Skip to content

Legal

Privacy policy

Effective July 12, 2026

oruk, Inc. (“oruk”, “we”, “us”) is a Delaware corporation headquartered in California, United States. We operate the website at oruk.ai and the speech inference API at speech-api.oruk.ai. This policy explains what we collect, what we never keep, and where processing happens. Questions go to access@oruk.ai.

API content: not retained, not trained on

This is the section that matters most to API customers, so we state it exactly — what is discarded, and what is kept. Each point below is the default that applies to every account, and the only thing that changes it is a written agreement you sign:

  • Audio is not stored. Files you send to an inference endpoint are used only to produce the response and are not retained after the response is returned.
  • Outputs are not stored. Transcripts, emotion labels, and speaking-style labels are returned to you and are not retained by oruk.
  • We do not train on customer content. Customer audio and model outputs are not used to train, fine-tune, evaluate, or improve any oruk model, and are not shared with third parties for that purpose, unless you explicitly agree otherwise in writing.
  • Metadata is retained. For each request we keep billing and audit metadata only: request ID, API key ID, organization, model, task, measured audio duration, billable seconds, estimated cost, and timestamps. This metadata never includes your audio or its content.

Retention summary

DataRetention
Audio files sent to the APINot retained after the response is returned.
Model outputs (transcripts, emotion and style labels)Not stored. Returned to you and discarded.
API request metadata (request ID, key ID, model, task, audio duration, cost, timestamps)Retained for billing, abuse prevention, and audit.
API keysStored in a non-recoverable form. The plaintext key is shown once.
Account information (name, email, company, role, use case)Retained while your account is active, and deleted on request.
Billing and credit ledger recordsRetained as required for accounting and tax compliance.

Information we collect

When you create an account we collect the information you provide: name, email address, and optionally company, role, and intended use case. Account credentials are protected in a non-recoverable form. When you buy API credits we keep the resulting ledger records. We also keep standard operational logs (IP address, user agent, request path, status) for security and reliability.

Stripe processes card details, billing addresses, tax identifiers, receipts, and invoices. oruk stores the resulting customer, payment, and invoice identifiers but does not receive or store complete card numbers.

Advertising measurement, cookies, and consent

We use Google Analytics and, for visitors arriving from our search ads, Google Ads conversion measurement. Both run under Google Consent Mode: advertising and analytics storage default to denieduntil you make a choice in the cookie prompt, and remain denied if you choose “Essential only”.

  • First-party attribution cookie. If you arrive from an ad, we store the click identifiers Google appended to the URL (gclid/gbraid/wbraid), campaign parameters (UTMs, keyword, device), and the landing page in a first-party cookie for up to 90 days. If you create an account, this is saved with it so we know which search led to a working integration. It contains no audio, no API content, and no cross-site identifiers beyond the click ID itself.
  • What we report to Google. Only with your consent, and only conversion facts: that a click led to a verified account, a first successful API request, or a credit purchase and its amount. We never share your audio, API outputs, email address, or account contents with an advertising platform.
  • Changing your mind. Clear the site cookies to see the consent prompt again, or email access@oruk.ai to have stored attribution removed from your account.

Where processing happens

Customer audio is processed for inference in the United States. Network routing may occur in other locations, but audio processing remains limited to fulfilling the request.

Subprocessors

We use vetted service providers for application delivery, request processing, account and usage storage, and transactional email. They may process data only to provide their contracted services. A current provider list is available by emailing access@oruk.ai.

The public provider list and each provider's purpose are maintained on the security and trust page.

Sharing

We do not sell personal data and we do not share customer content with anyone. We disclose personal data only to service providers, as needed to provide the service, or when required by law.

Your rights

You can request access to, correction of, or deletion of your personal data at any time by emailing access@oruk.ai. Because we do not retain API audio or outputs, there is no customer content for us to produce or delete; deletion requests apply to account and billing records.

Security

Traffic is encrypted in transit. Credentials are protected in non-recoverable form, and production services use authenticated access controls and network protections.

Changes

If we change this policy we will update this page and its effective date. Material changes to the API content retention or training commitments above will be announced to account holders by email before they take effect.

See also the terms of service and the model catalog.