Orbit · Legal
Privacy Policy.
Written against the system itself, not from a template. Every category below is something Orbit actually stores, every company named is one we actually use, and the retention numbers are the ones the cleanup jobs run on.
- Effective
- August 3, 2026
- Last updated
- August 4, 2026
What this covers
This policy describes how Orbit Labs LLC handles personal data in the Orbit website and the Orbit mobile app. It is written against the actual system, not against a template: every category below corresponds to something Orbit stores or sends, and every company named in it is one we genuinely use.
The short version. Orbit runs no advertising, has no ad-tech or analytics SDK in either app, sells nothing about you, and does not use your content to train AI models. What we hold is what the product needs to work, plus a small amount of security data so you can see who has signed into your account.
The Terms of Service govern your use of Orbit. The ten promises describe the product commitments behind several of the choices explained here.
What we collect
Account and profile
Your email address and password are held by our authentication provider; we never see your password in readable form. Your profile holds what you put in it: username, display name, bio, avatar, cover image, website, a free-text location if you type one, interests, and your privacy and content settings.
Signup asks for your date of birth so we can check you are at least 13. That check runs in your browser and the date is not sent to us or stored.
What you post
Posts, comments, replies, moments, clips, live streams and their replays, marketplace listings, events, communities, sounds, drafts, and scheduled posts. Images and video you upload are stored in our file storage; video for clips, live, and replays is additionally processed and delivered by our video provider, and we store the identifiers it returns.
If you add a location to a post or a listing, it is text you typed. Orbit does not request or read your device's GPS location, on the web or in the app.
Messages
Direct messages, group conversations, attachments, and reactions. Message attachments live in a private storage area readable only by the people in the conversation. Messages are not end-to-end encrypted; see the security section below for what that means.
Activity
Likes, bookmarks, follows and follow requests, poll votes, mentions, reposts, saved searches, and the topic preferences you set with “see more” and “not interested”. Also your safety lists: blocks, mutes, restricted accounts, muted words, and close friends.
Three kinds of view data exist, and they differ. Posts, listings, and replays carry an aggregate view counter with no record of who viewed, and that counter is what everyone sees on the post.
Separately, when a post is shown to you we keep one row for that post per day, so the feed can tell what it has already put in front of you and how you responded to it. The row records which surface the post appeared on, one of For You, Following, Clips, a profile, a hashtag, search, or the post's own page. It also records the first and last time the post was shown to you that day, how many times it was shown, how long it was on screen, how much of its video you watched, how long that video is, and how many times you watched it to at least ninety percent. Alongside it we record actions you take from a post: opening the author's profile, clicking a link out, sharing to a direct message, sharing outside Orbit, expanding the post, and replaying its video, each with the surface and the time. Sharing a post into a message also records which post that message shared.
Those rows are readable only by you. The database grants each person access to their own and to nobody else's, and the view rows are written by one capped server function rather than by the app directly. Authors are never shown who viewed their posts. What an author will be able to see about their own posts is counts: how many people, not which people.
Moments are the deliberate exception. They record each viewer by name, because the person who posted is shown who watched.
Security and device data
Each sign-in attempt records the IP address, a device or browser descriptor, whether it succeeded, and the time, so you can review it under security settings and spot a session you do not recognize. On the web the IP is taken from the request, and the browser also asks a public IP-lookup service for the address it is connecting from. In the app the descriptor is your operating system, its version, and your device model.
If you turn on two-factor authentication, we store your recovery codes hashed, never in readable form.
Notifications
Your per-type notification settings, quiet hours and time zone offset, and the email digest setting. If you turn on push, we store the push token or endpoint your browser or device issues, along with the platform, so the notification can be routed to you.
Moderation
Reports you file and reports filed about you, automatic flags raised on your content, and any appeal you submit. These are visible to you under account status.
How we use it
We use the data above to:
- Run the service: show your feed, deliver your messages, encode and play your video, and keep your settings applied across the web and the app.
- Authenticate you, keep your session valid, and let you review sign-in activity on your own account.
- Send notifications you asked for, in the app, by push, and by email digest if that is on.
- Decide ranking and distribution: which posts For You puts in front of you, and how far a post travels. That is the only thing the per-viewer view data is used for. It is not sold, not shared, and there is no advertising for it to feed.
- Keep Orbit safe: detect spam and abuse, act on reports, and enforce the rules in the Terms of Service.
- Fix problems. Crash and error reports help us find bugs, and are sampled rather than collected from every session.
- Meet legal obligations and respond to lawful requests where we are required to.
Ranking on Orbit uses your own signals: who you follow, what you engaged with, the topic preferences you set, and what has already been shown to you. Your Following feed is strictly chronological and is not ranked at all. Nobody can pay to appear more often in anyone's feed.
What we never do
- No sale of personal data. We do not sell or rent your data, and we do not share it for cross-context behavioral advertising. There is nothing to opt out of because it does not happen.
- No advertising and no ad tech. Orbit carries no ads and neither app contains an advertising SDK, a tracking pixel, or a third-party analytics package.
- No AI training on your content.Your posts, photos, clips, and voice are not training data, ours or anyone else's.
- No reading your messages for profiling. We do not scan direct messages to build a profile of you or to target anything at you.
- No location tracking. Orbit never asks for your device location. Any location on your profile or a post is text you chose to type.
The companies that process data for us
Orbit is built on services run by other companies. Each is a processor acting on our instructions, gets only what its job requires, and cannot use your data for its own purposes. This is the complete list.
- Supabase hosts the database, authentication, file storage, and realtime connections. Effectively everything in this policy is stored there.
- Vercel hosts the website and the server code, and runs the scheduled jobs. Its infrastructure sees requests to Orbit and the IP addresses they come from.
- Mux encodes, stores, and delivers video for clips, live streams, and replays.
- Resend delivers email: verification, password reset, event reminders, and the daily digest. It receives your email address and the contents of the message.
- Cloudflare provides the Turnstile check that protects signup, login, and password reset from automated abuse, and the relay servers that carry live audio and video when a direct connection is not possible. Turnstile is a privacy-focused alternative to a captcha and does not profile you across sites.
- Apple, Google, and browser push servicesdeliver push notifications. In the mobile app they are reached through Expo's push service. They receive the notification and the token that routes it to your device.
- Sentry receives error and crash reports so we can fix bugs. A fraction of sessions is traced for performance, and a session recording is captured only when an error occurs.
- Anthropic, reached through Vercel's AI Gateway powers two optional features: suggesting a caption for an image or video you are about to post, and a second-pass check on post text before it publishes. Only the specific image or text involved is sent, only when the feature runs, and only to produce that one response. This is not training data, and both features fall back to local behavior when the service is unavailable.
- A public IP-lookup service is queried by your browser or app at sign-in to determine the address you are connecting from, which is what makes your sign-in history readable.
These companies are based in the United States, so using Orbit involves storing and processing your data there. We share data with anyone else only when you direct us to, when the law requires it, or if Orbit is ever acquired or merged, in which case we will say so before your data moves.
What other people can see
Your username, display name, avatar, bio, and public posts are visible to anyone, including people who are not signed in, and can be indexed by search engines. A private account limits your posts to approved followers, and posts set to followers-only or close friends go only to that audience.
Some things are visible to specific people by design: the person who posted a moment sees who viewed it, read receipts are reciprocal and can be turned off, and activity status can be hidden. Settings pages for privacy, content, and notifications control each of these.
Anything visible to another person can be screenshotted or copied. Privacy settings control distribution, not what someone does with what they already saw.
How long we keep it
- Moments expire 24 hours after posting. They stop being visible at expiry and are deleted on an hourly cleanup.
- Sign-in history is kept for 90 days, then deleted automatically.
- Event reminder records are kept for 30 days.
- Per-viewer view records are kept for 90 days. They are stored a day at a time and a whole day is dropped at once, not thinned row by row. What outlives them is a daily total for each post: how many times it was shown, how many different people saw it, the summed time on screen and watch time, and the completions. No viewer identities are in that total. The action records have no separate clock and go when the post or your account does.
- Posts, messages, and everything else you create are kept until you delete them or delete your account. We do not expire your content on our own schedule.
- Moderation records for actioned violations are kept after an account closes, so appeals can be answered and repeat abuse can be recognized.
- Backups hold copies for a short rolling window and age out on their own cycle.
Your rights and how to use them
Get a copy of your data
Settings, then Your data, produces a single JSON file you download on the spot, limited to one export every ten minutes. It contains your profile, your posts and their media, who you follow and who follows you, your bookmarks, likes, mutes, and blocks, and the view and action records described above for the posts you were shown. Direct messages are deliberately excluded, because a conversation belongs to everyone in it, not only to the person exporting.
Correct your data
Edit your profile and settings at any time. If something we hold about you is wrong and you cannot fix it yourself, write to privacy@orbitsocial.net.
Delete your account
Settings, then Account, then Delete account. It is immediate and permanent, with no grace period, and requires your second factor if two-factor authentication is on. Your profile and the content attached to it are removed along with your login.
Two things do not go automatically. Files already uploaded to storage may persist after the database records referring to them are gone; write to privacy@orbitsocial.net and we will purge them. Moderation reports naming the account are retained for the reasons in the retention section.
Control what reaches you
Notification settings choose which alerts arrive and when, including quiet hours and the daily email digest. Every digest carries a one-click unsubscribe link, and your mail client's own Unsubscribe button works on it too. Turning the digest off does not stop account email such as password resets and security notices, which we send because they protect your account.
Object, restrict, or complain
Depending on where you live, you may have the right to object to or restrict certain processing, to withdraw consent, and to lodge a complaint with your data protection authority. Write to privacy@orbitsocial.net and we will answer within 30 days. We never charge for a request and never degrade your account for making one.
Why we are allowed to process it
If you are in the European Economic Area or the United Kingdom, our legal bases are:
- Contract. Running your account and delivering the features you asked for.
- Legitimate interests. Keeping Orbit secure, preventing abuse and spam, and fixing errors, balanced against your rights and limited to what those aims need.
- Consent. Push notifications, the email digest, and optional features you switch on. You can withdraw consent at any time in settings.
- Legal obligation. Responding to lawful requests and meeting reporting duties, including reporting child sexual abuse material.
How your data is protected
All traffic to Orbit is encrypted in transit. Data in the database is protected by row-level security, which enforces at the database itself that one account cannot read another's private data, so a bug in the application cannot hand out records it should not. Message attachments sit in a private storage area that requires authentication.
Session cookies are HTTP-only, secure, and same-site, so page scripts cannot read them. You can turn on two-factor authentication, review every sign-in on your account, and end sessions you do not recognize. Recovery codes are stored hashed.
Direct messages are not end-to-end encrypted. They are encrypted in transit and at rest, but we hold the keys, which means we can access them when a legal obligation or a safety investigation requires it. If you need cryptographic secrecy from us, use a tool built for it.
No system is perfect. If we discover a breach that affects your personal data, we will notify you and the relevant authorities as the law requires, and tell you what happened rather than the least we can get away with.
Children
Orbit is not for anyone under 13, and we do not knowingly collect data from children under 13. If you believe a child under 13 has an account, write to privacy@orbitsocial.net and we will close it and delete the data.
Sexual content involving minors is removed immediately, the account is closed permanently, and we report it to the appropriate authorities.
Regional rights
United States
Residents of California and other states with comprehensive privacy laws have the right to know what is collected, to access and delete it, to correct it, and not to be discriminated against for asking. The tools above serve all of these. We do not sell personal information or share it for cross-context behavioral advertising, so there is no opt-out to offer.
European Economic Area and United Kingdom
You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority. Orbit Labs LLC is the controller for the data described here. Because our processors are in the United States, your data is transferred there under the standard contractual clauses or another approved mechanism.
Changes to this policy
When Orbit changes in a way that changes what we collect or who processes it, this page changes with it and the last updated date at the top moves. For a material change we give notice in the product or by email before it takes effect, rather than editing the page quietly.
Contact
Privacy questions, data requests, and anything in this document: privacy@orbitsocial.net.
By mail: Orbit Labs LLC, 1 Main Street, Suite 100, St. George, UT 84770. We are established in the State of Utah, United States.