Orby

Legal

Privacy Policy

Last updated September 29, 2026

Effective date: July 10, 2026
Last updated: September 29, 2026

In short: This Privacy Policy explains what information Orby collects when you use our services, how we use and share it, how long we keep it, and the rights and controls you have. Short "In short" summaries appear throughout for convenience; the full text controls.

This Privacy Policy applies to the Orby platform, including our website (orbysocial.com), our mobile apps, real-time chat features, APIs, moderator tools, advertiser tools, and all other products and services that link to this Privacy Policy (together, the "Services"), operated by Orby Social Inc. [registered address to be completed] ("Orby," "we," "us," or "our"). Capitalized terms not defined here have the meanings given in our Terms of Service.

This Privacy Policy does not apply to third-party websites, apps, or services, even if you reach them through the Services, or to the data practices of advertisers on their own properties. Jurisdiction-specific disclosures — including for the EEA/UK, U.S. states including California, Brazil, Canada, and Australia — appear in Sections 13-15 and supplement the rest of this Policy.

CONTENTS
1. Information We Collect
2. How We Use Information
3. How Information Is Shared
4. Advertising and Personalization
5. Recommendations and How Content Is Ranked
6. Messages, Chat, and Voice
7. Identity and Age Verification
8. Your Rights and Choices
9. Data Retention
10. Data Security
11. International Data Transfers
12. Children and Teens
13. Supplemental Disclosures for the EEA, United Kingdom, and Switzerland
14. Supplemental Disclosures for U.S. States (Including California)
15. Supplemental Disclosures for Other Jurisdictions
16. Changes to This Privacy Policy
17. How to Contact Us

1. INFORMATION WE COLLECT

In short: We collect information you give us (like your account details and the content you post), information generated when you use Orby (like device and usage data), and limited information from other sources (like verification providers and advertisers' measurement data).

1.1 Information you provide to us

1.2 Information we collect automatically

1.3 Information from other sources

We may combine the information described in this Section 1 to provide, personalize, secure, and improve the Services.

2. HOW WE USE INFORMATION

In short: We use your information to run Orby, personalize your feeds and recommendations, keep the platform safe, show and measure ads, provide paid features, communicate with you, improve the Services, and meet our legal obligations.

We use the information we collect to:

3. HOW INFORMATION IS SHARED

In short: Public content is public. We share information with your consent, with service providers working for us, for legal and safety reasons, and in aggregate with advertisers. We do not sell your personal information for money.

3.1 Visible to other users and the public

3.2 Service providers

We share information with vendors who process it on our behalf and under our instructions to provide the Services — including cloud hosting and storage, content delivery, communications delivery (email, SMS, push), payment processing, customer support tooling, security, anti-fraud and anti-abuse, content-safety and AI moderation vendors that help scan content for policy violations, and verification providers. Service providers are bound by contractual obligations to protect the information and to use it only for the services they provide to us.

3.3 Advertisers and measurement

We provide advertisers with aggregate reporting about campaign delivery and performance (for example, impressions, clicks, conversions, and audience-level statistics). We do not share information that directly identifies you (such as your name, email address, or phone number) with advertisers without your consent. Where measurement involves matching (Section 4.5), you can opt out as described in Sections 4 and 14.

3.4 Safety, legal, and protection of rights

We may access, preserve, and share information with law enforcement, government authorities, courts, or other parties when we believe in good faith that doing so is reasonably necessary to: (a) comply with applicable law, regulation, legal process, or enforceable governmental request; (b) enforce our Terms of Service and policies, including investigating potential violations; (c) detect, prevent, or address fraud, abuse, security, or technical issues; (d) protect the rights, property, and safety of Orby, our users, or the public, including to prevent death or imminent bodily harm; and (e) report suspected child sexual exploitation to NCMEC and equivalent authorities, as required or permitted by law. We require valid legal process for non-emergency government requests and notify users where legally permitted.

3.5 Corporate transactions

If Orby is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of our assets, information may be disclosed and transferred as part of that transaction, subject to standard confidentiality protections. We will notify you of any transaction that results in your information becoming subject to a materially different privacy policy.

3.6 With consent and at your direction

We share information with third parties when you direct us to, and otherwise with your consent.

We do not sell personal information in exchange for money. Disclosures that certain laws define as a "sale" or "share" are described in Section 14, together with your opt-out rights.

4. ADVERTISING AND PERSONALIZATION

In short: Orby is supported in part by ads, shown in feeds and on post pages and always labeled. Ads are selected using your activity on Orby, limited advertiser-provided data, and coarse signals like country and language. You get real controls, under-18 (or age-unconfirmed) accounts never get personalized ads, sensitive categories are never used for targeting, and your messages are never used for ads.

4.1 How ads work on Orby. We show ads in feeds and on post conversation pages, labeled as "Promoted." Ads may be selected based on: contextual signals (such as the community or surface you are viewing); your activity on Orby (such as the communities you have joined and the interest categories they carry); coarse information such as your profile country, language, and platform; and the audience selections in Section 4.5 (advertiser lists, website audiences, engagement audiences, and similar audiences derived from them).

4.2 Limits on ad targeting. We do not use for ad targeting: (a) the content of your DMs, group chats, or channel messages — no message content or messaging activity feeds advertising, and for DM text this is structural, because our ad systems cannot use what our servers cannot read; (b) sensitive categories of personal information — advertisers cannot target communities whose topic is a special category (such as health, religion, politics, or sexual orientation), and we reject such targeting even when a community's name obscures its category; (c) profiling of minors — personalized (profiling-based) ads are served only to viewers with a confirmed 18+ date of birth who have personalization enabled; everyone else, including anyone whose age we cannot confirm, receives only contextual ads; and (d) identity- and age-verification data, which is never used for advertising.

4.3 Your advertising controls. You can: see why you are seeing a specific ad ("Why am I seeing this?" shows the main parameters, such as location or an advertiser audience list); turn off "Personalized ads" and "Share my data with ad partners" in Settings → Data & Privacy → Ad preferences; and manage the iOS App Tracking Transparency permission. If you are in the EEA, UK, or Switzerland, personalized ads and partner data sharing are OFF by default and stay off unless you turn them on. Turning personalization off does not reduce the number of ads; they become contextual instead.

4.4 Ad transparency. Ads are labeled as Promoted and identify the advertiser. We disclose the main parameters used to select each ad for you, and we maintain any legally required advertising transparency records.

4.5 Off-Orby data (advertiser pixel and conversions API). Advertisers may install the Orby pixel on their own websites or send us server-to-server conversion events. These events (such as page visits, content views, searches, sign-ups, add-to-carts, and purchases) can include an ad-click identifier, a first-party visitor identifier, and hashed contact details (email or phone, hashed before they reach us). We match such events to Orby accounts — for example, after you click an Orby ad, or when a hashed email an advertiser sends matches your account's — to measure campaigns and to build "website audiences" for targeting. The controls in Section 4.3 stop your account from receiving ads targeted this way, and Section 14 describes related opt-out rights. We do not buy browsing histories or profiles from data brokers, and our own properties carry no third-party ad trackers.

5. RECOMMENDATIONS AND HOW CONTENT IS RANKED

In short: Feeds and recommendations are ranked using signals like your subscriptions, activity, and content quality. You can see and influence how this works, use a chronological feed, and turn personalization off.

5.1 Our recommendation and ranking systems select and order the posts, communities, and users you see in home feeds, community feeds, notifications, search, and discovery surfaces. Main parameters include: the communities you have joined and your declared interests; your interactions (views, votes, comments, saves, hides, subscriptions); characteristics of the content (recency, topic, community, format, and quality signals such as community reception); language and coarse location (profile country); and integrity signals (spam, manipulation, and policy-risk scores that reduce the distribution of violating or borderline content).

5.2 Your controls. You can influence recommendations by joining or leaving communities, following, blocking, or muting users, hiding posts, and adjusting content preferences (including mature-content settings). You can browse chronologically with the "New" sort. In Settings → Data & Privacy you can turn off "Use my data to personalize my feeds" and "Use my data to improve Orby."

5.3 We use activity data described in Section 1 to train and improve the models behind ranking, recommendations, search, and safety, consistent with Section 2 and applicable law.

6. MESSAGES, CHAT, AND VOICE

In short: DM text is end-to-end encrypted and stored as ciphertext we cannot read. At send time, the app submits a transient plain-text copy for safety screening; it is discarded immediately unless the message fails the screen, in which case it is held encrypted for up to 48 hours for conversation-level safety analysis and then deleted. Attachments and non-DM chat are visible to our systems and scanned for serious harms. Nothing from your messages feeds ads.

6.1 Direct messages — end-to-end encrypted text. The text of your DMs is encrypted on your device with keys that stay on your devices (the private key never leaves your device's secure storage; only the public key is uploaded). Our servers store and relay the encrypted text but cannot read it. We retain, in readable form, only: conversation metadata (participants, timestamps, delivery/read state) needed to deliver and sync messages, and DM attachments as described in 6.4.

6.2 Send-time safety screening. When you send a DM, the app also submits a short-lived plain-text copy of the message for automated safety screening — content filters, abuse-pattern matching, and AI moderation services (including trusted external moderation vendors acting as our service providers). The screening runs in memory before delivery and can block messages that violate our rules. If the message passes, the plain-text copy is discarded at once and never written to storage. If the message fails the screen, that copy is retained in encrypted form, for up to 48 hours, for one purpose only: some of the most serious harms — grooming and sextortion in particular — cannot be recognised from a single message and are only visible across a conversation, so our automated analysis needs a short window of the flagged messages between the same two people. It is never delivered to anyone, is not used for advertising, ranking, or model training, is not readable by our moderation staff in the dashboard, and is deleted automatically once the window passes. We chose this design deliberately — encrypted at rest and in transit, with abuse blocked at the door — rather than offering fully unscreened DMs.

6.3 Channels and group chats. Content in community channels and group chats is stored on our servers in readable form so we can deliver it in real time, sync it across devices, preserve history, and moderate it. Disappearing messages, where offered, are deleted on the schedule shown in the feature, subject to Section 9.

6.4 Attachments and images. DM attachments must be uploaded through Orby (or come from our integrated, moderated GIF providers) and are scanned at upload time, including matching against known child-sexual-abuse-material hashes. Images that pass through our standard pipeline are re-encoded, which strips metadata including EXIF GPS coordinates; a file our pipeline cannot decode is stored as-is, so strip metadata client-side first if that matters to you.

6.5 Human review of messages happens only in limited circumstances: when a participant reports a message (reporting shares the reported content with us so we can review it); when automated systems flag scannable content (such as an attachment) indicating serious harm that requires confirmation before reporting to authorities; when required by valid legal process; or when necessary to investigate violations, security incidents, or to comply with law.

6.6 Never used for ads. No message content — DM or otherwise — is used to target advertising, and messaging activity does not feed advertising audiences. For DM text this is a structural guarantee, not just a policy: our ad systems cannot use what our servers cannot read.

6.7 Voice and live features. Real-time voice, video, and live sessions, where offered, are transmitted through our infrastructure and are not recorded or retained by us beyond the transient buffering needed to deliver them. Any feature that records will say so clearly to participants before it does.

6.8 What encryption cannot protect. End-to-end encryption protects DM text from Orby and from third parties in transit — it does not prevent the people you message from saving, screenshotting, or sharing what you send them, including with us via reports.

7. IDENTITY AND AGE VERIFICATION

In short: When verification is required, specialized providers perform it. Orby receives outcomes — not your ID document or biometric data, which we do not retain. Verification data is never used for ads.

7.1 We may require age, identity, or humanity verification for certain features, in certain jurisdictions, for account recovery, or when our systems flag an account as a suspected bot (verification restores full access). Verification is performed by us or by specialized verification providers acting on our behalf (for example, providers offering government-ID checks with liveness detection). Humanity checks may use CAPTCHA-style challenges, and phone verification uses one-time codes delivered by SMS.

7.2 What Orby receives and retains. Our systems are designed so that Orby receives and retains only: the verification outcome (for example, verified / not verified; over or under an age threshold), the method and provider used, the date, and limited anti-fraud signals (such as indicators that a document or session was fraudulent or reused). Orby does not receive or retain copies of your raw government-issued identity documents, document photographs, or raw biometric identifiers.

7.3 Provider processing. Verification providers process your verification data under contracts that require them to use it only to provide verification to us, to protect it with appropriate safeguards, and to retain it no longer than necessary and in accordance with applicable law (including biometric privacy laws). The specific provider and its processing are disclosed at the point of verification.

7.4 Verification outcomes are retained as described in Section 9 and used only for the purposes described at collection — such as gating age-restricted features, meeting legal obligations, preventing repeat abuse, and account recovery — and never for advertising.

8. YOUR RIGHTS AND CHOICES

In short: You can access, download, correct, and delete your information, control visibility and personalization, and exercise legal rights depending on where you live — without being discriminated against for doing so.

8.1 Tools available to everyone, regardless of location:

8.2 Legal rights. Depending on your jurisdiction, you may have rights to: access/know; portability; correction; deletion; restriction of processing; objection to processing (including direct marketing); opt out of targeted advertising, "sale"/"sharing," and certain profiling; withdraw consent (without affecting prior processing); appeal a refusal; not be subject to solely automated decisions with legal or similarly significant effects; and lodge a complaint with a supervisory or enforcement authority. Jurisdiction-specific details appear in Sections 13-15.

8.3 How to exercise rights. Use the in-product tools above or email privacy@orbysocial.com. We will verify your request — typically by confirming control of the account or its associated email — and respond within the time required by applicable law. You may use an authorized agent where the law allows; we will require proof of authorization and may still verify your identity. We will not discriminate against you for exercising your rights. If we decline a request, we will explain why, and where the law provides an appeal right you may appeal by replying to our decision.

9. DATA RETENTION

In short: We keep information for as long as your account exists and as long as needed for the purposes described. Deleting your account offers three choices and they behave differently: schedule deletion, which starts a 7-day cancellation window (sign back in to cancel); delete now, which takes effect immediately and cannot be cancelled; or "Remove all my data", which also takes effect immediately and deletes your votes and reactions with it. Only the scheduled choice can be cancelled, and none of the three removes your posts or comments -- all three leave them up under an anonymous byline unless you delete them yourself first. Entries already written to our append-only moderation audit log are the one exception — they cannot be edited or deleted (Section 9.5).

9.1 General rule. We retain personal information for as long as necessary for the purposes described in this Policy — generally, for the life of your account — and then delete or de-identify it, unless a longer period is required or permitted by law.

9.2 Content you delete is removed from public or participant view immediately and deleted from our active systems on a defined schedule; backup copies age out on the backup rotation schedule. Copies re-shared by other users and messages already delivered to other participants may persist in their spaces.

9.3 Account deletion. Orby offers three ways to delete your account and they do not behave the same way. (a) Schedule deletion: your account is hidden immediately and deletion is scheduled 7 days out — signing back in within those 7 days cancels it and restores everything. After the window your profile is removed, your personal information is deleted or anonymized, and your public posts and comments are retained in disassociated form (shown as from a deleted account) so other users' threads stay intact. (b) Delete now: the same removal and anonymization, applied immediately — there is no cancellation window and we cannot reverse it. (c) "Remove all my data": everything in (b), and your votes and reactions are permanently deleted as well; your posts and comments remain on Orby, no longer attributed to you, and replies other people wrote beneath them are not deleted — to remove a post or comment itself, delete it before you delete your account; this also takes effect immediately, with no cancellation window. Only the scheduled path can be cancelled, and none of the three paths removes your posts or comments — each keeps them under an anonymous byline. Where the law of your jurisdiction requires deletion, we delete. Deactivation, by contrast, is reversible and simply hides your account until you return. One record is not reached by any of this: entries already written to our append-only moderation audit log (Section 9.5) cannot be edited or deleted, so personal data inside an entry remains there after your account is deleted.

9.4 Exceptions. We may retain specific information longer where reasonably necessary to: comply with legal obligations (for example, tax and accounting records for transactions); comply with legal holds, preservation requests, and valid legal process; investigate or address violations of our Terms and policies, including records of enforcement actions; preserve evidence of serious harms (child-safety evidence is retained as required or permitted by law, permanently where applicable); prevent banned users from returning (limited identifiers and enforcement records); maintain safety and security logs on defined schedules; resolve disputes and enforce agreements; and maintain aggregated or de-identified data. Separately from that list, entries already written to our append-only moderation audit log are retained because they cannot be removed: the log is built so that no one — including us — can alter or delete what it has recorded (Section 9.5).

9.5 Representative periods. Active-session records last while the session lives and appear in your security list; disappearing messages are deleted on their per-message timer by a daily job; moderation and audit records carry per-category retention schedules that are enforced by automated pruning and reviewed periodically; our tamper-evident moderation audit log is the exception, and it is append-only, so entries in it are never edited, pruned, or deleted, including when an account is deleted — an entry today records a one-way token in place of any phone number or email address, but entries written before that change can still contain those details; verification outcomes are kept for the life of the account plus a limited period, or shorter where law requires.

10. DATA SECURITY

10.1 We maintain administrative, technical, and physical safeguards designed to protect personal information — including encryption in transit and at rest, end-to-end encryption for DM text, hashed credentials, optional multi-factor authentication (authenticator apps and passkeys), access controls and least-privilege policies, network protections, logging and monitoring (including a tamper-evident audit log for sensitive moderation actions, which is append-only and so by design cannot be edited or deleted — see Section 9.5), secure development practices, vendor review, and an incident response program. Security researchers can reach us at security@orbysocial.com.

10.2 No system is perfectly secure, and we cannot guarantee absolute security. You play a role too: use a strong unique password, enable multi-factor authentication, and be cautious about phishing. If we learn of a breach of security affecting your personal information, we will notify you and the relevant authorities as required by applicable law.

11. INTERNATIONAL DATA TRANSFERS

11.1 Orby operates from the United States, and information we collect is transferred to, stored, and processed in the United States and other countries where we or our service providers operate, which may have data protection laws different from those in your country.

11.2 Where we transfer personal information from the EEA, United Kingdom, or Switzerland to countries not recognized as providing an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum or International Data Transfer Agreement (copies available on request), supplementary measures where appropriate, and, if and where Orby certifies to it, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. For transfers from other jurisdictions, we implement mechanisms required by local law.

12. CHILDREN AND TEENS

12.1 The Services are not directed to children under 13 (or a higher minimum age where local law sets one), and we do not knowingly collect personal information from them. We collect a date of birth at sign-up to enforce this. If we learn that we have collected personal information from a child under the applicable minimum age, we will delete it and terminate the account. Parents or guardians who believe a child under the minimum age is using the Services can contact us at privacy@orbysocial.com.

12.2 For users under 18 (or whose adulthood we have not confirmed): we do not serve personalized advertising based on profiling — such accounts receive only contextual ads, and this cannot be switched on; we apply default protections, including exclusion from mature-designated spaces; and we look for signals that an account may belong to someone under the declared age. A parent or guardian and their teen can also link accounts by mutual code to enable family supervision tools, such as restricting which communities the teen can visit.

13. SUPPLEMENTAL DISCLOSURES FOR THE EEA, UNITED KINGDOM, AND SWITZERLAND

In short: If you're in the EEA, UK, or Switzerland, this section explains who the controller is, the legal bases we rely on, and your GDPR rights. Personalized ads are off by default for you and require your consent.

13.1 Controller. The controller of your personal information is Orby Social Inc. [EEA/UK establishment or Article 27 representative to be identified here once appointed]. Our Data Protection Officer, if appointed, can be reached at privacy@orbysocial.com.

13.2 Legal bases. We process your personal information on the following legal bases under the GDPR / UK GDPR:

13.3 Your rights. Subject to conditions and exemptions under applicable law, you have the rights of access; rectification; erasure; restriction; portability; objection (including an absolute right to object to direct marketing); withdrawal of consent; and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, other than as permitted by Art. 22 GDPR. Enforcement decisions that significantly affect you include appeal paths with human review. You can exercise rights as described in Section 8.3, and you have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in Switzerland, the FDPIC) — though we would appreciate the chance to address your concerns first at privacy@orbysocial.com.

13.4 Automated decision-making. We use automated systems for ranking, recommendations, and safety (Sections 5 and 6). Ads shown to you are non-profiling unless you consent (13.2); minors never receive profiling-based ads regardless of settings; and a chronological, non-profiling feed option ("New") is available.

13.5 Data sources and recipients are as described in Sections 1 and 3; retention criteria are as described in Section 9; transfer safeguards are as described in Section 11.

14. SUPPLEMENTAL DISCLOSURES FOR U.S. STATES (INCLUDING CALIFORNIA)

In short: This section provides the disclosures required by California's CCPA/CPRA and similar state privacy laws, including the categories of information we collect and your opt-out rights.

14.1 Scope. This Section supplements the rest of this Policy and applies to residents of U.S. states with comprehensive privacy laws.

14.2 Categories of personal information. In the preceding 12 months, we have collected the following CCPA categories, from the sources and for the purposes described in Sections 1-2, and disclosed them for business purposes to the recipient categories in Section 3:

14.3 Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA (such as providing the Services, security, and legal compliance), and we do not use it to infer characteristics about you. We therefore do not offer a "Limit the Use of My Sensitive Personal Information" link, because none is required.

14.4 "Sale" and "sharing." We do not sell personal information for money, and we do not knowingly sell or share the personal information of consumers under 16. If and to the extent our advertising measurement and matched-audience practices (Section 4.5) constitute "sharing" for cross-context behavioral advertising or a "sale" as broadly defined, you can opt out in Settings → Data & Privacy → Ad preferences ("Personalized ads" and "Share my data with ad partners"). Our own website deploys no third-party cross-context advertising trackers; where a Global Privacy Control signal applies to data we process in a browser context, we treat it as an opt-out for that browser.

14.5 Your rights. Depending on your state, you may have the rights to know/access, correct, delete, obtain a portable copy, opt out of targeted advertising, sale/sharing, and certain profiling, and to appeal a denial — exercisable as described in Section 8.3, without discrimination. California residents may designate an authorized agent and may request information about disclosures under California's "Shine the Light" law at privacy@orbysocial.com. We do not offer financial incentives in exchange for personal information. Retention criteria per category follow Section 9.

14.6 Do Not Track. Because there is no common standard for legacy browser "Do Not Track" signals, we do not respond to them; we honor the Global Privacy Control as described above.

15. SUPPLEMENTAL DISCLOSURES FOR OTHER JURISDICTIONS

15.1 Brazil (LGPD). We process personal information under the legal bases of Law No. 13,709/2018 (contract performance, legitimate interests, consent, legal obligation, and protection of life), and you have the rights set out in Article 18, including confirmation, access, correction, anonymization, deletion, portability, and information about sharing. Requests may be submitted per Section 8.3; the contact for our representative (encarregado) will be published here once appointed. You may also lodge complaints with the ANPD.

15.2 Canada. We process personal information in accordance with PIPEDA and applicable provincial laws, including Quebec's Law 25. Quebec residents have rights to access, rectification, de-indexing where applicable, and information about automated processing; our person in charge of the protection of personal information can be reached at privacy@orbysocial.com. Personal information may be processed outside your province or Canada, as described in Section 11.

15.3 Australia. We handle personal information consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may complain to us first, and then to the OAIC if unresolved. Overseas disclosure occurs as described in Section 11.

15.4 Other jurisdictions' mandatory rights apply to the extent required by local law, and nothing in this Policy limits them.

16. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. The current version, with its effective date, is always available in the app (About → Privacy Policy) and on our website, and prior versions are available on request. If we make material changes, we will provide reasonable advance notice — for example, by email or in-product notification — and, where required by law, obtain your consent. Material changes affecting how we process previously collected information will not be applied retroactively without a lawful basis.

17. HOW TO CONTACT US

Orby Social Inc.
Attn: Privacy
[Registered address to be completed]
United States