On this page
Orbit needs limited device, relay, and subscription information to provide the VPN service; connection history and preferences are primarily stored on your device. Orbit does not read or store your web content, DNS query content, or VPN traffic payloads, but your ISP, Apple, selected relay, and DNS service may process information under their own policies.
Scope
This policy applies to the Orbit iOS app, its Packet Tunnel network extension, and the Orbit-operated control-plane interfaces (together, the “Service”). It explains what we collect, why we use it, who may process it, and how long it is kept.
This policy does not replace the privacy policies of Apple, a relay or DNS provider you choose, or another third-party service. If you follow an external link out of Orbit, review that service’s terms and privacy policy.
Information we process
We process information only as needed to provide, secure, bill for, or improve the Service. The current app version handles the main categories below.
| Category | What it contains and why | Primary location |
|---|---|---|
| Device and app environment | Language, region, operating-system version, device-model signature, app version, and App Store storefront. Used for compatibility, node policy, language, and purchase delivery. | Service requests |
| Relay and connection configuration | Relay region, relay label, relay address/port, latency-probe parameters, and your DNS, routing, MultiHop, and kill-switch choices. Used to load the relay directory, assemble the tunnel, and process connection requests. | Device and control plane |
| Subscriptions and purchases | Product identifier, StoreKit transaction identifier, purchase environment, subscription status, and expiry. Used to request a purchase from Apple, validate it with the Service, and deliver ORBIT PILOT benefits. | Apple and control plane |
| Local records | Privacy consent, selected relay, favorites/recent relays, connection counts, protected time, connection/disconnection timeline, and preferences, used to restore the experience and show statistics. The timeline does not store relay IP addresses. | Your device |
What we do not collect for this Service
- Web, message, file, or VPN traffic payload content;
- A complete history of the sites you visited, destination list, or DNS query history;
- Personal information used for ad profiling, cross-app tracking, or sale to data brokers.
“Not intentionally collected” does not mean that network metadata cannot exist elsewhere on the Internet. Your ISP, Apple, a selected relay, a DNS resolver, or a website operator may see or retain parts of a connection under the way that service operates and applicable law.
How we use information
- Assemble, start, switch, and stop the iOS VPN tunnel and provide relay-latency features;
- Validate App Store transactions and deliver, restore, or end subscription benefits;
- Prevent abuse, troubleshoot faults, maintain security, and meet legal obligations;
- Respond to support requests using the information you choose to provide.
The current version is designed without advertising SDKs, behavioral analytics SDKs, or third-party tracking SDKs. If we add a new material purpose, we will update this policy and obtain consent again where applicable law requires it.
Retention, deletion, and withdrawal
On-device data: preferences, connection statistics, recent relays, favorites, connection timeline, and consent status remain on the device until you clear the relevant record in the app or the data is replaced/deleted.
Service data: purchase-validation results and necessary service records are kept for as long as needed to provide the Service, resolve disputes, prevent abuse, or meet legal obligations. The exact period depends on the data type, technical need, and applicable law; afterward, data is deleted, anonymized, or securely isolated.
You may stop using the Service and clear available records in the app. Records that lawfully must be retained will not be deleted immediately.
Security, children, and updates
Security measures
We use application-layer encryption, request signing, access controls, and data minimization to protect service requests; local data is managed by the iOS app container. No software, network, or storage system is absolutely secure, so keep your system and app updated.
Children’s privacy
Orbit is not designed for children. If you are below the age of independent consent in your location, use the Service only with a parent or guardian’s consent and guidance. If we learn that children’s information was collected without the required consent, we will handle it as required by applicable law.
Updates
We may update this policy when features, providers, or laws change. The revised version will be posted here and through the in-app entry, and we will ask for confirmation again when applicable law requires it. Continued use means you have had an opportunity to review the update; it does not replace legally required express consent.