Privacy Policy
Last updated: July 16, 2026
Orbit is built around the idea that "social" shouldn't mean "public." This policy explains what data we collect, what we do with it, what we don't do with it, and the rights you have over it. We've tried to keep it readable, actual sentences, not boilerplate.
If you read nothing else: we don't sell your data, we don't share it with advertisers, we don't track you across other apps, and the people in your orbits are the only ones who see what you post.
1. Who we are
Orbit is a privacy-first social app published by Orbit Social ("we", "us", "our"). Contact: privacy@social-orbit.app
The app is currently available in the United States. If you are outside the US, this policy still applies, but our infrastructure may be located in the US.
2. What data we collect
Information you give us
- Account info: email address, username, display name, password (stored as a one-way hash; we never see your plaintext password)
- Profile content: avatar, bio
- Content you create: posts, captions, thoughts, pulses (direct messages, text, images, videos), voice messages (transcribed on your device, audio is never sent anywhere for transcription), scheduled time capsules, comments, reactions, channel subscriptions
- Social graph: which orbits you've created, who you've invited, who's joined, blocks
Information from your device
- Camera and photo library access, only when you explicitly add an image or video to a post or pulse. We do not access these continuously. Photo and video metadata (location, device info, timestamps) is stripped on your device before upload.
- Push notification token, if you grant notification permission, an opaque token issued by Apple is stored so we can send you push notifications.
- Crash and diagnostic data, provided by iOS (MetricKit). This includes stack traces, app version, and the OS-supplied signal/exception type. It does not include your content or personal information.
Information generated by your use of the app
- Activity timestamps (when you last opened a conversation, when a post was viewed)
- Screenshot events on posts and pulses, when iOS notifies the app that you've taken a screenshot of someone else's content, we log it so the author can see who captured their material. The author is shown only the screenshotter's username and the timestamp.
- Sign-in security log, when you sign in, our infrastructure records the IP address and timestamp of that sign-in, retained for up to 90 days. We keep this for us and for you: it's how we investigate a compromised account, and it's what lets us hand law enforcement something real when someone uses Orbit to harm children or other people. It is used for security and abuse investigations only, never for advertising, profiling, location tracking, or anything else. If you never break the rules, this log does nothing but expire. If you exploit children here, it goes straight to the authorities.
We collect this data because the app cannot function without it (a social messaging app needs to store messages somewhere). We do not collect data for advertising, behavioral profiling, or sale.
3. What we don't collect
- Tracking identifiers for advertising. We don't use the Identifier for Advertisers (IDFA), and our App Privacy manifest declares
NSPrivacyTracking = false. - Third-party analytics SDKs. There are no Google Analytics, Facebook SDK, Sentry, Firebase Analytics, or similar libraries running in the app. Crash reporting uses Apple's own MetricKit.
- Location data. We don't request location permission and we strip GPS metadata from photos and videos on upload.
- Contacts. We don't read your address book.
- Web browsing or app usage outside Orbit. We have no visibility into anything outside our own app.
4. How we use the data
- To deliver the app, sign you in, show your feed, route messages, post your content to the orbits you choose
- To enforce safety, process reports, action suspensions, respect blocks
- To send you notifications you've opted into (new pulses, replies, screenshots of your content, etc.)
- To detect and fix crashes, MetricKit diagnostics are reviewed in aggregate to fix bugs
- To respond to legal requests when required by law
We do not use your data to train AI models, sell to third parties, or share with advertisers.
5. Who sees what
- Your posts and thoughts are visible only to members of the orbit you posted to. Orbits are invite-only by default; a viewer must be accepted by the orbit owner.
- Your pulses (direct and group messages) are visible only to the participants in the conversation. When end-to-end encryption is on, the message text is encrypted on your device with a key that never leaves it, our servers store ciphertext that we cannot read, and neither can our moderators. Non-encrypted content can be viewed by a moderator only when it has been reported, and only the reported content.
- Your profile (username, display name, avatar, bio) is visible to anyone you've interacted with through the app.
- Your email is visible only to you and Orbit's infrastructure (for account recovery and security notifications).
When you block someone:
- They can no longer see your posts, thoughts, comments, likes, or pulses
- You no longer see their posts, thoughts, comments, likes, or pulses
- Neither of you appears in the other's user search
- This is enforced at the database layer, not just in the app's UI
6. How we moderate
Privacy-first does not mean anything-goes. Orbit prohibits child sexual abuse material, sexual content, and abusive content entirely, see the Terms of Service for the full list. Here is exactly how enforcement works, because how a platform moderates is a privacy question:
- Public surfaces are screened proactively. Content posted to channels, discoverable orbits, and public-facing profile fields (username, bio, avatar) may be automatically checked by an AI safety classifier at upload time. These are the surfaces strangers can see, so they get scanned.
- Private content is reviewed only when reported. We do not proactively scan posts inside private orbits or your messages. If a participant reports content, that specific content is queued for review, an AI classifier assists with triage, and a human moderator makes the decision.
- End-to-end encrypted messages cannot be scanned by anyone, including us. We hold ciphertext. If a recipient of an encrypted message reports it, they can share what they received, including attaching screenshots to the report. The report is based on the recipient's copy, not on us reading your messages, because we can't.
- AI-assisted, human-decided. Automated classifiers flag, score, and prioritize. Account suspensions and bans are decided by a human, with one narrow exception: content flagged with high confidence as child sexual abuse material is quarantined automatically and immediately, pending human review.
- Zero tolerance for child exploitation, and we're proud to say exactly what that means. Confirmed child sexual abuse material is reported to the National Center for Missing & Exploited Children (NCMEC) and law enforcement as US law requires, and we provide any and all data and information we collect, account details, the content, timestamps, sign-in IP addresses, and the interaction records of everyone who engaged with it. The poster and anyone who liked, reacted to, commented on, or shared the material are frozen and included in the report. Evidence is preserved for law enforcement for the legally required period. Our privacy commitments protect people, not predators.
- Accounts under review are frozen, not deleted. When content is quarantined for a serious violation, the involved accounts see an "account under review" notice at sign-in, and account deletion is blocked while the review or any legal obligation is active, so evidence can't be destroyed. If a human review overturns an automated flag, the hold is released, you're notified, and everything returns to normal.
- Content shared with the AI classifier is used for moderation only, it is not used to train models, and it is not retained by the classifier beyond processing.
You can report any post, message, comment, user, or orbit from inside the app, with up to three screenshots attached as evidence, and block anyone. If we action your content or account, you can appeal via Settings → Support.
7. How long we keep it
- Account data, until you delete your account
- Posts and pulses you marked as expiring, automatically deleted at the time you specified (1 hour, 24 hours, 7 days)
- View-once pulses, deleted from our database after they've been opened
- Crash reports, retained for 30 days, then deleted
- Screenshot events, retained for 14 days, then deleted
When you delete your account, deletion runs immediately and is permanent, there is no grace period and no way to restore the account by signing back in. It removes:
- Profile, posts, thoughts, pulses, comments, likes, reactions
- Media files in storage
- Subscriptions, orbits you owned (members keep their own content)
- Push notification tokens, encryption keys, pending data exports
The narrow exception: if specific content is subject to an active abuse investigation or a legal preservation obligation, we may retain that content for as long as the law requires before destroying it.
8. Where the data lives
Orbit's databases and media storage are hosted on Supabase infrastructure. The data is encrypted at rest and in transit (TLS).
We do not transfer data to advertising networks or analytics processors.
9. Your rights
You can:
- Access your data, open the app and view your profile, posts, pulses
- Correct your data, edit your profile, edit captions on posts, edit thought text
- Delete your account, Settings → Delete Account. Immediate and permanent; wipes all content tied to your user ID
- Export your data, Settings → Export my data. We email you a download link (valid for 7 days) containing everything we store about you: account info, posts, messages, and your media. End-to-end encrypted messages are included as the ciphertext we hold, we can't decrypt them, so we can't export them as plaintext either. (Email privacy@social-orbit.app if you can't access the app.)
- Block anyone, Settings → Blocked Users
- Withdraw consent for notifications, iOS Settings → Notifications → Orbit
If you're in a jurisdiction with GDPR-equivalent rights, you also have the right to lodge a complaint with your supervisory authority.
10. How we protect your data
- End-to-end encryption for pulses, when enabled, message text (and voice-message transcriptions) are encrypted on your device using keys stored only in your device's Keychain. Our servers relay and store ciphertext they cannot decrypt. If you lose the device, those messages are unrecoverable, by you or by us. That's the design.
- Row-level security on every database table, each user can only read what they're authorized to see
- Signed URL expiry on media, image and video links expire roughly every hour to limit the window of any leaked URL
- Photo and video metadata stripping on upload, GPS, device info, timestamps removed before bytes leave your device
- Screen-recording detection, when iOS reports that your device is being screen-recorded, sensitive content in the app is blanked out
- Screenshot notifications, when someone screenshots your post or pulse, you're notified
- No save or re-share affordances, the app deliberately provides no way to download or export someone else's content
We use industry-standard cryptography (TLS 1.2+ for transit, AES-256 for storage encryption). However, no system is perfectly secure. If we ever experience a data breach affecting your account, we'll notify you within 72 hours.
11. Children
Orbit is intended for users 18 and older. You must confirm you are 18+ at sign-up. If we learn that someone under 18 has created an account, we'll delete it. We do not knowingly collect data from anyone under 13 (COPPA).
If you're a parent who believes your child has registered, contact privacy@social-orbit.app and we'll remove the account immediately.
12. Changes to this policy
If we make material changes, we'll notify you via in-app banner and email at least 14 days before the changes take effect. The "Last updated" date at the top tracks when this document last changed.
13. Contact
- Privacy questions: privacy@social-orbit.app
- Account deletion help: Settings → Delete Account, or email above
- Data export: Settings → Export my data, or email above
We aim to respond within 7 days.
This policy is written in plain English on purpose. If anything is unclear, ask us, we'd rather explain than hide behind legalese.