Orcaworks Chrome Extension Privacy Policy
Effective Date: June 15, 2026
Extension Name: Orcaworks Chrome Extension
Website: https://orcaworks.ai
Contact: contracts@orcaworks.ai
Legal Entity: Orcaworks Inc.
1. Overview
This Privacy Policy explains how Orcaworks Inc. handles information when users install and use Orcaworks Chrome Extension.
The Orcaworks Chrome Extension is designed for authorized users of customer organizations. It helps users launch Orcaworks workflows from supported web applications, extract relevant page context, and, where configured, send results back to the customer’s systems.
Examples of supported workflows may include assessment marking workflows, case assignment workflows, document review workflows, or other customer-approved business processes.
The extension is not intended for general consumer browsing. It is intended to operate only on supported customer systems and only for authorized business or educational workflows.
2. Scope of this Policy
This policy applies to the Orcaworks Chrome Extension and the browser-based functionality provided through it.
This policy should be read together with:
- Any agreement between Orcaworks / Orcaworks Inc. and the customer organization;
- Any privacy notices provided by the customer organization to its own users, staff, students, clients, or end customers;
- Any in-product disclosures shown in the extension or related Orcaworks application.
Where we process information on behalf of a customer organization, the customer organization remains responsible for determining whether and how that information may be used in its own workflows.
3. What the Extension Does
The extension allows authorized users to interact with Orcaworks from supported browser pages.
Depending on the customer configuration, the extension may:
- Detect that the user is on a supported page;
- Extract relevant information from the current page;
- Send extracted context to the Orcaworks backend;
- Launch an Orcaworks workflow using that context;
- Display workflow outputs to the user;
- Ask the user to approve, reject, or edit a result;
- Write an approved result back to a customer system, where enabled.
For example, in an assessment workflow, the extension may help retrieve submitted answers and submit marking outcomes. In a case workflow, the extension may help retrieve case context and write back an assigned staff member, reviewer, or attorney.
The extension’s purpose is to help authorized users complete customer-approved workflows inside systems they already use.
4. Information the Extension May Access or Collect
The extension may access or collect the following types of information, depending on the customer workflow and supported site.
4.1 Current Page Information
When used on a supported customer system, the extension may read relevant information from the current page, such as:
- Page URL;
- Page title;
- Page identifiers;
- Case IDs, matter IDs, assessment IDs, student IDs, submission IDs, or similar workflow identifiers;
- Visible form fields or page fields needed for the configured workflow;
- Selected text or user-highlighted content, where the user chooses to use it;
- Page content required to complete the user-facing workflow.
The extension does not collect general browsing history for unrelated websites.
4.2 Workflow and Business Data
Depending on the workflow, the extension may process data such as:
- Assessment questions;
- Student or learner answers;
- Model answers or marking rubrics;
- Trainer, assessor, or reviewer comments;
- Assessment outcomes, scores, confidence levels, or feedback;
- Case details;
- Client, customer, or matter information;
- Assignment recommendations;
- Approval decisions made by authorized users;
- Workflow inputs and outputs.
The exact data processed depends on the customer’s configuration and the workflow being run.
4.3 User Account and Authentication Information
The extension may process information needed to authenticate and authorize the user, such as:
- Username;
- Email address;
- Organization or tenant identifier;
- Role or permission information;
- Authentication tokens or session information;
- Identity provider information, such as Auth0, Microsoft Entra ID, or another customer-approved identity provider.
Authentication tokens may be stored locally in the browser using Chrome extension storage so that the user can remain signed in securely.
4.4 Technical and Diagnostic Information
We may collect technical information required to operate, secure, debug, and improve the extension, such as:
- Extension version;
- Browser version;
- Timestamp of requests;
- Error messages;
- Request IDs;
- Workflow run IDs;
- System logs;
- Performance and reliability information;
- Security and audit logs.
Where possible, logs are limited to the information needed for operation, support, security, and auditability.
5. Information the Extension Does Not Intentionally Collect
The extension does not intentionally collect:
- Passwords entered into third-party websites;
- Payment card details;
- Personal browsing history unrelated to supported customer systems;
- Content from unsupported websites;
- Data for advertising or personalized advertising;
- Data for sale to third parties.
The extension is designed to operate on supported pages and supported customer workflows. It is not designed to monitor general browsing activity.
6. How Information Is Collected
Information may be collected or accessed in the following ways:
- Through browser content scripts that run on supported customer domains;
- When the user opens the extension, side panel, popup, or workflow interface;
- When the user clicks a button or starts a workflow;
- When the extension communicates with the Orcaworks backend;
- When the extension communicates with a configured customer system or connector;
- Through browser storage used for extension settings and authentication state.
The extension only uses permissions required to provide its user-facing workflow features.
7. How We Use Information
We use information accessed by the extension to:
- Authenticate and authorize users;
- Detect supported pages and workflows;
- Extract page context needed for the workflow;
- Run customer-approved Orcaworks workflows;
- Generate or retrieve workflow outputs;
- Display recommendations, results, or actions to the user;
- Submit approved results back to customer systems where configured;
- Maintain audit logs;
- Monitor reliability and security;
- Debug and support the extension;
- Improve the functionality, accuracy, and reliability of the extension.
We do not use information accessed by the extension for advertising or personalized advertising.
We do not sell information accessed by the extension.
8. AI and Automated Processing
Some Orcaworks workflows may use AI or automated decision-support systems.
Where AI processing is used, data may be sent to an approved AI model provider or hosted model environment for the purpose of completing the configured workflow.
AI outputs may include recommendations, draft results, classifications, extracted fields, feedback, or other workflow-specific outputs.
Unless otherwise agreed with the customer in writing, we do not use customer workflow data to train general-purpose AI models.
AI output may be incorrect or incomplete. Where the workflow requires human approval, the authorized user or customer organization remains responsible for reviewing and approving the result before it is submitted to another system.
Approved AI providers may include OpenAI, Microsoft Azure OpenAI Service, Anthropic, Amazon Bedrock, or other customer-approved model providers.
10. Chrome Web Store Limited Use Disclosure
The Orcaworks Chrome Extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
Information accessed by the extension is used only to provide or improve the extension’s single purpose and user-facing workflow features.
We do not use information accessed by the extension for advertising or personalized advertising.
We do not sell information accessed by the extension.
We do not transfer information accessed by the extension except where necessary to provide or improve the extension’s user-facing features, comply with law, protect security, or as otherwise permitted by the Chrome Web Store User Data Policy.
We do not allow humans to read user data accessed by the extension except where necessary for support requested by the customer or user, security investigation, legal compliance, internal operations using appropriately protected data, or with appropriate authorization.
Where the extension receives information from Google APIs or Chrome extension APIs, our use of that information will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
11. Browser Permissions
The extension may request permissions necessary to provide its features and services, including:
- Access to supported customer domains, so the extension can detect supported pages and extract workflow context;
- Storage permissions, so the extension can store settings, authentication state, or workflow state locally;
- Scripting or content script permissions, so the extension can read relevant page fields from supported systems;
- Network permissions, so the extension can communicate with Orcaworks backend APIs and configured customer systems.
The extension uses these permissions only to provide its disclosed workflow features.
12. Local Browser Storage
The extension may store limited information locally in the browser, such as:
- User session state;
- Authentication tokens;
- Extension configuration;
- Last-used workspace or workflow settings;
- Temporary workflow state;
- Error or diagnostic information.
Local storage is used to provide the extension’s functionality and improve the user experience.
Users may remove local extension data by uninstalling the extension or clearing the extension’s stored data through browser settings. Some server-side data may remain subject to customer agreements, audit requirements, retention rules, or legal obligations.
13. Data Retention
We retain information only for as long as needed to provide the service, maintain auditability, support customer workflows, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.
Retention periods may vary depending on:
- The customer agreement;
- The type of workflow;
- Whether audit logs are required;
- Whether the data is stored in Orcaworks systems or customer systems;
- Legal, security, or compliance requirements.
Customer organizations may request deletion or export of their data according to their agreement with us.
14. Security
We use reasonable technical and organizational measures to protect information processed by the extension and related backend systems.
These measures may include:
- HTTPS/TLS encryption in transit;
- Authentication and authorization controls;
- Role-based or policy-based access controls;
- Tenant isolation;
- Audit logging;
- Secure credential handling;
- Access restrictions for staff and service providers;
- Monitoring errors, misuse, and security issues.
No system can be guaranteed to be completely secure. Users and customer organizations should use the extension only in accordance with their internal security policies.
15. Student, Learner, Client, or Case Information
Some workflows may involve sensitive or regulated information, such as student submissions, assessment results, client records, case details, or business records.
The extension is intended for use by authorized staff, contractors, or representatives of customer organizations. It is not intended for direct use by children.
Where student, learner, client, or case information is processed, we process that information only for the customer-approved workflow and according to the applicable customer agreement.
Customer organizations are responsible for ensuring that they have the necessary rights, notices, consents, and legal bases to use the extension with their own users, students, clients, staff, or records.
16. International Processing
Information may be processed in countries where we, our service providers, or customer-approved processors operate.
Where required, we use appropriate contractual, organizational, and technical safeguards for cross-border processing.
17. User and Customer Choices
Depending on the customer configuration and applicable agreement, users or customer administrators may be able to:
- Access workflow records;
- Correct inaccurate information;
- Delete certain information;
- Export certain information;
- Disable or uninstall the extension;
- Revoke access through the relevant identity provider;
- Request support or privacy assistance.
Where we process data on behalf of a customer organization, individual privacy requests may need to be directed to that customer organization.
18. Changes to this Policy
We may update this Privacy Policy from time to time.
When we make material changes, we will update the effective date above and may provide additional notice through our website, customer communications, or the extension.
19. Contact Us
Orcaworks Inc.
Email: contracts@orcaworks.ai
Website: https://orcaworks.ai
One Glenlake Parkway, Suite 525, Atlanta, GA 30328
