Privacy Policy

Last updated 16 July 2026

Orbita is a place to keep things you save. That only works if you know what happens to them. This page explains what we collect, who else sees it, and what we cannot promise.

Orbita is operated by Eclipse Studio (“we”, “us”). It covers the Orbita mobile app, the web app at useorbita.app, and the Orbita browser extension.

What we collect

Your account

When you sign up we store your email address. If you sign in with Google or Apple we receive a token confirming your identity with that provider, along with your email. If you set a display name or profile photo, we store those too. Passwords are handled by our authentication provider and stored hashed. We never see your password in readable form.

Things you save

The core of the product. Depending on what you save, this includes links and their page titles, notes and text you write, photos and videos you upload, tasks and events you create, the names of your spaces, and tags.

What the browser extension reads

When you save a page with the extension, it sends the page’s address and title. If you right-click a selection, it sends the selected text. If you right-click an image, it sends that image’s address (not the image itself).

The extension also reads the visible text of the page you are saving, so the AI can tag and route it usefully. This is limited to the text a person can see, capped at roughly 16,000 characters, and only ever on the tab you actively chose to save. The extension does not read pages in the background, and it cannot read pages you have not saved.

You can switch page-text reading off in the extension’s options. It is on by default. Separately, the extension never reads page text on a built-in list of banking, healthcare, and password-manager sites.

Be aware of the limit of that protection: the built-in list and the options toggle stop the page’s text from being sent. If you actively save one of those pages, its address and title are still sent and still analysed. If you do not want a page recorded at all, do not save it.

Diagnostics

The mobile app reports crashes and errors so we can fix them. A report contains the technical detail of what went wrong: the error, where in the code it happened, the sequence of actions leading up to it, and your device and OS version.

It does not include a screenshot, a recording of your screen, or your IP address. We do not record sessions where nothing goes wrong. The web app and the extension send no diagnostics at all.

If you send us feedback from inside the app, we receive what you wrote.

How the AI works

Orbita uses Google’s Gemini to read what you save and work out what it is, what to call it, how to tag it, and which of your spaces it belongs in. This is the feature, so it is worth being precise about what leaves our systems.

We send Google:

  • the address of the link you saved, and up to 8,000 characters of the page’s visible text;
  • any text you selected, and the page’s title and description;
  • the names of your spaces, so it can pick the right one. Space names are written by you and can themselves be revealing;
  • photos and videos you save, when a feature needs to read them. Images are sent in full and the model is asked to transcribe all visible text, which is how saving a screenshot turns into a usable item;
  • for links where we have no page text, the address alone, and Google’s own fetcher then visits that address.

Google processes this content to return a result to us, under the Gemini API terms in force between Google and us. We do not sell this content, and we do not use it to train any model of our own.

Some analysis produces inferences rather than facts. Estimated nutrition figures for a recipe, for example, or a difficulty rating for a workout. These are guesses generated by a model. They are stored alongside the item. Do not rely on them for anything that matters to your health.

We visit the links you save

When you save a link, our server requests that page to pull its title, description, and preview image. Google’s fetcher may also request it. Two consequences worth understanding:

  • the site you saved sees a request from our infrastructure, identifying itself as OrbitaBot, at roughly the time you saved it;
  • if you save a page that only you can normally see, our fetch will not be signed in as you and will generally just fail, but the request still reaches that site.

How we use your information

  • To run the product: store what you save and show it back to you.
  • To sort, tag, and route saved items, as described above.
  • To sync across your devices and the web.
  • To let you share a space with someone you invite.
  • To manage subscriptions and payment status.
  • To fix crashes and diagnose problems.
  • To respond when you contact us.

We do not sell your personal information. We do not serve ads and we do not share your content with advertisers. We do not use your content for marketing.

Who else handles your data

We rely on other companies to run Orbita. Each one receives only what its job requires.

ProviderWhat it receives
SupabaseHosting, database, authentication, and file storage. Holds your account and everything you save.
Google (Gemini)Page text, space names, and photos or videos you save, for analysis. See above.
VercelServes the web app. Receives standard request data, including your IP address.
SentryCrash and error reports from the mobile app: the error, the code path, and your device type. US-based.
ApifyThe address of an Instagram or TikTok post you save, so its details can be read back. Receives no information about who you are.
SpotifyA search term built from a title you saved, to match it to an album or show. Receives no information about who you are.
RevenueCatYour Orbita account ID and your subscription status, to manage purchases.
Apple / GooglePayment is handled by the app store you bought through. We never receive your card details.

These providers are located in the United States and elsewhere, so using Orbita involves transferring your information internationally, including out of the UK and EEA.

Where your data lives

Your account and saved items are held in our database, protected by row-level access rules so that one account cannot read another’s items. Traffic is encrypted in transit.

Please read this before saving sensitive photos.Files you upload (photos, videos, profile pictures) are stored in buckets where the file itself is readable by anyone who has its exact address. Nobody can browse or search those files, and only you can list your own, but the address is not protected by your password. Anyone you send a file’s address to can open it without signing in, and it stays reachable. Treat uploaded media as unlisted rather than private. We are moving these to expiring, signed addresses; that work needs a mobile release, so it has not landed yet.

Spaces you share

If you invite someone to a space, they can see the items in it. That is the point of the feature, but it is worth stating plainly: sharing a space shares its contents with the person you invited, and you should invite only people you intend to show those items to.

How long we keep things

We keep what you save until you delete it or delete your account. We do not currently expire or auto-delete old items. If you saved it in 2026 and never touch it again, it stays. We also keep a running record of AI usage per account, for rate limiting and cost control.

Deleting your account

You can delete your account from Settings, on the web or in the mobile app. This removes your account, your items, your spaces, your tags, your settings, your profile photo, and every photo and video you uploaded. It is immediate and cannot be undone.

One honest limit: deletion does not reach our payments provider or our crash-reporting provider, both of which hold records keyed to your account ID. Email privacy@useorbita.app and we will pass those requests on.

Your rights

Depending on where you live, you may have the right to see the personal data we hold about you, correct it, delete it, object to how we use it, or receive a copy of it. To exercise any of these, email privacy@useorbita.app. We will not charge you or make the product worse because you asked.

If you are in the UK or EEA and you think we have handled your data badly, you can complain to your local data protection authority. We would rather you told us first so we can fix it.

Children

Orbita is not intended for children under 13, and we do not knowingly collect their personal information. If you believe a child has created an account, email privacy@useorbita.app and we will remove it.

Security

We take reasonable measures to protect your information, but no service is perfectly secure and we will not pretend otherwise. If we discover a breach affecting your data, we will tell you and the relevant regulator as required by law.

Changes

If we change this policy we will update the date at the top. If a change materially affects how we handle your information, we will tell you in the app or by email rather than quietly editing this page.

Contact

Questions, requests, or complaints: privacy@useorbita.app. A person reads that address.