Skip to content
OriginPage
Open navigation
Privacy

Your document work stays
on your PC.

This page explains what OriginPage processes, stores, sends, and deletes.

Local-only operation

OriginPage performs document extraction, indexing, retrieval, persistence, and answer generation on the current device. During ordinary Document and Conversation use, the OriginPage process tree makes no network connection.

During ordinary document work, OriginPage does not send Document content, questions, answers, prompts, retrieved context, identifiers, analytics, diagnostics, or licence checks over a network. There is no cloud-model fallback.

Optional feedback

When you select Send in the feedback form, OriginPage sends the message you wrote and any optional reply email through Cloudflare and AWS SES to the developer's support inbox at support@originpage.app, hosted by Fastmail. We use this information to review your feedback and, if you leave an email, follow up about it.

No Documents, questions, answers, filenames, diagnostic logs, app metadata, or device identifiers are automatically attached. Only include information you intend to share. Sending feedback requires an internet connection; document work continues to run locally and offline. Unsent drafts remain in memory until the app closes.

Submitted feedback is stored in our email inbox rather than a separate feedback database. Contact support@originpage.app to request deletion. Cloudflare processes the network request and uses its source IP for basic abuse protection; the IP is not included in feedback emails. AWS SES processes the message for email delivery, and Fastmail processes and stores the resulting email. These providers may retain operational metadata under their own policies.

What stays on your device

Imported Documents, their processed retrieval data, the current Conversation, backups, and allowlisted diagnostic events are stored inside OriginPage’s private non-roaming application storage.

OriginPage creates a managed copy when you import a Source File. It never modifies or deletes the original file outside the app.

Diagnostics

Diagnostics are designed around stable event codes and non-content measurements. They exclude filenames, file paths, Document text, questions, answers, prompts, retrieved passages, and clipboard content.

The boundaries of this claim

Local-only does not mean air-gapped or encrypted by the application. Another process running with your Windows account or administrator access may be able to read local data. Memory paging, hibernation, antivirus scanning, Windows Error Reporting, Microsoft Store delivery, and operating-system file-picker history are Windows facilities outside OriginPage’s process-tree claim.

Windows Repair preserves the Workspace. Windows Reset and uninstall remove OriginPage’s locally stored Workspace; your original Source Files remain unchanged.

The useful promise is not that risk disappears. It is that your document workflow does not require sending app content to someone else’s server.