Privacy Policy
Last updated August 24, 2026
Who we are
Orbily ("we", "us") is an AI-powered study application and website (orbily.net), run by the Orbily project. The publisher is an individual who has not formed a company yet; the full legal identity will be published as soon as the entity exists.
For any privacy request: contact@orbily.net. You can also use the "Account, data or privacy" topic of the contact form on this site.
Summary
Your study content (courses, notes, documents, chats) lives on your device. We only receive your account email, a few study preferences, activity metadata, and what you explicitly send us through forms or AI features.
We do not sell data. There is no social feed and no public profile.
Data we collect
Website forms. Contact form: your email address, your message, the topic you pick and the interface language. Waitlist: your email address and language. When you submit these forms, we compute a salted hash of your IP address to rate-limit spam; the raw IP is never stored.
App account. Your email address and an encrypted password (or the identifier your Google or Apple account shares when you sign in with them). If you sign in with Apple, we request your name and email only.
Study profile. Session duration preference, days per week, daily activity goal, streak dates and best streak, subscription tier and status, AI quota counters.
Learning activity metadata. Each time you complete an activity we store its type (quiz, flashcards, correction, timer, reading time and so on), duration, the folder name you attached it to, and scores. We never receive the content of your courses or documents through this log.
Onboarding telemetry. During onboarding, answers you give to product questions (study level, motivation, blockers and similar), plus an anonymous device identifier, app language, platform and version. This starts before you create an account and gets linked to your account only if you sign up. A optional gender question exists for aggregated statistics; leaving it empty is supported.
Error reports. When the app crashes or hits an unexpected error, we store the error message, a stack trace, the app version and the platform. Reports deliberately avoid serialising your content.
Payments. Purchases go through Apple. We never see card numbers. Apple and our subscription processor RevenueCat tell us your entitlement (tier, status, expiry date, product identifier).
What stays on your device
Your imported documents, generated chapters, multi-lesson courses, flashcards, chat history with Orby and preferences live in local storage (SQLite and AsyncStorage) on your device, scoped per account.
None of this content is synchronised to our servers. It leaves the device only at the moment you use an AI feature that needs it (for example generating a course from an imported document), and only the relevant excerpt is sent.
AI processing
AI features run through our server proxy, so provider keys never live in the app. When you use one, the relevant text, images or audio are sent to AI providers chosen by us:
OpenRouter (United States) is our single AI gateway: each request is routed to the third-party model provider selected for the task (text generation and chat, vision, audio transcription).
Document transcription (PDF, Word, PowerPoint files) goes directly to Mistral AI (France).
We send only what the requested feature needs, we do not add your data to advertising profiles, and we route requests through providers configured so that your inputs are not retained or used to train models.
Analytics
In the app, product analytics run on PostHog (European Union cloud). Events are pseudonymous: they carry a random identifier, never your email. Examples: sign-up method, which AI feature was used, paywall views, quota warnings. Lifecycle events are recorded automatically; nothing else is captured.
On this website, Google Analytics 4 loads only if you accept cookies in the banner. As long as you have not accepted, and after you decline, no measurement request is sent to Google. Two cookieless tools always measure aggregate traffic and page speed without identifying anyone: Vercel Web Analytics and Speed Insights. Details on the Cookies page.
Why we process data (legal bases)
To provide the service you asked for: account management, generation of your study tools, streaks, quotas, subscription entitlements (performance of contract).
To keep the service safe and improve it: rate limiting, error reports, aggregated telemetry about onboarding and feature usage (legitimate interests).
To measure the website audience with Google Analytics: your consent, collected before any cookie is set and withdrawable at any time.
To answer your messages sent through the contact form (steps prior to entering a contract, or legitimate interests).
Recipients and sub-processors
Supabase (European Union, Stockholm region): database, authentication and edge functions for both the app and this website.
Vercel (United States): hosting of this website, plus its cookieless analytics.
OpenRouter (United States): single gateway through which AI model providers process requests, under configurations chosen so that inputs are not retained.
Mistral AI (France): document transcription.
PostHog (European Union cloud): app product analytics.
RevenueCat (United States): subscription infrastructure; it receives your opaque user identifier and purchase events from Apple.
Google and Apple: authentication when you use those sign-in buttons; Apple for in-app purchases.
Resend (SMTP provider): delivery of transactional emails such as verification codes.
These providers act under contract as processors or independent controllers for their own infrastructure; we share only what each one needs.
International transfers
Your account data is stored in the European Union. Some providers above are based in the United States. Where required, transfers rely on the European Commission Standard Contractual Clauses or an adequacy framework (such as the EU-US Data Privacy Framework).
Retention
Account data is kept while your account is active. Deleting your account from the app settings immediately deletes your profile, activity history and quota counters on our servers, and anonymises error reports and onboarding telemetry linked to you.
Contact messages are kept only as long as needed to handle your request. Waitlist addresses are kept until launch communications end or you ask for removal.
Error reports and telemetry are kept only as long as useful to fix bugs and improve onboarding; ask us anytime to erase them.
Security
Data travels over TLS. Database access is locked by row-level security so no user can read another user's rows. Administrative access requires an allowlisted account plus two-factor authentication, and every administrative action is logged. Provider secrets live only on servers, never inside the app.
Your rights
You can access, correct, export or delete your personal data.
Export: the app settings contain "Export my data" (a JSON archive of your profile, activity and locally stored content) and "Export my stats" (CSV).
Deletion: Settings then Account then Delete account removes your server-side data as described above. Uninstalling the app removes everything stored on the device.
For anything else, email contact@orbily.net. Under the GDPR you may also lodge a complaint with your supervisory authority (in France, the CNIL).
Minors
Orbily is a study tool used by students of many ages. If you are below the age at which your country lets you consent to data processing on your own (15 in France), ask a parent or guardian before creating an account.
If you believe a child under that age gave us personal data without parental consent, write to contact@orbily.net and we will delete it.
Changes to this policy
We update this policy when the service changes. The date under the title reflects the latest revision; material changes will be announced in the app or on this site.
