Privacy
Privacy policy
Orbit is a personal contact manager. You bring your own address book, your LinkedIn connections and your Instagram followers; Orbit merges them into one list of people for you alone. This page says exactly what is stored, why, where, and how you remove it.
1. Controller
Fritz Kürmayr, Friedhofstrasse 33, 4311 Schwertberg, Austria. Contact for privacy questions and requests: privacy@frilabs.dev.
2. What Orbit stores
- Your account: your Google name and e-mail address (used to sign you in and to key your data). Orbit never sees your Google password.
- Your CRM: the contacts you import or sync — names, phone numbers, e-mail addresses, companies, titles, locations, profile links and handles from your address book, your LinkedIn export and your Instagram export — plus what you add yourself: tags, notes, merges, pins.
- LinkedIn profile data read by the optional browser extension in your own browser with your own LinkedIn login: city, headline, current company/school and, once per contact, the work, education and volunteering history shown on the profile.
- Connected accounts: if you connect iCloud, your Apple ID and an app-specific password, stored encrypted (AES-256-GCM) and used only to sync your own address book. Access tokens for the browser extension and for AI assistants (MCP) are stored as hashes.
- Organizations:if you join one, Orbit contributes — for people on that organization's list that you are connected to — only public LinkedIn data (name, headline, company, title, LinkedIn-read location, career history). Never phone numbers, e-mail addresses, Instagram, tags or notes, and never who is connected to whom.
- Technical logs: our hosting provider keeps short-lived request logs (time, path, status, IP address) to operate and secure the service.
Orbit has no advertising, no tracking cookies and no analytics. The only cookie is your sign-in session.
3. Google user data
Signing in requests only your basic profile (openid, email, profile). If — and only if — you choose Google as your address book and press "Connect Google Contacts", Orbit additionally requests read-only access to your contacts (contacts.readonly) to import names, phone numbers, e-mail addresses, organizations, addresses and photos into your own CRM.
Orbit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Google data is used only to provide the contact features you see in Orbit, is not transferred to others except as needed to provide those features (our hosting and database providers below), is never used for advertising, and is not read by humans unless you ask us for support, it is necessary for security, or the law requires it. You can withdraw the access at any time at myaccount.google.com/permissions.
4. Why — purposes and legal bases (GDPR)
- Providing the service you signed up for: Art. 6(1)(b) GDPR.
- Data about your contacts, which you bring for your own personal or professional networking: you decide what you import; where the household exemption (Art. 2(2)(c)) does not apply, our and your legitimate interest in keeping an address book, Art. 6(1)(f).
- Security, abuse prevention and logs: legitimate interest, Art. 6(1)(f).
5. Who processes data for us
- Vercel Inc. (USA) — hosting and request logs; EU Standard Contractual Clauses.
- Supabase Inc. — database, region London (UK, adequacy decision).
- Google Ireland Ltd. — sign-in and, if connected, the People API.
- Apple — only if you connect iCloud: your address book is read from and written to your own iCloud.
- OpenStreetMap Foundation (Nominatim) and OpenFreeMap — the map: only location strings such as "Vienna, Austria" are sent to find coordinates, never a name.
We do not sell data and do not share it with anyone else.
6. How long
As long as your account exists. Settings → Delete account removes your CRM, tokens, stored credentials and organization contributions immediately; backups held by our database provider expire within 30 days. Request logs are kept by the hosting provider for a short period.
7. Your rights
Access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR). Most of it is built in: Sources → Backup exports everything as JSON/CSV, every field is editable, and deletion is one button. For anything else write to privacy@frilabs.dev. You may also complain to a supervisory authority — in Austria the Datenschutzbehörde (dsb.gv.at).
If you are a person who appears in someone else's Orbit and want to know or object, write to the same address; we will pass the request to that user or act on it ourselves where we are responsible.
8. Security
Encrypted transport, credentials encrypted at rest, hashed access tokens, per-user data separation, no third-party scripts.
Last updated: 18 September 2026