Privacy Policy
Orbit is built so that your content stays yours. The app works fully without an account, and when you choose to sync across devices, everything you write, scan or record is encrypted on your device before it leaves, so our servers only ever hold data no one but you can read.
Who we are
Orbit is published by Netsphere Technologies Private Limited, a company incorporated in India (CIN U62099MP2024PTC072918), with its registered office in Jabalpur, Madhya Pradesh, India. For the purpose of the Digital Personal Data Protection Act, 2023, Netsphere Technologies Private Limited is the data fiduciary for the limited personal data described below. You can reach us about privacy at netsphere.official@gmail.com.
The short version
- You can use every feature of Orbit without an account, and with no network connection.
- If you sign in to sync, your tasks, chat, documents, scanned text, display name and photo are end-to-end encrypted on your device. We cannot read them.
- Signing in gives our authentication provider your email address or phone number and an account identifier, so sign-in and sync can work. That is the only readable personal data involved.
- There are no ads, no analytics, and no tracking across apps or websites.
- You can delete your account and all of its data from inside the app at any time.
What Orbit stores on your device
Almost everything in Orbit lives on your device: your tasks, lists, projects, habits, focus sessions, meeting alarms, chat messages, voice notes and their transcripts, and your vault documents along with the text extracted from them. Vault documents and chat media are encrypted on disk with a key held in your device Keychain. Text extracted from documents for search is stored encrypted and indexed in a local database that is excluded from backups and only opened while your vault is unlocked. If you never sign in, none of this leaves your device.
What we process when you sign in
Signing in is optional and only enables sync across your own devices. When you sign in, two different kinds of data are involved, and they are treated very differently.
1. Account identifiers (readable to our provider)
To authenticate you, our provider needs an identifier for the sign-in method you choose:
- Email address, when you sign in with Apple, Google or email. If you use Sign in with Apple and choose to hide your email, we only receive Apple's private relay address.
- Phone number, when you sign in with phone.
- A user identifier assigned to your account, which is used to label and separate your encrypted data.
These identifiers are used only to run sign-in and sync. They are not used for advertising, profiling or tracking, and they are not sold or shared for any such purpose.
2. Your content (end-to-end encrypted, unreadable to us)
When sync is on, your content is sealed on your device using AES-GCM encryption before it is uploaded. The stored documents in our database contain only ciphertext in a uniform shape; stored files are encrypted binary data. Your display name and profile photo are encrypted the same way and are never written to the authentication record in readable form. The key that unlocks this content is generated on your device and is never sent to our servers. It travels between your own devices through Apple's iCloud Keychain, and you can optionally set a recovery passphrase that wraps the key so a new device can restore it. Because we never hold the key, we cannot read, search or hand over the content of your tasks, chat, documents or profile.
Permissions Orbit may ask for
Orbit requests each permission only when you use the feature that needs it, and explains why at the time:
- Alarms, to ring real alarms before your calls and meetings.
- Notifications, for reminders and task alerts.
- Calendar, read-only, to show upcoming events and set alarms before them.
- Camera and Photos, to scan or import documents into your vault.
- Microphone and Speech Recognition, for voice notes, which are transcribed on the device.
- Location, when in use only, if you choose to attach a place to a note. It is not tracked in the background.
- Face ID or Touch ID, to unlock your vault.
Data captured through these permissions follows the same rule as everything else: it stays on your device, and if sync is on it is encrypted before it leaves.
Apple Intelligence
Orbit's optional intelligent features, such as the daily briefing, category suggestions and quick-add refinement, run on your device using Apple's on-device models. Your document and chat text is not sent off the device for these features.
Who processes data for us
We use Google Firebase (Authentication, Cloud Firestore and Cloud Storage) as our processor to run sign-in and to store your encrypted content. Firebase stores the readable account identifiers above and the ciphertext of your content. Data is hosted in the asia-south1 region (Mumbai, India). Google acts on our instructions as a processor and provides protections consistent with this policy. We use Google Sign-In and Sign in with Apple as authentication options you can choose. We do not use analytics or advertising SDKs, and we do not share your data with data brokers.
Data retention and backups
We keep your encrypted content and account identifiers for as long as your account exists. When you delete your account, your content and identifiers are removed as described below. For resilience, our database keeps automatic backups on a rolling basis; these backups are retained for up to 14 days and then expire, after which deleted data is gone from backups too. Because backup copies are also ciphertext, no one can read them.
Deleting your account and data
You can delete your account from inside the app, in Settings → Account & Sync → Delete Account. This re-verifies that it is you, removes your authentication record, and permanently deletes your data in our database and file storage. The app also wipes the encrypted data and keys on your device. Deleted data is removed from live storage immediately and ages out of rolling backups within 14 days. You can also sign out, or use Orbit without an account, at any time.
Your rights
Under the Digital Personal Data Protection Act, 2023 and other applicable laws, you have the right to access, correct and erase your personal data, to withdraw consent, and to raise a grievance. Because your content is end-to-end encrypted and we cannot read it, the most reliable way to access or correct it is in the app itself, where it is decrypted for you. For requests about your account identifiers, or to raise a grievance, contact us at netsphere.official@gmail.com and we will respond within the timelines the law requires.
Children
Orbit is a general productivity app and is not directed at children. We do not knowingly collect personal data from children in a way that requires verifiable parental consent. If you believe a child has provided personal data to us, contact us and we will delete it.
Security
We protect your data with end-to-end encryption using Apple's cryptography, device Keychain protection, biometric vault locking, owner-only access rules on stored data, and encrypted transport (HTTPS/TLS) for everything sent to our processor. No system is perfectly secure, but because your content is encrypted with a key we never hold, a breach of our storage would expose only ciphertext.
Changes to this policy
If we change this policy, we will update the effective date above and, for material changes, give notice in the app or on this page. Continued use of Orbit after a change means you accept the updated policy.
Contact
Netsphere Technologies Private Limited
Jabalpur, Madhya Pradesh, India
netsphere.official@gmail.com