Orbit — Data Handling Summary
A plain-language overview of what Orbit collects, why, how long we keep it, who processes it, and what control you have. The full detail is in the Privacy Policy.
At a glance: no selling of data · no ads · no third-party advertising or tracking SDKs · location only while you actively share · date of birth never stored.
| Data type | Why collected | Retention | Processor | Your control |
|---|---|---|---|---|
| Account identity, login | Until account deletion | Supabase | Delete account in-app | |
| Username / display name / avatar | Your public profile | Until account deletion | Supabase | Edit in-app; delete account |
| Date of birth | Verify 16+ at signup | Not stored (only an age-confirmed timestamp is kept) | — | N/A (never persisted) |
| Location | Find nearby matches while you share an intent (foreground only) | Interim: kept until you leave the group or delete your account (no fixed post-expiry purge yet); a scheduled purge of location from expired broadcasts is planned | Supabase | Stop sharing; OS location permission; delete account |
| Photos in burner chats | Share an image inside a private group chat | Private bucket, no public link; viewed via a 1-hour signed link; expire with the chat, swept ~30 min after; re-encoded on upload, which removes embedded metadata | Supabase | Chat expiry deletes them; block purges the chat; delete account |
| Push token | Deliver notifications | Until you disable notifications or delete account (no separate staleness window) | Supabase / Expo | Disable in OS/app settings |
| Intents | Core broadcast feature | Row persists after expiry (marked inactive); removed on group-leave or account deletion | Supabase | Delete in-app; export; delete account |
| Burner messages | Group coordination chat | Ephemeral — chat expires 2 h after the intent ends, purged by a job every 10 min; purged immediately on block | Supabase | Block purges; export own; delete account |
| Pings | 1:1 coordination | Until account deletion (pending pings purged on block) | Supabase | Delete account |
| Product analytics events | First-party measurement to improve Orbit | No fixed window yet — kept until account deletion (then de-linked); never sold/shared | Supabase | Delete account |
| Age-confirmed timestamp | Proof the 16+ check passed | Until account deletion | Supabase | Delete account |
| Website waitlist (email + optional campus/source tag) | One email when Orbit opens on your campus — the only use; never linked to an app account | Until that launch email is sent, or on request | Supabase (stored) / Cloudflare (in transit) | Email hello@onorbit.app to be removed |
| Website page views (path + link source; cookieless, no identity) | First-party measurement of which posters/invites work | No fixed window yet; never linked to a person | Supabase | Nothing identifies you; nothing to remove |
Your rights (GDPR)
- Export — download the data you authored, in-app (Profile → Privacy & data).
- Delete — remove your account and associated data, in-app (Profile → Privacy & data).
- Access / correct / object / complain — contact hello@onorbit.app; you may also lodge a complaint with a supervisory authority.
Processors
- Supabase — database, auth, storage (incl. the private burner-photo bucket), realtime, serverless functions. Runs on AWS in London, UK (lawful under the EU–UK adequacy decision).
- Expo — push notification delivery only (title/body + device token; no chat/location/account).
- Sentry — crash and error monitoring (sensitive fields stripped before send). Data region pending a configuration decision — until set, data may be processed in the US.
- Cloudflare — website delivery (
onorbit.app) and forwarding of email to our contact address; sees connection data in transit, stores none of your app data.
Not collected / not done
- No selling or sharing of personal data for others' commercial use.
- No advertising and no advertising identifiers.
- No third-party analytics or tracking SDKs.
- No background or continuous location tracking.