Privacy Policy
Last updated: September 20, 2026
This Privacy Policy explains what data OrbitOracle.AI handles, why we handle it, and the choices you have. It applies to the OrbitOracle.AI app and website (the "Service"), operated by Sheehan Gillis. It should be read together with our Terms of Service.
The short version: your chat history and settings stay in your own browser. To answer a message we send that message to our server and to an AI model provider — we do not sell your data, and you can turn anonymous usage statistics off in Settings.
1. Data we handle
| Data | Where it lives | Why |
|---|---|---|
| Messages you type, and images you attach | Stored in your browser (local storage) on your device; transmitted to our server and our AI provider to generate the answer | To provide the Service and return an answer |
| Preferences, saved ideas, identity choice, skin | Your browser (local storage) on your device | To remember your settings between visits |
| Anonymous usage statistics (feature events, error counts, rough device/browser type) | Our analytics store | To understand what is used and improve the product; you can opt out in Settings |
| Technical logs (IP address, timestamps, request status) | Our hosting and AI providers' logs | Security, abuse prevention, rate limiting and debugging |
| Payment details (paid plans only) | Processed by Stripe and/or PayPal; we receive a customer id, plan and status | To bill your subscription and manage your plan |
| Contact details you send us (for example, a support email) | Our email inbox | To reply to you |
If you enter your own API key in Settings, it is stored on your device and used only to call the AI provider directly. It is not sent to us.
2. What we do not do
- We do not sell or rent your personal data.
- We do not use your chats to build advertising profiles.
- We do not keep a server-side copy of your chat history on the public web build.
- We do not knowingly collect data from anyone under 18.
3. How we use data
- to provide, operate and secure the Service;
- to generate the answers you ask for;
- to enforce free-tier limits and prevent abuse;
- to measure anonymous, aggregated usage so we can improve the product;
- to process payments and provide support;
- to comply with legal obligations and enforce our Terms.
4. Anonymous usage data and your choice
The app sends aggregate counts of which features get used — for example "a message was sent" or "the stats card was opened". What we store is an allow-listed event name and how many times it happened on a given day. Nothing else: no identifier of any kind is attached, no message text, no file, no memory and no account. The random anonymous id the app keeps is stored in your browser only and is never transmitted.
What is not collected: the contents of your messages and attachments, your files, your projects, your notes and sheets, and your device memory. Those are transmitted only to generate the answer you asked for (see section 2).
How long we keep it: daily event counts are kept for up to 400 days and then expire. To stop the endpoint being abused we also keep, for at most one hour, a one-way salted hash of the connecting address — only to count requests from one client. It is never joined to the event counts, never written next to them, and the salt changes daily so one day's hash cannot be matched to another's.
You can stop all of it at any time: open Settings → Privacy & anonymous usage data and uncheck the box. Anything already queued on your device is deleted at that moment.
5. Sharing with service providers
We share data only with providers that help us run the Service, and only as needed:
- AI model provider — receives your message and attachments to generate the answer.
- Hosting / CDN — serves the app and processes requests, including technical logs.
- No script CDN — the interface's tooltip library is served from our own origin, so there is no third-party script or style host that sees your visits.
- Page reader (api.allorigins.win) — when you ask the app to read a web page, that page is fetched through this public proxy, which therefore sees the address you asked about. If you would rather not use a third party, do not use the read-a-page feature; nothing else depends on it.
- Payment processors (Stripe, PayPal) — handle subscription payments.
- Email provider — delivers support and account email.
- Legal and safety — where required by law, or to protect rights, safety and the integrity of the Service.
Some of these providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for those transfers.
6. Device storage, recovery, and optional backup
Your chat, preferences, documents, memory and session state are kept in local storage on your device, and the app works without any account and without a server-side copy of your chats. A service worker caches the app so it can load offline.
Device Vault. OrbitOracle.AI generates a random encryption key on your device and keeps an encrypted (AES-256-GCM) copy of your local data in that device's browser storage. That key is protected by a 24-word recovery phrase which is shown to you once and is never stored by OrbitOracle.AI. If your browser storage is cleared without your asking, OrbitOracle.AI restores your data from the encrypted device copy on the next launch and tells you that it did.
Cloud backup is optional. You may export one encrypted backup file and keep it wherever you choose — including a cloud drive you own — or not at all. The file contains only ciphertext and the wrapped key; it never contains your recovery phrase, and OrbitOracle.AI never receives a copy and cannot read it. Without your recovery phrase the file cannot be opened by anyone, including us.
Clearing your browser storage or using the in-app "Clear All" removes local data. If you have kept your recovery phrase and an encrypted backup, you can restore it on this or another device. If you have neither, the data cannot be recovered — no one, including OrbitOracle.AI, holds a copy.
7. Retention
Messages are processed to produce your answer and are not kept as a server-side chat history on the public build. Technical logs and anonymous usage data are kept for a limited period for security and product analysis. Payment records are kept as long as required for tax and accounting law. Support emails are kept while needed to help you.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete or restrict the processing of your personal data, to object to processing, to data portability, and to withdraw consent. You can exercise most of these directly in the app (clear your local data, turn off anonymous usage data, cancel your plan). For anything else, email sheehangillis@proton.me. We will respond within the time required by applicable law.
9. Security
We use reasonable technical and organisational measures to protect data, including encryption in transit (HTTPS). No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Keep your device and access codes safe.
10. Children
OrbitOracle.AI is not directed to children. You must be at least 18 years old, or the age of majority in your jurisdiction, to use the Service. If you believe a minor has provided us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will change the "Last updated" date and, for material changes, provide reasonable notice in the app. Continued use after the changes take effect means you accept the updated policy.
12. Contact
Privacy questions or requests: sheehangillis@proton.me.