content it needs to generate a reply to the following AI sub-processors:
| Sub-processor | Purpose |
|---|---|
| OpenRouter, Inc. | routes most inference to the underlying model |
| Alibaba Cloud (Model Studio / DashScope, Singapore) | the default fast tier |
| Voyage AI | text embeddings for memory and retrieval |
Data sent to these sub-processors is used solely to generate the response you asked for. We do not train models on customer data, and we do not authorise a sub-processor to use it for anything other than producing the response that was requested.
Bring Your Own Key. If you supply your own Anthropic, OpenAI, or Google AI Studio key, those requests go directly to that provider under your own agreement with them, and your Oro credits are not consumed. In our system, the only path that reaches Google's Gemini API is a BYOK request, and only with a key you supplied.
9. Infrastructure sub-processors and where they run
We rely on the following infrastructure providers to host the service and store data:
| Sub-processor | Purpose | Region |
|---|---|---|
| Google Cloud Platform | Cloud Run services, Cloud SQL (control plane) | us-central1 |
| Neon | the per-customer business database | as provisioned |
| Cloudflare | CDN, WAF, and R2 object storage for media | global |
| E2B | the isolated sandbox the agent computes in | — |
| Google Play Billing | subscriptions on Android | — |
10. International transfers
Our sub-processors operate in more than one country. The control plane and the agent's sandbox run in the United States (Google Cloud's us-central1 region). The default fast AI tier runs on Alibaba Cloud's international endpoint in Singapore. Cloudflare's edge network and R2 object storage are global.
Where personal data leaves the EEA or the UK, we rely on the transfer mechanisms our sub-processors make available, including the European Commission's Standard Contractual Clauses where the sub-processor offers them. To ask which mechanism applies to a particular transfer, and to obtain a copy of it, email support@oroshin.site.
11. How long we keep things, and deletion
We keep each category of personal data only as long as there is a reason to hold it. The criteria we apply, by category, are:
- Account and configuration data: for as long as your account is active.
- Connected-platform tokens: until you disconnect the channel or delete your account.
- End-customer messages and comments: for as long as they are needed to answer and to maintain the conversation memory you configured, and no longer than the life of your account.
- Technical and security logs: for a limited period set by operational and security need.
- Billing records: for as long as tax and accounting law requires us to keep them.
When you delete your account, or disconnect a channel, we delete the associated data, including the stored access tokens for that connection. Content that other people already posted on a platform stays on that platform and is outside our control. You can start a deletion at any time; the methods are described on our Data Deletion page.
12. Security
- Provider tokens are encrypted at rest and are only ever used by the backend. A connector token never reaches the agent's sandbox and never reaches the app.
- The agent's sandbox is isolated per customer and holds no platform credentials.
- Business data lives in a separate database per customer, and the control plane enforces row-level isolation so one account cannot read another's data.
- Connections to our services use standard transport encryption.
No method of storage or transmission is perfectly secure, but these controls are designed so that the highest-risk data, your platform tokens, never leaves the backend.
13. Your rights and how to exercise them
Subject to applicable law, you have the right to access, correct, delete, restrict, and port your personal data, to object to certain processing, and to withdraw consent. Withdrawing consent does not affect the lawfulness of any processing we carried out on the basis of your consent before you withdrew it. You can also lodge a complaint with your data protection authority.
- To access, correct, or export your data, email support@oroshin.site.
- To delete your data, follow the steps on our Data Deletion page.
- To stop a channel, disconnect it in the app at any time; the stored token for that connection is removed.
14. Platform-specific terms
Our use of data from each platform is also governed by that platform's own developer terms:
- Meta Platform Terms for Facebook, Messenger, Instagram, and WhatsApp.
- Google API Services User Data Policy, including its Limited Use requirements, for Google Business Profile, YouTube, and any Google AI Studio key you bring.
- TikTok developer terms for TikTok.
Oro AI Agent's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve the features you enabled; it is not transferred except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with your consent; it is not used for advertising; and no human reads it except with your affirmative consent, for security purposes, to comply with applicable law, or where it has been aggregated and anonymised.
Data obtained from each platform's APIs is used only to provide the feature you enabled. It is never sold, and it is never used for advertising. Oro AI Agent is an independent third-party tool and is not affiliated with, endorsed by, or sponsored by these platforms.
15. Children
Oro AI Agent is not intended for anyone under 13 years of age, and we do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will remove it.
17. Changes to this policy
We may update this policy from time to time. When we make a material change, we will post the new version on this page and update the "Last updated" date above. Continued use of the service after a change means you accept the updated policy.
18. Contact
If you have questions about this policy or how we handle your data, contact us at support@oroshin.site.