Back to all policies

Privacy Policy

Orlim Privacy Policy

Last updated: 28 August, 2026

Orlim is a macOS menu-bar workstation operated by Jambo.team. It brings connected AI coding provider quotas, local coding activity, system health, and window management into one place. This policy explains how Orlim handles credentials, browser sessions, local logs, quota history, system and window data, and requests to connected providers. Orlim does not require a Jambo account or operate a Jambo-hosted Orlim data backend in the current build. Information that remains on your Mac is not uploaded to Jambo by Orlim.

Table of Contents

Article 1. Collection and use of personal information

Article 2. Purpose of use of personal information

Article 3. Provision or sharing of personal information with third parties

Article 4. Entrustment of personal information

Article 5. Retention and use period of personal information

Article 6. Procedures and methods for destroying personal information

Article 7. Rights of users and legal representatives and methods of exercising them

Article 8. Matters related to installation, operation and refusal of automatic personal information collection devices

Article 9. Technical, managerial and physical protection measures for personal information

Article 10. Changes to personal information processing policy

Article 11. Personal information protection officer or personal information department

Article 1. Collection and use of personal information

Orlim processes the information needed to connect services, retrieve quota and status information, summarize local coding activity, show system and window controls, save settings, and respond to support requests. The categories below distinguish local processing from information sent to the connected provider you choose.

Orlim does not collect this information into a Jambo account or central Orlim database. Credentials, logs, activity summaries, quota history, system readings, window data, and settings are processed locally unless a specific action sends information to a connected provider, a local service, the public policy website, or a support contact as described below.

A. Information provided by users

1. Connection and credential information - API keys or cookie headers that you choose to paste into Orlim. Orlim stores these values in the macOS Keychain for the selected provider. - Provider credentials and session material that already exist in a connected provider's CLI, editor, application, or macOS Keychain, when Orlim needs to read them for the connection method you choose. - Browser session cookies that you explicitly ask Orlim to import for a supported provider. Depending on the browser, Orlim may read Safari, Chrome, Chromium, Edge, Brave, Arc, or Firefox cookie stores and may request Full Disk Access or permission to read the browser's Safe Storage key. 2. Local activity and session information - Orlim may read local Codex and Claude session logs to determine recent agent state and build an activity summary. The activity feature extracts timestamps, runtime, model names, completed-turn counts, token counts, and recognizable project or session labels; its cache stores summary events rather than full transcript text. - When Ari-Nomous is installed and available, Orlim may read its local status, bot names, task titles or summaries, thread identifiers, and runtime events through the local 127.0.0.1 interface. 3. Quota, status, and local device information - Quota responses, account labels, plan information, reset times, remaining fractions, and refresh timestamps returned by connected providers. - Local quota history containing a provider and quota-window identity, observation time, remaining fraction, and reset time. - System readings such as CPU, memory, storage, battery, and network activity, plus window-server information needed for window management, such as window identifiers, process names, positions, sizes, and screen arrangement. 4. Settings and support information - Provider order and visibility, refresh and status-check settings, quota-history and notification preferences, alert thresholds, language, menu-bar metric choices, shortcuts, window-management preferences, companion or top-panel visibility, and related local settings. - The contents of messages or attachments that you voluntarily send to Jambo.team for support or privacy assistance.

B. How to collect personal information

Orlim receives information when you connect a provider, paste a credential, approve a macOS permission, enable local activity tracking or quota history, open a provider login flow, or contact support. It also reads enabled local sources and refreshes connected-provider quota or service-status endpoints according to the settings and refresh behavior you choose. Requests to connected providers are made directly from Orlim to those providers. Orlim does not set cookies in the macOS app.

Article 2. Purpose of use of personal information

Orlim uses information for the following purposes. If the purpose or the data flow materially changes, this policy will be updated before or when the change takes effect where required.

- Connecting the provider accounts and local sessions that you choose to use, including supported CLI, browser, API-key, cookie, editor, and local-service connection methods.

- Requesting and displaying current usage limits, quota windows, plan or account labels, reset times, and supported provider service-status information.

- Reading local Codex and Claude activity summaries and local Ari-Nomous status so Orlim can show coding activity, working or waiting states, completions, failures, and attention notices.

- Building the local quota history and activity views, including model, task, token, provider, and time-based summaries that the app displays on your Mac.

- Sampling system health and reading window-server information so Orlim can display metrics and perform the window-management actions you request.

- Saving your preferences, delivering local alerts or notifications that you enable, improving reliability, responding to support or privacy requests, protecting the app, and complying with legal obligations.

- Orlim does not include advertising SDKs, advertising identifiers, third-party analytics, or a routine Jambo telemetry endpoint in the current build.

Article 3. Provision or sharing of personal information with third parties

Orlim does not sell your personal information and does not send local activity summaries, system metrics, window data, or Orlim settings to a Jambo-hosted application backend. Information may be made available to a third party in the following limited situations.

- A connected AI coding provider receives the authentication material and request data needed to answer the quota, usage, login, or status request that you initiate or have enabled. The provider controls its own processing, records, and privacy practices.

- A provider CLI, editor, browser, or local companion service may receive information as part of a sign-in, credential, browser, window, or local integration flow that you choose. Orlim does not control the subsequent processing by those products.

- Ari-Nomous, when present on the same Mac, can receive Orlim's local requests over the loopback interface. Those requests are not sent to Jambo's remote servers by Orlim.

- The public policy website and its hosting provider may process ordinary technical request data needed to deliver, secure, and monitor the policy page.

- A sharing action, export, support request, or other action that you start can pass selected information to the recipient you choose. That recipient controls its subsequent processing.

Information may also be disclosed when required by law, valid legal process, or an urgent need to protect the rights, safety, or security of users, Jambo.team, or the public.

Article 4. Entrustment of personal information

Orlim does not operate a hosted account or data-processing backend for the local information described in this policy. For the limited external processing associated with the product, the relevant service providers or platform services are as follows.

- Connected AI coding providers: quota, usage, account, authentication, and service-status processing when you connect or enable a provider.

- macOS Keychain, browser storage, provider CLIs, editors, and local companion services: credential, session, browser, or local integration processing that occurs on your Mac and is controlled by the relevant product or operating system.

- Cloudflare Pages or another static hosting provider: delivery of the public Orlim privacy page and ordinary website security and request processing.

- Jambo.team support systems: handling privacy or support correspondence that you choose to send.

These services process information under their own terms and privacy notices. Changes to Orlim's external integrations or the categories of information sent to them will be reflected in this policy where required.

Article 5. Retention and use period of personal information

Orlim keeps information only for as long as it is needed for the purpose described in this policy, unless a longer period is required by law or needed to resolve a dispute or security issue. Orlim does not maintain a central copy of local app data.

A. Credentials and local app data

API keys and cookie headers pasted into Orlim remain in the Orlim provider Keychain entry until you clear them or use the provider account-change flow. Credentials written by a provider's CLI, editor, browser, or Keychain remain in those products' normal locations until you or the relevant provider removes them. Orlim may remove the specific credential files and Keychain entries listed in its account-change confirmation, but it does not clear browser cookies as part of normal use.

B. Quota history and activity cache

When quota history is enabled, Orlim stores quota trend samples locally in the Orlim application-support directory. The current history store retains samples for up to 45 days and caps the file at 25,000 records. Disabling quota history clears that history file. When local activity tracking is enabled, Orlim keeps a local cache of summary events needed for its 16-week activity view; disabling activity tracking clears that cache, while the original Codex, Claude, or other provider logs remain under the control of those products.

C. External and support records

Provider services, browsers, local tools, the public policy host, and support systems retain information according to their own policies and legal obligations. Orlim settings remain in local macOS preferences until changed, removed, or cleaned up through the operating system. Support correspondence is retained only as long as reasonably needed to respond, document, or resolve the request.

Article 6. Procedures and methods for destroying personal information

Orlim removes local information when you use the applicable in-app control or delete the relevant local data, subject to normal macOS and file-system behavior.

- Turn off local activity tracking to stop scanning and remove Orlim's activity cache. This does not delete the original Codex or Claude logs that belong to those tools.

- Turn off quota history to clear Orlim's local quota-history file. You can also remove Orlim's local preferences or application-support data through macOS file-management tools when the app is not running.

- Use Orlim's account-change flow to review and remove the listed provider credential files and Keychain entries, including the Orlim-owned entry. Browser cookies and unrelated provider data must be removed through the browser or provider that owns them.

- Delete source session logs, provider accounts, browser records, or provider-side data through the relevant tool or provider. Information held by a connected provider, policy host, or support system must be deleted through that recipient and is subject to its retention rules.

Orlim does not maintain paper files containing user data. Electronic records under Orlim's control are removed using the applicable local storage, Keychain, preference, or provider deletion mechanism.

Article 7. Rights of users and legal representatives and methods of exercising them

You can review and manage the information Orlim stores locally by changing or deleting settings, disabling activity tracking or quota history, clearing provider credentials through the account-change flow, disconnecting providers, and removing local application data.

You can revoke macOS permissions that Orlim no longer needs, including Full Disk Access, Keychain access, and Accessibility access, through macOS settings. You can also exercise account, access, correction, deletion, or objection rights directly with the connected provider whose service processes your information.

Because Orlim does not operate a Jambo account backend and does not retain local activity or system data on a Jambo server, Jambo.team cannot retrieve or delete those local records on your behalf. For a privacy question or complaint, contact [email protected] with enough detail to investigate; do not send API keys, cookie headers, provider tokens, or private session-log contents unless they are specifically necessary.

Orlim is a desktop utility for AI coding tools and is not directed to children under 13. It does not knowingly request personal information from children. A parent or legal representative who believes a child has provided personal information may contact [email protected].

Article 8. Matters related to installation, operation and refusal of automatic personal information collection devices

Orlim does not set or use web cookies, advertising identifiers, or cross-service tracking identifiers in the macOS app. Its browser-cookie connection option is a user-started import of existing provider session cookies; it is not a cookie that Orlim creates for tracking.

A. Local automatic collection and refresh

When enabled, Orlim periodically reads local agent logs, local Ari-Nomous status, system metrics, window information, and connected-provider quota or service-status endpoints so the menu bar and panels stay current. You can disable local activity tracking, quota history, service-status checks, notifications, and connected providers in the app settings. Refresh behavior also adapts to your interaction and configured preferences.

B. Browser and public website requests

Orlim may read existing browser cookie stores only when you select a supported browser-cookie connection method and approve the required macOS permissions. The public privacy page is delivered by a website; a browser or hosting provider may process ordinary technical request information needed to deliver and secure that page.

Article 9. Technical, managerial and physical protection measures for personal information

Jambo.team uses reasonable technical and organizational measures appropriate to Orlim's local-first design and limited external data flows.

A. Technical protection measures

Orlim stores user-pasted API keys and cookie headers in the macOS Keychain, uses direct secure transport for remote provider requests, and restricts its special local trust behavior to 127.0.0.1 and localhost for local integrations. Quota history is written with restrictive 0600 file permissions. Browser-cookie database copies used during import are temporary and are removed after reading when the operating system permits it. Orlim does not send local activity, system, window, or settings data to a Jambo backend.

B. Administrative protection measures

Access to any support or operational information is limited to people who need it for development, reliability, security, or support. We review data flows when provider integrations, authentication methods, or release configuration changes.

C. Physical protection measures

Local information is protected by macOS account, Keychain, file-system, and device-security controls. You are responsible for protecting your Mac, browser sessions, provider accounts, and any credentials you authorize Orlim to use. Connected providers and hosting providers apply their own security controls to information they receive.

Article 10. Changes to personal information processing policy

If Orlim's data practices, integrations, authentication methods, or purposes change, we will update this policy, the app's legal notice, or both, and change the effective date. For material changes, we will provide notice through the app, release documentation, public policy page, or another appropriate channel where required.

Article 11. Personal information protection officer or personal information department

Jambo.team is responsible for operating Orlim and handling privacy questions or complaints about the service.

[Orlim privacy contact]

- Operator: Jambo.team

- Privacy email: [email protected]

When contacting us, please avoid sending API keys, cookie headers, provider tokens, private session logs, or other sensitive credentials unless we specifically request information that is necessary to resolve the issue.

This personal information processing policy comes into effect on 28 August, 2026.

Trusted Partners & Collaborators

Partner logo 1
Partner logo 2
Partner logo 3
Partner logo 4
Partner logo 5
Partner logo 6
Partner logo 7
Partner logo 8
Partner logo 9
Partner logo 10
Partner logo 11
Partner logo 12
Partner logo 13
Partner logo 14
Partner logo 1
Partner logo 2
Partner logo 3
Partner logo 4
Partner logo 5
Partner logo 6
Partner logo 7
Partner logo 8
Partner logo 9
Partner logo 10
Partner logo 11
Partner logo 12
Partner logo 13
Partner logo 14

Hope Together. Grow Together.
Building a world where everyone can thrive through technology and creativity.

Company

MissionProjectsCareersContact

Get in Touch

General Inquiry

[email protected]

Partnerships

[email protected]

© 2026 Seedbox LC. All rights reserved.

Crafted with

by Jambo.Team