oravelby Nextus
Log in

Privacy Policy

Last updated: July 21, 2026

This policy explains what Oravel (operated by Nextus Digital Solutions) collects, how we use it, and the choices you have. Short version: we collect what's needed to run the product, we don't sell your data, and credentials you connect are encrypted.

1. What we collect

  • Account data — name, email, and authentication data, handled by our sign-in provider (Clerk).
  • Workspace content — the websites you add, brand kits, article briefs and drafts, product photos you upload or import, keywords, and settings.
  • Connected-platform credentials — for example a Shopify access token you provide to enable publishing. These are encrypted at rest (AES-256) and never shown back to you or anyone else.
  • Usage & logs — standard technical logs (IP, browser, timestamps, errors) needed to operate and secure the Service.
  • Support messages — anything you send to support@oravel.tech.

2. How we use it

  • To provide the product: generate strategies, articles, and images for your workspace; fetch keyword data; run the scans you request; publish to platforms you connect.
  • To operate, secure, and improve the Service and to communicate with you about it.
  • To comply with law and enforce our Terms.

We do not sell your personal information or use your private workspace content to advertise to you.

3. AI processing

Generating content requires sending relevant inputs (for example your site's text, a brief, or a product photo) to AI providers — currently Anthropic (text) and OpenAI (images) — via their business APIs. We rely on providers whose API terms state customer content is not used to train their models. Keyword metrics come from search-data providers (currently DataForSEO).

4. Who else processes data

We use a small set of infrastructure providers under their own security terms: Clerk (authentication), Supabase (database & file storage), Railway (hosting), plus the providers named above. If you connect a platform like Shopify, content you choose to publish is sent to it.

5. Retention & deletion

Workspace data is retained while your account is active. Disconnecting an integration deletes its stored credential. If you delete your account (or ask us to at support@oravel.tech), we delete workspace data within 30 days, except minimal records we must keep for legal or security reasons.

6. Cookies

The app uses essential cookies for sign-in sessions (via Clerk). The marketing site sets no tracking cookies.

7. Security

Data is encrypted in transit (TLS) and at rest at our infrastructure providers; connected-platform credentials get an additional application-layer encryption (AES-256-GCM). Access to production systems is restricted. No system is perfectly secure — if we learn of a breach affecting your data we will notify you as required by law.

8. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Email support@oravel.tech and we'll honor verified requests.

9. Children

The Service is for businesses and is not directed to children under 16.

10. Changes

We'll update this policy as the product evolves and notify account holders of material changes.

11. Contact

support@oravel.tech · Oravel, a Nextus Digital Solutions product.

oravel
FeaturesPricingAboutTermsPrivacysupport@oravel.tech
© 2026 Oravel · a Nextus Digital Solutions product