Effective date: July 10, 2026
Last updated: September 29, 2026
In short: This Privacy Policy explains what information Orby collects when you use our services, how we use and share it, how long we keep it, and the rights and controls you have. Short "In short" summaries appear throughout for convenience; the full text controls.
This Privacy Policy applies to the Orby platform, including our website (orbysocial.com), our mobile apps, real-time chat features, APIs, moderator tools, advertiser tools, and all other products and services that link to this Privacy Policy (together, the "Services"), operated by Orby Social Inc. [registered address to be completed] ("Orby," "we," "us," or "our"). Capitalized terms not defined here have the meanings given in our Terms of Service.
This Privacy Policy does not apply to third-party websites, apps, or services, even if you reach them through the Services, or to the data practices of advertisers on their own properties. Jurisdiction-specific disclosures — including for the EEA/UK, U.S. states including California, Brazil, Canada, and Australia — appear in Sections 13-15 and supplement the rest of this Policy.
CONTENTS
1. Information We Collect
2. How We Use Information
3. How Information Is Shared
4. Advertising and Personalization
5. Recommendations and How Content Is Ranked
6. Messages, Chat, and Voice
7. Identity and Age Verification
8. Your Rights and Choices
9. Data Retention
10. Data Security
11. International Data Transfers
12. Children and Teens
13. Supplemental Disclosures for the EEA, United Kingdom, and Switzerland
14. Supplemental Disclosures for U.S. States (Including California)
15. Supplemental Disclosures for Other Jurisdictions
16. Changes to This Privacy Policy
17. How to Contact Us
1. INFORMATION WE COLLECT
In short: We collect information you give us (like your account details and the content you post), information generated when you use Orby (like device and usage data), and limited information from other sources (like verification providers and advertisers' measurement data).
1.1 Information you provide to us
- Account information. When you create an account we collect your username, email address, password (stored only in hashed form — we never store it in plain text), and date of birth, which we use for our minimum-age gate and to apply under-18 protections. You choose a country at onboarding and can optionally add a city, a display name, an avatar (including Avatar Studio customizations), a banner, a bio, links, interests, and a preferred language. You may optionally add a phone number for verification and account recovery. Your username and the profile information you make public are visible to others.
- Content you create. We collect the content you post, upload, send, or store on the Services — posts, comments, votes, polls, images, video, links, community names, descriptions, and rules — together with associated metadata such as when the content was created, its community, and edit history. Remember that content posted to public communities is public.
- Messages. We collect the messages you send and receive through community channels, group chats, and direct messages ("DMs"), including attachments, reactions, and metadata such as sender, recipients, timestamps, and delivery/read state. DM text is end-to-end encrypted: your device encrypts it, and our servers store and relay only the encrypted form, which we cannot read. At send time our apps also submit a short-lived plain-text copy of a DM for automated safety screening. If the message passes, that copy is discarded immediately and never stored. If it does not pass, the copy is kept in encrypted form for up to 48 hours so we can analyse the wider conversation for grooming and other serious harms, and is then deleted automatically. Section 6 describes all of this in detail.
- Community and moderation activity. If you create or moderate communities, we collect your community configurations, moderation actions and logs, removal reasons, ban lists, and communications made through moderation tools (including modmail).
- Purchase information. If you buy paid services such as Orby+ or run advertising campaigns, our payment processors (such as Stripe) collect your payment method details; we receive limited information such as the payment method type, billing region, transaction amount and status, and subscription state. We do not store full card numbers on our systems.
- Verification information. If you complete age, identity, or humanity verification, we receive verification outcomes and limited anti-fraud signals as described in Section 7. Orby does not retain copies of your raw government-issued ID documents or raw biometric identifiers.
- Communications with us. When you contact support, report content, submit appeals, respond to surveys, or communicate with us in any other way, we collect the contents of those communications and any information you choose to include.
- Contacts (optional). If you choose to use "find friends," your device normalizes and cryptographically hashes each contact's phone number or email before anything is uploaded — your address book never leaves your device in readable form. We compare those hashes (further protected server-side with a keyed hash) only against members who verified the same phone or email, return the matches, and do not build profiles of non-members. Contact matching is optional, never required to use the Services, and can be turned off in settings.
- Advertiser account information. If you use our advertiser tools, we collect business contact details, organization and billing information, campaign configurations, creative assets, and audience and targeting selections. Advertisers uploading customer lists must attest that they have a lawful basis and any required consents.
1.2 Information we collect automatically
- Usage information. We collect information about your activity on the Services, such as the communities you join and visit, content you view, create, vote on, save, hide, report, or share, searches you run, features you use, ads you see and interact with, session frequency, and interactions with other accounts (such as follows, blocks, and mutes).
- Device and technical information. We collect information about the devices and software you use to access the Services, such as device model, operating system and app version, preferred language and time zone, IP address, performance and diagnostic information, a push-notification token when you enable notifications, and device-integrity signals we use to detect bots and abuse. We do not collect your device's advertising identifier.
- Location information (coarse and user-declared only). We use two kinds of coarse location information: (a) the country you select at onboarding and, optionally, a city you choose to add to your profile (user-declared, editable, and removable at any time); and (b) an approximate city/country derived from the IP address of each sign-in, which we show in your active-sessions security list so you can recognize unfamiliar logins, and use for security, regional legal compliance, and language/content defaults. We do not collect precise (GPS-level) location, we do not derive anything finer than city-level from your IP, and the apps never request device location permissions. If we ever introduce a feature that uses precise location, it will be optional, permission-based, and described in this Policy before launch.
- Cookies and similar technologies. On our own properties we use only the cookies and similar storage needed to keep you signed in, remember your preferences, and protect the Services (for example, anti-abuse and bot-defense checks). We do not run third-party advertising or analytics trackers on our own website or apps. The Orby pixel that advertisers may place on their own websites is described in Section 4.5.
- Inferred information. We generate inferences from the information described in this Section — for example, the topics and communities you may be interested in (based on your memberships and activity), signals that an account may belong to someone under 18, and safety-related risk signals — to personalize the Services, enforce age requirements, and protect users.
- Log information. Our servers automatically record log data when you use the Services, including access times, API calls, and error events.
1.3 Information from other sources
- Other users. We receive information about you from other users — for example, when they mention you, reply to you, message you, or report you or your content. If someone reports a message you sent them, the report shares the reported content with us so we can review it (Section 6.5).
- Verification and safety partners. We receive verification outcomes from verification providers (Section 7), and safety signals from industry hash-sharing databases and organizations, hotlines, and security vendors, used to detect and prevent serious harms such as child sexual exploitation, terrorism, malware, spam, and platform manipulation.
- Advertisers and measurement partners. Advertisers may share information with us for campaign delivery and measurement — such as conversion events from their websites and hashed identifiers for audience matching, where permitted by law and our policies (Section 4.5). We require partners to have the necessary rights and consents before sharing personal information with us.
- Service providers and other sources. We receive information from vendors that support the Services (such as payment processors, cloud hosting, security, anti-fraud, and content-safety providers), from authentication providers you choose to use for sign-in (such as Sign in with Apple), and from publicly available sources where lawful, including for safety investigations.
We may combine the information described in this Section 1 to provide, personalize, secure, and improve the Services.
2. HOW WE USE INFORMATION
In short: We use your information to run Orby, personalize your feeds and recommendations, keep the platform safe, show and measure ads, provide paid features, communicate with you, improve the Services, and meet our legal obligations.
We use the information we collect to:
- Provide and operate the Services — create and maintain your account; host, display, and distribute content; deliver messages in real time; operate communities and moderation tools; enable votes, reactions, and other social features; provide search; process transactions and deliver paid services such as Orby+; provide customer support; and honor your settings.
- Personalize your experience — rank your home and community feeds; recommend communities, posts, and users; personalize search results and notifications; remember your preferences; and select the content most relevant to you, as described in Section 5 and subject to the controls there.
- Protect users, the public, and the Services — detect, investigate, and act on violations of our Terms of Service and Community Guidelines; detect and prevent spam, fraud, platform manipulation, security incidents, and other harmful or illegal activity; scan for known child sexual abuse material and report it to the National Center for Missing & Exploited Children (NCMEC) and appropriate authorities; enforce age requirements; protect accounts from compromise; verify identity, age, or humanity where required; maintain audit logs; and defend the integrity of votes, rankings, and communities.
- Show and measure advertising — select and deliver ads (subject to the limits in Section 4), cap ad frequency, measure ad performance, provide advertisers with aggregate reporting, and detect invalid or fraudulent ad traffic.
- Communicate with you — send service, security, transactional, and legal notices; respond to your inquiries, reports, and appeals; and send marketing communications you can opt out of at any time (with your consent where required).
- Improve, develop, and research — analyze how the Services are used; debug, test, and improve features and infrastructure; run experiments; develop new features; and train, evaluate, and improve the machine-learning systems that operate the Services, including recommendation, ranking, search, and safety models, consistent with Section 5 and applicable law. Exports of moderation training data are admin-gated, require two-person approval, and are recorded in a tamper-evident audit log. We do not sell your content or personal information to third parties to train their AI models, and we do not permit third parties to scrape the Services for AI training.
- Aggregate and de-identify — create aggregated or de-identified data (for example, platform-level statistics and transparency reports), which we may use and share for any purpose. We commit to maintaining and using such data only in de-identified form and not attempting to re-identify it.
- Comply with law — meet our legal obligations, including responding to valid legal process and regulatory requirements, performing legally required transparency reporting, and establishing, exercising, or defending legal claims.
3. HOW INFORMATION IS SHARED
In short: Public content is public. We share information with your consent, with service providers working for us, for legal and safety reasons, and in aggregate with advertisers. We do not sell your personal information for money.
3.1 Visible to other users and the public
- Public content. Your username, the profile information you make public, and your posts and comments in public communities are visible to anyone, on or off the Services, and may be viewed, shared, re-posted, indexed by search engines, and cached by third parties. Public content may remain visible in quotes, cross-posts, or copies made by others even after you delete the original.
- Audience-limited content. Content posted in private or restricted communities, group chats, and DMs is visible to the members or participants of those spaces, subject to the space's settings. Recipients can copy or re-share what you send them — including DM text, which is end-to-end encrypted against Orby but fully readable by your recipients.
- Presence and activity signals. Depending on your settings, other users may see indicators such as online status or typing indicators.
3.2 Service providers
We share information with vendors who process it on our behalf and under our instructions to provide the Services — including cloud hosting and storage, content delivery, communications delivery (email, SMS, push), payment processing, customer support tooling, security, anti-fraud and anti-abuse, content-safety and AI moderation vendors that help scan content for policy violations, and verification providers. Service providers are bound by contractual obligations to protect the information and to use it only for the services they provide to us.
3.3 Advertisers and measurement
We provide advertisers with aggregate reporting about campaign delivery and performance (for example, impressions, clicks, conversions, and audience-level statistics). We do not share information that directly identifies you (such as your name, email address, or phone number) with advertisers without your consent. Where measurement involves matching (Section 4.5), you can opt out as described in Sections 4 and 14.
3.4 Safety, legal, and protection of rights
We may access, preserve, and share information with law enforcement, government authorities, courts, or other parties when we believe in good faith that doing so is reasonably necessary to: (a) comply with applicable law, regulation, legal process, or enforceable governmental request; (b) enforce our Terms of Service and policies, including investigating potential violations; (c) detect, prevent, or address fraud, abuse, security, or technical issues; (d) protect the rights, property, and safety of Orby, our users, or the public, including to prevent death or imminent bodily harm; and (e) report suspected child sexual exploitation to NCMEC and equivalent authorities, as required or permitted by law. We require valid legal process for non-emergency government requests and notify users where legally permitted.
3.5 Corporate transactions
If Orby is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of our assets, information may be disclosed and transferred as part of that transaction, subject to standard confidentiality protections. We will notify you of any transaction that results in your information becoming subject to a materially different privacy policy.
3.6 With consent and at your direction
We share information with third parties when you direct us to, and otherwise with your consent.
We do not sell personal information in exchange for money. Disclosures that certain laws define as a "sale" or "share" are described in Section 14, together with your opt-out rights.
4. ADVERTISING AND PERSONALIZATION
In short: Orby is supported in part by ads, shown in feeds and on post pages and always labeled. Ads are selected using your activity on Orby, limited advertiser-provided data, and coarse signals like country and language. You get real controls, under-18 (or age-unconfirmed) accounts never get personalized ads, sensitive categories are never used for targeting, and your messages are never used for ads.
4.1 How ads work on Orby. We show ads in feeds and on post conversation pages, labeled as "Promoted." Ads may be selected based on: contextual signals (such as the community or surface you are viewing); your activity on Orby (such as the communities you have joined and the interest categories they carry); coarse information such as your profile country, language, and platform; and the audience selections in Section 4.5 (advertiser lists, website audiences, engagement audiences, and similar audiences derived from them).
4.2 Limits on ad targeting. We do not use for ad targeting: (a) the content of your DMs, group chats, or channel messages — no message content or messaging activity feeds advertising, and for DM text this is structural, because our ad systems cannot use what our servers cannot read; (b) sensitive categories of personal information — advertisers cannot target communities whose topic is a special category (such as health, religion, politics, or sexual orientation), and we reject such targeting even when a community's name obscures its category; (c) profiling of minors — personalized (profiling-based) ads are served only to viewers with a confirmed 18+ date of birth who have personalization enabled; everyone else, including anyone whose age we cannot confirm, receives only contextual ads; and (d) identity- and age-verification data, which is never used for advertising.
4.3 Your advertising controls. You can: see why you are seeing a specific ad ("Why am I seeing this?" shows the main parameters, such as location or an advertiser audience list); turn off "Personalized ads" and "Share my data with ad partners" in Settings → Data & Privacy → Ad preferences; and manage the iOS App Tracking Transparency permission. If you are in the EEA, UK, or Switzerland, personalized ads and partner data sharing are OFF by default and stay off unless you turn them on. Turning personalization off does not reduce the number of ads; they become contextual instead.
4.4 Ad transparency. Ads are labeled as Promoted and identify the advertiser. We disclose the main parameters used to select each ad for you, and we maintain any legally required advertising transparency records.
4.5 Off-Orby data (advertiser pixel and conversions API). Advertisers may install the Orby pixel on their own websites or send us server-to-server conversion events. These events (such as page visits, content views, searches, sign-ups, add-to-carts, and purchases) can include an ad-click identifier, a first-party visitor identifier, and hashed contact details (email or phone, hashed before they reach us). We match such events to Orby accounts — for example, after you click an Orby ad, or when a hashed email an advertiser sends matches your account's — to measure campaigns and to build "website audiences" for targeting. The controls in Section 4.3 stop your account from receiving ads targeted this way, and Section 14 describes related opt-out rights. We do not buy browsing histories or profiles from data brokers, and our own properties carry no third-party ad trackers.
5. RECOMMENDATIONS AND HOW CONTENT IS RANKED
In short: Feeds and recommendations are ranked using signals like your subscriptions, activity, and content quality. You can see and influence how this works, use a chronological feed, and turn personalization off.
5.1 Our recommendation and ranking systems select and order the posts, communities, and users you see in home feeds, community feeds, notifications, search, and discovery surfaces. Main parameters include: the communities you have joined and your declared interests; your interactions (views, votes, comments, saves, hides, subscriptions); characteristics of the content (recency, topic, community, format, and quality signals such as community reception); language and coarse location (profile country); and integrity signals (spam, manipulation, and policy-risk scores that reduce the distribution of violating or borderline content).
5.2 Your controls. You can influence recommendations by joining or leaving communities, following, blocking, or muting users, hiding posts, and adjusting content preferences (including mature-content settings). You can browse chronologically with the "New" sort. In Settings → Data & Privacy you can turn off "Use my data to personalize my feeds" and "Use my data to improve Orby."
5.3 We use activity data described in Section 1 to train and improve the models behind ranking, recommendations, search, and safety, consistent with Section 2 and applicable law.
6. MESSAGES, CHAT, AND VOICE
In short: DM text is end-to-end encrypted and stored as ciphertext we cannot read. At send time, the app submits a transient plain-text copy for safety screening; it is discarded immediately unless the message fails the screen, in which case it is held encrypted for up to 48 hours for conversation-level safety analysis and then deleted. Attachments and non-DM chat are visible to our systems and scanned for serious harms. Nothing from your messages feeds ads.
6.1 Direct messages — end-to-end encrypted text. The text of your DMs is encrypted on your device with keys that stay on your devices (the private key never leaves your device's secure storage; only the public key is uploaded). Our servers store and relay the encrypted text but cannot read it. We retain, in readable form, only: conversation metadata (participants, timestamps, delivery/read state) needed to deliver and sync messages, and DM attachments as described in 6.4.
6.2 Send-time safety screening. When you send a DM, the app also submits a short-lived plain-text copy of the message for automated safety screening — content filters, abuse-pattern matching, and AI moderation services (including trusted external moderation vendors acting as our service providers). The screening runs in memory before delivery and can block messages that violate our rules. If the message passes, the plain-text copy is discarded at once and never written to storage. If the message fails the screen, that copy is retained in encrypted form, for up to 48 hours, for one purpose only: some of the most serious harms — grooming and sextortion in particular — cannot be recognised from a single message and are only visible across a conversation, so our automated analysis needs a short window of the flagged messages between the same two people. It is never delivered to anyone, is not used for advertising, ranking, or model training, is not readable by our moderation staff in the dashboard, and is deleted automatically once the window passes. We chose this design deliberately — encrypted at rest and in transit, with abuse blocked at the door — rather than offering fully unscreened DMs.
6.3 Channels and group chats. Content in community channels and group chats is stored on our servers in readable form so we can deliver it in real time, sync it across devices, preserve history, and moderate it. Disappearing messages, where offered, are deleted on the schedule shown in the feature, subject to Section 9.
6.4 Attachments and images. DM attachments must be uploaded through Orby (or come from our integrated, moderated GIF providers) and are scanned at upload time, including matching against known child-sexual-abuse-material hashes. Images that pass through our standard pipeline are re-encoded, which strips metadata including EXIF GPS coordinates; a file our pipeline cannot decode is stored as-is, so strip metadata client-side first if that matters to you.
6.5 Human review of messages happens only in limited circumstances: when a participant reports a message (reporting shares the reported content with us so we can review it); when automated systems flag scannable content (such as an attachment) indicating serious harm that requires confirmation before reporting to authorities; when required by valid legal process; or when necessary to investigate violations, security incidents, or to comply with law.
6.6 Never used for ads. No message content — DM or otherwise — is used to target advertising, and messaging activity does not feed advertising audiences. For DM text this is a structural guarantee, not just a policy: our ad systems cannot use what our servers cannot read.
6.7 Voice and live features. Real-time voice, video, and live sessions, where offered, are transmitted through our infrastructure and are not recorded or retained by us beyond the transient buffering needed to deliver them. Any feature that records will say so clearly to participants before it does.
6.8 What encryption cannot protect. End-to-end encryption protects DM text from Orby and from third parties in transit — it does not prevent the people you message from saving, screenshotting, or sharing what you send them, including with us via reports.
7. IDENTITY AND AGE VERIFICATION
In short: When verification is required, specialized providers perform it. Orby receives outcomes — not your ID document or biometric data, which we do not retain. Verification data is never used for ads.
7.1 We may require age, identity, or humanity verification for certain features, in certain jurisdictions, for account recovery, or when our systems flag an account as a suspected bot (verification restores full access). Verification is performed by us or by specialized verification providers acting on our behalf (for example, providers offering government-ID checks with liveness detection). Humanity checks may use CAPTCHA-style challenges, and phone verification uses one-time codes delivered by SMS.
7.2 What Orby receives and retains. Our systems are designed so that Orby receives and retains only: the verification outcome (for example, verified / not verified; over or under an age threshold), the method and provider used, the date, and limited anti-fraud signals (such as indicators that a document or session was fraudulent or reused). Orby does not receive or retain copies of your raw government-issued identity documents, document photographs, or raw biometric identifiers.
7.3 Provider processing. Verification providers process your verification data under contracts that require them to use it only to provide verification to us, to protect it with appropriate safeguards, and to retain it no longer than necessary and in accordance with applicable law (including biometric privacy laws). The specific provider and its processing are disclosed at the point of verification.
7.4 Verification outcomes are retained as described in Section 9 and used only for the purposes described at collection — such as gating age-restricted features, meeting legal obligations, preventing repeat abuse, and account recovery — and never for advertising.
8. YOUR RIGHTS AND CHOICES
In short: You can access, download, correct, and delete your information, control visibility and personalization, and exercise legal rights depending on where you live — without being discriminated against for doing so.
8.1 Tools available to everyone, regardless of location:
- Access and portability. You can access your profile and content in the product, and download a machine-readable export of your account data from Settings.
- Correction. You can edit your profile and most account information in Settings.
- Deletion. You can delete individual content, and you can deactivate or delete your account in Settings → Account Actions, with the effects and timelines described in Section 9.
- Visibility and contact controls. You can use private and restricted communities, control who can DM you and who can add you to group chats, block and mute accounts, and manage notification settings.
- Personalization and ad controls. As described in Sections 4 and 5, including the Ad preferences and Data & Privacy toggles.
- Marketing opt-out. You can opt out of marketing emails via the unsubscribe link in each message and manage push notifications in your device or app settings. Service and legal notices will still be sent.
8.2 Legal rights. Depending on your jurisdiction, you may have rights to: access/know; portability; correction; deletion; restriction of processing; objection to processing (including direct marketing); opt out of targeted advertising, "sale"/"sharing," and certain profiling; withdraw consent (without affecting prior processing); appeal a refusal; not be subject to solely automated decisions with legal or similarly significant effects; and lodge a complaint with a supervisory or enforcement authority. Jurisdiction-specific details appear in Sections 13-15.
8.3 How to exercise rights. Use the in-product tools above or email privacy@orbysocial.com. We will verify your request — typically by confirming control of the account or its associated email — and respond within the time required by applicable law. You may use an authorized agent where the law allows; we will require proof of authorization and may still verify your identity. We will not discriminate against you for exercising your rights. If we decline a request, we will explain why, and where the law provides an appeal right you may appeal by replying to our decision.
9. DATA RETENTION
In short: We keep information for as long as your account exists and as long as needed for the purposes described. Deleting your account offers three choices and they behave differently: schedule deletion, which starts a 7-day cancellation window (sign back in to cancel); delete now, which takes effect immediately and cannot be cancelled; or "Remove all my data", which also takes effect immediately and deletes your votes and reactions with it. Only the scheduled choice can be cancelled, and none of the three removes your posts or comments -- all three leave them up under an anonymous byline unless you delete them yourself first. Entries already written to our append-only moderation audit log are the one exception — they cannot be edited or deleted (Section 9.5).
9.1 General rule. We retain personal information for as long as necessary for the purposes described in this Policy — generally, for the life of your account — and then delete or de-identify it, unless a longer period is required or permitted by law.
9.2 Content you delete is removed from public or participant view immediately and deleted from our active systems on a defined schedule; backup copies age out on the backup rotation schedule. Copies re-shared by other users and messages already delivered to other participants may persist in their spaces.
9.3 Account deletion. Orby offers three ways to delete your account and they do not behave the same way. (a) Schedule deletion: your account is hidden immediately and deletion is scheduled 7 days out — signing back in within those 7 days cancels it and restores everything. After the window your profile is removed, your personal information is deleted or anonymized, and your public posts and comments are retained in disassociated form (shown as from a deleted account) so other users' threads stay intact. (b) Delete now: the same removal and anonymization, applied immediately — there is no cancellation window and we cannot reverse it. (c) "Remove all my data": everything in (b), and your votes and reactions are permanently deleted as well; your posts and comments remain on Orby, no longer attributed to you, and replies other people wrote beneath them are not deleted — to remove a post or comment itself, delete it before you delete your account; this also takes effect immediately, with no cancellation window. Only the scheduled path can be cancelled, and none of the three paths removes your posts or comments — each keeps them under an anonymous byline. Where the law of your jurisdiction requires deletion, we delete. Deactivation, by contrast, is reversible and simply hides your account until you return. One record is not reached by any of this: entries already written to our append-only moderation audit log (Section 9.5) cannot be edited or deleted, so personal data inside an entry remains there after your account is deleted.
9.4 Exceptions. We may retain specific information longer where reasonably necessary to: comply with legal obligations (for example, tax and accounting records for transactions); comply with legal holds, preservation requests, and valid legal process; investigate or address violations of our Terms and policies, including records of enforcement actions; preserve evidence of serious harms (child-safety evidence is retained as required or permitted by law, permanently where applicable); prevent banned users from returning (limited identifiers and enforcement records); maintain safety and security logs on defined schedules; resolve disputes and enforce agreements; and maintain aggregated or de-identified data. Separately from that list, entries already written to our append-only moderation audit log are retained because they cannot be removed: the log is built so that no one — including us — can alter or delete what it has recorded (Section 9.5).
9.5 Representative periods. Active-session records last while the session lives and appear in your security list; disappearing messages are deleted on their per-message timer by a daily job; moderation and audit records carry per-category retention schedules that are enforced by automated pruning and reviewed periodically; our tamper-evident moderation audit log is the exception, and it is append-only, so entries in it are never edited, pruned, or deleted, including when an account is deleted — an entry today records a one-way token in place of any phone number or email address, but entries written before that change can still contain those details; verification outcomes are kept for the life of the account plus a limited period, or shorter where law requires.
10. DATA SECURITY
10.1 We maintain administrative, technical, and physical safeguards designed to protect personal information — including encryption in transit and at rest, end-to-end encryption for DM text, hashed credentials, optional multi-factor authentication (authenticator apps and passkeys), access controls and least-privilege policies, network protections, logging and monitoring (including a tamper-evident audit log for sensitive moderation actions, which is append-only and so by design cannot be edited or deleted — see Section 9.5), secure development practices, vendor review, and an incident response program. Security researchers can reach us at security@orbysocial.com.
10.2 No system is perfectly secure, and we cannot guarantee absolute security. You play a role too: use a strong unique password, enable multi-factor authentication, and be cautious about phishing. If we learn of a breach of security affecting your personal information, we will notify you and the relevant authorities as required by applicable law.
11. INTERNATIONAL DATA TRANSFERS
11.1 Orby operates from the United States, and information we collect is transferred to, stored, and processed in the United States and other countries where we or our service providers operate, which may have data protection laws different from those in your country.
11.2 Where we transfer personal information from the EEA, United Kingdom, or Switzerland to countries not recognized as providing an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum or International Data Transfer Agreement (copies available on request), supplementary measures where appropriate, and, if and where Orby certifies to it, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. For transfers from other jurisdictions, we implement mechanisms required by local law.
12. CHILDREN AND TEENS
12.1 The Services are not directed to children under 13 (or a higher minimum age where local law sets one), and we do not knowingly collect personal information from them. We collect a date of birth at sign-up to enforce this. If we learn that we have collected personal information from a child under the applicable minimum age, we will delete it and terminate the account. Parents or guardians who believe a child under the minimum age is using the Services can contact us at privacy@orbysocial.com.
12.2 For users under 18 (or whose adulthood we have not confirmed): we do not serve personalized advertising based on profiling — such accounts receive only contextual ads, and this cannot be switched on; we apply default protections, including exclusion from mature-designated spaces; and we look for signals that an account may belong to someone under the declared age. A parent or guardian and their teen can also link accounts by mutual code to enable family supervision tools, such as restricting which communities the teen can visit.
13. SUPPLEMENTAL DISCLOSURES FOR THE EEA, UNITED KINGDOM, AND SWITZERLAND
In short: If you're in the EEA, UK, or Switzerland, this section explains who the controller is, the legal bases we rely on, and your GDPR rights. Personalized ads are off by default for you and require your consent.
13.1 Controller. The controller of your personal information is Orby Social Inc. [EEA/UK establishment or Article 27 representative to be identified here once appointed]. Our Data Protection Officer, if appointed, can be reached at privacy@orbysocial.com.
13.2 Legal bases. We process your personal information on the following legal bases under the GDPR / UK GDPR:
- Performance of a contract (Art. 6(1)(b)) — to provide the Services under our Terms of Service: operating your account, hosting and delivering content and messages, providing feeds and the core personalization inherent to the service, processing purchases, and providing support.
- Legitimate interests (Art. 6(1)(f)) — where not overridden by your interests, rights, and freedoms: securing the Services and preventing abuse, fraud, and platform manipulation; enforcing our policies; measuring and improving the Services; training and improving the models that operate the Services; providing non-profiling contextual advertising; and establishing, exercising, or defending legal claims. You can obtain information about our balancing assessments by contacting us.
- Consent (Art. 6(1)(a)) — where required: personalized advertising based on profiling and data sharing with advertising partners (both off by default in the EEA/UK/Switzerland until you enable them); optional features such as contact matching; marketing communications where consent is required; and any processing of special-category data you deliberately make public, where consent is the applicable condition. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — compliance with EU/member-state or UK law, including responding to valid orders, Digital Services Act obligations (statements of reasons, complaint handling, transparency reporting), tax and accounting rules, and child-safety reporting obligations.
- Vital interests (Art. 6(1)(d)) — to protect someone's life or physical safety in emergencies.
13.3 Your rights. Subject to conditions and exemptions under applicable law, you have the rights of access; rectification; erasure; restriction; portability; objection (including an absolute right to object to direct marketing); withdrawal of consent; and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, other than as permitted by Art. 22 GDPR. Enforcement decisions that significantly affect you include appeal paths with human review. You can exercise rights as described in Section 8.3, and you have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in Switzerland, the FDPIC) — though we would appreciate the chance to address your concerns first at privacy@orbysocial.com.
13.4 Automated decision-making. We use automated systems for ranking, recommendations, and safety (Sections 5 and 6). Ads shown to you are non-profiling unless you consent (13.2); minors never receive profiling-based ads regardless of settings; and a chronological, non-profiling feed option ("New") is available.
13.5 Data sources and recipients are as described in Sections 1 and 3; retention criteria are as described in Section 9; transfer safeguards are as described in Section 11.
14. SUPPLEMENTAL DISCLOSURES FOR U.S. STATES (INCLUDING CALIFORNIA)
In short: This section provides the disclosures required by California's CCPA/CPRA and similar state privacy laws, including the categories of information we collect and your opt-out rights.
14.1 Scope. This Section supplements the rest of this Policy and applies to residents of U.S. states with comprehensive privacy laws.
14.2 Categories of personal information. In the preceding 12 months, we have collected the following CCPA categories, from the sources and for the purposes described in Sections 1-2, and disclosed them for business purposes to the recipient categories in Section 3:
- Identifiers (username, email, optional phone, IP address, device identifiers such as a push token): collected.
- Customer records (billing details held by our payment processors; transaction records): collected.
- Protected classifications (age; other classifications only as you voluntarily disclose in content): limited.
- Commercial information (purchases such as Orby+, subscription status, advertising transactions): collected.
- Biometric information: not collected or retained by Orby (verification providers may process it transiently, per Section 7).
- Internet or network activity (usage data, interactions, log data): collected.
- Geolocation: user-declared country and optional city, plus coarse sign-in city derived from IP for session security; no precise geolocation.
- Sensory or audiovisual information (content you post; live audio/video transmitted but not recorded): collected as you provide it.
- Professional or employment information (only if you provide it, such as advertiser business accounts): limited.
- Education information: not collected except as voluntarily disclosed.
- Inferences (interest and personalization inferences): collected.
- Sensitive personal information (account log-in credentials; message contents — DM text end-to-end encrypted and unreadable by us; verification outcomes; sensitive traits only as voluntarily disclosed in content): limited.
14.3 Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA (such as providing the Services, security, and legal compliance), and we do not use it to infer characteristics about you. We therefore do not offer a "Limit the Use of My Sensitive Personal Information" link, because none is required.
14.4 "Sale" and "sharing." We do not sell personal information for money, and we do not knowingly sell or share the personal information of consumers under 16. If and to the extent our advertising measurement and matched-audience practices (Section 4.5) constitute "sharing" for cross-context behavioral advertising or a "sale" as broadly defined, you can opt out in Settings → Data & Privacy → Ad preferences ("Personalized ads" and "Share my data with ad partners"). Our own website deploys no third-party cross-context advertising trackers; where a Global Privacy Control signal applies to data we process in a browser context, we treat it as an opt-out for that browser.
14.5 Your rights. Depending on your state, you may have the rights to know/access, correct, delete, obtain a portable copy, opt out of targeted advertising, sale/sharing, and certain profiling, and to appeal a denial — exercisable as described in Section 8.3, without discrimination. California residents may designate an authorized agent and may request information about disclosures under California's "Shine the Light" law at privacy@orbysocial.com. We do not offer financial incentives in exchange for personal information. Retention criteria per category follow Section 9.
14.6 Do Not Track. Because there is no common standard for legacy browser "Do Not Track" signals, we do not respond to them; we honor the Global Privacy Control as described above.
15. SUPPLEMENTAL DISCLOSURES FOR OTHER JURISDICTIONS
15.1 Brazil (LGPD). We process personal information under the legal bases of Law No. 13,709/2018 (contract performance, legitimate interests, consent, legal obligation, and protection of life), and you have the rights set out in Article 18, including confirmation, access, correction, anonymization, deletion, portability, and information about sharing. Requests may be submitted per Section 8.3; the contact for our representative (encarregado) will be published here once appointed. You may also lodge complaints with the ANPD.
15.2 Canada. We process personal information in accordance with PIPEDA and applicable provincial laws, including Quebec's Law 25. Quebec residents have rights to access, rectification, de-indexing where applicable, and information about automated processing; our person in charge of the protection of personal information can be reached at privacy@orbysocial.com. Personal information may be processed outside your province or Canada, as described in Section 11.
15.3 Australia. We handle personal information consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may complain to us first, and then to the OAIC if unresolved. Overseas disclosure occurs as described in Section 11.
15.4 Other jurisdictions' mandatory rights apply to the extent required by local law, and nothing in this Policy limits them.
16. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. The current version, with its effective date, is always available in the app (About → Privacy Policy) and on our website, and prior versions are available on request. If we make material changes, we will provide reasonable advance notice — for example, by email or in-product notification — and, where required by law, obtain your consent. Material changes affecting how we process previously collected information will not be applied retroactively without a lawful basis.
17. HOW TO CONTACT US
Orby Social Inc.
Attn: Privacy
[Registered address to be completed]
United States
- Privacy requests: privacy@orbysocial.com
- Security: security@orbysocial.com
- General support: support@orbysocial.com
- Data Protection Officer and EEA/UK representative: to be published here once appointed.