The box

“MyOrbit does not offer end-to-end encrypted or zero-access messaging.”

That sentence sits in a highlighted box near the top of our own security page, under the heading what we do not claim. The box goes further: we are technically able to access message content, and we do so where safety, moderation, legal, or support processes require it. And then the line that makes it unusual for the genre: please don’t read anything on the page as a promise that we cannot see your messages.

Companies don’t usually publish boxes like that. This essay is about why we do, and what we actually promise instead.

What we do claim

The claims we make are concrete, and each is on the security page in plain terms.

Message content is encrypted at rest. Stored data is protected with AES-256, the industry-standard algorithm, with encryption keys held in a managed key service under restricted access. In transit, everything moves over TLS 1.3. Translation for non-specialists: your data does not sit on a disk in readable form, the keys that unlock it are guarded separately from the data itself, and it never travels naked between you and us.

Deletion is user-triggered and real. Not “submit a request for consideration.” You trigger it — “delete your data at any time” is the page’s language, and it means what it says.

Training is opt-in, not ambient. We don’t train models on your data unless you choose otherwise — a commitment our plans and creator pages both carry.

Real claims, precisely scoped. Now the part we won’t say.

What we don’t claim, and why

End-to-end encryption means only the conversation’s participants can ever read it — the platform mathematically cannot. Zero-access means the same thing wearing a different suit. We claim neither, because neither is true here, and the reason is a genuine design tension rather than an oversight.

myOrbit is a platform where AI participates in conversations and where safety scanning protects users in real time. An assistant that acts on your messages has to read them. Moderation that catches abuse before it spreads has to see content. A platform that can help when something goes wrong has to be able to look at what went wrong. True zero-access would make every one of those impossible — you can have a platform that cannot see anything, or one where intelligence and safety operate inside the conversation, but not both at once.

We chose intelligence and safety, and we wrote the choice down where you can read it.

The phrase to watch for

Here’s the consumer-protection takeaway, usable on any product you evaluate: the AI industry is drenched in privacy language engineered to imply zero-access without committing to it. “Military-grade encryption” — of what, in which state, with keys held by whom? “Your conversations are private” — private from other users, or from the company? “We take your privacy seriously” — that one means nothing at all.

Encryption at rest and end-to-end encryption sound like siblings and are actually different species. Most vendors are counting on you not knowing the difference. Now you do: at rest protects data from thieves and leaked disks; end-to-end protects it from the platform itself. Any AI product whose assistant reads your messages is almost certainly in the first category — whatever the marketing hums.

Most AI companies won’t tell you this. That silence is a strategy, and its cost lands on you at the worst possible time: after you’ve shared what you assumed nobody could read.

Honesty as architecture

We hold a simple position: trust built on a misunderstanding is a liability with a delay on it. Users who believe a stronger promise than the one actually made will eventually discover the gap — through a news cycle, a subpoena story, or a careful read of a terms page — and the trust doesn’t just shrink back to accurate size. It collapses past it.

So we’d rather state the weaker, true thing than let you infer the stronger, false one. The “what we do not claim” box costs us something in a feature-comparison table. It buys something better: every promise on the page is one we can keep in the worst week, not just the best one.

Read the security page yourself — the claims and the disclaimers sit side by side, which is where they belong. And whatever platform you’re evaluating, ours included: skip the adjectives, find the box that says what they don’t claim. If there isn’t one, that’s your answer.