Privacy Policy
Last updated: August 31, 2026
This Privacy Policy explains how Batuhan Bayır, doing business as Orbit ("Orbit," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information when you use the Orbit iOS application, its Share Extension, the joinorbit.web.app website, and related support services (together, the "Services").
Orbit is designed to help adults notice people whose paths crossed theirs and remember the places, photos, and music connected to those moments. Because that experience can involve precise location data, we have described each location layer separately below. Please read this Policy before enabling location or photo access.
Privacy at a glance
- Location sharing is optional and can be turned off in Orbit at any time.
- Orbit does not use continuous GPS tracking. It relies on infrequent iOS visit and significant-location-change signals.
- Precise route points support your private personal map. Cross-user matching uses a separate approximate-area layer.
- Your photo library is not uploaded. A photo leaves your device only when you deliberately share that photo with a mutual connection.
- Orbit does not automatically read your Apple Music listening history. It processes only songs you send to Orbit through the iOS Share Sheet.
- We do not sell personal information, show third-party advertising, or use location for advertising.
1. Who is responsible for your data
The data controller and service provider is:
Batuhan Bayır, doing business as OrbitDumlupınar Mah., Ilıca Sk., Demir Çağla Apt. No: 2/6
Nilüfer, Bursa 16285, Türkiye
Email: bbayir686@gmail.com
You may use this email for privacy requests, account-deletion questions, complaints, or questions about this Policy.
2. Scope and eligibility
This Policy applies when you create or use an Orbit account, use location-based crossing features, use Gallery Map, share music to Orbit, purchase or restore a subscription, visit our website, follow an Orbit invite link, or contact support.
Orbit is intended only for people aged 18 or older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18.
3. Information we collect
3.1 Account and authentication information
You sign in using Sign in with Apple or Google Sign-In. Depending on your provider choices, we may receive your provider account identifier, display name, email address (including an Apple private relay address), profile image URL, and authentication tokens needed to maintain your session. We assign a Firebase user identifier to your Orbit account. We do not receive your Apple or Google password.
3.2 Profile information
You may provide a display name, unique username, profile image, city, biography, and social links. Your display name, username, profile image or on-device-created profile cutout, social links, and discoverability setting support search and social features. City and biography are stored in your private account record. Profile background removal is performed on your device with Apple Vision; Orbit uploads the resulting cutout only after you save it and does not create a facial-recognition template.
3.3 Location and visit information
If you enable Location sharing, Orbit may process:
- Private route points: latitude, longitude, event time, whether the signal represents passing through or staying at a place, and approximate dwell duration. These points power your personal map and are access-controlled to your account.
- Approximate visit signals: an approximately 150-metre geohash cell, event time, a ten-minute lookup index, and limited dwell metadata. The server-side matcher uses this separate layer to look for crossings. Other users do not receive your raw route point.
- Crossing records: the two participant identifiers, approximate cells, event time, crossing type, counts, and source type (for example, visit or music). Crossings are created by the server and can be read only by their participants.
iOS may provide visit or significant-location-change events while Orbit is not open if you have granted the required permission. Orbit does not request continuous high-accuracy GPS tracking.
3.4 Photo library and Gallery Map information
Photo permission is requested from the Gallery Map flow, not merely because you opened Orbit. If you grant full or limited Photos access, Orbit reads the creation date and embedded location of accessible images to build local memories and approximate historical visit signals. Local identifiers, thumbnails, and full-size photos remain on your device unless you choose to share a particular image. If your library uses iCloud Photos, iOS may retrieve an image from Apple so Orbit can display it locally.
When you deliberately share a Gallery Map photo with a mutual connection, Orbit uploads a resized JPEG together with its capture time, sharing time, place label, and coordinates. That shared copy is visible to the two crossing participants while they remain mutual connections. Orbit stores an opaque hash instead of uploading the original PhotoKit asset identifier.
3.5 Apple Music sharing information
Orbit does not continuously access your Apple Music account or listening history. When you choose Share → Orbit from Apple Music, the Share Extension processes the Apple Music link, catalog identifier, song title, artist, album name, artwork URL, and time shared. Orbit may use Apple's public iTunes lookup service, and, if you have already authorized it, MusicKit, to resolve song metadata.
If a sufficiently recent approximate location is available at the moment you share, the song may also receive an approximate geohash. A share without a recent location can still appear in your music history, but it cannot create a location-based music crossing.
3.6 Social, safety, and support information
We process crossings, waves, friend or mutual-connection status, dismissed requests, invite codes, notification records, blocked-user identifiers, shared-photo visibility choices, and reports you submit about another user. If you contact support, we process your email address, message, attachments, device details you provide, and our correspondence with you.
3.7 Subscription and transaction information
Orbit Premium purchases are billed by Apple through StoreKit and your Apple ID. Apple handles payment-card and billing information. RevenueCat helps Orbit validate purchases and maintain subscription access across app sessions. For that purpose, Orbit and RevenueCat process the product identifier, an Orbit account identifier, transaction and renewal information, storefront or country information supplied with the transaction, and current entitlement status. Orbit and RevenueCat do not receive or store your full payment-card number.
3.8 Device, security, and technical information
Firebase and related infrastructure may process IP address, device or app identifiers, operating system and app version, request timestamps, authentication and security events, and diagnostic or server logs. Firebase App Check may use Apple App Attest or DeviceCheck signals to confirm that requests come from a genuine Orbit installation. These services do not give Orbit your device passcode or Apple ID password.
3.9 Website information
The public Orbit website does not currently use advertising cookies or behavioural analytics. Firebase Hosting and network providers may process standard request logs such as IP address, browser type, requested URL, and timestamp for delivery, reliability, and abuse prevention. Pages that load Google Fonts may send a request, including your IP address and browser information, to Google.
4. How location and crossing detection work
Orbit's matching is automated, but it does not make legal or similarly significant decisions about you. A match is an approximate product result, not proof that two people met, saw each other, or were at an exact address.
- Visit crossings: the matcher looks for compatible approximate cells and event timestamps no more than one hour apart. The ten-minute value stored with a visit is only a database search index; it does not limit a crossing to ten minutes.
- Place crossings: longer-stay signals may enrich a crossing when both users have sufficient overlapping dwell evidence.
- Music crossings: two location-stamped shares may create or enrich a physical crossing when they involve the same song or artist, occur no more than one hour apart, and their approximate geohash centres are within one kilometre.
- Duplicate and crowd protection: nearby signals from the same physical session may be merged, and unusually crowded candidate windows may be suppressed to reduce false matches and abuse.
Location services, photo metadata, device settings, buildings, signal delays, missing background events, and approximate cells can all produce missed or incorrect crossings.
5. How and why we use information
| Purpose | Typical information | Legal basis where required |
|---|---|---|
| Create and secure your account | Authentication, account, App Check, security logs | Contract; legitimate interests in security |
| Provide crossings, private maps, Gallery Map, music memories, friends, invites, and notifications | Profile, location layers, photo metadata, music shares, social activity | Contract; consent for device permissions and precise location |
| Provide and verify Orbit Premium | Account identifier, StoreKit products, transactions, renewals, entitlement status | Contract; legal obligations |
| Prevent abuse and protect users | Blocks, reports, account identifiers, technical logs | Legitimate interests; legal obligations |
| Operate, debug, and improve reliability | Diagnostics, feature errors, server logs, support messages | Legitimate interests |
| Respond to requests and enforce legal terms | Account, correspondence, relevant records | Contract; legitimate interests; legal obligations |
Where consent is the basis, you may withdraw it through Orbit or iOS Settings. Withdrawal does not make earlier lawful processing unlawful, but some features may stop working.
6. Who can see information
- You: your private account record, personal route, local Gallery Map, music history, blocks, and notifications.
- Signed-in Orbit users: public-profile fields needed for usernames, search, crossing cards, and social features. Turning on Private profile removes you from ordinary search discovery; it does not erase your profile or hide you from existing friends and crossing participants.
- Crossing participants: the approximate crossing record and eligible music match. Exact private route points are not disclosed.
- Mutual connections: shared Gallery Map photos and their associated place, time, and coordinate information. A photo is not shared automatically.
- Orbit and processors: authorized systems and service providers process information only to operate, secure, support, and comply with law.
- Authorities or transaction parties: information may be disclosed when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or complete a merger, acquisition, or asset transfer subject to appropriate safeguards.
We do not sell personal information and do not share it for cross-context behavioural advertising or targeted advertising.
7. Service providers and third parties
- Google Firebase: Authentication, Firestore, Cloud Storage, Cloud Functions, App Check, and Hosting.
- Google Sign-In: optional account authentication.
- Apple: Sign in with Apple, iOS Photos and location frameworks, App Attest or DeviceCheck, MusicKit and iTunes metadata, iCloud Photos where enabled, App Store distribution, and StoreKit payments.
- RevenueCat: subscription product presentation, purchase validation, restoration, renewal events, and Orbit Premium entitlement management.
- Email and network providers: delivery of support messages and website traffic.
These providers process information under their own terms and privacy notices. Social links you publish can take another user to a third-party service; Orbit does not control that service.
8. Retention and deletion
- Private route points: each point is assigned an expiration date 30 days after creation and is retained for no longer than needed for the personal route feature, subject to short deletion-processing delays.
- Approximate visits, music shares, profile, crossings, connections, and notifications: generally retained while your account is active or until you delete applicable content or your account.
- Local photo data: remains under iOS Photos controls. Orbit's in-memory thumbnails and place-name cache are not a separate cloud photo library.
- Shared photos: retained until the uploader removes the photo, the mutual connection is removed, or an involved account is deleted.
- Support, reports, security, and legal records: may be kept for a reasonable period necessary to investigate abuse, resolve disputes, prevent fraud, enforce our Terms, or meet legal obligations.
You can delete your account in Orbit under Profile → Settings → Delete account. Orbit then attempts to delete your authentication account; private user document and subcollections; username reservation; connections and invites; crossings involving you; and associated shared-gallery files. Some provider records, transaction records, security logs, legal records, and temporary backups may remain for the period required by law or ordinary backup rotation. Deletion is irreversible and may require recent sign-in for security.
9. Your controls and rights
- Turn Location sharing on or off in Orbit Settings and manage When In Use or Always permission in iOS Settings.
- Grant full, limited, or no Photos access and change that selection in iOS Settings.
- Edit profile information and public social links.
- Use Private profile to leave ordinary search discovery while keeping existing relationships.
- Remove or hide eligible shared photos, remove a connection, block a user, or report abuse.
- Manage or cancel Orbit Premium in Apple ID → Subscriptions.
- Delete your Orbit account in the app.
Depending on where you live, including under the GDPR/UK GDPR, Türkiye's KVKK, and applicable U.S. state privacy laws, you may have rights to request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or information about disclosures; to appeal certain request decisions; and to complain to your local data protection authority. These rights are not absolute and may be limited by law.
Send requests to bbayir686@gmail.com. We may ask for information reasonably necessary to verify that you control the relevant account. We will not discriminate against you for exercising a privacy right.
U.S. state disclosures
In the preceding 12 months, Orbit may have collected identifiers; customer-record information; commercial or subscription information; internet or network activity; precise and approximate geolocation; photos and other electronic content; and inferences limited to connection or music matching. Orbit does not knowingly sell these categories, use them for targeted advertising, or use sensitive personal information to infer characteristics unrelated to providing the Services.
10. Security and international processing
We use access-controlled Firebase rules, server-authoritative crossing creation, App Check, authenticated storage paths, separate precise and approximate location layers, opaque photo identifiers, transport encryption, and account-deletion routines. No security system is perfect. Protect your Apple or Google account, keep your device secure, and contact us if you suspect unauthorized access.
Orbit and its providers may process information in Türkiye, the United States, and other countries where they operate. Those countries may have different data-protection laws. Where required, we rely on provider contracts and lawful transfer mechanisms designed to protect transferred information.
11. Children
Orbit is for adults aged 18 or older. If we learn that a person under 18 has provided personal information, we will take reasonable steps to delete the account and related information. Contact us if you believe a minor is using Orbit.
12. Changes and contact
We may update this Policy when Orbit's features, providers, or legal obligations change. We will revise the date above and, when appropriate, provide an in-app or other prominent notice before a material change takes effect.
For privacy questions or requests, email bbayir686@gmail.com. For product assistance, see Orbit Help & Support.
Note: This Policy describes Orbit's current technical behaviour and privacy practices. It is not intended to limit any non-waivable rights you have under applicable law.