Privacy Policy
Last updated: September 2026
Introduction
Orbit is a personal habit tracking app. We take your privacy seriously and are committed to protecting your personal data. This policy explains what data we store, how we use it, and your rights under the LGPD (Lei Geral de Proteção de Dados) and equivalent data-protection laws.
Who Controls Your Data
The data controller is TL SOFTWARE ENGINEERING LTDA (CNPJ 58.429.979/0001-06), the company that operates Orbit. For privacy requests or questions, contact our data protection lead at contact@useorbit.org.
Data We Store
Account information: name and email address (via email signup or Google OAuth)
Habit data: habits you create, completion logs, schedules, tags, and goals
AI chat messages: conversations with the Orbit AI assistant
Preferences: language, timezone, color scheme, and notification settings
Device data: a push notification token (to deliver reminders) and crash diagnostics with personal identifiers removed. On Orbit for Android before version 1.3.35, also your device advertising identifier, which the ad SDK could access
How We Use Your Data
To provide and operate the Orbit service
To personalize your experience with AI-powered insights and summaries
To send push notifications and habit reminders you have configured
Third-Party Services
We use the following services to operate Orbit:
Google OAuth: for sign-in directly with Google
Google AdMob: Orbit for Android before version 1.3.35 could show ads to free users and could use your device advertising identifier for them. Version 1.3.35 and later show no ads.
Stripe - for subscription payment processing
Firebase Cloud Messaging - for push notifications
OpenAI - for AI chat features and daily summaries
Amazon SES (us-east-2): for transactional and marketing emails
Google Play Billing - for subscription purchases on Android
Sentry - for crash and error diagnostics, with personal identifiers removed
PostHog (US Cloud): for product analytics linked to an account identifier and plan details, plus web traffic and performance analytics; we do not send habit or chat content
Render (Ohio, United States): for web and API hosting and the database
Amazon S3 (us-east-2): for file uploads
Cloudflare Turnstile: for bot protection during sign-in
How Long We Keep Your Data
We retain your data only as long as needed to provide the service:
Account data: kept for as long as your account is active.
Authentication sessions and push tokens: kept while active and removed on logout, token expiry, or device unsubscribe.
AI chat history: kept while AI features are enabled and removed when you delete your account.
Sent reminder, slip alert, and streak freeze records: kept for 90 days from the record date.
Records deleted for offline sync: kept for 31 days before permanent removal.
Google Calendar import suggestions that you do not import: kept for 14 days.
Operational request and billing records: processed requests and Google Play billing notifications are kept for 30 days; processed Stripe webhook events are kept for 90 days.
Account deletion: personal data is permanently erased 7 days after confirmation, or 7 days after the end of the current paid period, whichever is later, except where the law requires limited records.
Google Account & Calendar Access
If you connect Google, we request only the scopes needed for the features you use:
Basic profile and email, to create and identify your account.
Read access to your Google Calendar events, used solely to show events alongside your habits and to suggest imports.
We never expose raw Google event payloads to the AI, and you can disconnect Google at any time, which deletes the stored access and refresh tokens.
Where Your Data Is Stored
Render hosts the web application, API, and database in Ohio, United States. Orbit uses Amazon SES for transactional and marketing emails and Amazon S3 for file uploads in us-east-2 (Ohio, United States). PostHog processes product, web traffic, and performance analytics in its US Cloud. Other processors, including OpenAI, Stripe, Google, and Cloudflare Turnstile, may process data outside Brazil. International transfers to these providers rely on the safeguards the LGPD allows for international transfers, including contractual commitments from each provider.
AI & Automated Processing
Orbit's AI assistant, Astra, processes your habit and chat data to generate summaries, retrospectives, and suggestions. This is assistive only and does not make legally significant decisions about you. You can disable AI summaries at any time in AI Settings, and you may object to automated processing by contacting us.
Age Requirement
Orbit is not directed to children. You must be at least 13 years old to create an account. If we learn that we have collected data from a child under 13 without appropriate consent, we will delete it.
Your Right to Export Your Data
You can download a copy of all your Orbit data (habits, logs, goals, tags, and settings) as a JSON file from the Profile page, in line with your data-portability rights under LGPD Art. 18.
We Do Not Sell Your Data
Your data is not sold to third parties and is not used to train AI models. Your habit data and conversations are used solely to provide you with the Orbit service.
Data Security
All connections to Orbit use HTTPS encryption. Authentication uses rotating refresh sessions. Payment information is handled entirely by Stripe and never touches our servers.
Data Deletion
You can delete your account and all associated data at any time from the Profile page in the app. The process requires email confirmation:
1. Go to Profile and tap "Delete account"
2. A confirmation code will be sent to your email
3. Enter the code to confirm deletion
7 days after confirmation, or 7 days after the end of your current paid period, whichever is later, all data is permanently deleted, including habits, completion history, AI conversations, and settings. This action is irreversible.
Contact
If you have questions about this privacy policy or your data, contact us at contact@useorbit.org.