Last updated: September 7, 2026
Information handled by the licensing service
Orca's licensing website processes account details such as display name, email address, password verifier, role, subscription status, license status, device identifiers and labels, app version, activation timestamps, and administrative audit events. Compatible signed-in builds also store an account-scoped encrypted copy of profiles, saved website account credentials, proxies, tags, and contact/address autofill data. After accepting the expanded browser-state disclosure, newer builds also checkpoint browsing history, reading lists, tabs, supported cookies and website storage for transfer between computers.
Encrypted account library
Orca encrypts the synchronized library on your computer before upload. The service stores authenticated ciphertext and encrypted key envelopes, not plaintext profile content or a plaintext library key. Your Orca password is used on your computer to unlock or update the recovery envelope after sign-in; it is not stored in the sync record.
Information kept on your computer
Older builds keep browser state local. With expanded sync, supported session cookies, first-party local storage and per-tab session storage are encrypted and transferred; those contents can include authentication tokens and other sensitive website data. Orca payment-card records, CVV fields, mailbox integration credentials, device-bound keys, extensions, caches, IndexedDB and unsupported storage are not included. Order records and other unlisted application data remain local unless separately transmitted.
How information is used
Licensing information is used to authenticate accounts, determine access, enforce device limits, display subscription details, support account security, and record administrative changes. Encrypted library and checkpoint data is used to synchronize and restore supported Orca data for the same authenticated account. Only one current device session can access the vault. A checkpoint is made available only after its encrypted parts verify; offline or unfinished changes cannot transfer. Websites may still require reauthentication on another computer.
Security
Passwords are stored as salted password verifiers rather than plaintext. License and administrator authenticator secrets are encrypted at rest, while recovery codes are stored only as one-way hashes. Administrator sessions require two-factor verification. Session cookies are HttpOnly and use secure transport in production. No system can guarantee absolute security, so customers should protect their credentials and devices.
Retention and control
Account, subscription, device, encrypted library, and audit records may be retained while access is active and afterward as needed for synchronization, security, support, and administrative records. The signed-in customer can delete the encrypted cloud copy and sign out while keeping local data. Administrators can inspect operational metadata, revoke devices, cancel licenses and disable accounts; this account-sync protocol does not give administrators the customer's decryption key.
Third-party websites and proxies
Orca can open third-party websites and use proxy services selected by the customer. Those services operate under their own privacy terms. Orca does not control how a destination website or proxy provider processes traffic.
Changes
This notice may be updated as Orca's distribution, payments, support, or product capabilities change. The date shown below identifies the current version.