OrbitOrbit
Sign inGet Started
PrivacyTermsContact
OrbitOrbit
PricingConnectInterest listPrivacyContact
By Jason Pereira

Privacy

What Orbit knows, and what it does with it.

Orbit holds the working memory of your professional network — who you met, what you said, and who you still owe a reply. This page is the plain description of how that information is handled.

Last updated
September 19, 2026
Applies to
The Orbit web app and browser extension
Read time
About 12 minutes

The short version

Your network isn't a product

Orbit doesn't sell personal information or run ad pixels, and its traffic analytics set no cookies.

AI runs on your key

AI features are opt-in and you choose the provider. Every call, on every plan, bills to a key you supply. Settings shows what the last 30 days cost.

Export on demand

One control in Settings produces a JSON download of your core Orbit data, on every plan including Free.

Deletion is real deletion

Delete some or all of your data from Settings, or delete your account — which erases your data, keys and sign-in and cancels any subscription.

On this page
  • Who this covers
  • What we collect
  • How it's used
  • Google user data
  • Recruiter scan & directory
  • Who else sees it
  • AI processing
  • Payments
  • Cookies, storage & analytics
  • Your controls
  • Retention
  • Security
  • Operator access
  • Where it's processed
  • Children
  • Changes
  • Questions

On this page

  • Who this covers
  • What we collect
  • How it's used
  • Google user data
  • Recruiter scan & directory
  • Who else sees it
  • AI processing
  • Payments
  • Cookies, storage & analytics
  • Your controls
  • Retention
  • Security
  • Operator access
  • Where it's processed
  • Children
  • Changes
  • Questions
01

Who this covers

Orbit is a personal networking tracker: it captures contacts, keeps a history of your relationships, imports data you already have, and uses AI to organise follow-ups. This policy covers the Orbit web app, its browser extension and the services run alongside them, and describes how the product behaves today rather than how it might later.

Orbit is built and run by one person, Jason Pereira. Where this policy says we, that is who it means.

02

What Orbit collects

Almost everything in Orbit is there because you put it there. Depending on the features you use:

  • Account information — from our sign-in provider, Clerk: your user id, name, email address and profile image; your plan; and when you accepted the Terms and which version.
  • Network and CRM content — contacts and their details (name, company, title, location, school, email, phone, LinkedIn URL, website, notes, tags, closeness, follow-up dates), interactions, goals, reminders, chat threads, events, outreach campaigns and messages, recruiter records, and import history. When you capture notes, Orbit keeps the text and any photos you attach so you can look back at the original. Photos are resized and stripped of their metadata (including location) before they are stored; photos from a capture you never save are deleted after 24 hours.
  • Voice and meetings — audio you record is sent to be transcribed and is not kept. The transcript is: a voice note becomes the text of your note, and a meeting keeps its transcript until you delete the meeting.
  • Connected accounts — if you connect Google, Orbit reads only what the feature you turned on needs (see Google user data). If you connect Microsoft, Orbit asks for one read-only permission per feature you turn on: your Outlook contacts, so you can pick who to import; your calendar, to add meetings with people you know to their timelines; and your mail, only for the recruiter scan you start. Each connection also asks for your Microsoft sign-in identity and email address, to show which account is connected. Orbit cannot send mail or change anything in your Microsoft account. Disconnecting deletes the tokens Orbit holds; to also revoke the grant on Microsoft’s side, remove Orbit from your Microsoft account’s app permissions.
  • The browser extension— when you open its panel on a LinkedIn profile, it sends that page’s text to Orbit, which fills in a contact using your AI key. A contact is created only when you save it.
  • Secrets you provide — API keys for AI, enrichment, email, SMS and transcription providers, and the tokens for accounts you connect. Encrypted at rest.
  • Derived data — AI summaries, suggestions, embeddings (search indexes) and timeline events computed from what you store.
  • Usage records — for each AI call: the feature, provider, model, token counts, an estimated cost, duration and whether it succeeded. Never the prompt or the reply. This powers your cost view; you can see your last 30 days in Settings under Integrations → AI provider.
  • Page views — which pages are opened, when and for how long; device type; the referring site and campaign tags; and approximate location looked up from the IP address. Linked to your account while you are signed in. See cookies, storage, and analytics.

Worth knowing

Contact records are usually about other people. When you add or import someone, you decide what Orbit stores about them, and you remain responsible for having a lawful basis to keep it. Recording a meeting captures everyone on the call, and many places require their consent first.

03

How that data is used

Orbit uses the information above to:

  • Authenticate you and keep every query scoped to your account
  • Run the CRM itself — search, reminders, the relationship graph and the dashboard
  • Power the AI features you use, on your key
  • Run the imports, syncs, enrichment and outbound email or SMS you set up
  • Look up public profile photos for your contacts
  • Apply plan limits and process payments if you upgrade
  • Understand which pages are read, where visitors arrive from, and which features get used
  • Honour export, deletion and account requests

Orbit does not use your content to train AI models, its own or anyone else’s, and does not build advertising profiles from it.

04

Google user data

Orbit can connect to a Google account you choose. Each feature asks Google only for the permission it needs, at the moment you turn it on, and Google’s own screen shows exactly what is being granted. You can allow one feature and decline another.

PermissionWhat Orbit does with itAsked for when
Sign-in identity (openid)Confirms which Google account you connected.Every Google connection
Your email address (userinfo.email)Shown on the connection so you can tell which account is connected, and the address mail is sent from when you send from Gmail.Every Google connection
See your contacts (contacts.readonly)Lists your Google Contacts so you can pick who to import. Only the people you select are saved: name, company, title, email, phone and photo.Connect Google on Imports → Google Contacts
Read your email (gmail.readonly)Recruiter scan: finds recruiting conversations and summarizes each with your own AI key. Confirmation emails: reads mail from Luma, Partiful, Eventbrite, Meetup and Posh to find events you registered for. Message bodies are never stored.Connect Gmail on Recruiters, or turn on Confirmation emails on Events
Send email as you (gmail.send)Sends the recruiter messages you write and press Send on, from your own address, so replies reach your inbox. Orbit never sends a message you did not send.Allow Gmail to send, in the recruiter composer
See your calendar events (calendar.readonly)Reads recent and upcoming events on your primary calendar and adds meetings with people in your network to their timelines.Connect Google Calendar on Events

Orbit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice: Orbit uses Google data only to provide the features in the table, shown to you inside Orbit. It does not sell it, does not use it for advertising, and does not use it to develop or train AI models. Where a feature uses AI (the recruiter scan), the text involved goes to the AI provider you chose, on your own key, only to produce the result you asked for. A person at Orbit reads Google data only with your permission for a support request you raise, to investigate abuse or a security problem, or where the law requires it.

Disconnecting Google in Orbit deletes the tokens Orbit holds. To also revoke the grant on Google’s side, remove Orbit from your Google Account’s third-party access page.

Confirmation emails

If you turn on event discovery from confirmation emails, Orbit searches your Gmail for mail from event platforms only — Luma, Partiful, Eventbrite, Meetup and Posh — and opens a message only when Google’s signature check confirms it came from one of them. It keeps the event link, the subject line, the sender’s domain and the date; it stores no message bodies, reads no other mail, and never sends this mail to an AI provider. Turning it off stops the scanning and removes what it recorded about where each event was found.

05

The recruiter scan and the shared directory

The scan.When you connect Gmail on the Recruiters page and press Scan, Orbit uses Gmail search to find messages that look like recruiting — terms such as “recruiter”, “talent acquisition” and “open role”, excluding newsletters and mailing lists. For each likely recruiter, up to 400 a scan, it sends the subject and text of up to five of their most recent messages, with their name and address, to the AI provider you chose, on your key. The model decides whether the sender is a recruiter and writes a short summary of the conversation.

Outlook. If you connect Outlook instead, or as well, the scan works the same way on Outlook mail: it needs the read-only mail permission, which Orbit asks for only when you press Allow mail access on the Recruiters page. It searches your mailbox for the same terms, skips Junk Email and Deleted Items, and sends the same text to the same AI provider on your key. What is kept is the same too, apart from the thread id, which Outlook does not provide. Message bodies are not stored.

What is kept.For each recruiter found: their name, firm and email address; the companies and roles discussed; how many emails you exchanged and when; the latest thread id, so a reply can continue it; and the summary, which only you can see. Message bodies are not stored. The scan’s work list — the name, address and Gmail message ids of every sender it considered — stays with the scan in your import history until you delete it.

The shared directory.A recruiter’s record has a shared core — name, firm, specialty, and work email, phone and LinkedIn when known — so two people who work with the same recruiter point at one record. Your notes, summaries and email threads stay yours. Sharing is off by default. If you turn it on in Recruiters, the recruiters you add (except any you exclude) join a pool: other people who also share can see those recruiters’ shared core and an average rating that includes yours, and you see theirs. Contact details on a shared record are shown to someone else only when that recruiter is in the pool and they share too. Turning sharing off takes your recruiters out of the pool.

06

Who else touches your data

Orbit relies on the processors and integrations below. “Required” ones handle every account; “Automatic” ones run without a setting (photo lookups for contacts); “Optional” ones stay dormant until you use the feature.

Clerk

Required

Sign-in, sessions and account lifecycle. Holds your sign-in identity and records when you accepted these terms.

Vercel

Required

Hosting, and file storage for contact photos, capture photos and feedback screenshots. Also runs Web Analytics and Speed Insights, which receive page addresses with ids and tokens removed.

Neon

Required

The Postgres database that holds your Orbit data.

Sentry

Required

Error reports: the error, where in the code it happened, the page and browser. Configured not to attach IP addresses or cookies, and with session replay off.

Slack

Required

Operational alerts to the operator: job status, route names and error messages. An error message can occasionally include a value it was processing.

Better Stack

Required

Uptime heartbeat. Receives a ping, no personal data.

unavatar.io

Automatic

Looks up a public profile photo for contacts with a LinkedIn URL. Receives the LinkedIn username only.

Microlink

Automatic

When unavatar.io has no photo, fetches the public preview image of the contact's LinkedIn profile URL.

Gravatar

Automatic

Checks for a public avatar for a contact's email. Receives a one-way hash of the address, not the address.

Stripe

Optional

Orbit Pro and Orbit Lifetime payments. Card details go to Stripe directly; Orbit stores a customer reference.

Google Gemini, OpenAI, Anthropic

Optional

AI features: notes, chat, drafts, search indexing, transcription and reading pages you scan. On the provider and key you choose in Settings.

Google

Optional

Gmail, Contacts and Calendar, one permission per feature you turn on. See Google user data.

Microsoft

Optional

Outlook, read-only, one permission per feature you turn on: your contacts to import, your calendar to log meetings with people you know, and your mail only for the recruiter scan you start. See The recruiter scan.

Eventbrite

Optional

Guest lists of events you host, through Eventbrite sign-in.

Luma

Optional

Guest lists of events you host (with your Luma API key), and your personal Luma calendar link if you paste it.

Partiful

Optional

Your personal Partiful calendar link, if you paste it, to list events you are going to.

Apollo

Optional

People search and contact enrichment, with your Apollo key, or Orbit's on Pro.

Resend

Optional

Email Orbit sends: the waitlist confirmation, messages you send through the contact page, and outreach you send from Orbit.

Twilio

Optional

SMS outreach you send, through the Twilio account you connect.

We do not sell your personal information. Using AI, enrichment, sync or outreach shares the relevant content with those providers, where it is governed by their own terms and privacy policies.

Assistants you connect yourself.If you connect Orbit to Claude, ChatGPT or another assistant, whatever it reads from Orbit goes to that assistant’s provider under their privacy policy, not ours — the same as if you had copied the text into their chat window. Orbit sends nothing on its own: a connected assistant can draft a message, but it waits for you to read and approve it before anything leaves. You can disconnect an assistant from its own settings, and revoke any API key from Orbit’s.

07

AI processing

When you use an AI feature, the content it needs — notes, contact context, chat prompts, meeting audio, photos of pages you scan, recruiter emails when you run the scan — is sent to the provider you chose in Settings: Google Gemini, OpenAI or Anthropic. On every plan, every call runs on an API key you supply, so the request lands on your own account with that provider and is governed by the retention settings you have agreed with them. Orbit never runs AI on its own provider accounts.

Some AI work runs in the background. Search indexing runs when contacts change, so search understands meaning. Importing LinkedIn messages writes a short summary for up to 40 of the people you talked with most. Deriving timeline events from imported LinkedIn conversations is off until you turn it on, shows an estimated cost first, skips threads with a single message, and processes at most 300 conversations a day. Settings → Integrations → AI provider shows every call from the last 30 days and its estimated cost.

Don’t store anything in Orbit you would be unwilling to send to an AI provider. AI output can be wrong or invented — review anything before you act on it or send it to a real person.

08

Payments

The Free Plan needs no payment details. Orbit Pro and Orbit Lifetime are sold through Stripe.

Orbit never sees your card. Orbit stores a Stripe customer reference, your plan and subscription status, and a record of each charge, refund and dispute for its accounts. When you delete your account, that accounting record is kept with your account id removed. Pricing is on the pricing page.

09

Cookies, local storage, and analytics

Orbit uses Clerk session cookies to keep you signed in. On your very first visit it also sets one first-party cookie, orbit_attr, recording where you arrived from — the referring site and any campaign tags in the link — so we can tell which channels bring people here. It holds no personal information, is never shared, and expires after 90 days. The app also stores preferences on your device in localStorage — theme flash helpers, saved graph layout positions, and per-device notification opt-in. Delivered notification history and account preferences live with your account instead.

Orbit counts its own traffic, and does it without cookies. Each page view records which page was opened, when, and for how long; whether it was on a desktop, phone, or tablet; the site that linked there and any campaign tags; and an approximate location — city, region, and country — looked up from the IP address. The IP address itself is not kept: Orbit's analytics reduces it, together with your browser type, to a one-way hash mixed with a value that changes every day, and stores only the hash. That hash cannot connect one day's visit to the next, and it cannot be turned back into an address from the data alone. To group the pages of a single visit, your browser holds a random session id in sessionStorage; it is discarded when you close the tab, and replaced after 30 minutes without a page view.

For a signed-out visitor, that is all it is: a count of how many people read which pages on a given day, with no way to tell who they were. While you are signed in, your page views are also recorded against your account — which pages you open, when, and for how long. Only Orbit's operator can see them, in the internal console described under operator access. They are used to understand which features get used and where people get stuck, and they are never sold, shared, or used for advertising.

Orbit also runs two of its host's tools: Vercel Web Analytics, which counts page views and visitors in aggregate, and Vercel Speed Insights, which measures how quickly pages load. Along with each page, Vercel receives the site that linked to it, the browser and device type, and an approximate location. Neither tool uses cookies; Vercel tells visitors apart with a hash of the request that it discards after 24 hours. Before anything is sent to Vercel, ids and one-time tokens in the page address are replaced with placeholders, every query parameter except campaign tags is removed, and views of the operator console are not sent at all. There are no advertising pixels and no cross-site tracking.

10

Your controls

In Settings, under Data and privacy, on every plan including Free:

  • Export a JSON download of your contacts, interactions, reminders, tags, imports and AI suggestions. It does not yet include capture text and photos, meeting transcripts, chat history, events, companies, goals, outreach or recruiter records — ask through the contact page for a copy of those.
  • Delete data, choosing by category. Your account, plan and API keys stay.
  • Delete your account. This erases all of your Orbit data and settings, including saved API keys and connected accounts, cancels an active Orbit Pro subscription, and removes your sign-in. It cannot be undone.

Deleting your account from Clerk’s own account page does the same deletion through our account webhook. Settings → Integrations → AI provider shows your AI usage, and you can disconnect any connected account from the Integrations dialog.

11

How long data is kept

Your Orbit data is kept while your account is active, until you delete it with the controls above. Downgrading never deletes anything: contacts added while you were subscribed stay visible and exportable on the Free Plan.

Capture photos stay with the capture they belong to until you delete it; photos from a capture you never save are deleted after 24 hours. Audio is never kept. Page views are deleted after 180 days; deleting your data or your account unlinks the ones made while you were signed in, keeping only the anonymous count.

When you delete your account, every table holding your data is cleared, including your settings, keys and tokens. What remains: Stripe’s own records of your payments, held by Stripe; Orbit’s accounting record of charges and refunds, with your account id removed; the operator’s audit log of actions taken on your account, which refers to an account id that no longer exists; and a few operational counters keyed by that same id. Encrypted database backups are kept for 90 days, so deleted data leaves the last backup within 90 days.

12

Security

Traffic runs over HTTPS, every database query is scoped to your account, and API keys and account tokens are encrypted at rest (AES-256-GCM). Sign-in is handled by Clerk, and card data never touches Orbit’s servers.

No system is perfectly secure, and Orbit is an early-stage product built by one person. Use a strong, unique password, and treat the API keys you paste into Settings with the same care you would anywhere else.

13

Operator access

Running Orbit means occasionally looking at how it is doing, and at one account when something goes wrong for it. There is an internal operator console for that. This is what it can see and do.

  • For every account: name, email and profile picture; plan and billing status; sign-up and last-active times; which integrations are connected and whether each has a key saved (never the key); AI usage totals and estimated cost; recent imports and errors; a timeline of recent activity that names contacts and chat thread titles; and the pages you opened while signed in.
  • When the operator opens an account: its contact list — names, email addresses, companies and titles. Opening one contact shows that record in full: phone, location, notes, AI summary, key facts, and the notes on its recent interactions.
  • Never: API keys, account tokens, webhook secrets or the calendar feed link; chat messages; the original text of your captures; meeting transcripts; capture photos. These are blocked in the code that reads the database, so the console cannot display them even by mistake.
  • Feedback you send through the in-app feedback button, including any screenshot you attach, is read by the operator.

The operator can comp or revoke a plan, suspend or delete an account, retry or cancel an import, reset onboarding, disconnect an integration, turn a calendar feed on or off, and create a one-time link that signs in as your account (for support, and for the demo account). Each of these requires a written reason, recorded in an audit log. Opening your account is recorded, and so is every individual contact record opened, by its id.

The operator looks only to answer a support request from you, to investigate abuse, a security problem or a failure affecting your account, or where the law requires it.

14

Where data is processed

Orbit’s hosting, database, payment and AI providers operate globally, so your data may be processed outside the country you live in — most often the United States. Where you supply your own API keys, the processing location follows what you configured with that vendor.

15

Children

Orbit is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided information to Orbit, get in touch and it will be removed.

16

Changes to this policy

This policy will change as the product does. The Last updated date at the top is revised whenever it happens, and material changes are called out in the app. Continuing to use Orbit after a change means you accept the updated policy.

17

Questions

Questions about this policy, or about what Orbit holds on you, can go to the operator through the contact page. For routine export or deletion, the Settings controls are faster than an email.

Prefer to check for yourself?

Export your data, delete some of it, or delete your account from the Data and privacy panel in Settings — no request required.

Open SettingsRead the terms