Privacy
orchid runs on your machine.
orchid has no account, no server and no analytics. It never holds an API key and never proxies a request.
What orchid keeps
- The run’s durable state, committed to your repository’s integration branch: requirements, roadmap, tasks, reviews, the journal and lessons.
- Runtime files kept out of git, in
.orchid/runtime/: locks, job manifests, logs and result envelopes. - Machine-local settings and trust records in
~/.orchid.
Who orchid talks to
Only the tools you configure, on your machine: git, and the agent CLIs you bind to roles. Each CLI talks to its vendor with your own login, as it always does, and sees the code you point it at. If you set up a notify channel, the question for you is sent through it, and nothing else.
This website
Static pages, with no cookies, no analytics and no fonts or scripts from elsewhere. The theme you pick is kept in your browser. Cloudflare serves the pages.
The source of both is on GitHub.