Your work stays
with you.
OriginPage’s privacy claim is deliberately specific so you can understand exactly what happens to your Documents and Conversation.
Local-only operation
OriginPage performs document extraction, indexing, retrieval, persistence, and answer generation on the current device. During ordinary Document and Conversation use, the OriginPage process tree makes no network connection.
OriginPage does not send Document content, questions, answers, prompts, retrieved context, identifiers, analytics, diagnostics, or licence checks over a network. There is no cloud-model fallback.
What stays on your device
Imported Documents, their processed retrieval data, the current Conversation, backups, and allowlisted diagnostic events are stored inside OriginPage’s private non-roaming application storage.
OriginPage creates a managed copy when you import a Source File. It never modifies or deletes the original file outside the app.
Diagnostics
Diagnostics are designed around stable event codes and non-content measurements. They exclude filenames, file paths, Document text, questions, answers, prompts, retrieved passages, and clipboard content.
The boundaries of this claim
Local-only does not mean air-gapped or encrypted by the application. Another process running with your Windows account or administrator access may be able to read local data. Memory paging, hibernation, antivirus scanning, Windows Error Reporting, Microsoft Store delivery, and operating-system file-picker history are Windows facilities outside OriginPage’s process-tree claim.
Windows Repair preserves the Workspace. Windows Reset and uninstall remove OriginPage’s locally stored Workspace; your original Source Files remain unchanged.
The useful promise is not that risk disappears. It is that your document workflow does not require sending app content to someone else’s server.