Privacy Policy
Orbis (“Orbis,” “we,” “us,” or “our”) is a local-first AI workspace and productivity application provided by Orbis.
This Privacy Policy explains how information is processed when you use the Orbis desktop application, the Orbis website at https://www.orbis-intelligence.com/, Orbis integrations, and related services.
We designed Orbis around a simple principle:
Your work should remain on your device whenever technically possible.
Orbis is designed to perform a substantial amount of its processing locally. Some features, such as connecting GitHub, Google, GitLab, Notion, Discord, Spotify, other third-party services, or using external AI models, necessarily require communication with those services.
This Privacy Policy explains those situations.
1. Who We Are
The data controller or responsible entity for Orbis is:
Orbis
201 Hauz Khas, New Delhi 110016, India
Email: neilsarjal@gmail.com
Website: https://www.orbis-intelligence.com/
Questions about this Privacy Policy or your personal information may be sent to the email address above.
2. Information Orbis Processes
The information Orbis processes depends on which features you choose to use.
2.1 Information Stored Locally on Your Device
Orbis may store information locally including:
- application preferences;
- projects and project metadata;
- generated files;
- conversation or agent history;
- integration connection metadata;
- user-created workflows;
- application configuration;
- local activity history;
- AI-generated outputs;
- authentication state;
- encrypted credentials for services you connect.
Local information is generally stored on the computer where Orbis is installed.
We do not automatically receive locally stored information merely because you use Orbis.
2.2 Connected Account Information
You may choose to connect third-party services such as:
- GitHub;
- GitLab;
- Google;
- Notion;
- Discord;
- Spotify;
- and other integrations that Orbis may support in the future.
When you connect a service, that provider may provide Orbis with information necessary to establish the connection, such as:
- account identifier;
- username;
- display name;
- profile image;
- email address, where authorized;
- workspace or organization identifier;
- repositories, workspaces or resources you authorize;
- OAuth access or refresh credentials;
- permissions or scopes granted to Orbis.
Orbis requests access only to permissions required for the features you choose to use.
Where the provider allows it, Orbis may progressively request additional permissions only when a feature requiring those permissions is used.
3. OAuth Credentials and Authentication
Orbis uses industry-standard authorization mechanisms such as OAuth 2.0 and PKCE to connect third-party accounts.
We do not ask for your provider password.
For example, when connecting GitHub, Google, GitLab or another service, authentication takes place on that provider's own website or authorization interface.
The provider then gives Orbis an authorization credential instead of giving Orbis your password.
Credentials stored on your device
Where supported by the platform, OAuth access and refresh credentials are encrypted before being stored locally.
Orbis is designed so that raw OAuth credentials are not exposed to:
- the ordinary application interface;
- AI prompts;
- logs;
- browser local storage;
- unencrypted application configuration.
Disconnecting an integration removes the corresponding local credentials and may also revoke the credential with the provider where supported.
4. Orbis Authentication Relay
Some providers require confidential application credentials that cannot safely be embedded inside a desktop application.
For those integrations, Orbis may use an authentication service operated at:
auth.orbis-intelligence.com
The authentication relay exists only to securely complete the authorization process.
For example:
Orbis → Orbis authentication relay → GitHub → Orbis authentication relay → Orbis
The relay may temporarily process:
- authorization session identifiers;
- OAuth state information;
- provider authorization codes;
- temporary OAuth credentials;
- security and device-binding information necessary to prevent replay or misuse;
- limited network and security metadata.
Authentication sessions and credential handoffs are designed to be short-lived and single-use.
The relay is not intended to permanently store:
- your projects;
- your source code;
- your conversations;
- your documents;
- your design files;
- your connected-service content;
- your long-term OAuth credentials.
Once an authentication credential has been securely delivered to Orbis, temporary authentication information is deleted or allowed to expire according to the security requirements of the authorization flow.
5. Information From Connected Services
Once you authorize a third-party integration, Orbis may access information from that service when necessary to perform an action you request.
For example, if you connect GitHub and ask Orbis to inspect a repository, Orbis may process:
- repository names;
- branches;
- files;
- source code;
- issues;
- pull requests;
- commits;
- related metadata.
If you connect Google services, information processed may include, depending on the permissions you explicitly grant:
- files and file metadata from Google Drive;
- calendar events;
- email messages or drafts;
- account profile information.
If you connect Notion, information may include pages, databases and content that you specifically authorize.
Orbis does not obtain unrestricted access to a third-party account merely because that provider is supported. Access depends on the permissions you grant.
6. AI Providers
Orbis may allow you to use AI models, coding assistants or AI providers.
Depending on your configuration, these may include third-party AI services.
When an external AI provider is used, information necessary to complete your request may be sent to that provider. This may include:
- your prompt;
- relevant conversation context;
- selected project information;
- source code;
- documents;
- content retrieved from an integration;
- tool results;
- other information necessary to complete the requested task.
The third-party AI provider's processing of that information is governed by its own terms and privacy practices.
Orbis is designed to minimize unnecessary disclosure and only provide the AI system with information reasonably relevant to the requested task.
If you use an AI provider through your own account, subscription, local installation or authentication, that relationship may be directly between you and that provider.
You should avoid sending highly sensitive information to an external AI provider unless you understand and accept that provider's privacy and data-handling terms.
7. How We Use Information
Where information is processed by Orbis or Orbis-operated infrastructure, we may use it to:
Provide the service
Including to:
- authenticate connected accounts;
- execute commands you request;
- access resources you authorize;
- maintain integration sessions;
- synchronize connection status;
- provide requested AI functionality.
Protect Orbis and its users
Including to:
- prevent OAuth attacks;
- prevent replay attacks;
- identify abusive activity;
- investigate security incidents;
- protect our infrastructure;
- enforce usage limits where necessary.
Maintain and improve Orbis
We may process limited technical information necessary to:
- diagnose failures;
- understand application compatibility;
- fix bugs;
- improve reliability;
- maintain integrations.
We aim to minimize this information and avoid collecting the content of your projects or connected services unless necessary for the feature you are using.
Comply with legal obligations
We may process or disclose information when reasonably necessary to comply with applicable laws, lawful requests or legal obligations.
8. Legal Bases for Processing
Where laws such as the GDPR require us to identify a legal basis, we may process personal information based on:
Performance of a contract
When processing is necessary to provide Orbis or a feature you requested.
Consent
When you explicitly authorize an integration, permission, optional feature or other processing based on consent.
You may withdraw consent where applicable.
Legitimate interests
Where necessary for interests such as:
- protecting Orbis from abuse;
- maintaining security;
- diagnosing failures;
- maintaining service reliability;
provided those interests are not overridden by your rights.
Legal obligations
Where processing is necessary to comply with applicable law.
9. Data Minimization
Orbis is designed to access only information reasonably necessary for the feature being performed.
Where technically practical, Orbis uses:
- scoped OAuth permissions;
- selected repository access;
- selected workspace or page access;
- incremental authorization;
- local processing;
- temporary authentication sessions;
- encrypted credential storage.
We do not intentionally collect additional personal information simply because a connected service makes that information available.
10. Information We Do Not Sell
Orbis does not sell your personal information.
We also do not use your private project content, source code, connected account content or OAuth credentials for third-party advertising.
We do not knowingly sell or share personal information of individuals under 16 years of age.
If our business practices materially change, this Privacy Policy and any legally required privacy controls will be updated before the new practice applies.
11. Advertising
Orbis does not use your private workspace, source code, documents, integrations or AI conversations to build advertising profiles.
We do not provide private Orbis workspace content to advertising networks for behavioral advertising.
12. Service Providers
We may use carefully selected infrastructure providers to operate limited parts of Orbis.
Depending on the feature, these providers may include companies that provide:
- hosting;
- domain and network infrastructure;
- security services;
- authentication infrastructure;
- error monitoring;
- email or customer support infrastructure.
Such providers may process limited information on our behalf where necessary to provide those services.
For example, network infrastructure providers may automatically process technical information such as:
- IP address;
- connection timestamp;
- HTTP request metadata;
- security signals.
This processing may occur even where Orbis itself does not permanently store that information.
13. Third-Party Services
Orbis connects to services operated by other companies.
Examples may include:
- GitHub;
- GitLab;
- Google;
- Notion;
- Discord;
- Spotify;
- AI model providers.
Those services operate independently from Orbis and have their own privacy policies.
When you authenticate with or use a third-party service, that provider may collect information about your use according to its own terms.
Orbis is not responsible for the independent privacy practices of third-party services.
We recommend reviewing the privacy policy of any provider before connecting it to Orbis.
14. Data Retention
Retention depends on the type of information involved.
Local data
Information stored locally remains on your device until you:
- delete it;
- clear application data;
- disconnect the relevant service;
- uninstall Orbis;
- or otherwise remove it.
OAuth credentials
Credentials remain locally encrypted while the integration remains connected or until the credential expires, is revoked or is removed.
Authentication relay information
OAuth sessions, handoffs and temporary authentication information are retained only for the short period necessary to complete or secure the authorization process and are then deleted or allowed to expire.
Security and operational information
Limited operational or security information may be retained for only as long as reasonably necessary to investigate security incidents, maintain reliability, prevent abuse or satisfy applicable legal requirements.
Support communications
If you contact us, we may retain your message and related correspondence for as long as reasonably necessary to resolve the request, maintain support records or comply with legal obligations.
We aim not to retain personal information longer than required for the purpose for which it was collected.
15. Data Security
We use technical and organizational safeguards designed to protect information handled by Orbis.
Depending on the platform and feature, these safeguards may include:
- encryption of stored authentication credentials;
- operating-system-backed credential protection;
- encrypted HTTPS communications;
- OAuth state validation;
- PKCE;
- short-lived authorization sessions;
- single-use credential handoffs;
- restricted application permissions;
- minimum necessary OAuth scopes;
- secret redaction;
- access controls;
- replay protection;
- credential revocation;
- security testing.
No software or network system can guarantee absolute security, but Orbis is designed to minimize both the amount of sensitive information centrally stored and the amount of infrastructure capable of accessing it.
16. Your Privacy Controls
Orbis gives you direct control over many types of information.
Depending on the feature, you may:
- connect an integration;
- decline requested permissions;
- disconnect an integration;
- revoke access through the third-party provider;
- delete local project information;
- delete conversations or history where supported;
- change application settings;
- uninstall Orbis.
You may also revoke Orbis access directly through providers such as GitHub, Google and other connected services.
17. Your Privacy Rights
Depending on where you live, applicable law may give you rights concerning personal information that Orbis controls.
These may include the right to:
- know what personal information is processed;
- request access to personal information;
- request correction of inaccurate information;
- request deletion;
- withdraw consent;
- object to certain processing;
- restrict certain processing;
- obtain a portable copy of eligible information;
- complain about how your personal information is handled;
- appeal certain privacy decisions where applicable.
Because much of Orbis's information is stored locally on your own computer, you may already have direct control over that information.
For information controlled by Orbis-operated infrastructure, requests can be submitted to:
We may need to verify your identity before fulfilling certain requests.
We will not discriminate against you for exercising applicable privacy rights.
18. India Privacy Rights
Where India's Digital Personal Data Protection Act and applicable rules apply, you may have rights concerning personal data processed by us, including rights to obtain information about processing, seek correction or erasure, withdraw consent where processing relies on consent, and raise a grievance.
Where consent is the basis of processing, Orbis aims to make withdrawal reasonably accessible.
You may contact us regarding privacy concerns or exercise applicable rights at:
19. European Economic Area, United Kingdom and Switzerland
Where applicable data-protection laws provide additional rights, you may have rights including:
- access;
- rectification;
- erasure;
- restriction;
- objection;
- portability;
- withdrawal of consent.
You may also have the right to lodge a complaint with the appropriate data-protection authority.
Withdrawal of consent does not affect processing that was lawful before the withdrawal.
20. California Residents
If California privacy law applies to Orbis and to your information, California residents may have rights including:
- the right to know;
- the right to access;
- the right to correct;
- the right to delete;
- the right to obtain information about disclosures;
- the right to opt out of certain sale or sharing;
- the right to limit certain uses of sensitive personal information where applicable;
- the right not to receive discriminatory treatment for exercising privacy rights.
Categories of information that may be processed
Depending on the services you use, Orbis may process:
- identifiers such as username or email address;
- internet and network information;
- account or authentication information;
- professional or organizational information associated with connected accounts;
- electronic content that you choose to process through Orbis;
- interaction and application information;
- security information.
Sources may include:
- you;
- your device;
- services you choose to connect;
- infrastructure necessary to operate Orbis.
These categories are used for the purposes described in this Privacy Policy.
Sale and sharing
Orbis does not sell personal information.
Orbis does not share personal information for cross-context behavioral advertising as part of the practices described in this Privacy Policy.
Therefore, where no sale or advertising sharing occurs, an opt-out from such activity is not necessary.
If these practices change, we will update this Policy and provide any legally required privacy choices.
21. International Processing
Orbis users and third-party providers may operate in different countries.
Information sent to third-party providers may therefore be processed in countries outside your country of residence.
For example, a connected service or AI provider may operate servers in the United States, European Union or other jurisdictions.
Where required, we will use legally recognized safeguards for international transfers of personal information under our control.
Third-party providers' international processing is governed by their respective terms and privacy policies.
22. Cookies and Website Technologies
The Orbis website may use cookies, local storage or similar technologies necessary to:
- operate the website;
- maintain security;
- remember preferences;
- prevent abuse;
- support essential functionality.
If Orbis introduces non-essential analytics, advertising or tracking technologies that require consent or additional choices under applicable law, we will provide appropriate notice and controls.
The desktop application does not rely on advertising cookies to access your private projects or connected-service content.
23. Automated Processing and AI
Orbis uses artificial intelligence to assist users with tasks such as understanding requests, generating content, analyzing information and interacting with authorized tools.
AI-generated recommendations or actions may not always be accurate.
For potentially consequential external actions, Orbis may provide confirmation or approval controls depending on the feature and configuration.
Orbis should not be used as the sole basis for decisions that produce significant legal or similarly significant effects on individuals unless appropriate human review, legal authority and safeguards are in place.
24. Children
Orbis is designed for professional and general productivity use and is not intended for children under 16 years of age.
We do not knowingly collect personal information from children under 16 through Orbis-operated services.
If you believe a child has provided personal information to us, contact:
and we will review the request and take appropriate action.
25. Government and Legal Requests
We may disclose information under our control where we reasonably believe disclosure is required by:
- applicable law;
- court order;
- valid legal process;
- regulatory requirement;
- protection of users or the public;
- investigation of fraud, abuse or security threats.
Because Orbis stores much of its information locally, we may not possess information that exists only on a user's device.
26. Business Transfers
If Orbis or its operating entity undergoes a merger, acquisition, financing, restructuring or sale of assets, information controlled by us may be transferred as part of that transaction where legally permitted.
Any successor will remain subject to applicable privacy obligations concerning transferred personal information.
27. Changes to This Privacy Policy
We may update this Privacy Policy as Orbis evolves.
If an update materially changes how personal information is processed, we will provide reasonable notice where required.
The date at the top of this Privacy Policy indicates when it was last updated.
We encourage users to review this Policy periodically.
28. Contact and Privacy Requests
For privacy questions, requests, complaints or concerns, contact:
Orbis
Email: neilsarjal@gmail.com
Address: 201 Hauz Khas, New Delhi 110016, India
Website: https://www.orbis-intelligence.com/
Please include enough information for us to understand and respond to your request, but do not send passwords, OAuth access tokens, private keys or other authentication secrets by email.