> ## Documentation Index
> Fetch the complete documentation index at: https://documentation.orbitdev.org/llms.txt
> Use this file to discover all available pages before exploring further.

# How Orbit AI Stores and Protects Your Data

> Learn where your Orbit AI data lives, how it is protected, and what happens when you request account deletion.

Orbit AI stores different types of data in different places depending on what it is and how it is used. This page explains where your data lives, how access is controlled, and what to expect if you request account deletion.

## Where your data lives

| Data | Location |
| - | - |
| **Auth session** | Stored on your device by the Supabase client. |
| **Local preferences** | Sidebar state and selected workspace ID are kept in your browser's localStorage. |
| **Account data** | Stored in Orbit's cloud database, including your profile, plan, token balance, chat history, and workspace memberships. |
| **Avatars and files** | Uploaded to Orbit's cloud storage buckets. Mission artifacts use short-lived signed URLs. |
| **AI requests** | Sent from Orbit's servers to the configured AI providers. Your prompts are not sent directly from your browser to the provider. |
| **Payments** | Handled by Stripe. Orbit does not store your full payment card details. |

## How access is controlled

Access to your account data is controlled by sign-in requirements, optional multi-factor authentication (MFA), and server-side row-level security (RLS) policies in the database. Protected routes in the app check your authentication and role before showing sensitive screens. These protections apply on the server, not just in the browser.

## Information to keep private

Never give Orbit, support, or an untrusted third party:

* Your account password or one-time MFA code
* Authenticator enrollment secret, recovery material, or password-reset link
* Private access tokens or workspace invitation codes
* Payment-card security code or full payment credentials
* Source-code signing credentials, service credentials, or provider keys

End users do not need backend credentials to use the hosted application.

## Files and AI-generated answers

Uploading a file or using voice can transmit content to the configured backend and external providers. Check the current privacy notice and organization policy before submitting company, client, health, financial, legal, or otherwise sensitive data. Remove unnecessary personal information before upload.

Treat generated text, code, plans, and images as drafts. Check accuracy, licenses and permissions, accessibility, safety, security, and suitability before relying on or publishing them. For legal, medical, financial, or other high-impact decisions, consult an appropriately qualified person.

## Shared devices

Sign out after use. Do not store passwords on public computers. If you suspect another person used your account, change your password through the official flow, review active sessions in Settings if available, and contact support.

## Account deletion

You can request account deletion through the confirmation form in your settings. This starts a deletion process handled by a server-side function. Because deletion involves multiple systems, completion timing may vary and is not guaranteed to be immediate. Details such as backup retention and provider data treatment are controlled by backend processes and may differ based on current operations.

## Final user checklist

Before using Orbit, confirm that you are signed in to the right account and workspace. Before submitting a prompt or file, confirm it contains only information you are allowed to share. Before approving a device action or purchase, verify the destination and consequences. Before deleting anything, read the confirmation and consider whether you need a copy. When something fails, retry cautiously and contact support with enough context to help, but never with passwords, MFA codes, private keys, or full payment details.

## Related topics

<CardGroup cols={2}>
  <Card title="Privacy overview" icon="shield-halved" href="/privacy/overview">
    Learn how Orbit AI handles your data, ads, analytics, and consent.
  </Card>

  <Card title="Manage ad preferences" icon="sliders" href="/privacy/manage-ad-preferences">
    Opt in or out of personalized advertising and product analytics.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.