Orcaworks Chrome Extension Privacy Policy

Effective Date: June 15, 2026

Extension Name: Orcaworks Chrome Extension

Website: https://orcaworks.ai

Contact: contracts@orcaworks.ai

Legal Entity: Orcaworks Inc.

1. Overview

This Privacy Policy explains how Orcaworks Inc. handles information when users install and use Orcaworks Chrome Extension.

The Orcaworks Chrome Extension is designed for authorized users of customer organizations. It helps users launch Orcaworks workflows from supported web applications, extract relevant page context, and, where configured, send results back to the customer’s systems.

Examples of supported workflows may include assessment marking workflows, case assignment workflows, document review workflows, or other customer-approved business processes.

The extension is not intended for general consumer browsing. It is intended to operate only on supported customer systems and only for authorized business or educational workflows.

2. Scope of this Policy

This policy applies to the Orcaworks Chrome Extension and the browser-based functionality provided through it.

This policy should be read together with:

  • Any agreement between Orcaworks / Orcaworks Inc. and the customer organization;
  • Any privacy notices provided by the customer organization to its own users, staff, students, clients, or end customers;
  • Any in-product disclosures shown in the extension or related Orcaworks application.

Where we process information on behalf of a customer organization, the customer organization remains responsible for determining whether and how that information may be used in its own workflows.

3. What the Extension Does

The extension allows authorized users to interact with Orcaworks from supported browser pages.

Depending on the customer configuration, the extension may:

  • Detect that the user is on a supported page;
  • Extract relevant information from the current page;
  • Send extracted context to the Orcaworks backend;
  • Launch an Orcaworks workflow using that context;
  • Display workflow outputs to the user;
  • Ask the user to approve, reject, or edit a result;
  • Write an approved result back to a customer system, where enabled.

For example, in an assessment workflow, the extension may help retrieve submitted answers and submit marking outcomes. In a case workflow, the extension may help retrieve case context and write back an assigned staff member, reviewer, or attorney.

The extension’s purpose is to help authorized users complete customer-approved workflows inside systems they already use.

4. Information the Extension May Access or Collect

The extension may access or collect the following types of information, depending on the customer workflow and supported site.

4.1 Current Page Information

When used on a supported customer system, the extension may read relevant information from the current page, such as:

  • Page URL;
  • Page title;
  • Page identifiers;
  • Case IDs, matter IDs, assessment IDs, student IDs, submission IDs, or similar workflow identifiers;
  • Visible form fields or page fields needed for the configured workflow;
  • Selected text or user-highlighted content, where the user chooses to use it;
  • Page content required to complete the user-facing workflow.

The extension does not collect general browsing history for unrelated websites.

4.2 Workflow and Business Data

Depending on the workflow, the extension may process data such as:

  • Assessment questions;
  • Student or learner answers;
  • Model answers or marking rubrics;
  • Trainer, assessor, or reviewer comments;
  • Assessment outcomes, scores, confidence levels, or feedback;
  • Case details;
  • Client, customer, or matter information;
  • Assignment recommendations;
  • Approval decisions made by authorized users;
  • Workflow inputs and outputs.

The exact data processed depends on the customer’s configuration and the workflow being run.

4.3 User Account and Authentication Information

The extension may process information needed to authenticate and authorize the user, such as:

  • Username;
  • Email address;
  • Organization or tenant identifier;
  • Role or permission information;
  • Authentication tokens or session information;
  • Identity provider information, such as Auth0, Microsoft Entra ID, or another customer-approved identity provider.

Authentication tokens may be stored locally in the browser using Chrome extension storage so that the user can remain signed in securely.

4.4 Technical and Diagnostic Information

We may collect technical information required to operate, secure, debug, and improve the extension, such as:

  • Extension version;
  • Browser version;
  • Timestamp of requests;
  • Error messages;
  • Request IDs;
  • Workflow run IDs;
  • System logs;
  • Performance and reliability information;
  • Security and audit logs.

Where possible, logs are limited to the information needed for operation, support, security, and auditability.

5. Information the Extension Does Not Intentionally Collect

The extension does not intentionally collect:

  • Passwords entered into third-party websites;
  • Payment card details;
  • Personal browsing history unrelated to supported customer systems;
  • Content from unsupported websites;
  • Data for advertising or personalized advertising;
  • Data for sale to third parties.

The extension is designed to operate on supported pages and supported customer workflows. It is not designed to monitor general browsing activity.

6. How Information Is Collected

Information may be collected or accessed in the following ways:

  • Through browser content scripts that run on supported customer domains;
  • When the user opens the extension, side panel, popup, or workflow interface;
  • When the user clicks a button or starts a workflow;
  • When the extension communicates with the Orcaworks backend;
  • When the extension communicates with a configured customer system or connector;
  • Through browser storage used for extension settings and authentication state.

The extension only uses permissions required to provide its user-facing workflow features.

7. How We Use Information

We use information accessed by the extension to:

  • Authenticate and authorize users;
  • Detect supported pages and workflows;
  • Extract page context needed for the workflow;
  • Run customer-approved Orcaworks workflows;
  • Generate or retrieve workflow outputs;
  • Display recommendations, results, or actions to the user;
  • Submit approved results back to customer systems where configured;
  • Maintain audit logs;
  • Monitor reliability and security;
  • Debug and support the extension;
  • Improve the functionality, accuracy, and reliability of the extension.

We do not use information accessed by the extension for advertising or personalized advertising.

We do not sell information accessed by the extension.

8. AI and Automated Processing

Some Orcaworks workflows may use AI or automated decision-support systems.

Where AI processing is used, data may be sent to an approved AI model provider or hosted model environment for the purpose of completing the configured workflow.

AI outputs may include recommendations, draft results, classifications, extracted fields, feedback, or other workflow-specific outputs.

Unless otherwise agreed with the customer in writing, we do not use customer workflow data to train general-purpose AI models.

AI output may be incorrect or incomplete. Where the workflow requires human approval, the authorized user or customer organization remains responsible for reviewing and approving the result before it is submitted to another system.

Approved AI providers may include OpenAI, Microsoft Azure OpenAI Service, Anthropic, Amazon Bedrock, or other customer-approved model providers.

9. Sharing of Information

We may share information accessed by the extension only as needed to provide, secure, support, or improve the extension and related OrcaWorks workflows.

Information may be shared with the following categories of recipients:

9.1 Orcaworks Backend Services

Information may be sent to Orcaworks backend systems to run workflows, store workflow state, enforce permissions, maintain audit logs, and return results to the user.

9.2 Customer Systems

Where configured, information may be exchanged with customer systems, such as assessment platforms, case management systems, document systems, CRM systems, or other approved business systems.

For example, the extension may retrieve information from a supported customer page and submit an approved result back to that customer system.

9.3 Identity and Authentication Providers

We may use identity providers such as Auth0, Microsoft Entra ID, or customer-approved authentication systems to authenticate users and manage access.

9.4 Cloud Hosting and Infrastructure Providers

We may use cloud hosting, databases, storage, monitoring, logging, and security providers to operate the service.

9.5 AI/Model Providers

Where a workflow uses AI processing, information may be sent to approved AI/model providers or hosted model environments solely to provide the configured workflow.

9.6 Legal, Security, and Compliance Purposes

We may disclose information where required to comply with law, enforce agreements, protect rights, investigate security incidents, prevent fraud or abuse, or protect users and customer systems.

We do not sell information accessed by the extension.

We do not share information accessed by the extension with advertising networks.

10. Chrome Web Store Limited Use Disclosure

The Orcaworks Chrome Extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

Information accessed by the extension is used only to provide or improve the extension’s single purpose and user-facing workflow features.

We do not use information accessed by the extension for advertising or personalized advertising.

We do not sell information accessed by the extension.

We do not transfer information accessed by the extension except where necessary to provide or improve the extension’s user-facing features, comply with law, protect security, or as otherwise permitted by the Chrome Web Store User Data Policy.

We do not allow humans to read user data accessed by the extension except where necessary for support requested by the customer or user, security investigation, legal compliance, internal operations using appropriately protected data, or with appropriate authorization.

Where the extension receives information from Google APIs or Chrome extension APIs, our use of that information will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

11. Browser Permissions

The extension may request permissions necessary to provide its features and services, including:

  • Access to supported customer domains, so the extension can detect supported pages and extract workflow context;
  • Storage permissions, so the extension can store settings, authentication state, or workflow state locally;
  • Scripting or content script permissions, so the extension can read relevant page fields from supported systems;
  • Network permissions, so the extension can communicate with Orcaworks backend APIs and configured customer systems.

The extension uses these permissions only to provide its disclosed workflow features.

12. Local Browser Storage

The extension may store limited information locally in the browser, such as:

  • User session state;
  • Authentication tokens;
  • Extension configuration;
  • Last-used workspace or workflow settings;
  • Temporary workflow state;
  • Error or diagnostic information.

Local storage is used to provide the extension’s functionality and improve the user experience.

Users may remove local extension data by uninstalling the extension or clearing the extension’s stored data through browser settings. Some server-side data may remain subject to customer agreements, audit requirements, retention rules, or legal obligations.

13. Data Retention

We retain information only for as long as needed to provide the service, maintain auditability, support customer workflows, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.

Retention periods may vary depending on:

  • The customer agreement;
  • The type of workflow;
  • Whether audit logs are required;
  • Whether the data is stored in Orcaworks systems or customer systems;
  • Legal, security, or compliance requirements.

Customer organizations may request deletion or export of their data according to their agreement with us.

14. Security

We use reasonable technical and organizational measures to protect information processed by the extension and related backend systems.

These measures may include:

  • HTTPS/TLS encryption in transit;
  • Authentication and authorization controls;
  • Role-based or policy-based access controls;
  • Tenant isolation;
  • Audit logging;
  • Secure credential handling;
  • Access restrictions for staff and service providers;
  • Monitoring errors, misuse, and security issues.

No system can be guaranteed to be completely secure. Users and customer organizations should use the extension only in accordance with their internal security policies.

15. Student, Learner, Client, or Case Information

Some workflows may involve sensitive or regulated information, such as student submissions, assessment results, client records, case details, or business records.

The extension is intended for use by authorized staff, contractors, or representatives of customer organizations. It is not intended for direct use by children.

Where student, learner, client, or case information is processed, we process that information only for the customer-approved workflow and according to the applicable customer agreement.

Customer organizations are responsible for ensuring that they have the necessary rights, notices, consents, and legal bases to use the extension with their own users, students, clients, staff, or records.

16. International Processing

Information may be processed in countries where we, our service providers, or customer-approved processors operate.

Where required, we use appropriate contractual, organizational, and technical safeguards for cross-border processing.

17. User and Customer Choices

Depending on the customer configuration and applicable agreement, users or customer administrators may be able to:

  • Access workflow records;
  • Correct inaccurate information;
  • Delete certain information;
  • Export certain information;
  • Disable or uninstall the extension;
  • Revoke access through the relevant identity provider;
  • Request support or privacy assistance.

Where we process data on behalf of a customer organization, individual privacy requests may need to be directed to that customer organization.

18. Changes to this Policy

We may update this Privacy Policy from time to time.

When we make material changes, we will update the effective date above and may provide additional notice through our website, customer communications, or the extension.

19. Contact Us

Orcaworks Inc.

Email: contracts@orcaworks.ai

Website: https://orcaworks.ai

One Glenlake Parkway, Suite 525, Atlanta, GA 30328

See Orca in Action