Your data, explained
Privacy Policy
Orbit helps you organize attention across connected email and calendar accounts. This policy explains what Orbit collects, why it is used, and the choices available to you.
Effective date:
1. Information Orbit processes
When you sign in or connect a provider, Orbit processes the information needed to authenticate you and operate your dashboard. This can include your name, email address, profile image, provider account identifiers, and OAuth authorization data.
For connected accounts, Orbit may store read-only email and calendar data such as message sender, subject, preview, received time, message body excerpts, thread identifiers, calendar events, event times, and provider links. Orbit also stores local events, attention preferences, classifications, detected deadlines, action plans, reply suggestions, meeting-preparation cards, and feedback that you choose to provide.
Orbit uses cookies for sessions and for the short-lived state and PKCE values required to secure OAuth sign-in. Session tokens are stored as hashes in the database. Provider grants are encrypted at rest using a key derived from the server session secret.
2. How Orbit uses information
- Authenticate your Orbit account and maintain secure sessions.
- Synchronize connected mail and calendar accounts at your request.
- Rank messages using deterministic attention signals and, when enabled, AI classification.
- Generate on-demand plans, suggested replies, and meeting-preparation cards.
- Remember preferences, feedback, local events, and corrections so the dashboard can be personalized.
- Protect, troubleshoot, maintain, and improve the service.
3. AI processing and external services
Orbit does not let users select the AI model. The service operator configures the model and provider. When AI features are enabled, Orbit may send relevant context to OpenRouter for processing. For new email classification, that context can include the sender, subject, preview, received time, up to 1,800 characters of the message body, your urgency criteria, priority senders, time zone, and relevant feedback. On-demand productivity features may use stored email, calendar, preference, and feedback context needed for the requested feature.
Orbit may export AI traces to Arize AX when tracing is enabled by the service operator. Depending on the deployment configuration, traces can include prompts, model responses, metadata, and content used for the AI request. Review the privacy terms of Google, Microsoft, OpenRouter, Arize, and other providers involved in your use of the service.
Orbit does not send email, edit provider calendars, or follow instructions contained in email content. AI output can be incomplete or incorrect and should be reviewed before you rely on it.
4. When information is shared
Orbit shares information only as needed to provide the service, including with the provider accounts you connect, the configured AI provider, configured observability services, and infrastructure providers that host the application or database. Orbit does not sell your personal information or use connected email and calendar data for advertising.
5. Retention and your choices
Orbit retains account and connected-data records while they are needed to provide the service. You can sign out at any time, disconnect secondary provider accounts from Settings, and remove local events and feedback through the product features that support those actions. Signing out invalidates the current session; it does not automatically delete the underlying account or synchronized records.
To request account or data deletion, correction, or a copy of your information, contact support@tryorbit.email from the email address associated with your Orbit account. The operator may need to verify the request before acting on it and may retain information where required for security, legal, or legitimate operational purposes.
6. Security
Orbit uses HTTPS in transit, HTTP-only secure session cookies, hashed session tokens, encrypted provider grants, and access controls intended to protect stored information. No online service can guarantee absolute security. Do not use Orbit to store information that you are not authorized to share with the service or its configured providers.
7. Children and changes
Orbit is not directed to children under 13, and the operator does not knowingly collect personal information from children under 13. The operator may update this policy when the service or its data practices change. The effective date above identifies the current version.
8. Contact
Privacy questions and requests can be sent to support@tryorbit.email.