Who this policy covers
This Privacy Policy describes the Orka iOS application and the website at orka.didac.dev. Orka is developed and operated by Dídac Sabatés. It is an independent client for the official Coolify API and is not affiliated with or endorsed by Coolify or CoolLabs.
Orka does not provide user accounts, analytics, advertising, crash-reporting services, tracking SDKs, or a relay backend. The developer does not receive your Coolify API token, infrastructure data, application logs, or configuration through Orka.
Data on your device
Connection metadata
Orka stores the connections you create in the app's local preferences. This includes a local connection identifier, the installation name and HTTPS address you provide, the detected Coolify version and team name, the last successful connection date, known API permission states, and the selected installation.
API credentials
Each Coolify API token is stored as a generic password item in the iOS Keychain. New tokens are configured for use only while the device is unlocked and are not synchronized through iCloud Keychain or migrated to another device by Orka.
Coolify content
To display and manage your installation, Orka processes API responses such as projects, environments, resources, deployments, servers, domains, configuration, logs, team metadata, and integration details. Values you enter, including configuration, commands, provider tokens, GitHub secrets, and private-key material, are held in app memory while needed and sent to your configured Coolify server. Orka does not persist an API response cache.
Device authentication
Protected operations may use Face ID, Touch ID, or the device passcode through Apple's Local Authentication framework. Orka receives only whether authentication succeeded; it does not receive or store biometric or passcode data.
Network connections
Orka makes the following network requests as part of its functionality:
Authenticated API requests go directly from your iOS device to the trusted HTTPS origin you configure. Requests can contain your Bearer token, resource identifiers, configuration, actions, and other data required by the operation you choose.
When you browse one-click services, Orka retrieves the public template catalog from cdn.coollabs.io without your API token.
Service logos may load from raw.githubusercontent.com in the public coollabsio/coolify repository, also without your API token.
Those destinations may observe ordinary connection metadata such as your IP address, request time, and requested path according to their own logging and privacy practices. Data sent to your Coolify installation and services it controls is governed by that server's operator and configuration.
Retention and deletion
Connection metadata remains on the device until you remove that installation, clear the app's data, or delete the app container. API-derived view state remains in memory for the active app session and is not written to an Orka response cache.
Removing an installation from Orka deletes its saved local metadata and matching Keychain token. It does not revoke that token on the Coolify server, delete remote resources, or remove data retained by Coolify. To invalidate access completely, revoke the token from Coolify as well. Because Keychain lifecycle is controlled by iOS, revoking the remote token is also the safest step before uninstalling Orka.
Security
Orka accepts trusted HTTPS installation URLs and rejects embedded credentials, query parameters, fragments, and unsupported schemes. API networking uses an ephemeral URL session with response caching disabled. Authorization is preserved only for safe same-origin redirects; cross-origin and mutation redirects are rejected.
Critical operations can require device-owner authentication, and the app obscures its interface when inactive to reduce app-switcher exposure. No method of storage or transmission can guarantee absolute security, so you remain responsible for protecting the device, server, and API token you configure.
Children, purchases, and tracking
Orka is a developer tool and is not directed to children. The app contains no advertising, cross-app tracking, subscriptions, in-app purchases, or push-notification service.
Changes to this policy
This policy may be updated when Orka's data practices or functionality change. The effective date at the top of this page will be revised when a new version is published. Material changes will be described clearly in the updated policy.
Contact
Questions about privacy or requests concerning information you believe the developer has received can be sent to:
Dídac Sabatés hi@didac.dev didac.dev