Where your data lives
How access is controlled
Access to your account data is controlled by sign-in requirements, optional multi-factor authentication (MFA), and server-side row-level security (RLS) policies in the database. Protected routes in the app check your authentication and role before showing sensitive screens. These protections apply on the server, not just in the browser.Information to keep private
Never give Orbit, support, or an untrusted third party:- Your account password or one-time MFA code
- Authenticator enrollment secret, recovery material, or password-reset link
- Private access tokens or workspace invitation codes
- Payment-card security code or full payment credentials
- Source-code signing credentials, service credentials, or provider keys
Files and AI-generated answers
Uploading a file or using voice can transmit content to the configured backend and external providers. Check the current privacy notice and organization policy before submitting company, client, health, financial, legal, or otherwise sensitive data. Remove unnecessary personal information before upload. Treat generated text, code, plans, and images as drafts. Check accuracy, licenses and permissions, accessibility, safety, security, and suitability before relying on or publishing them. For legal, medical, financial, or other high-impact decisions, consult an appropriately qualified person.Shared devices
Sign out after use. Do not store passwords on public computers. If you suspect another person used your account, change your password through the official flow, review active sessions in Settings if available, and contact support.Account deletion
You can request account deletion through the confirmation form in your settings. This starts a deletion process handled by a server-side function. Because deletion involves multiple systems, completion timing may vary and is not guaranteed to be immediate. Details such as backup retention and provider data treatment are controlled by backend processes and may differ based on current operations.Final user checklist
Before using Orbit, confirm that you are signed in to the right account and workspace. Before submitting a prompt or file, confirm it contains only information you are allowed to share. Before approving a device action or purchase, verify the destination and consequences. Before deleting anything, read the confirmation and consider whether you need a copy. When something fails, retry cautiously and contact support with enough context to help, but never with passwords, MFA codes, private keys, or full payment details.Related topics
Privacy overview
Learn how Orbit AI handles your data, ads, analytics, and consent.
Manage ad preferences
Opt in or out of personalized advertising and product analytics.