MyOrbit Privacy Policy
MyOrbit, Inc. and its affiliates ("MyOrbit," "we," "our," or "us") respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our websites, mobile applications, and services (collectively, the "Services").
By accessing or using the Services, you acknowledge that you have read, understood, and agree to this Policy and our Terms of Service. If you do not agree, please do not use the Services.
Table of Contents
- Information We Collect
- How We Use Your Information
- How We Share Information
- Your Privacy Rights and Controls
- Data Security
- Data Retention
- International Data Transfers
- Children's Privacy
- Platform-Specific Features
- Cookies and Tracking
- Third-Party Services
- Contact Us
- Changes to This Policy
- Additional Provisions
1. Information We Collect
1.1 Information You Provide Directly
Account Registration and Profile
- Basic information: name, username, email, phone number
- Profile details: bio, avatar, preferences
- Age verification data (for age-appropriate experiences)
- Optional: demographic information for personalization
Messages and Content
- Your messages are stored. We save your conversations on our servers so that your chat history is there when you come back, on any device. Messages are not ephemeral, and they are not discarded after delivery.
- Alongside the text of a message we store a numerical representation of its meaning (an "embedding"). This is what lets AI companions, twins, and assistants recall relevant things you said in earlier conversations instead of starting from nothing each time.
- Messages travel to us over TLS 1.3, and our databases, file storage, and backups are encrypted at rest at the infrastructure layer. We apply additional application-level encryption to some message fields, but not to all of them, so please do not assume that any particular field is protected beyond the storage encryption described here.
- MyOrbit is technically able to read message content, and content is processed for safety features. We do not offer a zero-access or end-to-end encrypted messaging mode.
- We do not edit the words in your messages. We do generate derived data from them, such as the embeddings described above and safety classifications.
Contacts (Find Friends)
- If you choose to use Find Friends, the app reads your device address book and converts each phone number into a one-way SHA-256 hash on your device, before anything is sent.
- Only those hashes are sent to us. Raw phone numbers, contact names, email addresses, and any other detail from your address book never leave your device.
- We compare the hashes we receive against hashes of registered users so we can tell you which of your contacts are already on MyOrbit. We do not store the hashes you send, and we do not build a contact graph or shadow profiles from them.
- The feature is optional and needs the contacts permission, which you can refuse or revoke at any time in your device settings.
Digital Twins and AI Interactions
- Training data for your personal AI twin (FameWave OS)
- Conversation context for AI assistants
- Avatar customizations and preferences
- Business twin configurations (EchoBurst OS)
Creator and Monetization Data
- Payment information for subscriptions and Nuggets
- Tax information where required
- Creator verification documents
- Revenue and earnings data
- Orbit membership information
Support and Feedback
- Support tickets and correspondence
- Bug reports and feature requests
- Survey responses
- Beta testing feedback
1.2 Information Collected Automatically
Usage and Analytics
- Features you use and frequency
- Interaction patterns with AI companions
- Content engagement metrics
- Session duration and activity levels
- Device information (OS, browser, app version)
Location Information
Location is not only analytics for us. It is used to make features work, so we want to be specific about what we take.
- Precise location, if you grant permission. When you allow location access, the app collects your device's actual GPS coordinates, at full precision, together with an accuracy radius in metres. We store these coordinates on your account record and update them as your location changes.
- What we use precise location for. Location-dependent product features, including discovery of people and content near you, distance-based matching and recommendations, and personalizing what you are shown. This is functional use, not just measurement.
- Coarse location, without the permission. We derive an approximate location from your IP address. To do this we send your public IP address to ipinfo.io, a third-party lookup service, which returns an approximate city, region, and postal code. We also derive your country.
- Your control. You can decline or revoke the location permission at any time in your device settings. Features that depend on precise location will stop working or fall back to the coarser IP-derived location described above. Coarse, IP-derived location cannot be switched off separately, because your IP address is part of making a network request at all.
Technical Data
- IP addresses
- Device identifiers
- Log data and diagnostics
- Performance metrics
- Crash reports
Cookies and Tracking
See our Cookie Notice for detailed information about:
- Strictly necessary cookies
- AI feature cookies
- Analytics cookies
- Advertising cookies (optional)
1.3 Information from Third Parties
- Other Users: When they invite you or mention you
- Social Platforms: If you connect accounts
- Payment Providers: Transaction confirmations
- Business Partners: Integration data from connected services
- Public Sources: Publicly available information for verification
1.4 Special Categories of Data
Face and Voice Data (not biometric identification)
Some features involve a photo of your face or a recording of your voice, for example creating an avatar or giving a twin a voice. We use that input to produce the thing you asked for, and for nothing else.
- We do not run facial recognition. We do not create a faceprint, face template, or other biometric identifier from your photos, and we do not match your face against other photos, other users, or any database.
- We do not use your voice to identify or authenticate you, and we do not create a voiceprint for that purpose.
- Synthetic speech for AI voices is generated by our speech provider (ElevenLabs) under contract.
Age Estimation Selfie
To confirm that an account belongs to an adult, we ask for a selfie in the app. The selfie is used for our age check, and it is not retained after the check is complete. It is not facial recognition, we do not use it to identify you, we do not match it against any other photo or database, and we do not use it to build a face template.
If the estimate reads an adult as a minor, you may appeal by verifying with a government ID through our identity partner, Stripe Identity. That appeal is optional and is never required to reach any content level. Documents you submit for an appeal are handled by Stripe Identity under its own privacy terms and are deleted once the appeal is decided.
What we do keep from the check. The photo is not retained, but the result is. From the estimate we keep an age bracket, a confidence value for that estimate, an estimated numeric age, and an apparent-gender value returned by the estimator. We keep these on your account so that we can apply age-appropriate defaults and keep minors out of adult surfaces without asking you to repeat the check.
Health and Fitness Data
We do not collect health or fitness data. MyOrbit does not connect to Apple Health, Google Fit, or any other health or fitness source, and there are no health or wellness tracking features in the app.
2. How We Use Your Information
2.1 To Provide Services
- Create and manage your account
- Enable messaging and communication features
- Power AI companions and digital twins
- Process transactions and subscriptions
- Deliver requested content and features
- Provide customer support
2.2 To Improve and Personalize
- Customize your experience based on preferences
- Recommend relevant content and connections
- Optimize AI model selection for cost and performance
- Develop new features and services
- Fix bugs and improve performance
- Conduct research and analytics
2.3 For Safety and Security
- Detect and prevent harmful content
- Identify and block spam, fraud, and abuse
- Verify age for age-appropriate experiences
- Respond to safety reports and emergencies
- Protect against unauthorized access
- Maintain platform integrity
2.4 To Communicate
- Send service updates and notifications
- Deliver security alerts and warnings
- Provide product announcements (with consent)
- Share policy changes
- Respond to your inquiries
2.5 For Legal Compliance
- Meet legal obligations
- Respond to legal requests and court orders
- Protect rights, property, and safety
- Enforce our Terms of Service
- Investigate violations
2.6 With Your Consent
- Additional purposes you specifically agree to
- Optional features requiring extra permissions
- Marketing communications (opt-in)
- Participation in research or beta programs
3. How We Share Information
3.1 Service Providers and Subprocessors
We share data with vendors that process it on our behalf, under contract, for the purposes listed here. These are the categories of recipient we actually use today, grouped by what they do.
- Infrastructure and hosting: Amazon Web Services (compute, databases, file storage, content delivery, backups) and Expo (mobile app builds and over-the-air app updates).
- AI and model providers: OpenAI, Anthropic, Google (Gemini), and xAI. These power AI companions, twins, and assistants. The content and context you send to an AI feature is transmitted to the relevant provider so it can generate a response. They are contractually limited to providing the service to MyOrbit and are not permitted to train their own models on your content.
- Research and retrieval: SerpAPI, Perplexity, and Exa perform web lookups when you use research features. Replicate runs certain image and media generation models. Your search or generation prompt is sent to these services.
- Speech and voice: ElevenLabs generates synthetic speech for AI voices.
- Real-time calls: LiveKit (LiveKit Cloud) carries live audio and video for calls.
- Payments and subscriptions: Stripe (card payments, Stripe Identity for the age appeal in section 1.4, and Stripe Connect for creator payouts) and RevenueCat (in-app purchase and subscription management). These two are our only payment paths.
- Bank linking: Plaid, only if you choose to connect a bank account. See section 11.4.
- Communications: Twilio (SMS and one-time codes) and SendGrid together with Amazon SES (email).
- Advertising: Google AdMob serves ads inside the app. See section 3.8 and our Cookie Notice.
- Location lookup: ipinfo.io turns an IP address into an approximate city and region.
Service providers are bound by confidentiality and data processing terms.
We do not use Google Analytics, and we do not use Firebase Analytics. Product and usage analytics are first-party.
3.2 Safety and Moderation
To keep the platform safe we use:
- Automated content moderation: OpenAI's multimodal moderation model screens message text and uploaded images (including avatars, stories, and chat attachments) against safety categories such as sexual content involving minors, exploitation, harassment, self-harm, and violence. Content you send or upload is transmitted to that service for this check. Flagged material is blocked or escalated for human review.
- Human review: our Trust & Safety team reviews reports and escalations.
- NCMEC: where we identify apparent child sexual abuse material we remove it, terminate the account, preserve evidence, and report it, together with the account data a report must include. Our registration as a formal reporting entity with the NCMEC CyberTipline is in progress; until it completes we escalate these cases directly to law enforcement. See our Child Safety Policy.
- Stripe Identity: handles the optional government-ID appeal described in section 1.4.
- Crisis support organizations: where a user appears to be at risk and we surface or route them to help.
3.3 Legal Disclosures
We may disclose information when required by:
- Valid legal process (subpoenas, warrants)
- Emergency situations involving danger
- Our Terms of Service enforcement
- Protection of rights and safety
Please note: MyOrbit does not offer a zero-access messaging mode. We are technically able to access message content, so message content is within the scope of what valid legal process can reach. We require valid legal process before disclosing it, and we disclose only what the process covers.
3.4 Business Transfers
If MyOrbit is involved in a merger, acquisition, or sale:
- Your information may transfer to the new entity
- We'll notify you before any transfer
- The new entity must honor this Privacy Policy
3.5 Public Information
Information you make public is visible to:
- Other users (based on your privacy settings)
- Search engines (public profiles only)
- Third-party services you connect
3.6 Consent-Based Sharing
We share information when you:
- Direct us to share with specific parties
- Connect third-party accounts
- Participate in partnerships or promotions
- Use collaborative features
3.7 Aggregated Data
We may share anonymized, aggregated data that cannot identify you for:
- Industry research
- Platform transparency reports
- Academic studies
- Business intelligence
3.8 Selling and Sharing Your Data for Advertising
We do not sell your personal information for money. We do not accept payment in exchange for your personal data, and we are not a data broker.
We want to be straight with you about advertising, though, because "we never sell your data" is a narrower promise than it sounds. MyOrbit shows ads through Google AdMob. When you are served personalized ads, AdMob receives:
- your device's advertising identifier (IDFA on iOS, GAID on Android);
- an approximate location derived from your IP address; and
- your interactions with the ad, such as views and taps.
It does not receive your messages, your contacts, your precise GPS coordinates, your phone number, or your email address.
Under the California Consumer Privacy Act as amended by the CPRA, and under several other state privacy laws, passing an advertising identifier to an ad network in order to personalize ads counts as "sharing" for cross-context behavioral advertising, even though no money changes hands. We would rather tell you that plainly than hide behind the "no sale for monetary consideration" formulation.
How to opt out of that sharing:
- iOS: decline the App Tracking Transparency prompt when we show it, or turn MyOrbit off later under Settings → Privacy & Security → Tracking.
- Android: opt out of ads personalization, or delete your advertising ID, under Settings → Privacy → Ads.
- Any platform: email privacy@myorbit.ai and ask us to stop sharing your information for advertising. We will honour it.
If you opt out, you will still see ads. They will be non-personalized, meaning they are chosen without using your advertising identifier or a behavioral profile. Opting out reduces targeting; it does not remove advertising from the app.
4. Your Privacy Rights and Controls
4.1 Universal Rights
All users can:
- Access your personal data
- Update incorrect information
- Delete your account and data
- Download your information
- Control privacy settings
- Opt-out of non-essential data uses
4.2 Regional Privacy Rights
European Union (GDPR)
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making
- Lodge complaints with supervisory authorities
California (CCPA/CPRA)
- Right to know what data we collect
- Right to delete personal information
- Right to opt-out of "sale" or "sharing"
- Right to non-discrimination
- Right to correct inaccurate information
- Right to limit sensitive data use
Other Jurisdictions
We respect privacy rights under all applicable laws including those in Canada, Brazil, Australia, and other regions.
4.3 How to Exercise Your Rights
- In-App: Settings > Privacy > Your Data Rights
- Email: privacy@myorbit.ai — this is the route for access, correction, deletion, portability, and opt-out requests.
- Account deletion: available directly in the app at Settings → Delete Account. See section 6.3.
We do not currently operate a separate self-service privacy rights portal. Email is the mechanism, and it is monitored.
We'll respond within:
- 30 days (GDPR requirement)
- 45 days (CCPA, with possible extension)
- As required by applicable law
4.4 Choice and Control Tools
Privacy Settings
- Profile visibility controls
- Messaging preferences
- Content sharing options
- Relationship-based privacy levels
Communication Preferences
- Marketing opt-out
- Notification customization
- Email frequency settings
AI and Data Training
- Control AI feature access
- Manage digital twin data
Content Levels
- Turn the Mature and Adults Only content levels on or off at any time (adults only)
- Leave both off to stay on General content
5. Data Security
5.1 Technical Safeguards
- Encryption in Transit: TLS 1.3 for all connections
- Encryption at Rest: AES-256 storage-layer encryption on our databases, file storage, and backups, plus application-level encryption on selected fields. Not every individual field carries application-level encryption on top of the storage layer.
- Secure Infrastructure: cloud providers that hold SOC 2 attestations
- Access Controls: Role-based, least privilege principle
- Regular Audits: Security assessments and penetration testing
5.2 Organizational Measures
- Security training for all employees
- Strict confidentiality agreements
- Limited access to personal data
- Background checks for key personnel
- Incident response procedures
- Regular security updates
5.3 Your Security Role
Help keep your account secure:
- Use strong, unique passwords
- Enable two-factor authentication
- Keep your app updated
- Report suspicious activity
- Don't share login credentials
- Be cautious with public Wi-Fi
5.4 Breach Notification
If a breach affects your data:
- We'll notify you within 72 hours (where required)
- Provide clear information about the incident
- Offer guidance on protective steps
- Work with authorities as needed
6. Data Retention
6.1 Retention Periods
We keep data only as long as necessary:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Data | While account active + 30 days | Service provision |
| Messages (and their embeddings) | Stored while your account is active. Deleted or de-identified within 30 days of account closure, unless a legal hold or open safety investigation applies. | Conversation history, AI recall, safety |
| Voice messages and call recordings | Retained until you delete them, or until your account is closed and the 30-day window above has passed. We do not currently apply an automatic expiry to stored audio. | Playback, transcripts, call quality and safety review |
| Precise (GPS) location | Current value retained while your account is active, overwritten as it updates | Discovery, nearby and distance-based features |
| Contact hashes from Find Friends | Not stored — matched and discarded | Finding contacts already on MyOrbit |
| Age estimation selfie (the photo) | Not retained | Used for our age check |
| Age estimate result (bracket, confidence, estimated age, apparent gender) | While account active | Age-appropriate defaults without repeating the check |
| Transactions | 7 years | Tax/legal requirements |
| Safety Reports | 2 years | Platform safety |
| Deleted Content | 30 days in backups | Recovery/legal holds |
| Analytics | 90 days | Service improvement |
| Marketing | Until opt-out + 30 days | Preference processing |
6.2 Deletion Practices
When you delete data:
- It stops being visible or reachable in the product right away
- It is removed or de-identified in our active systems according to the schedule above
- Copies inside encrypted backups age out on the normal backup cycle, within 30 days
- It may persist longer where law or a legal hold requires it
- Aggregated or de-identified data may be retained
6.3 Account Deletion
You can close your account yourself, in the app, at Settings → Delete Account. You can also email privacy@myorbit.ai and ask us to do it.
What happens immediately:
- Your account is marked as deleted and closed.
- Every active session and sign-in token is invalidated, so you are signed out everywhere and cannot sign back in.
- Your profile stops being reachable to other users.
What happens after that:
- Your data is deleted or de-identified according to the retention schedule in section 6.1.
- Backup copies age out within 30 days on our normal backup rotation.
- We keep the limited records described in section 6.1 and in our Data Deletion Policy where the law requires it, for example transaction records for tax purposes and records relating to safety enforcement.
To be precise about the mechanism: deleting your account closes it and revokes access at once. It is not an instant, irreversible wipe of every copy of your data across every system, and we are not going to claim it is. The account is closed immediately; the underlying data is then removed on the schedule above.
7. International Data Transfers
7.1 Global Operations
MyOrbit is available globally, but our production systems run in the United States. If you use the Services from anywhere else, including the EU and UK, your personal data is transferred to and processed in the United States. Some of the subprocessors listed in section 3.1 may process data in other countries under their own arrangements.
7.2 Transfer Safeguards
We ensure appropriate protection through:
- Standard Contractual Clauses (SCCs) for EU-US transfers
- Adequacy decisions where available
- Binding corporate rules for intra-group transfers
- Your consent where required
7.3 Regional Data Storage
We do not currently offer regional data residency. We are not going to tell you that EU data stays in the EU, because today it does not — our primary infrastructure region is in the United States. If that changes we will update this section.
8. Children's Privacy
8.1 Age Requirements
- Minimum age: 13 years old (16 in EU)
- Adult features: 18+ only
- Business features: 18+ or with guardian approval
8.2 Parental Controls
For users 13-17, we provide:
- Parental linking and consent mechanisms
- Account monitoring tools
- Content filtering options
- Privacy settings management
- Data access and deletion rights
8.3 Minor Protections
Default protections for users under 18:
- Private profiles
- Limited adult contact
- Enhanced content filtering
- No access to the Mature or Adults Only content levels, which require a Confirmed Adult account
- No access to creator monetization
- Non-personalized advertising only. Users we know to be minors, and users whose age we have not been able to establish, are served ads that are not selected using an advertising identifier or a behavioral profile. We do not share a minor's advertising identifier with advertising partners. To be clear about what this does and does not mean: ads are still shown to minors. They are contextual and non-personalized, not absent.
8.4 How We Establish Age
- Phone number (all users)
- A selfie-based age estimate to confirm an account is adult, before the Mature or Adults Only content levels can be turned on. The selfie is used for our age check and is not retained.
- An optional government-ID appeal through Stripe Identity, used only to correct an estimate that wrongly read an adult as a minor. It is never required to reach any content level.
9. Platform-Specific Features
9.1 AI Features and Privacy
Aura and Personal AI Twins (FameWave OS)
- Your twin's data is private to your account. It is not shown to other users unless you choose to share or publish it.
- Twin context and personalization data are processed on our servers, and are sent to the AI providers in section 3.1 in order to generate responses. There is no on-device-only or local training mode, and we are not going to imply otherwise.
- You control your twin's personality and boundaries
- AI and human participants are labeled distinctly in the interface
EchoBurst OS (Business AI)
- Business data segregated from personal
- Audit trails for compliance
- Enterprise-grade security
- GDPR/CCPA compliant processing
9.2 Creator Economy
Look Ma I'm Famous
- IP protection for celebrity likeness
- 30-day grace period for claims
- Revenue sharing transparency
- DMCA compliance tools
AdWorks
- Optional advertising participation
- Opt-out mechanisms as described in section 3.8
- Revenue share transparency
- We do not sell personal data for money. Personalized advertising does involve "sharing" under CPRA — section 3.8 explains exactly what is shared and how to stop it.
9.3 How Messaging Is Stored and Encrypted
MyOrbit messaging runs in one mode, and it is the same for everyone:
- Messages are stored, so your history persists across devices and so AI recall works. See section 1.1.
- Encrypted in transit with TLS 1.3
- Databases, file storage, and backups encrypted at rest at the infrastructure layer, with additional application-level encryption on some message fields but not all of them
- Content processed for safety features
- AI features available
- Crisis support active
There is no alternative zero-access, end-to-end, or device-only mode to choose, and MyOrbit is technically able to access message content. If you need a messenger where the operator mathematically cannot read your messages, MyOrbit is not that product.
11. Third-Party Services
11.1 Integrated Services
When you connect third-party services (connectors):
- We request only the scopes the feature needs
- The permissions being requested are shown to you before you approve
- You can disconnect a connector at any time
- Disconnecting stops any further access. Data we already retrieved is then deleted or de-identified on the retention schedule in section 6.1, rather than vanishing at the moment you disconnect.
11.2 External Links
Our Services may contain links to third-party sites:
- We're not responsible for their practices
- Review their privacy policies
- Exercise caution sharing data
11.3 App Stores
When downloading from app stores:
- Additional terms may apply
- Store policies govern app distribution
- We comply with store requirements
11.4 Bank Account Linking (Plaid)
MyOrbit lets you connect a bank account, and this is live in the app. If you choose to do it, the connection is made using Plaid Inc.
- Your banking credentials go to Plaid, not to us. You enter your online banking username and password inside Plaid's own interface. MyOrbit does not see, receive, or store those credentials.
- What we receive from Plaid: information about the accounts you authorize, which can include account and institution details, account balances, and transaction history.
- What we use it for: the feature you connected it for, such as payouts or letting an AI feature reason about your account activity. It is not used for advertising, and it is not shared with advertising partners.
- Plaid's own role: Plaid processes your information under its own privacy policy at plaid.com/legal, and acts as an independent controller for parts of that processing. Please read it before connecting an account.
- Disconnecting: you can ask us to disconnect a linked account at any time by emailing privacy@myorbit.ai, and you can also manage or revoke connections yourself through Plaid at my.plaid.com. Disconnecting stops future access.
12. Contact Us
12.1 Privacy Inquiries
Data Protection Officer
Email: privacy@myorbit.ai
This policy: myorbit.ai/privacy
General Privacy Questions
Email: privacy@myorbit.ai
Support: support@myorbit.ai
12.2 Mailing Address
MyOrbit, Inc.
730 Moreno Ave
Palo Alto, CA 94303
United States
12.3 Response Times
- Urgent safety issues: 24 hours
- Privacy rights requests: 30 days
- General inquiries: 48-72 hours
- Complex requests: 45 days with notice
12.4 Supervisory Authorities
EU residents may contact their local Data Protection Authority.
California residents may contact the California Privacy Protection Agency.
13. Changes to This Policy
13.1 Updates
We may update this Policy to reflect:
- Legal or regulatory changes
- New features or services
- Security improvements
- User feedback
13.2 Notification
For material changes:
- 30 days advance notice
- Email and in-app notifications
- Opportunity to review changes
- Option to close account if disagreeing
13.3 Version History
- Current Version: 3.4.0
- Effective: July 30, 2026
- Previous versions: Available on request via privacy@myorbit.ai
14. Additional Provisions
14.1 California Privacy Rights
"Shine the Light" Law: California residents can request information about personal data shared with third parties for marketing.
CCPA request metrics: where the CCPA requires a business to publish annual request metrics, we will publish ours in this section once we are within scope and have a full reporting year to report on. We would rather leave this stated plainly than publish placeholder numbers.
14.2 Legal Basis for Processing (GDPR)
We process personal data based on:
- Contract: To provide Services you requested
- Legal Obligation: To comply with laws
- Vital Interests: To protect life/safety
- Legitimate Interests: To operate and improve Services
- Consent: For optional processing activities
14.3 Automated Decision-Making
We use automated systems for:
- Content moderation
- Fraud detection
- Age estimation
- Personalization
You can request human review of significant automated decisions.
Acknowledgment
By using MyOrbit, you acknowledge that you have read and understood this Privacy Policy. We're committed to protecting your privacy while providing innovative AI-powered experiences. Thank you for trusting us with your personal information.
The short version:
- Your messages are stored, and we can read them
- We collect precise location if you allow it, and use it for discovery and personalization
- Your address book is only ever sent to us as one-way hashes
- We do not sell your data for money; personalized ads do involve sharing with Google AdMob, and you can opt out
- Messaging runs in one mode; there is no zero-access option
- You can delete your account in the app at any time
- We're here to help with privacy questions