Privacy
Orbit holds the working memory of your professional network — who you met, what you said, and who you still owe a reply. This page is the plain description of how that information is handled.
The short version
Your network isn't a product
Orbit doesn't sell personal information or run ad pixels, and its traffic analytics set no cookies.
AI runs on your key
You choose the provider and supply the key. Most AI features run only when you use them; a few, like deriving LinkedIn timeline events, run automatically in the background on that same key. Settings shows what the last 30 days cost.
Export on demand
One control in Settings produces a JSON download of your core Orbit data, on every plan including Free.
Deletion is real deletion
Delete some or all of your data from Settings, or delete your account — which erases your data, keys and sign-in and cancels any subscription.
Orbit is a personal networking tracker: it captures contacts, keeps a history of your relationships, imports data you already have, and uses AI to organise follow-ups. This policy covers the Orbit web app, its browser extension and the services run alongside them, and describes how the product behaves today rather than how it might later.
Orbit is built and run by one person, Jason Pereira. Where this policy says we, that is who it means.
Almost everything in Orbit is there because you put it there. Depending on the features you use:
Worth knowing
Contact records are usually about other people. When you add or import someone, you decide what Orbit stores about them, and you remain responsible for having a lawful basis to keep it. Recording a meeting captures everyone on the call, and many places require their consent first.
Orbit uses the information above to:
Orbit does not use your content to train AI models, its own or anyone else’s, and does not build advertising profiles from it.
Orbit can connect to a Google account you choose. Each feature asks Google only for the permission it needs, at the moment you turn it on, and Google’s own screen shows exactly what is being granted. You can allow one feature and decline another.
| Permission | What Orbit does with it | Asked for when |
|---|---|---|
| Sign-in identity (openid) | Confirms which Google account you connected. | Every Google connection |
| Your email address (userinfo.email) | Shown on the connection so you can tell which account is connected, and the address mail is sent from when you send from Gmail. | Every Google connection |
| See your contacts (contacts.readonly) | Lists your Google Contacts so you can pick who to import. Only the people you select are saved: name, company, title, email, phone and photo. | Connect Google on Imports → Google Contacts |
| Read your email (gmail.readonly) | Recruiter scan: finds recruiting conversations and summarizes each with your own AI key. Confirmation emails: reads mail from Luma, Partiful, Eventbrite, Meetup and Posh to find events you registered for. Replying in a thread: when you compose an email to a contact, finds your latest message with them so you can reply in that conversation, reading only its Message-ID, subject, date and thread. Sending: checks your Sent folder so a retried send is never delivered twice. Message bodies are never stored. | Connect Gmail on Recruiters, or turn on Confirmation emails on Events |
| Send email as you (gmail.send) | Sends the emails you write and press Send on — from Compose on a contact page, follow-ups, drafts from Chat, recruiter emails, and drafts an assistant prepared that you approved — from your own address, so replies reach your inbox. Each one waits about 10 seconds so you can undo it, or until the time you schedule, and can carry files you attach. Orbit never sends a message you did not send. | Connect Gmail to send, in Compose, Settings → Email, the recruiter composer, or on a draft in Chat |
| See your calendar events (calendar.readonly) | Reads recent and upcoming events on your primary calendar and adds meetings with people in your network to their timelines. | Connect Google Calendar on Events |
| See and open only the Google Docs and Slides you pick (drive.file) | Lets you pick Google Docs and Slides from the Google Picker to import. Orbit only ever sees files you explicitly select. | Connect Google on Imports → Google Drive |
Orbit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice: Orbit uses Google data only to provide the features in the table, shown to you inside Orbit. It does not sell it, does not use it for advertising, and does not use it to develop or train AI models. Where a feature uses AI (the recruiter scan), the text involved goes to the AI provider you chose — on your own key, or on Pro and Max on Orbit’s account with that provider — only to produce the result you asked for. A person at Orbit reads Google data only with your permission for a support request you raise, to investigate abuse or a security problem, or where the law requires it.
Disconnecting Google in Orbit deletes the tokens Orbit holds. To also revoke the grant on Google’s side, remove Orbit from your Google Account’s third-party access page.
Confirmation emails
If you turn on event discovery from confirmation emails, Orbit searches your Gmail for mail from event platforms only — Luma, Partiful, Eventbrite, Meetup and Posh — and opens a message only when Google’s signature check confirms it came from one of them. It keeps the event link, the subject line, the sender’s domain and the date; it stores no message bodies, reads no other mail, and never sends this mail to an AI provider. Turning it off stops the scanning and removes what it recorded about where each event was found.
The scan. When you connect Gmail on the Recruiters page and press Scan, Orbit uses Gmail search to find messages that look like recruiting — terms such as “recruiter”, “talent acquisition” and “open role”, excluding newsletters and mailing lists. For each likely recruiter, up to 400 a scan, it sends the subject and text of up to five of their most recent messages, with their name and address, to the AI provider you chose, on your key. The model decides whether the sender is a recruiter and writes a short summary of the conversation.
Outlook. If you connect Outlook instead, or as well, the scan works the same way on Outlook mail: it needs the read-only mail permission, which Orbit asks for only when you press Allow mail access on the Recruiters page. It searches your mailbox for the same terms, skips Junk Email and Deleted Items, and sends the same text to the same AI provider on your key. What is kept is the same too, apart from the thread id, which Outlook does not provide. Message bodies are not stored.
What is kept. For each recruiter found: their name, firm and email address; the companies and roles discussed; how many emails you exchanged and when; the latest thread id, so a reply can continue it; and the summary, which only you can see. Message bodies are not stored. The scan’s work list — the name, address and Gmail message ids of every sender it considered — stays with the scan in your import history until you delete it.
The shared directory. A recruiter’s record has a shared core — name, firm, specialty, and work email, phone and LinkedIn when known — so two people who work with the same recruiter point at one record. Your notes, summaries and email threads stay yours. Sharing is off by default. If you turn it on in Recruiters, the recruiters you add (except any you exclude) join a pool: other people who also share can see those recruiters’ shared core and an average rating that includes yours, and you see theirs. Contact details on a shared record are shown to someone else only when that recruiter is in the pool and they share too. Turning sharing off takes your recruiters out of the pool.
Orbit relies on the processors and integrations below. “Required” ones handle every account; “Automatic” ones run without a setting (photo lookups for contacts); “Always” runs whenever you use a voice feature, on Orbit’s own key rather than one you supply; “Optional” ones stay dormant until you use the feature.
Clerk
RequiredSign-in, sessions and account lifecycle. Holds your sign-in identity and records when you accepted these terms.
Vercel
RequiredHosting, and file storage for contact photos, capture photos, feedback screenshots and files you attach to email. Also runs Web Analytics and Speed Insights, which receive page addresses with ids and tokens removed.
Neon
RequiredThe Postgres database that holds your Orbit data.
Sentry
RequiredError reports: the error, where in the code it happened, the page and browser. Configured not to attach IP addresses or cookies, and with session replay off.
Slack
RequiredOperational alerts to the operator: job status, route names and error messages. An error message can occasionally include a value it was processing.
Better Stack
RequiredUptime heartbeat. Receives a ping, no personal data.
unavatar.io
AutomaticLooks up a public profile photo for contacts with a LinkedIn URL. Receives the LinkedIn username only.
Microlink
AutomaticWhen unavatar.io has no photo, fetches the public preview image of the contact's LinkedIn profile URL.
Gravatar
AutomaticChecks for a public avatar for a contact's email. Receives a one-way hash of the address, not the address.
Deepgram
AlwaysSpeech-to-text for voice notes, meetings and the chat microphone. Receives your audio and a list of your recent contact names so it spells them correctly. Every request sets Deepgram's zero-retention flag, which Deepgram documents as not storing your audio, text, transcripts or synthesized audio after the response is returned. Each request also carries a label so Orbit can check its own bill: a recording's own id for a meeting, and for everything else a random value Orbit generated for your account — not your name, your email or your account id. Labels sit in Deepgram's usage records, which the zero-retention flag does not cover; deleting your data in Settings replaces yours.
Stripe
OptionalOrbit Pro, Orbit Max and credit pack payments. Card details go to Stripe directly; Orbit stores a customer reference.
Google Gemini, OpenAI, Anthropic
OptionalAI features: notes, chat, drafts, search indexing, transcription and reading pages you scan. On the provider you choose in Settings: on your own key, or — for included AI on Orbit Pro and Orbit Max — on Orbit's account with that provider.
TypeSafe
OptionalJev, a decision model, for yes-or-no and ranking steps: spotting recruiters during a mail scan you start, choosing which contacts a chat answer draws on, telling two contact records apart before they are merged, reading captured notes, judging which calendar events were meetings with people, and deciding whether a note or message has anything in it worth sending to your chat model. Only if you add your own TypeSafe key in Settings.
Gmail, Contacts and Calendar, one permission per feature you turn on. See Google user data.
Microsoft
OptionalOutlook, one permission per feature you turn on: your contacts to import, your calendar to log meetings with people you know, your mail for the recruiter scan you start, and sending the email you write from your own address. See What Orbit collects and The recruiter scan.
Eventbrite
OptionalGuest lists of events you host, through Eventbrite sign-in.
Luma
OptionalGuest lists of events you host (with your Luma API key), and your personal Luma calendar link if you paste it.
Partiful
OptionalYour personal Partiful calendar link, if you paste it, to list events you are going to.
Apollo
OptionalPeople search and contact enrichment, with your Apollo key, or Orbit's on Pro, Max and Lifetime (up to your plan's monthly enrichments).
Resend
OptionalEmail Orbit sends on its own behalf: the waitlist confirmation and outreach campaigns you send from Orbit. Email you write to a person goes from your own Gmail or Outlook instead.
Twilio
OptionalSMS outreach you send, through the Twilio account you connect.
We do not sell your personal information. Using AI, enrichment, sync or outreach shares the relevant content with those providers, where it is governed by their own terms and privacy policies.
Assistants you connect yourself. If you connect Orbit to Claude, ChatGPT or another assistant, whatever it reads from Orbit goes to that assistant’s provider under their privacy policy, not ours — the same as if you had copied the text into their chat window. Orbit sends nothing on its own: a connected assistant can draft a message, but it waits for you to read and approve it before anything leaves. You can disconnect an assistant from its own settings, and revoke any API key from Orbit’s.
When you use an AI feature, the content it needs — notes, contact context, chat prompts, photos of pages you scan, recruiter emails when you run the scan — is sent to the provider you chose in Settings: Google Gemini, OpenAI or Anthropic. On the Free Plan and Orbit Lifetime, every call runs on an API key you supply, so the request lands on your own account with that provider and is governed by the retention settings you have agreed with them. On Orbit Pro and Orbit Max, AI is included: calls run on Orbit’s own accounts with those providers, under Orbit’s agreements with them, which do not allow your content to be used to train their models. Providers may keep requests for a limited period for abuse monitoring under those agreements. If you choose your own key on Pro or Max, those calls run on your account instead.
Voice notes, the chat microphone and meetings are transcribed by Deepgram instead, on Orbit’s own key on every plan — see Deepgram under Who else touches your data. If Deepgram is unavailable, transcription falls back to the AI provider and key above.
If you also add a TypeSafe key, the yes-or-no and ranking steps run on Jev, TypeSafe’s decision model, on your own TypeSafe account. Each one sees only what that step already works from: the emails described above, for deciding which senders in a recruiter scan are recruiters; your question and a short card per contact (name, title, company, school, tags and summary), for ranking which contacts a chat answer draws on, and those same cards for deciding whether two records are one person; a calendar event’s title, description and the domains — not the addresses — of its organiser and guests; and a note you captured, for matching the tags it proposes against the ones you already have and reading who was actually there. Jev is also asked, in front of the slower steps, whether there is anything in a note or a message thread worth sending to your chat model at all; when the answer is a confident no, that call is not made. Jev only returns yes-or-no answers and scores; it writes nothing.
Some AI work runs in the background. Search indexing runs when contacts change, so search understands meaning. Importing LinkedIn messages writes a short summary for up to 40 of the people you talked with most. Deriving timeline events from imported LinkedIn conversations happens automatically, on your own AI key: a thread with a single message gets a rule-based note and no AI call, and the cap of 300 conversations a day only counts the conversations that reach the model. Without an AI key connected, Orbit falls back to simple keyword matching instead. Settings → Integrations → AI provider shows every call from the last 30 days and its estimated cost.
Don’t store anything in Orbit you would be unwilling to send to an AI provider. AI output can be wrong or invented — review anything before you act on it or send it to a real person.
The Free Plan needs no payment details. Orbit Pro, Orbit Max and credit packs are sold through Stripe. Orbit Lifetime is no longer sold.
Orbit never sees your card. Orbit stores a Stripe customer reference, your plan and subscription status, a record of each charge, refund and dispute, and of the credits your plan and packs granted and used, for its accounts. When you delete your account, that accounting record is kept with your account id removed. Pricing is on the pricing page.
Orbit uses Clerk session cookies to keep you signed in. On your very first visit it also sets one first-party cookie, orbit_attr, recording where you arrived from — the referring site and any campaign tags in the link — so we can tell which channels bring people here. It holds no personal information, is never shared, and expires after 90 days. The app also stores preferences on your device in localStorage — theme flash helpers, saved graph layout positions, and per-device notification opt-in. Delivered notification history and account preferences live with your account instead.
Orbit counts its own traffic, and does it without cookies. Each page view records which page was opened, when, and for how long; whether it was on a desktop, phone, or tablet; the site that linked there and any campaign tags; and an approximate location — city, region, and country — looked up from the IP address. The IP address itself is not kept: Orbit's analytics reduces it, together with your browser type, to a one-way hash mixed with a value that changes every day, and stores only the hash. That hash cannot connect one day's visit to the next, and it cannot be turned back into an address from the data alone. To group the pages of a single visit, your browser holds a random session id in sessionStorage; it is discarded when you close the tab, and replaced after 30 minutes without a page view.
For a signed-out visitor, that is all it is: a count of how many people read which pages on a given day, with no way to tell who they were. While you are signed in, your page views are also recorded against your account — which pages you open, when, and for how long. Only Orbit's operator can see them, in the internal console described under operator access. They are used to understand which features get used and where people get stuck, and they are never sold, shared, or used for advertising.
Orbit also runs two of its host's tools: Vercel Web Analytics, which counts page views and visitors in aggregate, and Vercel Speed Insights, which measures how quickly pages load. Along with each page, Vercel receives the site that linked to it, the browser and device type, and an approximate location. Neither tool uses cookies; Vercel tells visitors apart with a hash of the request that it discards after 24 hours. Before anything is sent to Vercel, ids and one-time tokens in the page address are replaced with placeholders, every query parameter except campaign tags is removed, and views of the operator console are not sent at all. There are no advertising pixels and no cross-site tracking.
In Settings, under Data and privacy, on every plan including Free:
Deleting your account from Clerk’s own account page does the same deletion through our account webhook. Settings → Integrations → AI provider shows your AI usage, and you can disconnect any connected account from the Integrations dialog.
Your Orbit data is kept while your account is active, until you delete it with the controls above. Downgrading never deletes anything: contacts added while you were subscribed stay visible and exportable on the Free Plan, and unused pack credits are kept while you’re on a plan that can’t use them, and come back if you resubscribe.
Capture photos stay with the capture they belong to until you delete it; photos from a capture you never save are deleted after 24 hours. Files attached to an email are deleted 7 days after it is sent or canceled, and files you uploaded but never sent after 2 days. Audio is never kept. Page views are deleted after 180 days; deleting your data or your account unlinks the ones made while you were signed in, keeping only the anonymous count.
When you delete your account, every table holding your data is cleared, including your settings, keys and tokens. What remains: Stripe’s own records of your payments, held by Stripe; Orbit’s accounting record of charges, refunds and credit packs, with your account id removed; the operator’s audit log of actions taken on your account, which refers to an account id that no longer exists; and a few operational counters keyed by that same id. Encrypted database backups are kept for 90 days, so deleted data leaves the last backup within 90 days.
Traffic runs over HTTPS, every database query is scoped to your account, and API keys and account tokens are encrypted at rest (AES-256-GCM). Sign-in is handled by Clerk, and card data never touches Orbit’s servers.
No system is perfectly secure, and Orbit is an early-stage product built by one person. Use a strong, unique password, and treat the API keys you paste into Settings with the same care you would anywhere else.
Running Orbit means occasionally looking at how it is doing, and at one account when something goes wrong for it. There is an internal operator console for that. This is what it can see and do.
The operator can comp or revoke a plan, suspend or delete an account, retry or cancel an import, reset onboarding, disconnect an integration, turn a calendar feed on or off, and create a one-time link that signs in as your account (for support, and for the demo account). Each of these requires a written reason, recorded in an audit log. Opening your account is recorded, and so is every individual contact record opened, by its id.
The operator looks only to answer a support request from you, to investigate abuse, a security problem or a failure affecting your account, or where the law requires it.
Orbit’s hosting, database, payment and AI providers operate globally, so your data may be processed outside the country you live in — most often the United States. Where you supply your own API keys, the processing location follows what you configured with that vendor.
Orbit is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided information to Orbit, get in touch and it will be removed.
This policy will change as the product does. The Last updated date at the top is revised whenever it happens, and material changes are called out in the app. Continuing to use Orbit after a change means you accept the updated policy.
Questions about this policy, or about what Orbit holds on you, can go to the operator through the contact page. For routine export or deletion, the Settings controls are faster than an email.
Export your data, delete some of it, or delete your account from the Data and privacy panel in Settings — no request required.