Privacy Policy

Effective: 2026-07-12 · Operated by Celestify LTD · Contact: privacy@orbsnetwork.com

Orb collects nothing it doesn’t strictly need to work. No analytics, no trackers, no ads, no profiling. We make money one way — subscriptions — so you are never the product.

What we store

We also store account identifiers, network memberships, and the preferences and content you save, such as themes. The native iOS app does not request access to your address book or device location.

Google / Apple sign-in = login only

When you use Google or Apple sign-in, we use your verified email address to sign you in. Apple may also provide your name on first authorization, which the app sends to Orb for your account name. We do not request access to your email inbox, contacts, Drive, or calendar. The provider’s consent screen describes the information it shares.

Rooms with an AI agent

If a room has an ◍ agent in it, messages in that room are sent to whichever AI provider that agent is configured for (OpenAI, Anthropic, Groq, or a self-hosted model) so it can reply. An agent's prompt includes the recent conversation, not only the message that mentioned it — so if an agent is present, assume your messages in that room reach its provider even when you were not talking to it. Orb tells you on the way in: entering a room with an agent prints a line naming it and saying so.

Rooms with no agent do not send their conversation to an AI model for replies. Agents are added by the people who run a network, and you can see exactly who is one — they are the ◍ nicks in the member list.

What we never do

Don't take our word for it — verify

Privacy you can check beats privacy we promise. Both of these you can verify yourself, right now, without trusting us:

Security

Ordinary rooms, direct messages, and personal inboxes are not end-to-end encrypted. Our servers process their contents to deliver, store, and search them. Production transport uses HTTPS/WSS; store encryption depends on deployment configuration.

Opt-in secret direct messages encrypt message contents in the browser. This implementation has no forward secrecy or peer-key verification and has not received an independent cryptographic review. It is not equivalent to Telegram Secret Chats or Signal. A compromised server could substitute public keys or serve modified browser code. Secret messages are limited to the original browser keys; clearing site data can make them unreadable.

Your personal agent is off until enabled. When enabled, inbox context is sent to the configured model provider. Secret chats cannot receive plaintext integration alerts.

Your choices

Both are self-serve, in the app: click your nick in the sidebar, then Profile. Download gives you your account, your memberships and every message you sent, as JSON. Delete account removes your email, nick and messages, and cannot be undone. If you would rather we did it, write to privacy@orbsnetwork.com.

Children

Orb isn't for anyone under 13 (or 16 where required).

Changes

If this policy changes, we'll update this page and the effective date.

Terms of Service →