Orbit — Data Handling Summary
A plain-language overview of what Orbit collects, why, how long we keep it, who processes it, and what control you have. The full detail is in the Privacy Policy.
At a glance: no selling of data · no ads · no third-party advertising or tracking SDKs · location only while you actively share · date of birth never stored.
| Data type | Why collected | Retention | Processor | Your control |
|---|---|---|---|---|
| Account identity, login | Until account deletion | Supabase | Delete account in-app | |
| Username / display name / avatar | Your public profile | Until account deletion | Supabase | Edit in-app; delete account |
| Date of birth | Verify 16+ at signup | Not stored (only an age-confirmed timestamp is kept) | — | N/A (never persisted) |
| Location | Find nearby matches while you share an intent (foreground only) | Tied to the active intent; not stored as history | Supabase | Stop sharing; OS location permission |
| Push token | Deliver notifications | Until you disable notifications or delete account | Supabase / Expo | Disable in OS/app settings |
| Intents | Core broadcast feature | Until expiry or deletion | Supabase | Delete in-app; export; delete account |
| Burner messages | Group coordination chat | Ephemeral — auto-expire; purged on block | Supabase | Block purges; export own; delete account |
| Pings | 1:1 coordination | Per feature lifecycle | Supabase | Delete account |
| Product analytics events | First-party measurement to improve Orbit | Limited window, then deleted/aggregated | Supabase | — |
| Age-confirmed timestamp | Proof the 16+ check passed | Until account deletion | Supabase | Delete account |
Your rights (GDPR)
- Export — download the data you authored, in-app (Profile → Privacy & data).
- Delete — remove your account and associated data, in-app (Profile → Privacy & data).
- Access / correct / object / complain — contact hello@onorbit.app; you may also lodge a complaint with a supervisory authority.
Processors
- Supabase — database, auth, storage, serverless functions.
- Expo — push notification delivery.
Not collected / not done
- No selling or sharing of personal data for others' commercial use.
- No advertising and no advertising identifiers.
- No third-party analytics or tracking SDKs.
- No background or continuous location tracking.