Orbit Logo
Orbit
Back to home
Orbit Logo

Privacy First

Last updated: June 2026

Orbit is designed to help you remember your work, not collect your data. Almost everything stays on your Mac, and you remain in complete control of what Orbit stores, processes, and remembers.

1. What Orbit Captures

Orbit captures the following on your device to build your personal memory:

  • Active app and window title. Orbit tracks which application is in focus and what its window is titled, captured whenever the title changes.
  • On-screen text. The readable text visible in your active app's interface, accessed via macOS's built-in Accessibility API. This requires the Accessibility permission you grant during setup. Password fields are never read. They are identified and skipped before any text is accessed, at every level of the interface.
  • Browser URL and page title. The URL and title of your active browser tab. Captured natively from Chrome, Safari, Arc, Brave, and Edge using macOS Automation, and optionally via the Orbit Chrome extension for richer context like article text and search queries.
  • Clipboard text. Text you copy. Secrets are detected and replaced with [REDACTED] before any storage. The original value is never written to disk.
  • File activity. When you create, modify, or move files in your Documents, Desktop, and Downloads folders. Only the file name and path are recorded. File contents are never read.
  • App launches and quits. Which applications you open and close, to help Orbit understand the flow of your work sessions.
  • System events. When your screen locks or unlocks, and when your Mac sleeps or wakes. Used to mark session boundaries in your memory timeline.

Orbit does NOT capture:

  • File contents (only file names and paths)
  • Clipboard content from password managers (1Password, Bitwarden, Keychain, etc. are excluded by default)
  • Passwords, API keys, credit card numbers, or other secrets (detected and redacted before any storage)
  • Password fields or secure text inputs in any application (skipped unconditionally by the Accessibility reader)
  • Screenshots or video of your screen
  • Audio or microphone input
  • Network traffic, DNS queries, or HTTP request contents
  • Email message bodies or end-to-end encrypted messages

2. What Orbit Cannot See

For absolute clarity, Orbit cannot:

  • Read the contents of arbitrary files on your disk
  • Access your email or messaging accounts
  • Access saved passwords in your browser or keychain
  • Read messages from end-to-end encrypted services, unless they appear in a window title you have shared
  • Turn on your microphone or camera
  • Read text in apps that are not currently the focused foreground application

3. Where Your Data Is Stored

All captured activity is stored locally on your Mac at ~/.orbit/ in an SQLite database and a local vector index. This data never leaves your device unless you explicitly opt in to cloud sync (not yet available).

Orbit also transmits non-personal telemetry for crash reporting (Sentry) and anonymous usage analytics (PostHog). These never include captured content, query text, or anything that identifies what you were working on. You can disable analytics at any time in the app.

4. What Gets Sent to the Cloud

To generate session summaries and answer your recall questions, Orbit sends the following to cloud AI services via an encrypted proxy:

  • App names, window titles, browser URLs, and file paths from your recent activity. This gives the AI enough context to write a useful summary of what you worked on.
  • On-screen text snippets, already filtered to remove any detected secrets before they leave the app.
  • Short AI-generated session summaries of your activity, for example: “Worked on a Next.js project in VS Code, reviewed billing.service.ts, and browsed Stripe documentation.”
  • Your recall queries, the questions you ask Orbit.

Orbit never sends:

  • Raw clipboard content
  • File contents
  • Passwords, API keys, or other secrets. These are replaced with [REDACTED] before Orbit ever touches them.

Orbit currently uses Claude (Anthropic), Gemini Flash (Google), and Voyage AI to power AI features. These providers process only the information needed to fulfil your request and all communication is encrypted in transit.

5. Analytics

Orbit collects anonymous, non-personal usage analytics to understand how the app is being used. This includes:

  • Whether the app was opened
  • That a recall query occurred (never the contents of the query)
  • Whether a memory session was generated

We never collect query content, clipboard content, or anything you have typed. Analytics can be disabled at any time in the app's settings.

6. Your Controls

You have complete control:

  • Pause all capture at any time from the menu bar
  • Exclude specific apps from being tracked
  • Exclude specific websites from being tracked
  • Turn off on-screen text capture independently
  • Turn off file activity monitoring independently
  • Choose which folders are watched for file activity
  • View everything Orbit has stored in the Memory Viewer
  • Delete individual events, sessions, or everything at once
  • One-click full memory wipe with no recovery

7. Updates to This Policy

As Orbit evolves, this policy may be updated. Significant changes will be communicated through the app or website. The date at the top of this page reflects the most recent revision.

8. Contact

Questions about privacy? Email: saadaanedu@gmail.com