Privacy Policy

Last updated: April 10, 2026

1. Who we are

Orange Panda ("we", "our", or "us") operates the Orange Panda platform — a 1-on-1 meeting intelligence tool that helps managers track team health, log structured conversations, and follow up on commitments. This Privacy Policy explains how we collect, use, store, and protect information when you use our service at orangepanda.ai.

If you have questions about this policy, contact us at [email protected].

2. What data we collect

We collect the following categories of data:

CategoryExamples
Account dataName, email address, profile photo (from OAuth provider)
Team dataNames and roles of direct reports you add to your workspace
Meeting recordsQuestion answers, health scores, themes, notes, commitments, and meeting dates you log
Audio recordingsAudio files captured during AI-assisted 1-on-1 sessions (Pro plan only, with explicit consent)
TranscriptsText transcriptions generated from audio recordings
Usage dataPages visited, features used, session duration (anonymized analytics)
Payment dataBilling information processed by Stripe — we never store full card numbers

3. Audio recordings and transcripts

The AI recording feature is available on the Pro plan only. Before any recording begins, the application requires explicit consent confirmation from the manager. We strongly recommend that managers also inform their direct reports that a session is being recorded before starting.

Storage: Audio files are uploaded to encrypted cloud storage (AWS S3) and are processed solely to generate a transcript and extract meeting insights. Raw audio files are deleted immediately after transcription is complete.

Transcripts: Text transcripts are retained for 30 days from the date of the meeting. After 30 days, transcripts are automatically and permanently deleted. Managers may also delete a transcript at any time from the meeting record.

AI processing: Transcripts are sent to a large language model (LLM) to extract health scores, themes, and commitments. This processing happens server-side. We do not use your recordings or transcripts to train AI models.

Employee access: Employees (direct reports) do not have accounts in Orange Panda and cannot log in to view their own records. Meeting data is visible only to the manager who logged it and to workspace administrators.

4. How we use your data

We use the data we collect to:

  • Provide, operate, and improve the Orange Panda service
  • Generate health scores, meeting summaries, and analytics
  • Send product notifications and account-related emails
  • Process payments via Stripe
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your meeting content, team member data, or recordings for advertising purposes.

5. Data retention

Data typeRetention period
Account and profile dataUntil account deletion
Meeting records and answersUntil account deletion or manual deletion
Audio recordingsDeleted immediately after transcription
Transcripts30 days from meeting date, then auto-deleted
Usage analytics90 days (anonymized)
Payment records7 years (legal requirement)

6. Data sharing and third parties

We share data with the following third-party service providers only as necessary to operate the platform:

ProviderPurpose
AWS S3Encrypted file storage (audio, exports)
StripePayment processing
AI/LLM providerTranscript analysis and template generation (no training on your data)
Whisper (speech-to-text)Audio transcription (Pro plan only)

We do not share your data with employers, HR platforms, or any third parties for analytics, advertising, or profiling purposes.

7. Security

We take reasonable technical and organizational measures to protect your data, including:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Data at rest is encrypted using AES-256
  • Authentication is handled via OAuth 2.0 — we never store passwords
  • Session tokens are signed with a secret key and expire automatically
  • Audio files are stored in private S3 buckets with no public access
  • Access to production systems is restricted to authorized personnel

No system is 100% secure. If you discover a security vulnerability, please report it to [email protected].

8. Your rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your account and associated data
  • Portability: Export your meeting data in CSV format (via Settings → Data Export)
  • Objection: Object to certain processing activities

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

9. Cookies

Orange Panda uses a single session cookie to keep you logged in. We do not use third-party tracking cookies or advertising cookies. The session cookie is HTTP-only, Secure, and SameSite=Strict.

10. Children's privacy

Orange Panda is a professional tool intended for use by adults in a workplace context. We do not knowingly collect data from anyone under the age of 16. If you believe a minor has provided us with personal data, contact us at [email protected].

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify registered users by email. Continued use of the service after changes are posted constitutes acceptance of the updated policy.

12. Contact us

For privacy-related questions or requests, contact us at:

Orange Panda

Email: [email protected]

© 2026 Orange Panda