Oryn · Last updated August 18, 2026
Privacy Notice
What Oryn processes, why it is needed, who it reaches, how long it is kept, and what you can do about it.
1. Controller
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:
Brombach Technologies GmbH
Rheintalbahnstraße 35
68199 Mannheim
Germany
Email: lukas@brombach-technologies.de
2. What we process
- Account information: name, email address, profile image, account identifiers and authentication records.
- Email preference: whether you chose to receive optional Oryn tips and product updates, when you chose, the language and the wording version shown to you.
- Project information: prompts, chat messages, uploaded and imported assets, generated files, builds, previews, versions and project settings.
- Audio you upload for speech or voice cloning, including the recorded voice itself.
- Community activity: published games, comments, likes, follows, remix relationships and content reports.
- Billing information: plan, subscription status, credit ledger, invoices and the billing address needed to determine VAT.
- Usage and security information: feature activity, credit usage, device and browser details, diagnostics, errors and security events.
3. Why, and on what legal basis
- Art. 6(1)(b) GDPR — performance of a contract: your account, your projects, generation and build runs, publishing, plan and credit accounting, and payment processing. Without these there is no service to deliver.
- Art. 6(1)(c) GDPR — legal obligation: invoices, VAT records and the retention periods that apply to them, and acting on reports of illegal content.
- Art. 6(1)(f) GDPR — legitimate interests: server-side operational measurement (how often generation succeeds or fails), abuse prevention and security logging. This sets no cookies and reads nothing from your device.
- Art. 6(1)(a) GDPR — consent: the browser-side product analytics described in section 7 and, only if you choose it, occasional Oryn tips and product updates by email. You can withdraw either choice at any time with no effect on the service; every marketing email includes an unsubscribe link.
4. AI processing
To carry out what you ask for, we send prompts and the parts of your project the task needs — file contents, error output, project settings — to AI model providers. Attached images and audio go with them when a task uses them.
Your prompts are not used to train models. Requests routed through OpenRouter carry an instruction that excludes any upstream provider whose policy allows retaining prompts or training on them. OpenRouter itself does not train on what passes through. This costs us availability on some models rather than costing you your work.
Do not put credentials, API keys or personal information you do not need into prompts or project files. Nothing about how the service works requires them.
5. Voice recordings
If you generate speech or clone a voice, the audio file you supply is uploaded to fal.ai and passed to the voice model, which derives a reusable voice identifier from it. A recording of an identifiable person is that person's personal data, and cloning a voice affects their personality rights.
Only upload a voice you are entitled to use, and only with that person's agreement. We delete the uploaded audio with the project it belongs to.
6. Publishing and community
A project is private until you publish it. Once you do, the game, its title, artwork, description, your creator name and profile image, and its play and like counts are visible to anyone, signed in or not. Comments you write are public in the same way.
Content reports are stored with the reporter's account identifier so we can act on them and answer you. We keep a record of decisions we make about reported content.
How a play is counted. So that the number under a game means something, one visitor counts once per game per hour. We do not store your IP address to do it: the address is combined with the game, the hour and a secret of ours into a one-way hash, and only that hash is kept. It cannot be turned back into an address, and because the hour is part of it, two visits an hour apart cannot be linked to each other. Signed in, your account identifier is used instead. Legal basis is Art. 6(1)(f) GDPR — the creator's and our interest in a play count that is not trivially inflated.
7. Cookies and local storage
- Sign-in and session cookies set by Clerk. Strictly necessary — without them you cannot stay signed in.
- Analytics consent cookie (oryn-analytics-consent), which stores your answer to the banner for a year so we do not ask again.
- Referral cookie (oryn_ref), set for ninety days when you arrive through an invite link, so the person who invited you is credited when you sign up.
- Preference cookies (oryn-theme, oryn-language), kept for a year each so the interface comes back in the theme and language you picked. They are written only when you change one of those settings, and need no consent: a preference you asked for yourself is exempt.
- Product analytics (PostHog, hosted in the EU), only after you agree. PostHog sets its own cookie (ph_…_posthog) to recognise this browser across pages. Declining changes nothing about the service.
- In-product support (Featurebase), loaded only in the signed-in studio. Featurebase may use cookies and local storage to keep your support conversation and unread state available.
- Local storage for interface state such as editor layout and dismissed hints. This stays on your device.
8. Processors and recipients
These providers process personal data on our behalf under Art. 28 GDPR. Transfers outside the EU rely on the European Commission's standard contractual clauses.
- Clerk — sign-in, sessions and account records (USA).
- Convex — projects, chat history, runs, versions, billing records and usage (USA).
- Cloudflare — hosting, the isolated containers your project is built and exported in, and project, version and build storage (EU and USA).
- Stripe — payments, subscriptions, tax determination and invoices (Ireland and USA).
- PostHog — product analytics, hosted in the EU, and only with your consent.
- Featurebase — the in-product support messenger, support conversations and attachments, linked to your signed account identity.
- AI model providers — OpenRouter, OpenAI and the models routed through them, for prompts and project context.
- fal.ai — generation of images, 3D models, audio, speech and video, and the voice models behind them.
- GitHub — only if you connect a repository. Your project files are then sent to GitHub under your own account and GitHub's terms.
9. How long we keep things
- Account and projects: until you delete them. Deleting your account removes your projects, published games, chat history and community records; you can also export projects for thirty days after a contract ends.
- Invoices and the billing records behind them: ten years, because German tax and commercial law requires it.
- Content reports and moderation decisions: three years, so a repeat pattern is visible and a decision can be explained.
- Security and error logs: ninety days.
- Analytics: as configured in PostHog, and only for as long as your consent stands.
- Support conversations: as configured in Featurebase and for as long as needed to answer and document your request.
- Email preference: until you change it or delete your account. A record of a withdrawn consent may be retained for three years to demonstrate compliance.
10. Your rights
Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict processing (Art. 18), to receive it in a portable form (Art. 20), and to object to processing based on our legitimate interests (Art. 21). Where processing rests on your consent, you may withdraw it at any time with effect for the future.
You can delete your account and everything in it from your account settings. Some records may be retained where billing, security, fraud prevention or legal compliance requires it.
You also have the right to lodge a complaint with a supervisory authority — for Baden-Württemberg, the Landesbeauftragte für den Datenschutz und die Informationsfreiheit.
11. Children and changes
Oryn is not directed at children. You need to be at least 16 to use it, which is also the age from which you can consent to the analytics described above in Germany.
This notice may be updated as the product or legal requirements change, with the current date shown above.
12. Contact
For privacy questions or to exercise any of the rights above, write to lukas@brombach-technologies.de.