Privacy
Orbit holds the working memory of your professional network — who you met, what you said, and who you still owe a reply. This page is the plain description of how that information is handled.
The short version
Your network isn't a product
Orbit doesn't sell personal information or run ad pixels, and its traffic analytics set no cookies.
AI runs on your key
AI features are opt-in and you choose the provider. Every call, on every plan, bills to a key you supply. Settings shows what the last 30 days cost.
Export on demand
One control in Settings produces a JSON download of your core Orbit data, on every plan including Free.
Deletion is real deletion
Delete some or all of your data from Settings, or delete your account — which erases your data, keys and sign-in and cancels any subscription.
Orbit is a personal networking tracker: it captures contacts, keeps a history of your relationships, imports data you already have, and uses AI to organise follow-ups. This policy covers the Orbit web app, its browser extension and the services run alongside them, and describes how the product behaves today rather than how it might later.
Orbit is built and run by one person, Jason Pereira. Where this policy says we, that is who it means.
Almost everything in Orbit is there because you put it there. Depending on the features you use:
Worth knowing
Contact records are usually about other people. When you add or import someone, you decide what Orbit stores about them, and you remain responsible for having a lawful basis to keep it. Recording a meeting captures everyone on the call, and many places require their consent first.
Orbit uses the information above to:
Orbit does not use your content to train AI models, its own or anyone else’s, and does not build advertising profiles from it.
Orbit can connect to a Google account you choose. Each feature asks Google only for the permission it needs, at the moment you turn it on, and Google’s own screen shows exactly what is being granted. You can allow one feature and decline another.
| Permission | What Orbit does with it | Asked for when |
|---|---|---|
| Sign-in identity (openid) | Confirms which Google account you connected. | Every Google connection |
| Your email address (userinfo.email) | Shown on the connection so you can tell which account is connected, and the address mail is sent from when you send from Gmail. | Every Google connection |
| See your contacts (contacts.readonly) | Lists your Google Contacts so you can pick who to import. Only the people you select are saved: name, company, title, email, phone and photo. | Connect Google on Imports → Google Contacts |
| Read your email (gmail.readonly) | Recruiter scan: finds recruiting conversations and summarizes each with your own AI key. Confirmation emails: reads mail from Luma, Partiful, Eventbrite, Meetup and Posh to find events you registered for. Message bodies are never stored. | Connect Gmail on Recruiters, or turn on Confirmation emails on Events |
| Send email as you (gmail.send) | Sends the recruiter messages you write and press Send on, from your own address, so replies reach your inbox. Orbit never sends a message you did not send. | Allow Gmail to send, in the recruiter composer |
| See your calendar events (calendar.readonly) | Reads recent and upcoming events on your primary calendar and adds meetings with people in your network to their timelines. | Connect Google Calendar on Events |
Orbit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice: Orbit uses Google data only to provide the features in the table, shown to you inside Orbit. It does not sell it, does not use it for advertising, and does not use it to develop or train AI models. Where a feature uses AI (the recruiter scan), the text involved goes to the AI provider you chose, on your own key, only to produce the result you asked for. A person at Orbit reads Google data only with your permission for a support request you raise, to investigate abuse or a security problem, or where the law requires it.
Disconnecting Google in Orbit deletes the tokens Orbit holds. To also revoke the grant on Google’s side, remove Orbit from your Google Account’s third-party access page.
Confirmation emails
If you turn on event discovery from confirmation emails, Orbit searches your Gmail for mail from event platforms only — Luma, Partiful, Eventbrite, Meetup and Posh — and opens a message only when Google’s signature check confirms it came from one of them. It keeps the event link, the subject line, the sender’s domain and the date; it stores no message bodies, reads no other mail, and never sends this mail to an AI provider. Turning it off stops the scanning and removes what it recorded about where each event was found.
The scan.When you connect Gmail on the Recruiters page and press Scan, Orbit uses Gmail search to find messages that look like recruiting — terms such as “recruiter”, “talent acquisition” and “open role”, excluding newsletters and mailing lists. For each likely recruiter, up to 400 a scan, it sends the subject and text of up to five of their most recent messages, with their name and address, to the AI provider you chose, on your key. The model decides whether the sender is a recruiter and writes a short summary of the conversation.
Outlook. If you connect Outlook instead, or as well, the scan works the same way on Outlook mail: it needs the read-only mail permission, which Orbit asks for only when you press Allow mail access on the Recruiters page. It searches your mailbox for the same terms, skips Junk Email and Deleted Items, and sends the same text to the same AI provider on your key. What is kept is the same too, apart from the thread id, which Outlook does not provide. Message bodies are not stored.
What is kept.For each recruiter found: their name, firm and email address; the companies and roles discussed; how many emails you exchanged and when; the latest thread id, so a reply can continue it; and the summary, which only you can see. Message bodies are not stored. The scan’s work list — the name, address and Gmail message ids of every sender it considered — stays with the scan in your import history until you delete it.
The shared directory.A recruiter’s record has a shared core — name, firm, specialty, and work email, phone and LinkedIn when known — so two people who work with the same recruiter point at one record. Your notes, summaries and email threads stay yours. Sharing is off by default. If you turn it on in Recruiters, the recruiters you add (except any you exclude) join a pool: other people who also share can see those recruiters’ shared core and an average rating that includes yours, and you see theirs. Contact details on a shared record are shown to someone else only when that recruiter is in the pool and they share too. Turning sharing off takes your recruiters out of the pool.
Orbit relies on the processors and integrations below. “Required” ones handle every account; “Automatic” ones run without a setting (photo lookups for contacts); “Optional” ones stay dormant until you use the feature.
Clerk
RequiredSign-in, sessions and account lifecycle. Holds your sign-in identity and records when you accepted these terms.
Vercel
RequiredHosting, and file storage for contact photos, capture photos and feedback screenshots. Also runs Web Analytics and Speed Insights, which receive page addresses with ids and tokens removed.
Neon
RequiredThe Postgres database that holds your Orbit data.
Sentry
RequiredError reports: the error, where in the code it happened, the page and browser. Configured not to attach IP addresses or cookies, and with session replay off.
Slack
RequiredOperational alerts to the operator: job status, route names and error messages. An error message can occasionally include a value it was processing.
Better Stack
RequiredUptime heartbeat. Receives a ping, no personal data.
unavatar.io
AutomaticLooks up a public profile photo for contacts with a LinkedIn URL. Receives the LinkedIn username only.
Microlink
AutomaticWhen unavatar.io has no photo, fetches the public preview image of the contact's LinkedIn profile URL.
Gravatar
AutomaticChecks for a public avatar for a contact's email. Receives a one-way hash of the address, not the address.
Stripe
OptionalOrbit Pro and Orbit Lifetime payments. Card details go to Stripe directly; Orbit stores a customer reference.
Google Gemini, OpenAI, Anthropic
OptionalAI features: notes, chat, drafts, search indexing, transcription and reading pages you scan. On the provider and key you choose in Settings.
Gmail, Contacts and Calendar, one permission per feature you turn on. See Google user data.
Microsoft
OptionalOutlook, read-only, one permission per feature you turn on: your contacts to import, your calendar to log meetings with people you know, and your mail only for the recruiter scan you start. See The recruiter scan.
Eventbrite
OptionalGuest lists of events you host, through Eventbrite sign-in.
Luma
OptionalGuest lists of events you host (with your Luma API key), and your personal Luma calendar link if you paste it.
Partiful
OptionalYour personal Partiful calendar link, if you paste it, to list events you are going to.
Apollo
OptionalPeople search and contact enrichment, with your Apollo key, or Orbit's on Pro.
Resend
OptionalEmail Orbit sends: the waitlist confirmation, messages you send through the contact page, and outreach you send from Orbit.
Twilio
OptionalSMS outreach you send, through the Twilio account you connect.
We do not sell your personal information. Using AI, enrichment, sync or outreach shares the relevant content with those providers, where it is governed by their own terms and privacy policies.
Assistants you connect yourself.If you connect Orbit to Claude, ChatGPT or another assistant, whatever it reads from Orbit goes to that assistant’s provider under their privacy policy, not ours — the same as if you had copied the text into their chat window. Orbit sends nothing on its own: a connected assistant can draft a message, but it waits for you to read and approve it before anything leaves. You can disconnect an assistant from its own settings, and revoke any API key from Orbit’s.
When you use an AI feature, the content it needs — notes, contact context, chat prompts, meeting audio, photos of pages you scan, recruiter emails when you run the scan — is sent to the provider you chose in Settings: Google Gemini, OpenAI or Anthropic. On every plan, every call runs on an API key you supply, so the request lands on your own account with that provider and is governed by the retention settings you have agreed with them. Orbit never runs AI on its own provider accounts.
Some AI work runs in the background. Search indexing runs when contacts change, so search understands meaning. Importing LinkedIn messages writes a short summary for up to 40 of the people you talked with most. Deriving timeline events from imported LinkedIn conversations is off until you turn it on, shows an estimated cost first, skips threads with a single message, and processes at most 300 conversations a day. Settings → Integrations → AI provider shows every call from the last 30 days and its estimated cost.
Don’t store anything in Orbit you would be unwilling to send to an AI provider. AI output can be wrong or invented — review anything before you act on it or send it to a real person.
The Free Plan needs no payment details. Orbit Pro and Orbit Lifetime are sold through Stripe.
Orbit never sees your card. Orbit stores a Stripe customer reference, your plan and subscription status, and a record of each charge, refund and dispute for its accounts. When you delete your account, that accounting record is kept with your account id removed. Pricing is on the pricing page.
Orbit uses Clerk session cookies to keep you signed in. On your very first visit it also sets one first-party cookie, orbit_attr, recording where you arrived from — the referring site and any campaign tags in the link — so we can tell which channels bring people here. It holds no personal information, is never shared, and expires after 90 days. The app also stores preferences on your device in localStorage — theme flash helpers, saved graph layout positions, and per-device notification opt-in. Delivered notification history and account preferences live with your account instead.
Orbit counts its own traffic, and does it without cookies. Each page view records which page was opened, when, and for how long; whether it was on a desktop, phone, or tablet; the site that linked there and any campaign tags; and an approximate location — city, region, and country — looked up from the IP address. The IP address itself is not kept: Orbit's analytics reduces it, together with your browser type, to a one-way hash mixed with a value that changes every day, and stores only the hash. That hash cannot connect one day's visit to the next, and it cannot be turned back into an address from the data alone. To group the pages of a single visit, your browser holds a random session id in sessionStorage; it is discarded when you close the tab, and replaced after 30 minutes without a page view.
For a signed-out visitor, that is all it is: a count of how many people read which pages on a given day, with no way to tell who they were. While you are signed in, your page views are also recorded against your account — which pages you open, when, and for how long. Only Orbit's operator can see them, in the internal console described under operator access. They are used to understand which features get used and where people get stuck, and they are never sold, shared, or used for advertising.
Orbit also runs two of its host's tools: Vercel Web Analytics, which counts page views and visitors in aggregate, and Vercel Speed Insights, which measures how quickly pages load. Along with each page, Vercel receives the site that linked to it, the browser and device type, and an approximate location. Neither tool uses cookies; Vercel tells visitors apart with a hash of the request that it discards after 24 hours. Before anything is sent to Vercel, ids and one-time tokens in the page address are replaced with placeholders, every query parameter except campaign tags is removed, and views of the operator console are not sent at all. There are no advertising pixels and no cross-site tracking.
In Settings, under Data and privacy, on every plan including Free:
Deleting your account from Clerk’s own account page does the same deletion through our account webhook. Settings → Integrations → AI provider shows your AI usage, and you can disconnect any connected account from the Integrations dialog.
Your Orbit data is kept while your account is active, until you delete it with the controls above. Downgrading never deletes anything: contacts added while you were subscribed stay visible and exportable on the Free Plan.
Capture photos stay with the capture they belong to until you delete it; photos from a capture you never save are deleted after 24 hours. Audio is never kept. Page views are deleted after 180 days; deleting your data or your account unlinks the ones made while you were signed in, keeping only the anonymous count.
When you delete your account, every table holding your data is cleared, including your settings, keys and tokens. What remains: Stripe’s own records of your payments, held by Stripe; Orbit’s accounting record of charges and refunds, with your account id removed; the operator’s audit log of actions taken on your account, which refers to an account id that no longer exists; and a few operational counters keyed by that same id. Encrypted database backups are kept for 90 days, so deleted data leaves the last backup within 90 days.
Traffic runs over HTTPS, every database query is scoped to your account, and API keys and account tokens are encrypted at rest (AES-256-GCM). Sign-in is handled by Clerk, and card data never touches Orbit’s servers.
No system is perfectly secure, and Orbit is an early-stage product built by one person. Use a strong, unique password, and treat the API keys you paste into Settings with the same care you would anywhere else.
Running Orbit means occasionally looking at how it is doing, and at one account when something goes wrong for it. There is an internal operator console for that. This is what it can see and do.
The operator can comp or revoke a plan, suspend or delete an account, retry or cancel an import, reset onboarding, disconnect an integration, turn a calendar feed on or off, and create a one-time link that signs in as your account (for support, and for the demo account). Each of these requires a written reason, recorded in an audit log. Opening your account is recorded, and so is every individual contact record opened, by its id.
The operator looks only to answer a support request from you, to investigate abuse, a security problem or a failure affecting your account, or where the law requires it.
Orbit’s hosting, database, payment and AI providers operate globally, so your data may be processed outside the country you live in — most often the United States. Where you supply your own API keys, the processing location follows what you configured with that vendor.
Orbit is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided information to Orbit, get in touch and it will be removed.
This policy will change as the product does. The Last updated date at the top is revised whenever it happens, and material changes are called out in the app. Continuing to use Orbit after a change means you accept the updated policy.
Questions about this policy, or about what Orbit holds on you, can go to the operator through the contact page. For routine export or deletion, the Settings controls are faster than an email.
Export your data, delete some of it, or delete your account from the Data and privacy panel in Settings — no request required.