Your Data Stays on Your Machine
We built Oranos with a local-first philosophy: privacy is not an option or opt-out setting — it is built directly into our software architecture.
100% Local Storage
All boards and images reside in your browser's local origin storage.
Encrypted WebRTC P2P
Live sessions connect directly peer-to-peer between browsers.
Zero Database Retention
No user accounts, tracking cookies, or server-side telemetry.
1. Local-First Architecture
Oranos operates as a local-first client application. When you open a board, draw elements, or upload images, all state mutations occur strictly in browser memory and local storage (`localStorage`). No payload is transmitted to an external central cloud server or third-party analytical platform.
2. Peer-to-Peer WebRTC Collaboration
When you initiate a live collaboration session, Oranos uses WebRTC data channels to connect directly with up to 3 other peers. Room codes act as session passcodes. Cursor positions, drawing strokes, and embedded image chunks are sent browser-to-browser over DTLS-encrypted WebRTC channels. Standard Google STUN servers (`stun:stun.l.google.com:19302`) are queried solely to discover NAT candidates during room connection setup.
3. Portable .oranos Files
Exporting your board via "Save .oranos file" generates a self-contained JSON document with Base64-encoded image payloads embedded inside. You retain full ownership and control over your files. You can archive, move, or share these files on USB drives, local server shares, or private repos without third-party cloud lock-in.
Privacy & Security FAQ
Does Oranos send my canvas drawings or uploaded images to any cloud server?
No. Your canvas drawings, text notes, and uploaded images never touch an Oranos server or cloud database. They are stored locally in your browser's localStorage and saved to your device as .oranos files.
How does live collaboration work without a database server?
Live room sync uses WebRTC data channels — a direct peer-to-peer browser technology. Cursor positions and element updates are transmitted directly between connected browsers. STUN servers are only used to facilitate initial NAT connection setup and never store room data.
Is Oranos compliant with GDPR, CCPA, and HIPAA regulations?
Yes. Because Oranos collects zero personal identifier data, uses no tracking cookies, and maintains no server-side user database, it inherently complies with GDPR, CCPA, and HIPAA privacy standards.