Privacy Policy
Last updated: August 18, 2026
ORION Tweaks is operated by Orion Tweaks LLC, a limited liability company formed on August 14, 2026 under the laws of the State of Georgia, United States. Orion Tweaks LLC is the controller of the personal data described in this policy. Contact: support@oriontweaks.com or the support page; a postal address for formal notice is provided on request.
The short version
ORION Tweaks is local-first: system scans, tweak previews, apply/revert backups and rollback journals, verification read-backs, and ordinary benchmark runs happen on your PC. Data leaves your PC only when you use an online feature such as account sign-in, plan checks, checkout, optional Cloud Sync, optional benchmark-history submission, reviews, or support. We do not sell personal data, we run no advertising or analytics trackers, and we do not use your data to train models.
1. Required vs optional data
- Required for accounts: email address, password verifier or Discord sign-in profile, verification/reset codes, and session tokens.
- Required for paid plans: plan, subscription status and renewal date, purchaser email, and the device identifier/HWID and hardware summary needed to enforce device limits and to find your account for support.
- Required for payments: Stripe processes card data. ORION stores fulfillment records such as checkout session, plan, billing period, purchaser email, and Stripe customer/subscription IDs where applicable, plus a record of the terms you accepted at checkout.
- Optional: Elite Cloud Sync data, benchmark telemetry/history, public reviews, support or bug-report messages, newsletter consent, and referral activity.
2. Data categories
- Account: used for sign-in, email verification, password reset, Discord OAuth, tier lookup, and session refresh.
- License: used to deliver access, validate it, show order history, reset a device binding, and prevent license sharing.
- Device binding: the app sends a HWID/device identifier when you sign in on a PC, so a paid plan can be registered to it. Paid plans cannot work without it because Pro and Elite have device limits.
- Sync data: Elite-only and optional. The server stores the opaque sync payload the app sends, plus revision and update time.
- Telemetry and benchmark history: optional authenticated benchmark submissions may include HWID, account email from your session, CPU/GPU/RAM, applied tweak IDs, game/resolution, FPS, frame-time and latency metrics, and measurement time. Local benchmark runs do not have to be submitted.
- Reviews: optional owner reviews store account email privately for verification, plus display name, rating, review text, tier, approval status, and timestamp.
- Support messages: optional bug/suggestion messages may include your message, selected support category, optional email, Discord message metadata when relayed, triage/status history, anti-spam signals, and app-supplied diagnostic attachment metadata such as bundle ID/hash, app/worker/OS/driver versions, counts, byte sizes, last run ID, or last error code. Do not send passwords, account credentials, raw logs, file paths, local usernames, or other secrets.
- Consent and order records: which version of the Terms, EULA, Privacy Policy and Refund Policy you accepted, when, the plan and recurring price shown to you, and your separate marketing choice.
- Payments: Stripe handles card details; ORION receives fulfillment metadata needed to issue and maintain licenses.
We do not process special-category data (health, biometrics, political or religious views and the like), we do not knowingly process children's data, and we do not buy personal data from data brokers.
3. What we do not collect
- No keystrokes, screenshots, browsing history, or file contents.
- No card numbers or bank details; Stripe processes payments.
- No third-party advertising identifiers or marketing data resale.
We avoid absolute hardware-identifier promises because registering a paid plan to a PC and optional benchmark history can include device identifiers.
4. Why we process data, on what lawful basis, and for how long
This is the table required by Article 13 of the UK and EU GDPR. Each row ties one purpose to the data it uses, the lawful basis we rely on, and how long the data is kept. Where we rely on legitimate interests, the interest is named so you can weigh it and object under section 7.
| Purpose | Data used | Lawful basis | Retention |
|---|---|---|---|
| Create and operate your account; sign you in; verify your email; reset your password | Email, password verifier or Discord profile, verification/reset codes, session and refresh tokens | Contract (Art. 6(1)(b)) - we cannot give you an account without it | While the account exists. Deleted with the account; residual copies clear from encrypted backups within 35 days. Verification/reset codes expire in minutes; refresh tokens on sign-out or after 30 days |
| Issue and validate your plan; register devices to it and enforce the device limit | Plan, status, renewal date, purchaser email, HWID/device identifier, hardware summary, device history | Contract (Art. 6(1)(b)); and legitimate interests (Art. 6(1)(f)) in preventing account and licence sharing | For the life of the licence, plus the period in the next row where the licence is tied to a purchase. Device history is capped at the most recent entries |
| Take payment, issue receipts, handle refunds, chargebacks and disputes, and keep tax and accounting records | Stripe checkout session, payment intent, customer/subscription IDs, plan, amount, billing period, purchaser email | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting; legitimate interests (Art. 6(1)(f)) in defending chargebacks | 7 years from the transaction, to meet US tax-record and EU/UK accounting retention periods. Not removed by account deletion |
| Prove what you agreed to at checkout and at sign-up | Which policy versions you accepted, timestamps, plan and recurring price shown, auto-renewal consent, marketing choice | Legal obligation (Art. 6(1)(c)) - US automatic-renewal laws require the renewal consent to be retained; legitimate interests (Art. 6(1)(f)) in evidencing agreement | 3 years after the subscription ends, or 7 years where it forms part of a transaction record |
| Send transactional email: order confirmation, renewal and price-change notices, verification, security and release notices | Email address, order and plan details | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for renewal and price-change notices | Send logs kept 12 months; the underlying records follow their own rows |
| Send marketing email about ORION | Email address, marketing consent record | Consent (Art. 6(1)(a)) - a separate, never pre-ticked box you can withdraw at any time | Until you unsubscribe or delete your account. We keep the fact and date of consent and of withdrawal for 3 years afterwards as proof we had permission and honoured its withdrawal |
| Elite Cloud Sync: store and return your settings payload | Opaque sync payload, revision, update time | Contract (Art. 6(1)(b)) - an optional feature you request | Until you overwrite it, turn sync off, or delete your account |
| Benchmark history and product telemetry: show your own history and improve tweak quality | HWID, account email, CPU/GPU/RAM, applied tweak IDs, game/resolution, FPS, frame-time and latency metrics, timestamps | Consent (Art. 6(1)(a)) - opt-in, and every submission is a choice | Identifiable submissions for 24 months, then deleted or aggregated into statistics that no longer identify you. Withdrawing consent stops future submissions and deletes past ones on request |
| Publish reviews and community posts | Display name, rating, review text, tier, approval status, timestamp; account email held privately to verify the purchase | Contract (Art. 6(1)(b)) for the review service you asked for; legitimate interests (Art. 6(1)(f)) in showing genuine, verified reviews | While published, plus 12 months of moderation record after removal |
| Answer support requests, triage bug reports, and run support chat | Your message, category, optional email, Discord relay metadata, triage history, diagnostic attachment metadata | Contract (Art. 6(1)(b)) where you are a customer; legitimate interests (Art. 6(1)(f)) in helping people who are not, and in keeping a support history | 24 months from the last message on the ticket |
| Run the referral and creator programs: attribute a sign-up, credit a reward, pay a creator | Referral code, click and conversion records, the crediting account, payout amounts; for creators, payout and tax details | Contract (Art. 6(1)(b)) with the participant; legitimate interests (Art. 6(1)(f)) in detecting referral fraud; legal obligation (Art. 6(1)(c)) for payout tax records | Attribution records 24 months; payout and tax records 7 years |
| Keep the service secure: rate limiting, abuse and fraud detection, audit logs, incident investigation | IP address, request metadata, anti-spam signals, admin audit entries | Legitimate interests (Art. 6(1)(f)) in protecting the service, our customers and our revenue against abuse | Security and rate-limit logs 90 days; admin audit entries 24 months; anything pulled into an active investigation until it closes |
| Establish, exercise or defend legal claims, and comply with lawful requests | Whatever is relevant to the claim | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) | Until the claim and any appeal period ends |
Where a retention period has passed but a record is still needed for another row - most often a purchase record inside its 7-year accounting period - the longer period applies to that record only, and the rest is deleted on schedule. If we cannot delete something immediately because it sits in an encrypted backup, we isolate it and delete it when that backup rotates.
Automated decisions. Device-limit enforcement and anti-fraud checks run automatically. They can block a sign-in on a new PC or flag a referral. They are not the kind of solely automated decision with legal or similarly significant effect described in Article 22, and if one of them ever costs you access you asked for, a person will review it - contact support and say so.
5. Where your data goes
Orion Tweaks LLC is established in the United States, and the ORION API and its data store run on servers we operate. If you are in the EU, EEA or UK, using ORION means your data is processed in the United States.
We share personal data only with the processors listed under “Processors and service boundaries” below, each acting on our instructions under a written data-processing agreement. For transfers out of the EEA or the UK to those processors, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) together with the UK International Data Transfer Addendum, or on a processor's certification under the EU-US Data Privacy Framework and its UK extension where it holds one, plus the additional technical measures described in each agreement - transport encryption, encryption at rest, and access limited to named administrators. You can ask us for details of the safeguard that applies to a specific processor.
We also disclose data where the law requires it - a valid court order, subpoena, or tax or regulatory obligation - and to a buyer or successor if the business is ever sold, in which case we will tell you before your data moves and this policy continues to apply until you are given a new one. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
EU and UK representative. Orion Tweaks LLC has no establishment in the EU, EEA or UK, and has not yet appointed a representative under Article 27 of the EU GDPR or UK GDPR. We are taking advice on whether one is required for the scale on which we offer ORION to customers there, and will name any representative here as soon as one is appointed. Until then, address anything you would send a representative to support@oriontweaks.com, which reaches the controller directly.
6. Cookies and browser storage
The ORION website sets no advertising or analytics cookies, and loads no third-party script or tracker of any kind. Storing anything on your device - a cookie, localStorage, or anything similar - is regulated the same way, so everything we store is listed below. “Strictly necessary” means technically essential to deliver something you asked for, not merely useful to us; anything that fails that test is separated out and is not stored unless you say yes.
Cookies
Two, both strictly necessary, which is why the site does not ask permission for them - there is nothing here you could decline and still sign in safely:
orion_rtb- ties your refresh token to this browser, so a token copied off your device by anyone else cannot be used to sign in as you.HttpOnly,Secure,SameSite=Lax, limited to/api/account, expires after 30 days. Deleted when you sign out.oauth_state- a one-time value that proves a returning Discord sign-in is the one you started, which is what stops a cross-site request forgery attack on that flow.HttpOnly,Secure,SameSite=Lax, limited to/api/auth/discord, expires after 10 minutes.
The site also uses your browser's own localStorage, which is not a cookie but is disclosed here because it stores data on your device just the same. It is split by the same test.
Strictly necessary - stored without asking, because the feature you requested cannot work otherwise
orion_tokenandorion_refresh- your sign-in session, so you are not asked to sign in on every page. Cleared when you sign out.orion_email- the address you signed in with, so the account pages can show it without another request.orion_refresh_lock- a short-lived marker, held for a few seconds at a time, that stops two open ORION tabs from renewing the same sign-in session at once. It holds a random id and a timestamp, is never sent to us, and is removed as soon as the renewal finishes.orion_theme- which of the two visual styles (Vivid or Calm) you picked with the toggle in the footer, so the site looks the way you left it. Written only at the moment you click the toggle, which is what makes it a preference you asked us to remember. It holds one word, is never sent to us, and is not tied to your account.orion-cookie-notice-ackandorion_ref_consent- that you dismissed the storage notice, and your yes-or-no answer on referral attribution below. These exist only to honour a choice you made; without them we would have to ask you again on every page.
Not strictly necessary - we ask first, and store nothing if you decline
orion_refandorion_ref_at- the referral code you arrived with and when, kept for up to 90 days so the person who referred you is credited if you buy. This is attribution, not a technical necessity: the site, your account and your purchase all work identically without it, so it is not strictly necessary and we do not treat it as such. If you arrive with a referral link we show a short prompt explaining the trade; nothing is stored, and no referral click is reported to our API, unless you choose “Allow”. Choosing “No thanks” is remembered and we do not ask again. No profile is built from this and it is not shared with anyone.
You can change your mind at any time by clearing site data in your browser, which erases the stored choice along with everything else; the site keeps working, you will just be signed out and asked again. Because nothing here is used for advertising or cross-site tracking, there is nothing else to opt out of.
7. Your rights, and how to use them
Signed-in users can export account data from the account page; the API endpoint is /api/account/export. You can also delete your account from the account page. Deletion removes your account record, refresh tokens, cloud sync data, and email-keyed newsletter subscription. Purchase/license records, consent records, reviews, support history, telemetry, and referral accounting are kept for the periods in section 4 where law, accounting, refunds, fraud prevention, moderation or proof of licence ownership require it.
Wherever you live, and specifically under the UK GDPR and EU GDPR, you have the right to:
- Be informed - this policy, and the detail in section 4, is that information.
- Access your data and get a copy of it.
- Rectification - have inaccurate data corrected and incomplete data completed.
- Erasure - ask us to delete data where there is no overriding reason to keep it. We will tell you plainly which records we must keep and why.
- Restrict processing - have us hold data without using it, for instance while a dispute about its accuracy or about our legitimate interests is resolved.
- Data portability - receive the data you gave us, and that we process by consent or under our contract with you, in a structured, commonly used, machine-readable format, and have it sent to another controller where that is technically feasible.
/api/account/exportreturns JSON and exists for exactly this. - Object - to any processing we base on legitimate interests, on grounds relating to your situation; we then stop unless we can show compelling legitimate grounds that override your interests. You can object to direct marketing at any time, for any reason, and we must stop immediately - the unsubscribe link in every marketing email does this in one click.
- Withdraw consent at any time where we rely on consent - marketing email, benchmark telemetry, and referral attribution storage. Withdrawing is as easy as giving it, and does not affect the lawfulness of what we did beforehand.
- Not be subject to a solely automated decision with legal or similarly significant effect - see the note at the end of section 4.
Use any of these by emailing support@oriontweaks.com, through the support form, or on ORION Discord. We do not charge for this. We respond within one month; if a request is complex we may extend by up to two further months and will tell you why within the first month. We may ask you to confirm control of the account's email address before we act, because handing account data to the wrong person is the worse failure.
California residents have the rights to know, delete, correct, and to opt out of sale or sharing under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of, and we will not discriminate against you for exercising any right.
Complaints. If you think we have handled your data badly, please tell us first - we would rather fix it. You also have the right to complain to a supervisory authority without going through us:
- United Kingdom: the Information Commissioner's Office, ico.org.uk/make-a-complaint, helpline 0303 123 1113.
- EU/EEA: the data protection authority of the country where you live, work, or where the problem happened. The list is at edpb.europa.eu.
- Elsewhere: your national or state privacy regulator, where one exists.
8. Processors and service boundaries
- Stripe: payment processing, billing portal and subscription management (US/IE). Card numbers and bank details are handled by Stripe, not stored in ORION systems.
- Resend: transactional email such as verification, plan confirmation, and support/review messages (US).
- Anthropic: optional AI support/chat enhancement when configured (US); support chat can fall back to non-AI knowledge-base answers. Chat content is not used to train models.
- Cloudflare: CDN and network protection for the public website (global edge).
- Discord: optional OAuth, status, and support community features (US). What you post in a public Discord channel is governed by Discord's own policy as well as ours.
9. Security
Data is encrypted in transit, access to production systems is limited to named administrators with multi-factor authentication, admin actions are logged, and passwords are stored as verifiers rather than recoverable text. No system is perfect: if a breach ever puts your rights at risk we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell you without undue delay where the law requires it.
10. Local safety records
Tweak backups and the rollback journal are local safety records used to revert changes and troubleshoot what happened on your PC. They are not Cloud Sync payloads and should be shared with support only when you choose to export diagnostics or provide them during a support request. For the public safety summary, see Why ORION Is Safe; for the technical version, see How ORION Tweaks Works.
11. Children
ORION Tweaks is not directed at children under 13 (16 in the EU) and we do not knowingly collect their data. Buying a plan additionally requires the age of majority or a parent or guardian as the contracting party - see Terms of Service section 13. If you believe a child has given us data, tell us and we will delete it.
12. Changes
If we materially change this policy we will update the date above, notify purchasers by email or in-app notice, and keep the previous version available on request so you can see what changed.
13. Contact
Orion Tweaks LLC is the data controller. Questions or data requests: reach us through the support page, ORION Discord, or support@oriontweaks.com; a postal address for formal notice is provided on request. You can also export or delete your data yourself from your account page. See also our Terms of Service.