GitHubX
Orka

Orka · Legal

Privacy Policy

Orka is built to communicate with your infrastructure, not ours. There is no Orka account or developer-operated backend, and the developer does not receive your Coolify credentials or content.

Effective July 31, 2026

Who this policy covers

This policy describes the Orka iOS application and its project pages on didac.dev. Orka is developed and operated by Dídac Sabatés. It is an independent client for the official Coolify API and is not affiliated with or endorsed by Coolify or CoolLabs.

Orka has no user accounts, analytics, advertising, crash-reporting services, tracking SDKs, or relay backend. The developer does not receive your Coolify API token, infrastructure data, application logs, or configuration through Orka.

Data on your device

Orka stores local connection metadata, including the installation name and HTTPS address you provide, detected Coolify version and team name, permission states, last successful connection date, and selected installation.

Each Coolify API token is stored as a generic password item in the iOS Keychain for use only while the device is unlocked. Orka does not synchronize tokens through iCloud Keychain or migrate them to another device.

API responses and sensitive values are held in app memory while needed and sent to your configured Coolify server. Orka does not persist an API response cache.

Network connections

Authenticated API requests go directly from your device to the trusted HTTPS Coolify origin you configure. Requests contain only the token and data required for the operation you choose.

The public one-click service catalog may load from cdn.coollabs.io, and service logos may load from raw.githubusercontent.com, both without your API token. Those destinations may process ordinary network metadata under their own policies.

Device authentication

Protected operations may use Face ID, Touch ID, or the device passcode through Apple's Local Authentication framework. Orka receives only whether authentication succeeded and does not receive biometric or passcode data.

Sharing and browser links

Orka shares diagnostics or resource logs only when you invoke the iOS share sheet. Automated secret redaction cannot guarantee removal of every possible secret, so review generated content before sharing it.

Links to your Coolify server, application domain, or deployment page use the system browser. Orka does not attach its API Bearer token to those links.

Retention and deletion

Connection metadata remains on the device until you remove the installation, clear the app's data, or delete the app container. API-derived view state remains in memory for the active session.

Removing an installation deletes its local metadata and matching Keychain token, but does not revoke the token on Coolify. Revoke it from Coolify as well to invalidate access completely.

Security

Orka accepts trusted HTTPS installation URLs and rejects embedded credentials, query parameters, fragments, and unsupported schemes. Networking uses an ephemeral URL session with response caching disabled.

No storage or transmission method can guarantee absolute security. You remain responsible for protecting the device, server, and API token you configure.

This website

These project pages are hosted on didac.dev and may use PostHog product analytics to understand page visits and interactions. Website analytics are separate from Orka and are never connected to credentials or infrastructure data handled by the app.

The website's hosting and analytics providers may process technical and network information such as the page viewed, browser details, and IP address to deliver, measure, and secure the site.

Changes and contact

This policy may be updated when Orka's data practices or functionality change. The effective date above will be revised when a new version is published.

Questions about privacy can be sent to [email protected].