Orbital ORBITALRELATIONS.COM

Last updated: 10 September 2026

Privacy policy

Contemplation Inc., a Delaware corporation ("Company", "we", "us" or "our"), provides Orbital, an application for keeping track of the people you want to stay in touch with. This policy explains what we hold, why, who can reach it, and what you can do about it.

It applies to the Orbital mobile app, the website at orbitalrelations.com, and any email between you and us about either.

The short version

Everything you record is stored in your account and synced across your devices. Nobody else can see it. You can export or delete all of it at any time.

Orbital holds notes you write about other people — names, what you talked about, when their children have birthdays. That is the most sensitive thing in this product and it is why most of this document exists.

We do not sell your data, we do not share it for advertising, we do not run analytics on your content, and we do not use anything you write to train a model.

Who is responsible for your information

Contemplation Inc. is the controller of the personal information described here. You can reach us at hello@orbitalrelations.com.

Age

Orbital is for people aged 16 and over, and we do not knowingly collect personal information from anybody under 16. If you are under 16, do not use Orbital and do not give us any information.

If you are 16 or 17, or otherwise under the age of majority where you live, use Orbital only with the involvement of a parent or guardian, as described in our terms of use.

If you believe we hold information about somebody under 16, contact us and we will remove it.

What you give us

Your account. An email address and a password. The password is stored only as a hash by our authentication provider and is never visible to us.

What you record. The people you add and everything you record about them: names, optional phone numbers and email addresses, the folder you put them in, how often you want to reach out, freeform notes, open threads, important dates, and every reach-out you log with its date, method and what you talked about.

Your settings. Theme, default cadence, sort order, reminder day and time, and whether reminders are on.

Correspondence. If you write to us, we keep the message and your email address.

What you record about other people

This is the part worth reading carefully.

Most of what Orbital holds is personal information about people who are not our users and have not agreed to anything. Their names, how often you speak, what they told you, their children's ages. We hold it because you put it there.

You decide what goes in. We do not collect it, prompt for it, enrich it, or look anything up about anybody. Orbital knows only what you type, plus whatever you choose to bring in from a contact you pick yourself.

Under European and UK data protection law, you are most likely the controller of that information and we are your processor for it, in the same way you would be if you kept the same notes in a paper notebook or a spreadsheet. Personal, household record-keeping usually falls outside those laws entirely; using Orbital for business contacts may not. If you use it professionally, the obligations that come with holding information about other people are yours, and it is worth being sure you understand them.

A test worth applying: write every note as though the person could one day read it. That is the standard we designed this product around, and it is also the safest way to use it.

If somebody asks you to remove what you hold about them, you can delete them from Orbital yourself and it propagates to your devices. If you need our help with a request about somebody else's information, write to us.

What we do not collect

We do not collect your location, your photo library, your microphone, your camera, your call or message history, or your browsing.

We do not read your address book. Importing a contact opens your operating system's own picker; the system returns the one contact you choose, and Orbital never sees the rest.

We do not collect payment card details. Purchases go through the App Store or Google Play.

We do not run product analytics. There is no analytics SDK in Orbital. We cannot see which screens you visit or how often you open the app.

We do not use anything you record for advertising, profiling, or training machine learning models.

Device permissions

Contacts, only when you tap "Import from contacts", and only for the single contact you select.

Notifications, only if you turn on a reminder in Settings. Orbital never asks at launch.

You can grant or withdraw either at any time in your device settings. Orbital works without both.

Where your data is stored, and who can reach it

Your data is stored in a Supabase Postgres database hosted on Amazon Web Services in the United States (region us-east-1, Northern Virginia). It is encrypted in transit and at rest.

Access is restricted to your own account at the database level, using row-level security, so one account cannot read another's data even in principle. A small number of our staff can reach production systems for support and maintenance; that access is limited to what is necessary and is not used to browse content.

A copy of your data also lives on each device you have signed in on, so the app works without a network.

Why Orbital is not end-to-end encrypted

Orbital is deliberately not end-to-end encrypted, and you should know why. Cloud backup is a promise this product makes: forgetting your password must never mean losing years of somebody's relationship history. Recovering your data after a password reset is only possible if we can decrypt it, which rules out end-to-end encryption.

We would rather say that plainly than imply a protection we do not provide. If you need a tool whose provider mathematically cannot read your notes, Orbital is not it.

Notifications

Orbital sends at most one notification a day, scheduled and delivered entirely on your device. Nothing is sent to us to produce one, and none of it is logged.

There are two kinds. A weekly check-in tells you how many people are past due. An important-date notice names the person and the label you gave the date — for example, "Maya Karim · Birthday".

That second kind puts somebody else's name on your lock screen, which is the one place in this product where another person's information can be visible without your phone being unlocked. Your operating system controls whether lock-screen previews are shown at all, and both kinds of reminder can be turned off in Settings.

How we use your information, and our legal basis

If you are in the European Economic Area, the United Kingdom, or Switzerland, data protection law requires a legal basis for each use. They are named below. For everybody else, the same descriptions explain what we do and why.

To create your account and sign you in — your email address and password hash. Basis: performance of our contract with you.

To store and sync what you record — everything in your account. Basis: performance of our contract with you.

To send confirmation and password-reset emails — your email address. Basis: performance of our contract with you.

To schedule reminders — your reminder settings and the dates you have recorded, used on your device only. Basis: your consent, given when you turn a reminder on and withdrawn when you turn it off.

To confirm and restore your subscription — your purchase receipt and entitlement status. Basis: performance of our contract with you.

To answer your support requests — your correspondence and account details. Basis: performance of our contract and our legitimate interest in supporting our users.

To keep the service running and secure, and to prevent abuse — server logs and account records. Basis: our legitimate interest in a working, secure product.

To tell you about changes to these policies or your account — your email address. Basis: performance of our contract and compliance with our legal obligations.

To comply with the law — whatever is required. Basis: compliance with a legal obligation.

Where we rely on legitimate interests we have considered whether they are overridden by your rights, and you can object at any time. We do not carry out automated decision-making that produces legal or similarly significant effects.

An email address and a password are necessary to have an account. Everything else is optional.

Who we share it with

We do not sell your personal information, and we do not share it for advertising of any kind.

We use service providers who handle information on our behalf, under written terms, only on our instructions. As of the date at the top of this policy they are:

We may disclose personal information to a buyer or successor in a merger, acquisition, restructuring, or sale of assets, including in bankruptcy. You will be told before your information becomes subject to a different privacy policy.

We may disclose personal information to comply with a court order, law, or legal process, including a government or regulatory request; and to enforce our terms of use or protect the rights, property or safety of the Company, our users, or others.

We may disclose aggregated or de-identified information that identifies nobody.

International transfers

We are based in the United States and your data is stored there. If you are in the EEA, the UK, or Switzerland, your personal information is transferred to and processed in a country that may not provide the same level of data protection as your own.

Where we make such a transfer we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss addendum where they apply; or a valid adequacy decision covering the recipient, including the EU–US Data Privacy Framework and its UK extension where the recipient is certified.

You can request a copy of the relevant safeguards by writing to us.

How long we keep it

While your account exists, we keep what you have recorded, because that is the service.

Deleted records are marked deleted rather than erased. When you delete a person, a note, or use "Delete everything", the record stops being visible in Orbital on every device, immediately and permanently — but the row itself is retained in our database. This is what stops a deletion made on one device being undone by another device that was offline at the time. Those retained rows still contain what you wrote.

Deleting your account erases them. Account deletion is a real deletion: your account and every record attached to it, retained or not, is removed from our database and cannot be recovered by us or by you.

Support correspondence is kept for up to 24 months after the matter is closed.

Server and diagnostic logs are kept for up to 12 months. They record requests, not content.

Records we must keep by law, such as transaction records, are kept for the period the law requires.

Getting your data out, and deleting it

Export. Settings → Data → Export everything produces a complete copy as JSON, plus spreadsheet files. It is always available, including when a subscription has lapsed. This is also your data portability copy.

Delete everything. Settings → Data removes every person, note, thread and date from your account, on every device, subject to the retention rule above. Your account stays, so you can start again.

Delete your account. Settings → Account → Delete account removes the account itself and everything in it. This is permanent and there is no undo. Export first if you want to keep anything.

Your rights

Wherever you live, you can see and change everything Orbital holds about you from inside the app, export all of it, and delete it.

Rights in the EEA, the UK and Switzerland

If you are in the EEA, the UK or Switzerland you have the right to:

The app's export and delete controls cover most of these directly. For anything else, write to us. We will respond within one month, extendable by two further months for complex requests, and we will tell you if we need longer. We may need to verify your identity first. Exercising your rights is free and we will not treat you differently for it.

Rights in California and other US states

You may have the right to know what personal information we collect and how we use and disclose it, to access a copy, to correct it, to delete it, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these. Write to us or use the in-app controls. You may use an authorised agent, and we may ask for proof.

We do not sell personal information and we do not share it for cross-context behavioural advertising, including that of consumers under 16.

California's Shine the Light law, Civil Code section 1798.83, lets California residents request information about disclosures to third parties for their direct marketing purposes. We make no such disclosures.

Security

Data is encrypted in transit and at rest. Access to your records is enforced by row-level security in the database rather than by application logic alone, so no account can read another account's records. Administrative access is limited to those who need it.

The security of your account also depends on you. Choose a good password, keep it to yourself, and keep a passcode on your phone.

If a personal data breach occurs that is likely to risk your rights and freedoms, we will notify the relevant supervisory authority and, where required, you, as applicable law requires.

No transmission over the internet and no method of storage is completely secure. We do our best and cannot guarantee it.

The website

orbitalrelations.com uses no advertising cookies and no tracking across other companies' sites. Where the law requires consent for non-essential cookies, they are set only with your consent and you can withdraw it at any time.

Changes to this policy

If we change this policy in a way that matters, we will say so in the app before the change takes effect, rather than quietly updating the date at the top. Where the law requires your consent, we will ask for it.

Contact

Questions, requests, or anything you think this document gets wrong: hello@orbitalrelations.com