Orbit Orbit

Orbit — Privacy Policy

Version: 2026-07-04 Last updated: 2026-07-04

1. Who we are

Orbit ("we", "us") is operated by David Enachescu-Goldenberg, operating as Orbit. The app is available at onorbit.app. For any privacy question or to exercise your rights, contact us at hello@onorbit.app.

2. The data we collect

We collect only what the app needs to work. We do not sell your data, we do not show ads, and we do not embed third-party advertising or tracking SDKs.

Data When Why
Account: email, username, display name, optional avatar image At signup / profile setup Create and operate your account
Date of birth At signup Used only to verify you are 16+. It is NOT stored — we keep only a timestamp that age was confirmed (min_age_confirmed_at).
Location Only while you are actively sharing an intent (foreground) To find nearby matches ("serendipity"). Never collected in the background; never continuous tracking. The coordinates attached to a broadcast currently remain stored after the broadcast ends — until you leave the group or delete your account. A scheduled purge of location from expired broadcasts is planned; until it ships, see Retention (§5) for the honest current position.
Photos in burner chats Only when you attach a photo to a burner-chat message To share images inside a private group chat. Photos are held in a private storage bucket with no public link; they are viewed through a temporary signed link that is valid for 1 hour. Photos are re-encoded on upload, which removes embedded metadata such as location tags. Photos expire with the chat and are swept within about 30 minutes after it ends (see §5).
Push notification token Only if you enable notifications To deliver match / coordination alerts. The token is stored while notifications are enabled, re-registered when you log in, and deleted with your account; we do not attach it to a separate advertising profile.
Content you create: intents, burner-chat messages, pings, group memberships As you use the app To provide the core social features
Product analytics events (in-app actions) As you use the app First-party measurement to understand and improve the product
Website waitlist: email + how you found us (an optional campus/source tag and referral code) Only if you join the waitlist on our website To send you one email when Orbit opens on your campus — that is the only use. The entry is not linked to any app account, and you can ask us to delete it at any time via the contact address (§10).

The website. Our website (onorbit.app) is a static site and uses no cookies and no third-party analytics. It records first-party, cookieless page-view events (page path and the link source that brought you, never your identity) so we can tell which posters and invites work. The site is delivered by Cloudflare (see §7).

3. Age requirement

Orbit is intended for users aged 16 and over. 16 is the age of digital consent under GDPR Art. 8 as applied in Germany (BDSG). We ask your date of birth at signup solely to confirm you meet this threshold and block sign-ups that do not. We do not store the date of birth itself.

4. Legal bases (GDPR Art. 6)

  • Performance of a contract — operating your account and the core features you ask for.
  • Consent — push notifications, and location access at the point you choose to share.
  • Legitimate interests — first-party product analytics, safety and abuse prevention (blocking, reporting, moderation), and keeping the service secure and reliable. We have carried out a Legitimate Interests Assessment (LIA) for both the safety/moderation and the first-party analytics bases, and it is on file.

Cookies and device storage (TDDDG §25). Orbit does not store or access non-essential information on your device: no advertising cookies, no third-party analytics SDKs, and no cross-app or cross-device trackers. The only on-device storage we use is what the app needs to function (your session and local app state). Because we place nothing non-essential on your device, there is no cookie banner or equivalent consent prompt to show you.

5. Retention

  • Burner chats are ephemeral. A chat expires 2 hours after the underlying intent ends, and a background job runs every 10 minutes to delete expired chats and their messages.
  • Photos in burner chats are deleted when the chat ends: the photo object is swept within about 30 minutes of the chat's deletion, and the temporary link used to view it is valid for only 1 hour in the first place.
  • Blocking a user immediately closes and purges the burner conversation you shared with them.
  • Location attached to a broadcast is, at present, not purged on a fixed schedule after the broadcast expires — it is removed when you leave the group or delete your account. A scheduled purge of location from expired broadcasts is planned; we will update this section with the exact window once it is in place.
  • Product analytics events and the notification log do not yet have a fixed deletion window; they are retained until you delete your account (which removes or de-links them) and are never sold or shared. We are defining a maximum retention period for these; it will appear here once set.
  • Account deletion removes your data: it cascades across your rows, anonymises content you authored in shared spaces (shown as "Deleted user" rather than erased), and purges your stored files.

6. Your rights

Under the GDPR you can: access your data, export it, delete your account and data, correct inaccurate data, object to certain processing, and lodge a complaint with a supervisory authority. Account deletion and data export are available directly in the app (Profile → Privacy & data). You can also reach us at hello@onorbit.app.

7. Processors and third parties

We use the following processors to run Orbit:

  • Supabase — database, authentication, file storage (including the private burner-photo bucket), realtime delivery, and serverless functions. Supabase runs our project on Amazon Web Services (AWS) in London, United Kingdom. Your data therefore sits in the UK; this is lawful under the European Commission's EU–UK adequacy decision (extended June 2025), which permits EU personal data to be processed in the UK without additional transfer measures.

  • Expo (650 Industries, Inc.) — delivery of push notifications only. Expo relays the notification title/body to Apple and Google's push services using your device push token; it does not receive your chat content, location, or account data.

  • Sentry (Functional Software, Inc.) — crash and error monitoring. Before any report leaves your device, sensitive fields (location, chat content, tokens, email, password) are stripped and only an opaque user id is attached. Sentry's data region is pending a configuration decision; until it is set, error-monitoring data may be processed in the United States. We will name the region and the applicable transfer basis here once that decision is executed.

  • Cloudflare (Cloudflare, Inc.) — delivery of our website and forwarding of email sent to our contact address. Cloudflare serves the site from its edge network (your IP address and request metadata pass through it, as with any website host) and forwards mail addressed to hello@onorbit.app; it does not receive your app data. Waitlist submissions travel through Cloudflare in transit and are stored only in our own database (Supabase, above).

These providers process data on our behalf under our instructions.

8. Security

We protect your data with row-level access controls (each user can reach only their own private data), encrypted transport, and least-privilege access for our systems.

9. Changes to this policy

If we make material changes we will update the version date above and, where required, ask you to re-accept before continuing to use Orbit.

10. Contact

Questions or requests: hello@onorbit.app.

Orbit

Real plans with people nearby.

Legal

  • Privacy policy
  • Terms of service
  • How we handle data

Contact

  • hello@onorbit.app

© 2026 David Enachescu-Goldenberg, operating as Orbit. For students 16 and up.