Privacy Policy — Orbit
Effective date: July 20, 2026
Contact: orbit-journal.com/contact
Orbit is a gentle wellness journal. We believe your personal data belongs to you. This policy explains — plainly — what we collect, why we collect it, how we protect it, and what you can do about it.
1. Data We Collect
Account Data
- Email address (via Firebase Authentication)
- Password, if you sign up with email — handled entirely by Firebase; Orbit never sees it in plaintext
- Display name and profile photo, if you sign in with Google or Apple
- The identity token from Google or Apple when you use those sign-in options
Content You Create
- Journal entries (the text you write)
- Mood and emotion selections you log
- Photos you attach to entries (stored on Cloudflare R2)
- Voice recordings you attach to an entry or record in the vent space (stored on Cloudflare R2 and transcribed to text so you can read them back — see "Voice & Speech" below)
- The weather condition saved alongside an entry, if you have the weather card enabled
Your journal content is yours. We store and process it only to give the app back to you — never to profile you or sell you anything.
Device & Usage Data
- A push notification token (FCM) so we can deliver the reminders and gentle notes from Sunny that you've turned on
- Approximate, city-level location — only when you enable the weather card. It is used solely to fetch local weather and is not stored on our servers as a location history.
- Product analytics events (via Mixpanel) — for example, which screens you open and which features you use — so we can understand what's helpful and build better. See section 4 for exactly what this includes.
Voice & Speech
There are two separate things here, and they work differently:
- Live dictation (speaking instead of typing) runs on-device using Apple's or Google's built-in speech framework. The raw audio never leaves your phone.
- Voice recordings you deliberately save to an entry or the vent space are uploaded to our storage (Cloudflare R2) and transcribed to text on our server, so the recording is saved and readable. If you don't record and save a voice memo, no audio is sent to us.
2. How We Use Your Data
- Core functionality: Store, display, and sync your entries across your devices
- Notifications: Deliver the reminders and warm notes from Sunny that you've enabled
- Weather: Show local conditions in the home screen weather card
- Product improvement: Understand aggregate usage patterns to build better features
- Security: Verify your identity and prevent unauthorized access
We do not sell your data. We do not use your data for third-party advertising.
3. Orbit Is a Wellness Companion — Not a Medical or Emergency Service
Orbit is a warm space to reflect and care for yourself. It is not a medical device, a diagnosis, a therapist, or an emergency service, and nothing in the app is a substitute for professional care.
If you are in crisis, or worried about your safety or someone else's, please reach out to people who can help right now:
- 1323 — Thailand Department of Mental Health hotline (free, 24 hours)
- 1669 — Emergency medical services in Thailand
- Samaritans Thailand — 02-113-6789
You deserve real support, and asking for it is a brave, healthy thing to do.
4. Analytics & Tracking (Mixpanel)
We use Mixpanel to understand how Orbit is used so we can improve it. We'll be honest that this is a form of tracking: Mixpanel receives usage events tied to a per-user identifier (your Firebase account ID), and we set a small profile for you that can include your email and display name, your app locale and theme, when you signed up, and simple counts such as how many entries you've written. We do not send the contents of your journal entries, photos, or voice recordings to Mixpanel.
On iOS, we ask for App Tracking Transparency permission. If you decline, we turn Mixpanel tracking off for you.
5. Third-Party Services
We rely on a few trusted providers. Each handles only the data needed for its job, under its own privacy policy:
- Google Firebase Authentication — sign-in and account identity — firebase.google.com/support/privacy
- Cloudflare R2 — storage for your photos and voice recordings — cloudflare.com/privacypolicy
- Google Cloud — hosting for our backend and database — cloud.google.com/terms/cloud-privacy-notice
- Mixpanel — product analytics — mixpanel.com/legal/privacy-policy
- OpenWeatherMap — weather data for the weather card — openweathermap.org/privacy-policy
- Apple / Google speech frameworks — on-device dictation — apple.com/legal/privacy and policies.google.com/privacy
6. Data Retention
We keep your data for as long as your account exists. When you delete your account through the app (Profile → "Delete Account"), all your data — including photos and voice recordings stored on Cloudflare R2 — is removed from our servers within 30 days.
Anonymized analytics data may be retained by Mixpanel under its own policy.
7. Your Rights
- Access: View all your data directly inside the app
- Correction: Edit your display name or any content in the app
- Deletion: Delete your account and all associated data from the Profile screen
- Data request: Email us at orbit-journal.com/contact — we'll respond within 30 days
8. Children
Orbit is not intended for anyone under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has used Orbit, please contact us and we'll remove the account.
9. Security
All data traveling between the app and our servers is sent over HTTPS. Firebase Authentication manages password security, so Orbit never sees your password in plaintext.
10. Changes to This Policy
If we make meaningful changes, we'll let you know through an in-app notice or email. The updated policy takes effect when it's published at this URL.
11. Contact
Orbit
Email: orbit-journal.com/contact
Questions or concerns about your privacy are always welcome. We'd rather you ask.