Privacy Policy
Last updated: October 4, 2026
Orbit is a group-planning app built to be private by design. This policy explains what we collect, why, how we protect it, and the control you have over it. We’ve tried to write it plainly. If anything is unclear, email us at hello@orbitplan.net.
The short version. Orbit stores your account, your Circles, and the plans, votes, expenses, and photos inside them. Your data is encrypted in transit and at rest, and scoped by row-level security so only members of your Circle can see it. Location, contacts, and photos are optional and only used for the features you ask for. If you use contacts discovery, phone numbers are hashed on your device and only the hashes are sent, and we do not store them. Orbit's AI runs on Google Gemini, through Google's paid Gemini API, and Google receives a request only when someone asks for plan ideas or a summary; section 5 lists exactly what each one holds. You can export or delete your data at any time.
1. Who we are
Orbit (“Orbit”, “we”, “us”) provides the Orbit mobile application (Android package
app.orbit.orbit) and the website at orbitplan.net. This policy covers both. It
does not cover third-party services you reach through Orbit, which have their own policies.
2. Data we collect
Account and profile
When you create an account we collect the information needed to sign you in and identify you to your Circle: your name or display name, email address, and an optional profile photo. If you sign in with Google, we receive your basic Google account details (name, email, and profile image) to create and secure your account. We do not receive your Google password.
Google Meet links (optional)
If you tap Make a Meet on a plan, Orbit asks Google for one extra permission: to create Google Meet meetings for you (Google describes it as "Create, edit, and see information about your Google Meet conferences created by the app"). Orbit asks only when you tap that button, never when you sign in, and you can say no and paste any meeting link instead.
We use this permission for one thing: to create a single meeting when you ask for it. The access Google grants is used once, on your phone, to create the meeting; it is not sent to our servers and it is not stored. What we keep is the meeting link, saved on your plan so the people you invited to that plan can join. Orbit cannot see, list or change any meeting it did not create, and it never reads your calendar, contacts, email or other Google data through this permission. The link stays on the plan, visible only to the people on it, until the plan is deleted.
You can remove Orbit's access at any time in your Google Account, under Security, "Your connections to third-party apps and services".
Orbit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use information from Google APIs for advertising, we do not sell it, and we do not use it to train AI models.
Phone number
If you sign in with a phone number, or add one to your account later, we collect and store that number in standard international (E.164) format. We use it to sign you in, to help secure your account, and, if you turn on contacts discovery, to let people who already have your number find you on Orbit.
Verification codes are sent by SMS through Firebase Authentication, a Google service acting on our behalf. Your mobile carrier’s standard message and data rates may apply to those messages. We store your number so that discovery can work; we do not use it for marketing and we do not sell it.
Someone can only reach you through discovery if they already have that exact number saved on their own device. Discovery does not reveal phone numbers: it shows an Orbit profile, not a contact’s number, to either side.
Circles, plans, and activity
Orbit stores the content you and your Circle create so the app can work: the Circles you belong to, plans and events, the options people propose, votes and RSVPs, comments, and related timing and location details you enter for a plan.
Expenses and settlement
When you use the money features, we store the expenses you record, how they are split, and the resulting balances so Orbit can total them and suggest how to settle up. Orbit does not process payments and does not collect bank, card, or other financial account numbers. Settling up happens between you and your Circle, outside the app.
Optional location
If you turn it on, Orbit uses your device location to find nearby venues and improve place suggestions for a plan. Location is optional, is only used at the moment you ask for suggestions or set a plan’s location, and can be turned off in your device settings at any time.
Optional contacts
If you turn on contacts discovery, Orbit checks which of the people in your address book already have an Orbit account, so you can add them to a Circle without typing in numbers by hand. This is optional and stays off until you turn it on. The mechanism matters here, so we describe it exactly:
- Your device reads the phone numbers saved in your address book and converts each one to standard international format.
- Each number is then hashed on your device with SHA-256, a one-way function. A hash cannot be reversed back into the number it came from.
- Only those hashes are sent to us. Your contacts’ names, email addresses, photos, notes, and every other field in your address book stay on your device and are never transmitted.
- Our server combines what it receives with a secret value (a “pepper”) held in Supabase Vault and hashes it again before comparing it against the verified numbers of Orbit accounts. Because that secret is not in the database, a stolen copy of the database cannot be tested against a list of phone numbers.
- We do not keep the hashes you send. Matching is stateless: the comparison happens in memory and the uploaded hashes are discarded as soon as it finishes. There is no stored copy of your address book on our systems, hashed or otherwise.
Because a value derived from every number in your address book is transmitted to us, even briefly and even in a form we cannot reverse, we count contacts as data we collect rather than as purely on-device processing. We would rather declare more than less.
What this does not protect against: an attacker with live control of our servers could observe hashes as they arrive and test guesses against them. That is true of every contact-discovery system in use today, including those in encrypted messaging apps, and no design choice on our side eliminates it. The protection above is against the realistic threat, which is a database being copied or leaked.
One consequence of not storing anything: Orbit cannot tell you when someone in your contacts joins later, because that would require keeping your contact hashes on file. You will see new matches the next time you run discovery yourself.
You can turn contacts discovery off at any time in Orbit under Profile, then Privacy & safety, and you can revoke the contacts permission entirely in your device settings. Orbit only reads your contacts. It never adds, edits, or deletes anything in your address book.
Optional photos (plan memories)
If you add photos to a plan, we store those images so your Circle can see them as memories. Photos are shared only within that Circle and are never made public by Orbit.
Technical and diagnostic data
To keep Orbit reliable and secure, we process limited technical information such as a device identifier for your session, app version, and error and performance logs. We use this to operate the service, fix bugs, and prevent abuse - not to build advertising profiles.
3. How we use your data
- To provide the core app: Circles, plans, voting, RSVPs, expense splitting, settle-up, and memories.
- To generate AI plan ideas grounded in real venues, based on the details of your plan, your circle and, if enabled, your location.
- To write a summary of what your circle has shared with Summarise with AI, only when someone taps Summarise in What you've learned.
- To send invites and Circle-related notifications you have asked for.
- To secure your account, prevent abuse, and troubleshoot problems.
- To comply with legal obligations that apply to us.
We do not sell your personal data, and we do not use your plans, expenses, or photos to serve you third-party advertising.
4. How your data is stored and protected
Orbit’s backend is hosted on Supabase, which stores your data in managed PostgreSQL databases and object storage. Your data is encrypted in transit (over HTTPS/TLS) and encrypted at rest on Supabase’s infrastructure.
Access is enforced with row-level security. In practice, this means each row of data - a plan, a vote, an expense, a photo - is tied to a Circle, and the database only returns it to members of that Circle. Other users cannot read your Circle’s data, and it is not publicly accessible.
5. Third parties we share data with
We keep the list of third parties short, and we only use them to make Orbit work:
- Supabase - our hosting and database provider. It stores your account, Circles, plans, expenses, and photos on our behalf.
- Google Sign-In - if you choose to sign in with Google, Google authenticates you and shares basic profile details with us. Your use of Google is subject to Google’s own privacy policy.
- Google Meet - only if you tap "Make a Meet": Google creates the meeting and returns its link, which we save on your plan. See Google Meet links above.
- Firebase Authentication (Google) - if you sign in with a phone number, Firebase sends the SMS verification code and confirms to us that the number belongs to your device. Google processes your phone number for that purpose on our behalf, and your use of it is subject to Google’s own privacy policy.
- AI provider: Google Gemini - Orbit's own AI runs on Google Gemini, through Google's paid Gemini API, for every AI feature in the app: plan ideas and Summarise with AI. No other company's model is behind Orbit's AI. A request goes from your phone to Orbit's server and from there to Google, and only when someone asks for plan ideas or taps Summarise. What each one sends is listed below. If you add your own key instead, see Bring your own key.
We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the service. If Orbit is ever involved in a merger or acquisition, we will require any successor to honor this policy.
What Orbit sends to Google Gemini for plan ideas
When you ask for plan ideas, Orbit sends a profile of the plan and the circle it is for, so the ideas fit the people going:
- the kind of outing, the dates or time, the budget, the area you are planning in (a place name, not your coordinates) and the group size;
- the circle's name and description, and for each member their name, role and tastes (food and dietary needs, interests, atmosphere, budget), any note added about them in the circle, and how often they have said yes to plans, plus the group's combined constraints, such as dietary needs;
- recent plans in the circle, what each cost in total and how they went, feedback on earlier ideas, and answers the circle has already unlocked, without names;
- and real venues nearby, which Orbit looks up on Google Places.
Versions of the app before 1.1.82 also send how much each member has spent in the circle and the circle's balances (who owes whom); from version 1.1.82 these are not sent.
It does not include your email address, phone number, exact location, photos, or what anyone has written in chat.
What Orbit sends to Google Gemini for Summarise with AI
Only when someone taps Summarise in What you've learned. The request is for that reader and holds only what they can already see:
- the circle's name and kind, and the questions asked in it that the reader has answered;
- the answers the reader has unlocked: their own, and other people's answers to the questions the reader also answered;
- first names only, with a last initial where two people share a first name.
It never includes answers that are still locked, guesses, replies, the answers of anyone who has switched off "Include my answers in summaries" for that circle, or questions where "Use answers for suggestions" is off. The summary is kept for the reader only, for 3 days.
What Google does with it
Because Orbit uses Google's paid Gemini API, Google's Gemini API Additional Terms of Service say it does not use prompts or responses "to improve our products". Google keeps them for a limited time solely to detect and prevent abuse of its services and to meet legal requirements; its abuse monitoring page puts that at 55 days, and content its automated checks flag may be reviewed by authorised Google staff. Google may store it briefly, or cache it, in any country where it or its agents have facilities.
6. Bring your own key
Instead of Orbit's AI, you can use your own Claude (Anthropic) or OpenAI key, in Orbit under Profile, then AI suggestions. When you do:
- Plan ideas and summaries go straight from your phone to that provider, using your key, instead of to Google Gemini. For plan ideas, the details listed above go to that provider, and the request does not pass through Orbit's server (Orbit still looks up the nearby venues on Google Places).
- For a summary, your phone first fetches the request from Orbit's server, which builds it under the same rules as above, then sends it to your provider. The reply comes back to Orbit to be checked and kept for you, for 3 days.
- Your key is stored on your phone and is only ever sent to the provider you chose. Orbit's server never receives it.
- That provider's own terms and privacy policy apply to what you send it, and it bills your account with it.
Treat your key like a password. You can remove it at any time from the same screen, and Orbit's AI, Google Gemini, is used again.
7. Your rights and choices
- Access and export. You can request a copy of your data in a portable format.
- Deletion. You can delete your account and associated data from within the app or by contacting us. Some records may be retained briefly where required for security or legal reasons, then removed.
- Permissions. Location, contacts, and photo access are optional and controlled by your device permissions. You can revoke any of them at any time.
- Leaving a Circle. When you leave or delete a Circle, your access to its content ends. Content others contributed may remain visible to the remaining members.
To make any of these requests, email hello@orbitplan.net.
8. Data retention
We keep your data for as long as your account is active or as needed to provide Orbit. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must keep limited records to meet legal or security obligations.
Contact hashes are the exception to all of the above, because they are never retained in the first place. They exist only for the moment it takes to compare them and are then discarded.
What the AI features keep, and for how long:
- Plan ideas. The text Orbit sends to Google Gemini for plan ideas, and the reply, are kept with a record of the request for 30 days, so we can look into problems, and then deleted. The ideas themselves stay in your circle's history for up to 45 days (the newest 20 for each circle), and ideas you save stay until you remove them.
- Summarise with AI. A summary is kept for its reader only, for 3 days, and then deleted.
- Request records. A technical record of each AI request, such as the feature, the model, how long it took and how many tokens it used, holds no text of the request or the reply, and is kept for at most 180 days.
9. Children
Orbit is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will remove it.
10. International users
Your data may be processed in countries other than your own, including where our providers operate. Wherever it is processed, we apply the protections described in this policy.
11. Changes to this policy
We may update this policy as Orbit evolves. When we make material changes, we will update the date above and, where appropriate, notify you in the app. Continued use of Orbit after an update means you accept the revised policy.
12. Contact us
Questions, requests, or concerns about privacy? Email hello@orbitplan.net and we will help.