Privacy Policy
Last updated: July 16, 2026
1. Introduction
This Privacy Policy describes how Orbyt ("Orbyt", "we", "our", or "us") collects, uses, discloses, and safeguards information when you access or use our website, applications, APIs, and related services (collectively, the "Services"). By using the Services, you agree to the practices described in this Policy. If you do not agree, please do not use the Services.
Orbyt is a calendar, task, and scheduling platform that connects to third-party calendar providers to detect conflicts, propagate availability blocks, auto-schedule tasks, and surface productivity insights. This Policy applies to all users globally, including residents of the European Economic Area (EEA), United Kingdom, California, and other jurisdictions with applicable data protection laws.
2. Information We Collect
a. Information you provide. Account details such as your name, email address, password (stored as a one-way hash), profile photo, time zone, workspace names, billing information, and any content you submit (tasks, projects, notes, comments, support requests).
b. Calendar & productivity data. When you connect a third-party calendar (e.g. Google Calendar, Microsoft Outlook/Office 365, Apple iCloud, or other supported providers), we access and store calendar metadata required to operate the Services, including event titles, start and end times, attendees, response statuses, locations, descriptions, recurrence rules, visibility/free-busy data, calendar IDs, and the OAuth tokens needed to read and write events on your behalf.
c. Usage & device data. Log data (IP address, browser type, operating system, referring/exit pages, timestamps), device identifiers, approximate location derived from IP, in-product interactions, error reports, and cookies or similar tracking technologies.
d. Payment data. If you purchase a paid plan, our payment processor (Stripe) collects and processes your payment card or bank details. We do not store full card numbers; we retain only limited identifiers (e.g. last four digits, brand, billing country, customer and subscription IDs) needed for billing and fraud prevention.
e. Communications. Records of emails, chats, and support tickets you exchange with us, including any attachments.
3. How We Use Information
We use information to:
- Provide, operate, maintain, and improve the Services;
- Detect calendar conflicts, propagate availability blocks across connected calendars, auto-schedule tasks, and synchronize events you authorize us to manage;
- Authenticate users, prevent fraud, and secure the platform;
- Process payments, manage subscriptions, and issue invoices;
- Send transactional messages (e.g. account, security, billing, schedule updates) and, with your consent where required, product or marketing communications;
- Generate aggregated and de-identified analytics to understand usage and improve features;
- Comply with legal obligations and enforce our Terms of Service.
4. Legal Bases for Processing (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on the following legal bases: (i) performance of a contract with you to deliver the Services; (ii) legitimate interests in operating, securing, and improving our platform, provided your rights do not override those interests; (iii) consent, where required (e.g. for certain cookies or marketing), which you may withdraw at any time; and (iv) compliance with legal obligations.
5. How We Share Information
We do not sell your personal data and we do not share it with advertisers. We share information only as described below:
- Service providers (sub-processors) who process data on our behalf under contract, including:
- Supabase & Cloudflare — database, storage, authentication, and edge/serverless hosting;
- Stripe — payment processing and subscription management;
- Google, Microsoft, Apple and other calendar providers you connect — strictly to read and write the calendar data you authorize;
- Email and notification providers used to deliver transactional messages;
- Analytics and error-monitoring tools used to diagnose issues and improve reliability.
- Within your workspace. If you join or are invited to a shared workspace, other members may see your profile information and the tasks, projects, comments, and availability you share within that workspace.
- Legal & safety. When required by law, subpoena, or other valid legal process, or to protect the rights, property, or safety of Orbyt, our users, or the public.
- Business transfers. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to standard confidentiality protections.
- With your consent or at your direction.
6. Google API & Third-Party Calendar Disclosures
Orbyt's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The following disclosures describe our handling of Google user data specifically.
a. Data Access. When you connect your Google account, Orbyt requests the OAuth scopes https://www.googleapis.com/auth/calendar.readonly and https://www.googleapis.com/auth/calendar.events. Using these scopes we access the following raw Google user data: your Google account email address and profile name (for account identification); calendar list metadata (calendar IDs, names, time zones, ownership/access role); and calendar event data (event IDs, titles, descriptions, start/end times, locations, attendees and their response statuses, organizer, recurrence rules, reminders, visibility, free/busy status, and created/updated timestamps) from the calendars you authorize. We also store the OAuth access and refresh tokens Google issues to Orbyt. We generate aggregated/anonymized data from this raw data — such as counts of events synced, sync success/failure rates, and API latency — used solely for operational monitoring; these aggregates cannot reasonably be re-identified to an individual.
b. Data Use. Raw Google user data is used exclusively to deliver user-facing scheduling features you have requested: (i) detecting scheduling conflicts across your connected calendars; (ii) mirroring busy time from one calendar to another as "Unavailable" blocks so you don't get double-booked; (iii) auto-scheduling your tasks into free time slots; (iv) displaying your unified calendar and free/busy availability inside Orbyt; and (v) creating, updating, or deleting events on calendars you authorize (e.g. bookings from your public booking page, and Orbyt-managed availability blocks). Aggregated/ anonymized data is used solely for internal operational monitoring, debugging, and capacity planning. We do not use Google user data — raw or aggregated — to train, develop, or improve generalized or third-party AI/ML models, to serve advertising, or for any purpose unrelated to the scheduling features you use.
c. Data Transfer. We do not sell Google user data and we do not transfer it to advertisers, data brokers, or generative-AI providers (including OpenAI, Anthropic, or any LLM provider). Raw Google user data is transferred only to: (i) infrastructure sub-processors that host and process data on Orbyt's behalf under contract — specifically Supabase (managed Postgres database and authentication) and Cloudflare (edge/serverless compute and TLS termination); (ii) other calendar providers you explicitly connect (e.g. Microsoft, Apple) when you configure Orbyt to mirror availability between them; and (iii) other members of a shared workspace you join, limited to the free/busy availability and event metadata you choose to share within that workspace. Aggregated/anonymized data may also be processed by our error-monitoring and analytics sub-processors strictly for reliability purposes. We do not transfer Google user data for any other purpose.
d. Data Protection. Google user data is encrypted in transit using TLS 1.2+ and encrypted at rest by our database and storage providers. OAuth access and refresh tokens are additionally encrypted at the application layer before being written to the database, using an application-managed key that is separate from database credentials. Access to production systems is restricted using principle-of-least-privilege controls, scoped database row-level security policies that isolate each user's data, audit logging, and periodic access reviews. Employee access to raw Google user data is limited to a small number of authorized engineers and only for legitimate operational purposes (e.g. resolving a support ticket you have opened). We maintain an incident response process and will notify affected users of any confirmed unauthorized access to Google user data as required by law.
e. Data Retention & Deletion. We retain Google user data only while your Google calendar is connected to Orbyt and you have an active account. You can revoke Orbyt's access at any time from your Orbyt account settings ("Disconnect calendar") or from your Google Account security settings at myaccount.google.com/permissions. When you disconnect your Google calendar or delete your Orbyt account: (i) the associated OAuth access and refresh tokens are revoked with Google and purged from our systems immediately; and (ii) all raw Google user data cached by Orbyt (calendar list, event metadata, mirrored availability blocks) is deleted from our production database within 30 days, and from encrypted rolling backups within an additional 30 days as those backups age out. Aggregated/anonymized data that cannot reasonably be re-identified may be retained for operational analytics. Deletion requests can also be submitted directly to privacy@oneorbyt.com.
7. International Data Transfers
Orbyt operates globally and may transfer, store, and process information in countries other than your own, including the United States and the European Union. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms.
8. Data Retention & Deletion
We retain personal data only as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we delete or de-identify your personal data within a reasonable period, except for information we are required or permitted to retain (e.g. billing records, fraud prevention, backups that are cycled on a rolling basis).
Google user data. Google Calendar data (including event metadata, calendar IDs, and synced copies) is deleted within 30 days of account deletion or calendar disconnection, except for anonymized aggregates that cannot reasonably be re-identified. OAuth tokens used to access Google APIs are revoked and purged immediately when you disconnect a calendar or delete your account.
How to delete or disconnect. You can disconnect a calendar at any time from your Orbyt account settings or revoke Orbyt's access from your Google account security settings. Account deletion requests can be made by emailing privacy@oneorbyt.com or through the account deletion option in your profile settings.
9. Security
We implement administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit (TLS) and at rest, scoped database access with row-level security, OAuth token encryption, principle-of-least-privilege access controls, audit logging, and regular reviews. No system is perfectly secure; we cannot guarantee absolute security and you use the Services at your own risk. Notify us immediately at security@oneorbyt.com if you suspect unauthorized access.
10. Your Rights & Choices
Depending on your jurisdiction, you may have rights to: access, correct, update, port, restrict, or delete your personal data; object to processing; withdraw consent; and lodge a complaint with a supervisory authority. California residents have additional rights under the CCPA/CPRA, including the right to know, delete, correct, and limit use of sensitive personal information. We do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA.
You can exercise most rights directly from your account settings (export, disconnect calendars, delete account) or by emailing privacy@oneorbyt.com. We will respond within the timeframe required by applicable law.
11. Cookies & Similar Technologies
We use strictly necessary cookies to authenticate sessions and remember preferences, and limited analytics cookies to measure aggregate usage. You can control cookies through your browser settings; disabling certain cookies may impact functionality.
12. Children's Privacy
The Services are not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will delete it.
13. Automated Decision-Making
Orbyt uses automated logic (e.g. auto-scheduling, conflict detection) to organize your calendar. These features are advisory and you retain full control to accept, modify, or reject any suggested change. We do not make decisions that produce legal or similarly significant effects on you without human involvement.
14. Third-Party Links & Services
The Services may link to or integrate with third-party websites and services that we do not control. This Policy does not apply to those third parties; please review their privacy policies separately.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting an updated version on this page and, where appropriate, by email or in-product notice. Your continued use of the Services after changes take effect constitutes acceptance.
16. Dispute Resolution & Arbitration
All disputes arising out of or in connection with the present contract shall be finally settled under the Rules of Arbitration of the International Chamber of Commerce by one or more arbitrators appointed in accordance with the said Rules.
17. Contact Us
Questions, requests, or complaints about this Policy or our data practices can be sent to privacy@oneorbyt.com. For security-related reports, contact security@oneorbyt.com.