The short version, and why it needs a second sentence
We do not build models. So we are not training one on you.
That is true, and it is the sentence most companies would stop at. I won’t, because stopping there would leave you believing something we’d have to walk back the first time you read our own privacy policy. Your twin genuinely learns about you — that is the entire product — and a flat “we don’t use your data” would be a promise contradicted by the thing you can watch happening on screen.
So here is the longer version. It is a better story anyway.
What we don’t build
myOrbit trains no foundation models. We have no lab, no training run, no corpus of user conversations being turned into weights we own.
What we have is orchestration. Aura draws on the top models from three frontier labs — Anthropic, OpenAI, and Google — and picks per moment, which is why you never pick a model yourself. Your words travel to whichever lab answers best, they come back as a response, and the model on the other end is exactly as it was before you typed. Nothing you say makes it smarter.
That is a structural fact, not a policy we could quietly change next quarter. You cannot train on data with a model you don’t have.
What we can and cannot promise about the labs
The obvious follow-up: those labs do build models. What stops your conversation from ending up in one?
Here is where an earlier version of this note overreached, and where I would rather correct myself in public than leave it standing. It said the labs were contractually barred from training on your content, full stop, and pointed at three of our own pages that said the same. That sentence has now come off those pages, and it comes off this one.
The reason is not that something changed at a lab. It is that a blanket promise across every provider, every service configuration and every future change is not a promise we can stand behind for all of them at once — and a claim we cannot verify end to end has no business being the load-bearing beam of a note about precision.
What is true, and what our privacy policy now says: providers handle your content under their published terms and the services as we have configured them, and they may retain data for safety, abuse prevention, or legal obligations. Those are their terms, published by them, and they can change; ours is the choice of which services we configure and how.
That is a weaker sentence than the one it replaces. It is also one you can check.
The part that is not training
Now the distinction the flat claim erases.
Your twin remembers you. It holds what you told it, what you prefer, how you work, the context that means you aren’t starting from nothing every morning. Our privacy policy describes exactly this, in the section on why we hold conversation context at all: so your twin can continue conversations “instead of starting from nothing each time.”
That is personalization, and it is not the same species as training. Training bakes many people’s data into a general model that then serves strangers. Personalization holds one person’s context to serve that one person. One makes a product out of you; the other makes a product for you. The data stays attached to your account, and it shapes your twin and no one else’s.
An AI that forgot you every morning would not be more private. It would just be worse, and equally readable.
What deletion actually reaches
Our data deletion policy is the document that governs this, and it is worth reading rather than summarizing: it sets out the deletion routes we offer, what each one removes, and the schedule stored data comes off on. Deletion there is treated as specific rather than one nuclear button — conversation history, twin memories and personalization data are named separately.
What deletion cannot do is reach inside a model that was never ours. Our deletion policy carries a paragraph headed one thing we will not claim: we cannot “untrain” a general-purpose AI model, because removing an individual’s data from trained weights “is not technically achievable today, by us or by anyone else.” Instead we control the things that are controllable — we run no training of our own, personalization stops, and stored data is deleted on a published schedule.
A company that offers to untrain a model for you is describing something that does not exist.
The asterisk I’m not hiding
One honest caveat, already in our terms: de-identified data may be used for improvements. That is in the terms in those words, so it belongs here too rather than in a footnote someone finds later. It is not your conversations feeding a model with your name on it; it is aggregate signal about how the product behaves. But it is not nothing, and “we never touch your data” would be a lie by omission.
What you will not find in this note is a consent switch, and the reason is the one the whole note is built on. A switch is what you need when a company holds your data next to a model it owns and could point the one at the other. We own no model. There is nothing on our side to withhold consent from, so what we owe you here is the unconditional sentence — we build no models, so nothing of yours is training one — rather than a setting that would imply the conditional version were true.
Where encryption sits in this
Storage is a separate question from training, and I’ve written it up separately — including the box on our security page listing what we deliberately do not claim. If you want that half, read what we do and don’t claim about your data. The short version, with the qualifier our privacy policy exists to preserve: messages travel to us over TLS 1.3, and our databases, file storage and backups are encrypted at rest at the infrastructure layer. Some message fields get additional application-level encryption and not all of them do, so you should not assume any particular field is protected beyond that storage encryption. The keys are ours, which protects your messages from theft and not from us — we are technically able to read message content, there is no zero-access or end-to-end mode, and we say all of that out loud rather than letting “encrypted” do the work of a promise we haven’t made.
Two different promises, kept separately, neither borrowing credibility from the other.
Why bother with the precision
Because the imprecise version fails on contact. “We don’t train on your data” sounds absolute, and the moment a user notices their twin remembering last Tuesday, the absolute version looks like a lie — even though the thing they noticed was the feature working.
The precise version survives that moment: we build no models, the labs operate under their own published terms and we tell you so plainly, your twin learns you and only for you, and deletion does what deletion can. Every clause of that is checkable against a page we already publish. That’s the standard — not what sounds best, but what still reads true after you’ve gone looking. It is also why a sentence came out of this note rather than being quietly left in.
Go looking. I wrote this note assuming you would.
Take this with you
Share the canonical source, or copy a reading prompt for the AI you use.
Ask an AI
Copies the canonical Markdown source, then opens the service.
— orbiteer1