Orbis Privacy Policy

Last Updated: January 2025

Introduction

Orbis is an AI-powered relationship workspace that helps founders and early teams manage professional relationships across fundraising, hiring, and partnerships. This Privacy Policy explains what information we collect through Orbis, how we use, store, and share it, and your rights regarding your personal data.

By using Orbis, you agree to the data practices described in this policy. If you have any questions, please contact us at support@meetorbis.com.

Information We Collect

1. Account Information

When you sign up for Orbis, we collect personal information such as your name and email address. If you register via Google OAuth, we receive your Google account information (e.g., your Google profile name and email) to create your Orbis account. This information is used to identify you and provide access to the Orbis service.

2. Contacts and Relationship Data

Orbis allows you to input and manage contact details, notes, and interaction history. You may manually enter or import contact information (names, emails, phone numbers, company details, etc.) and relationship context. All such contact data and any notes, tags, or relationship intelligence you add are stored in our database as part of providing the relationship workspace functionality.

Chrome Extension Data

If you use the Orbis Chrome extension, we collect contact information you choose to import from supported platforms (such as Luma event pages). This may include:

  • Display names
  • Profile URLs
  • Social media links
  • Company and job title (when available)
  • Event host information

This data is imported only when you initiate the import action. We may use AI to enrich imported contacts with additional context from publicly available information.

3. Google Integrations

If you choose to connect your Google account, Orbis will access certain Google data with your explicit permission:

  • Google Contacts: Orbis can import your saved Google Contacts and "Other contacts" (automatically created by Gmail from your email interactions) to provide a complete view of your professional network.
  • Gmail (Email Threads): Orbis can import email thread metadata and message content from your Gmail account. This may include email subjects, timestamps, sender/recipient addresses, and email body content.
  • Google Calendar: Orbis can import your Calendar events (event titles, descriptions, dates/times, locations, attendees, etc.) to help track interactions and relationship context.

All Google integration data is fetched only after you explicitly grant Orbis access via Google's OAuth consent. You can revoke Orbis's access to your Google data at any time via Google's security settings at https://myaccount.google.com/permissions or by disconnecting the integration within Orbis.

4. AI-Generated Insights

Orbis offers AI-powered features to enhance your relationship management experience, including email draft generation, relationship sentiment analysis, and communication summaries. To enable these features, relevant data (such as email content or contact context) may be securely sent to our AI service providers for processing. These providers analyze the content and return insights, drafts, or suggestions, which we display to you.

5. Automatically Collected Information

When you use Orbis, we automatically collect certain technical information, including:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Pages visited and features used
  • Timestamps and session duration
  • Referring URLs

We collect this information through cookies, log files, and similar technologies to improve our service and maintain security.

How We Use Your Information

We use the information we collect to:

  • Provide the Service: Create and maintain your account, import and organize contacts, sync with connected services, and deliver AI-powered relationship intelligence features.
  • Improve the Service: Analyze usage patterns to enhance functionality, fix bugs, and develop new features.
  • Communicate with You: Send service-related notifications, respond to support requests, and provide updates about Orbis.
  • Ensure Security: Detect and prevent fraud, abuse, and unauthorized access.
  • Comply with Legal Obligations: Meet our legal and regulatory requirements.

We do not sell your personal information or use it for advertising purposes.

How We Use Google User Data

Orbis's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Orbis:

  1. Only uses Google user data to provide user-facing features that are prominent in our application's user interface. We use Gmail data to display your email history with contacts, generate AI-powered email drafts, and provide relationship context. We use Calendar data to track meetings and interactions. We use Contacts data to enrich your relationship database.
  2. Does not transfer Google user data to third parties except:
    • When necessary to provide or improve user-facing features (e.g., sending email content to our AI provider to generate a draft response)
    • With your explicit consent
    • For security purposes (e.g., investigating abuse)
    • To comply with applicable laws
  3. Does not use Google user data for advertising purposes. We do not use your Gmail, Calendar, or Contacts data to serve you ads, create advertising profiles, or for any marketing purposes.
  4. Does not allow humans to read your Google user data unless:
    • You have given us explicit consent to view specific data (e.g., for support purposes)
    • It is necessary for security purposes (e.g., investigating a bug or abuse)
    • It is necessary to comply with applicable law
    • The data is aggregated and anonymized for internal operations
  5. Limits our AI provider's use of your data. When we send email or calendar content to our AI providers (Anthropic/OpenAI) for processing, it is solely to generate the specific feature output you requested (such as an email draft or summary). Our AI providers do not use your data to train their general models.

How We Store Your Information

Data Storage and Location

Your data is stored on secure servers. We use industry-standard cloud infrastructure providers including:

  • Vercel for application hosting
  • PostgreSQL databases with encrypted connections for data storage
  • Google Cloud Platform for certain processing functions

Data may be stored and processed in the United States or other countries where our service providers maintain facilities. By using Orbis, you consent to the transfer of your data to these locations.

Data Retention

We retain your personal data for as long as your account is active or as needed to provide you services. Specifically:

  • Account data is retained until you delete your account.
  • Contact and relationship data is retained until you delete it or your account.
  • Google-synced data is retained until you disconnect the integration or delete your account.
  • Usage logs are retained for up to 12 months for security and analytics purposes.

When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal, regulatory, or security purposes. Residual copies may remain in backup systems for up to 90 days before being permanently deleted.

How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

Service Providers

We share data with third-party service providers who help us operate Orbis:

  • AI Service Providers (Anthropic, OpenAI): We send email content and contact context to generate AI features like email drafts and relationship insights. These providers process data only as instructed and are bound by confidentiality agreements.
  • Cloud Infrastructure (Vercel, Google Cloud Platform): Our hosting providers store and process your data to deliver the service.
  • Analytics Providers: We may use analytics tools to understand how users interact with Orbis.

Legal Requirements

We may disclose your information if required by law, legal process, or government request, or if we believe disclosure is necessary to:

  • Comply with applicable laws or regulations
  • Enforce our Terms of Service
  • Protect our rights, privacy, safety, or property
  • Protect users or the public from harm

Business Transfers

If Orbis is involved in a merger, acquisition, or sale of assets, your data may be transferred. We will notify you via email and/or prominent notice in the app before your data is transferred and becomes subject to a different privacy policy.

Data Security

We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption: Data is encrypted in transit (TLS/SSL) and at rest.
  • Access Controls: Access to user data is restricted to authorized personnel who need it to perform their job functions.
  • Secure Authentication: We use Google OAuth for secure authentication, meaning we never receive or store your Google password.
  • Regular Security Reviews: We regularly review and update our security practices.

While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

Your Rights and Choices

Access and Portability

You can access your personal data through your Orbis account. You may export your contacts and relationship data at any time.

Correction

You can update or correct your account information and contact data directly within Orbis.

Deletion

You can delete individual contacts, notes, and interaction data within Orbis. To delete your entire account and all associated data, contact us at support@meetorbis.com or use the account deletion feature in settings.

Revoking Google Access

You can disconnect your Google integration at any time within Orbis or by visiting https://myaccount.google.com/permissions. This will stop new data from syncing, and you can request deletion of previously synced Google data.

Opt-Out of Communications

You can opt out of non-essential communications by clicking "unsubscribe" in our emails or adjusting your notification preferences in settings.

Rights for EEA/UK Residents

If you are located in the European Economic Area or United Kingdom, you have additional rights under GDPR, including:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent

To exercise these rights, contact us at support@meetorbis.com. You also have the right to lodge a complaint with your local data protection authority.

Rights for California Residents

California residents have rights under the California Consumer Privacy Act (CCPA), including:

  • Right to know what personal information is collected
  • Right to know whether personal information is sold or disclosed
  • Right to say no to the sale of personal information (we do not sell your data)
  • Right to access your personal information
  • Right to equal service and price

To exercise these rights, contact us at support@meetorbis.com.

Cookies and Tracking Technologies

Orbis uses cookies and similar tracking technologies to:

  • Essential Cookies: Maintain your session and authentication state.
  • Analytics Cookies: Understand how users interact with Orbis to improve our service.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using Orbis.

Children's Privacy

Orbis is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at support@meetorbis.com, and we will promptly delete it.

Third-Party Links

Orbis may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with your personal information.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice in the app at least 15 days before the changes take effect. Your continued use of Orbis after the updated Privacy Policy becomes effective constitutes your acceptance of the changes.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Orbis Support Team

Email: support@meetorbis.com

For data protection inquiries, you may also reach our team at privacy@meetorbis.com.

Report security issues to security@meetorbis.com.

By using Orbis, you acknowledge that you have read and understood this Privacy Policy.