1. Controller and scope
Anass Anedjar, Oruva, based in Casablanca, Morocco, is the data controller for the desktop application's account, trial, licensing, and protected-conversion services. Contact and data-rights requests can be sent to hello@oruva.app.
Oruva is local-first, but it is not offline-only. An account is required to use Oruva 1.3.1, the version covered by this policy. Asset files, thumbnails, library databases, tags, captions, search vectors, settings, and local diagnostics stay on the computer unless you export them, open them elsewhere, choose an external service, or use a network feature described below.
This policy covers the desktop application and Oruva's account and licensing service. The desktop app does not use browser cookies for account authentication; it uses bearer session tokens held in operating-system-protected local storage.
2. Account, trial, and abuse prevention
When you register, Oruva processes your email address, a name if provided, and a one-way password hash. Oruva does not store your plaintext password. Email-verification, password-reset, session, security, device-public-key, entitlement, and protected-device records authenticate you, bind licensed devices, enforce the trial, prevent replay, and secure the service. The account service is hosted on Hostinger infrastructure. Ordinary requests expose connection data such as IP address and user agent to Oruva and its hosting and security providers.
An eligible new account receives a 14-day application trial, including five protected scene conversions. The trial uses the earliest applicable account or physical-machine trial date. Deleting local account state, wiping app data, reinstalling Oruva, or registering another account does not reset the machine anchor.
On Windows, Oruva reads the Windows MachineGuid and, when valid, the SMBIOS UUID, combines the available values with an Oruva-specific domain separator, and sends a SHA-256 hardware hash inside the signed registration and sign-in payload. Raw MachineGuid and SMBIOS values are not sent. Supported macOS builds use the platform UUID in the same one-way derivation. The service stores the 64-character machine hash, first/last-seen timestamps, earliest trial date, and registration-time account links needed to preserve the trial and limit account creation from one machine.
Registration is limited to three successful new accounts per source IP in a rolling 24-hour period. The IP day-cap key and timestamp are pruned after that window. Registration addresses whose domain or subdomain appears in Oruva's locally maintained disposable-email blocklist are rejected; mailbox content is not inspected.
3. Licensing and protected scene conversion
Entitlement and conversion-authorization records may include a protected device identifier or device public-key identity, a cryptographic hash of the source scene, source byte count, converter version, reservation and authorization identifiers, timestamps, completion status, a cryptographic hash of the converted output, and the output byte count.
Active licenses may receive a device-bound offline conversion pass (30 days for individual licenses, 90 days for studio seats) so conversions keep working without a connection. The service records each pass (device identity, converter build, issue and expiry times) and, on renewal, the number of distinct scenes converted offline, never the scenes themselves. Licensing requests are also logged with a truncated network prefix (the first three IPv4 octets or the first 48 bits of an IPv6 address, never the full address) for 90 days, to detect shared licenses; revocations are recorded with the operator and reason.
Source and output hashes are derived identifiers. Oruva does not upload the source scene, asset names, textures, previews, or scene contents to oruva.app for authorization. Scene conversion runs on the computer; only authorization and completion records are sent to the account service.
4. Payments
Paddle.com Market Ltd or Paddle.com Inc., as applicable, processes purchases as merchant of record and authorized reseller. Paddle handles payment details, billing information, taxes, receipts, refunds, and payment-risk checks under its own terms and privacy notice. Oruva does not receive or store full card or bank details. Oruva receives customer, transaction, purchase-status, refund or chargeback, and entitlement information needed to associate a purchase with an account.
5. Optional external actions and downloads
Search by Image is an optional, user-triggered upload. Choosing Google or Bing prepares a bounded JPEG copy of the selected local image and submits it directly from your browser to that provider. There is no clipboard or file-picker confirmation step. Oruva's servers do not receive or relay the image. The provider receives the image and ordinary connection metadata and may retain or use it under its own privacy policy. Selecting an asset alone does not upload it; choosing a provider is the explicit upload action.
Oruva's bundled example plugins that you can install, Find on Pinterest and 3DSky Hi-Res Match, send a bounded copy of the selected image directly from your computer to Pinterest or 3DSky only when you run them; Find on Pinterest's text fallback opens a Pinterest search built from up to six terms of the asset's caption, tags, and file name. Nothing is sent until you run the plugin on a selected asset.
Other optional plugins and external-link actions may send the data described in their permission disclosure to the selected provider.
- Account, entitlement, Paddle checkout/status, and protected-conversion requests contact the relevant service.
- Windows checks the release feed at startup no more than once per 24 hours and when you request a manual check. Oruva does not auto-download or install an available update.
- When you open the Plugin Center or install a bundled plugin, Oruva fetches its plugin catalog from plugins.oruva.app.
- When you use Import from links, Oruva downloads the address you provide directly from your computer to that site.
- On your setup request, Oruva can download and integrity-check the managed Ollama runtime from its official GitHub release and pull the selected local model through Ollama.
- On your Visual Search setup request, Oruva can download a signed exact-version runtime bundle and pinned model files, including from Oruva's runtime host and Hugging Face.
Download and external-service providers receive ordinary connection metadata under their own privacy policies. Oruva does not sell personal information and does not use advertising or third-party usage analytics in the desktop app.
6. Local AI, diagnostics, and failure reports
Prompts, images, captions, search vectors, and inference are processed by the local AI engine. Electron crash-report upload is disabled. Crash dumps and logs stay local. Export Diagnostics writes a redacted report only to the location you choose.
When a Generator run fails or sends only part of a requested result, Oruva may write a local support blob encrypted to the owner's support public key. It can contain the app version, run number, a path-sanitized failure reason and model basename or left-behind list, and at most the final four path-sanitized timeline records. There is no plaintext fallback, and Oruva does not transmit the blob automatically. Failed and cancelled run directories are eligible for local cleanup after seven days when a later Generator run starts; retained successful or partial-run output remains until you remove it.
Oruva has no general usage telemetry beyond the operational account, security, licensing, update-check, download, and user-selected external requests described here. Local diagnostics and sealed support blobs are not telemetry sent to Oruva.
7. Purposes and lawful bases
Depending on applicable law, Oruva relies on requested pre-contract steps and contract performance to provide access, licensing, downloads, and support; legitimate interests in account security, license and trial enforcement, fraud and abuse prevention, and service integrity, balanced against user rights; legal obligations for transaction, tax, consumer, and legal records; and consent where specifically requested.
Oruva is operated from Morocco and does not claim an EU establishment. Processing is subject to applicable data-protection law, including Morocco's Law No. 09-08 on protection of individuals with regard to processing of personal data. Where GDPR-style law applies, the corresponding lawful-basis, transparency, transfer, and data-subject-rights requirements apply.
8. Sharing, transfers, and security
Information is shared only as needed with Hostinger and other hosting/security providers, email-delivery providers, Paddle, a provider you deliberately select, or where law requires it. Providers may process data in other countries under their own terms and applicable transfer safeguards. Oruva uses technical controls designed to protect credentials, sessions, signed requests, and licenses, but no system can guarantee absolute security.
9. Retention and your rights
Local library and model data remains until you remove it. Uninstalling Oruva does not automatically delete user-created libraries, downloaded local-AI models, or all application data.
Account and active-license records are kept while needed to provide the account and document entitlements. Machine trial anchors and related anti-abuse records may be retained after account deletion where reasonably necessary to preserve a trial already used and prevent repeated abuse. Security, authorization, transaction, tax, dispute, and legal records may be retained for the applicable legal period or while needed for legal claims, then deleted or anonymized.
Subject to applicable law, you may request access, correction, deletion, restriction, objection, or portability, and may withdraw consent without affecting earlier lawful processing. Email hello@oruva.app; Oruva verifies requests before acting. Deleting an account may end account-based trial and license services. Some records may be retained for entitlement, security, anti-abuse, or legal-claims needs. You may complain to Morocco's CNDP or another competent data-protection authority where you have that right.
10. Governing law and contact
This policy and related privacy questions are governed by the laws of Morocco without displacing mandatory rights that apply where you live. Subject to any mandatory right to bring proceedings elsewhere, the courts of Casablanca, Morocco have non-exclusive jurisdiction.
Controller: Anass Anedjar, Oruva, Casablanca, Morocco. Contact: hello@oruva.app.