Privacy Policy

Effective date: August 5, 2026

This Privacy Policy explains how Orchestrate IQ, LLC ("Trazomo," "we," "us") collects, uses, discloses, and protects personal data when you use our website, learning platform, and related services (the "Services"). It is written to satisfy transparency obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and other applicable US state privacy laws.

For how AI features specifically process your submissions, please also read our AI Disclosure. For a detailed inventory of cookies and categories, see our Cookie Policy.

1. Controller Information

Controller: Orchestrate IQ, LLC (d/b/a Trazomo)
Address: 643 N York St, Suite 70, Elmhurst, IL 60126, USA
Privacy contact: [email protected]

We have not appointed a Data Protection Officer. For privacy requests concerning EU/UK data subjects, contact us at the address above.

2. Personal Data We Collect

  • Account and authentication data: your email address, a password hash managed by Supabase Auth, and session cookies. You may instead sign in with LinkedIn (see Section 2.1). We also store the date and time you acknowledged our AI confidentiality notice.
  • Profile and onboarding data: full name, firm or organization name, jurisdiction, role, who you serve, organization size, whether you work with a team, practice or work areas, level of AI experience, tool preferences, your free-text build goal, the builder archetype we derive from your answers, onboarding completion status, and account tier (free or paid).
  • Learning activity data: lesson progress and timestamps, quiz attempts including the specific answers you selected, scores and pass or fail results, XP (gamification) events, spaced-repetition review state, module access grants, and any completion certificates issued to you. A certificate carries your name and can be checked by anyone who holds its verification code, which is how certificate verification works.
  • Exercise and reflection submissions: the free text you write into AI-assisted exercises and reflections, together with the score and structured feedback the AI model returns. These are stored in your learning history until you delete them or we delete your account.
  • AI tutor conversations: the full transcript of your chats with the in-lesson AI tutor, including your messages, the tutor replies, and which model produced each reply. Transcripts are stored so a conversation can be resumed across sessions.
  • AI usage counters: for free accounts, a running count of AI interactions used against the free allowance.
  • Billing and transaction data: checkout session identifiers, transaction IDs, payment status, amount and currency, customer IDs, and the billing email used at checkout. Payment card data is never received or stored by Trazomo; it is handled by Creem (our Merchant of Record, see Section 6).
  • Marketing and plan-funnel data: if you ask to be notified about Trazomo or request a training plan before creating an account, we store the email address you give us, the source of the signup, and the answers you gave the plan questionnaire. This record is keyed to your email address and is separate from any account you later create.
  • Referral data: if you use or share a referral code, we store the link between the referring and referred accounts and any milestone rewards earned.
  • Support communications: messages you send us by email, including any content and metadata you volunteer.
  • Technical and usage data: authentication cookies, security and performance signals at the edge, and product analytics events collected via PostHog (see Section 3).

2.1 Signing in with LinkedIn

Trazomo offers exactly two ways to sign in: email and password, or LinkedIn. We use no other third-party sign-in provider. We do not offer Google, Microsoft, GitHub, or any other social login.

LinkedIn sign-in uses LinkedIn's OpenID Connect service. When you choose it, LinkedIn returns a standard OpenID Connect identity token covering your sign-in identifier, basic profile, and email address. We keep only your email address and your display name from that token. We do not store your LinkedIn profile URL, headline, connections, employer, or profile photo. Your profile photo, if any, is shown from the sign-in token while you are logged in and is never copied into our database.

LinkedIn sign-in is offered for authentication only. It is not consent to marketing, it is not a professional or licensure verification, and we do not post to LinkedIn, read your LinkedIn activity, or share your Trazomo activity with LinkedIn.

3. Cookies, Local Storage, and Analytics

We use cookies and similar storage technologies to operate and secure the Services, to remember your preferences, and to measure usage. The categories on our site are:

  • Strictly necessary. Authentication and session continuity (Supabase Auth), and security and traffic protection (Cloudflare). These cannot be disabled.
  • Functional. Theme and interface preferences stored in your browser.
  • Analytics. Product analytics events sent to PostHog EU Cloud, identified by a random first-party identifier stored in your browser's local storage.

What we do not do. We do not use advertising or cross-site tracking technologies. We do not use session replay: no recording of your screen, mouse movement, keystrokes, or form contents is captured at any time. We do not use automatic event capture, so the only analytics events that exist are the specific ones we have written into our own code.

Current state of consent controls. A category-level consent banner is not yet live on this site. Today, analytics events and the support Messenger load for every visitor, and the first-party analytics identifier is written to local storage on your first visit. Until the banner ships, you can prevent this by blocking or clearing site storage in your browser, or by writing to [email protected] to ask us to suppress analytics for you. We are working to gate these categories behind an opt-in choice and will update this policy and the Cookie Policy when that lands. For the full per-identifier inventory, see the Cookie Policy.

4. Why We Process Personal Data (GDPR Legal Bases)

  • Contract performance (Art. 6(1)(b)): account creation, login, course delivery, progress tracking, AI-assisted evaluation and tutoring, in-app support, and purchases.
  • Legitimate interests (Art. 6(1)(f)): platform security, abuse prevention, fraud and chargeback defense, service diagnostics, product analytics, understanding which learners are reaching the limits of the free tier, and internal administration. We balance these interests against your rights and freedoms and document the assessments we rely on.
  • Consent (Art. 6(1)(a)): marketing email you ask us to send, and non-essential storage on your device once our consent control is live. You can withdraw consent at any time.
  • Legal obligations (Art. 6(1)(c)): tax, accounting, and compliance record-keeping.

5. AI Processing Disclosures

AI-assisted exercises, reflections, and the in-lesson tutor send the text you write to an AI model for evaluation or a reply. Every production AI request is routed through Cloudflare AI Gateway to OpenRouter, which forwards it to a selected third-party foundation model at request time. Models in current use are supplied by Anthropic, OpenAI, Google, Alibaba Cloud (Qwen), and DeepSeek. We request OpenRouter's Zero Data Retention (ZDR) routing on every request.

Some inputs are sent to a model more than once: a short safety and scope classifier reviews your text before the main evaluation or tutor call. The tutor also receives context about you drawn from your onboarding answers, including your role, jurisdiction, experience level, and free-text goal. Your email address, name, and account identifiers are never sent to AI models.

Do not submit attorney-client privileged material, attorney work product, client personal data, information subject to ABA Model Rule 1.6, trade secrets, sealed or export-controlled data, or any other confidential information into AI-assisted fields. See our AI Disclosure for the full confidentiality clause, the data-flow chain, and training-retention details.

6. Service Providers and Subprocessors

We share personal data only as needed with the following processors and independent controllers:

  • Supabase, Inc. Authentication and database hosting. Our database and authentication service run in Supabase's EU (Ireland) region. DPA: supabase.com/legal/dpa.
  • Cloudflare, Inc. Application hosting on Cloudflare Pages and the Workers runtime, CDN and edge delivery, bot and traffic protection, and AI Gateway, through which all AI requests are proxied. Cloudflare does not train models on your inputs. DPA: cloudflare.com/cloudflare-customer-dpa.
  • OpenRouter, Inc. AI model routing. Does not log prompts or completions by default and does not train on them. Some downstream model providers may retain inputs for abuse monitoring; we request Zero Data Retention routing on every request. OpenRouter applies its Sensitive Info guardrail to our requests before forwarding them: pattern-based detection of formats such as email addresses, phone numbers, Social Security numbers, credit card numbers and IP addresses, which are replaced with a labeled placeholder or cause the request to be rejected before it reaches the model. It also scans requests for common prompt-injection patterns. NLP-based detection of personal names and addresses is not enabled, so those are not detected or removed. Privacy: openrouter.ai/privacy.
  • Model providers reached through OpenRouter. Your submission is processed by whichever model serves the request: Anthropic, OpenAI, Google, Alibaba Cloud (Qwen models), or DeepSeek. These providers are located outside the EEA, and the Qwen and DeepSeek models are supplied by companies established in China. See Section 7.
  • LinkedIn Ireland Unlimited Company (and LinkedIn Corporation for users outside the EEA, UK, and Switzerland). Optional sign-in provider, engaged only if you choose to sign in with LinkedIn. Privacy: linkedin.com/legal/privacy-policy.
  • Resend (Plus Five Five, Inc.) Email delivery. Resend carries both the authentication email sent by Supabase (address confirmation, password recovery, security notices) and the application email we send ourselves (list confirmations, your training plan and its share link, and the internal notification that tells us a new signup arrived). Privacy: resend.com/legal/privacy-policy. DPA: resend.com/legal/dpa.
  • Sendinblue SAS (d/b/a Brevo) Live chat. Brevo Conversations runs the support Messenger on our site and in the app. What reaches Brevo is the messages you type into the chat, and your email address if you enter it in the chat form so that our reply can find you by email once you have left the page. Sendinblue SAS is a French société par actions simplifiée with its registered office at 17 rue Salneuve, 75017 Paris, France, RCS Paris 498 019 298. The sub-processor list at Annex 2 of Brevo's data processing agreement names OVH in France and Google Cloud Platform in Belgium as the infrastructure Brevo hosts its services on. That data processing agreement is Appendix 3 of Brevo's Terms of Service and is incorporated into them automatically. Privacy: brevo.com/legal/privacypolicy. DPA, at Appendix 3: brevo.com/legal/termsofuse.
  • Armitage Labs OÜ (d/b/a Creem) Merchant of Record, payment processing, tax collection and remittance, and billing. Creem is the contractual seller of record for your purchase. Buyer Terms: creem.io/buyer-terms. Privacy: creem.io/privacy.
  • PostHog, Inc. (EU Cloud) Product analytics. Primary ingest and storage in the EU. Most events are identified by a random first-party identifier or by your account identifier. Two cases are different and we call them out in Section 6.1. DPA: posthog.com/dpa.
  • Slack Technologies, LLC (a Salesforce company) Internal operational alerting. One alert type carries a learner email address into our private Slack channel, described in Section 6.1. Privacy: slack.com/trust/privacy/privacy-policy.

6.1 Where your email address reaches analytics and internal alerting

Two flows send an email address beyond our database, and we describe them here rather than leaving them inside a general analytics statement:

  • Free-tier quota alert. Free accounts have a lifetime allowance of 30 AI interactions. When a free account reaches 25 of those 30, we raise one internal alert so we can follow up about upgrading. That alert sends your email address to PostHog as a property of a single analytics event, and posts your email address into our private Slack channel. It fires once per account, at that one threshold, and never again. Paid accounts do not generate it. Our legal basis is legitimate interests in understanding and supporting conversion; you can object to it at any time by writing to [email protected].
  • Plan funnel. If you request a training plan before you have an account, the identifier for those events is the email address you entered, because no account identifier exists yet. That means PostHog receives your email address as the event identifier for the plan funnel.

Apart from these two cases, analytics events carry a random first-party identifier or your account identifier, not your email address.

7. International Data Transfers

Your account, profile, learning history, exercise submissions, and tutor transcripts are stored in the European Union, in Supabase's Ireland region. Analytics events are ingested and stored by PostHog EU Cloud. The support Messenger is EEA-hosted.

Some processing necessarily occurs outside the EEA, including in the United States and, for the Qwen and DeepSeek models, in or by companies established in China. Where personal data leaves the EEA, we rely on approved transfer safeguards, including the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914) and, for transfers to organizations certified under the EU-U.S. Data Privacy Framework (DPF), adequacy under that framework. For transfers to the UK, we additionally use the ICO International Data Transfer Addendum (IDTA). China has not been the subject of an adequacy decision, so transfers reaching a China-established model provider rely on Standard Contractual Clauses and on the Zero Data Retention routing we request. If you would rather your text never reached those providers, do not use the free tier's AI features; contact us and we will tell you which models serve which tier at that time.

PostHog-specific transfer note. PostHog Cloud EU stores core product-analytics event data in the EU; certain ancillary services may transfer data to the United States. PostHog publishes the current list of such transfers at posthog.com/blog/posthog-cloud-eu. We review that list at each material revision of this Privacy Policy and update our disclosures accordingly.

Prior US hosting. Before August 4, 2026, our database ran in a United States region. Data created before that date was migrated to Ireland. If you want to know whether a copy of your data remains in the retired US project, ask us and we will tell you.

8. Retention

We do not currently run an automated deletion or anonymization job. The periods below describe what we hold and what we do, and where a period depends on a manual step we say so plainly rather than promising an automatic one.

  • Account, profile, onboarding, progress, quiz, XP, reflection, certificate, and tutor-transcript data: retained while your account exists. When we delete an account, these records are deleted with it because they are tied to the account by database constraint.
  • Exercise and reflection text: stored in your learning history until you delete the reflection or we delete your account. The prompt we assemble around it is not stored separately by us, but it does pass through Cloudflare AI Gateway, which may log request and response content according to our gateway configuration.
  • Tutor transcripts: stored until we delete your account, so that a conversation can be resumed.
  • Marketing and plan-funnel signup records: these are keyed to an email address rather than to an account, so they are not removed automatically when an account is deleted. We delete them on request.
  • Billing and tax records: retained for 7 years where required by accounting or tax law.
  • Inactive accounts: we do not currently delete accounts for inactivity. If we introduce an inactivity rule, we will state the period here before applying it.
  • Analytics events, provider logs, security logs, and backups are held for the periods set by the relevant provider (PostHog, Cloudflare, Supabase, Resend, Slack). We do not control those windows independently of the provider settings we choose.

9. Your GDPR, UK GDPR, and US State Privacy Rights

Subject to applicable law, you may request access, rectification, deletion (right to erasure), restriction of processing, objection to processing, and portability of your personal data, and you may withdraw any consent you have given. California and other US state residents additionally have rights to know, delete, correct, and opt out of the sale or sharing of personal information, and we do not sell personal information.

How to exercise them, and what actually happens. Trazomo has no self-service data export and no self-service account deletion. Every request is handled manually by us. Email [email protected] from the address on your account, or tell us which address the request concerns so we can verify it. We respond within 30 days (extendable by 60 days for complex requests, with notice). We may ask you for additional information to confirm your identity before we act, and we ask only what we need for that purpose.

The only self-service controls in the product today are the profile fields on your settings page, which you can correct yourself. Anything else, including export and deletion, goes through the email route above. You also have the right to lodge a complaint with your local data protection authority or, in the US, with your state attorney general.

10. Automated Decision-Making

AI-generated scores and feedback are coaching signals for your learning. They do not produce legal or similarly significant effects concerning you. We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of GDPR Article 22.

11. Security

We use technical and organizational measures designed to protect personal data, including TLS in transit, row-level access controls in the database, managed infrastructure providers, and data-minimization practices. No method of transmission or storage is fully secure.

12. Children

The Services are not intended for children under 18, and we do not knowingly collect personal data from children under 18. If you believe a child has provided us personal data, please contact us and we will delete it.

13. Changes to this Policy

We may update this Privacy Policy. If we make material changes, we will update the effective date and provide notice where required (for example, by email or by an in-app banner).

14. Contact

For privacy requests or questions, contact:
Orchestrate IQ, LLC
643 N York St, Suite 70, Elmhurst, IL 60126, USA
[email protected]