PRIVACY POLICY / A CLEARER BOUNDARY

Your browser.Your business.

Orbit is engineered around a clear commitment: your browsing data should never become something a browser developer collects, tracks, or sells. This policy explains honestly what the Android app keeps locally, and what the website collects when you choose to submit a support report.

No Telemetry from the App Voluntary Website Submissions Only Effective Date: October 2, 2026
01 / KNOW THE DIFFERENCE

A browser is one part
of your privacy.

Orbit the app, the Orbit website, your chosen search engine, and the external websites you visit each play distinct roles. Understanding this distinction matters.

ORBIT ANDROID APP

Data stays on your device

The Orbit Android application is designed to keep your browsing data locally on your device. Orbit does not send your browsing activity, history, bookmarks, or settings to any server.

  • Browsing history, bookmarks, and tabs — stored locally in the app sandbox.
  • Autofill and form data — kept on-device; not synced to any cloud.
  • Settings and appearance preferences — stored locally.
  • Omnibar keystrokes — no suggestions are sent to Orbit servers.
  • No automatic crash reporting or diagnostics uploaded by the app.
ORBIT WEBSITE (orbitbrowser.com)

Voluntary submissions only

The Orbit website may collect information you choose to submit through the support form. Nothing is collected automatically from visitors beyond what CDN infrastructure records for all web traffic.

  • Support, feedback, bug reports, and feature requests — submitted voluntarily.
  • Only the fields you fill in are recorded.
  • Name, email, and screenshots are optional — never required.
  • Form submissions are stored via Supabase (see full policy below).

Website support submissions and local Android app data are entirely separate systems. Clearing or uninstalling the Android app does not delete any report you submitted through this website.

02 / PRACTICAL CONTROLS

Meaningful everyday controls.

Everyday browsing features designed to put user agency ahead of corporate extraction.

Choose where your searches go

Select your default search provider with zero corporate bias. Orbit supports DuckDuckGo, Brave Search, Startpage, Google, Bing, or any custom query URL. Orbit does not intercept, proxy, or log queries.

Review history and granular data deletion

Your browsing history, cached assets, and website cookies are stored in isolated local storage on your device. You can purge them with a single tap or enable automatic session clearing.

Camera, microphone & location permissions

Orbit respects OS-level sandboxing. Websites cannot access your camera, microphone, or location without your explicit runtime authorisation through the standard Android permission system. Location permission requests from websites you visit through Orbit are separate from Orbit itself collecting your location — Orbit does not collect your location.

Audit the source code

Orbit is open source. You can inspect network sockets, grep for endpoints, and verify these claims directly in the repository.

03 / FORMAL LEGAL POLICY

Orbit Formal Privacy Policy

This policy applies to the Orbit Android application and the official Orbit website at orbitbrowser.com.
Effective date: October 2, 2026.
Data controller: Parveen Kumar, Project Lead, Orbit Browser.

1. Orbit Android App — What It Does Not Collect

The Orbit Android application is engineered without telemetry, analytics, or automatic data uploads. Orbit does not collect, transmit, store, or sell:

• Your browsing history, visited URLs, or page contents.
• Your search queries or omnibar keystrokes.
• Unique device identifiers (IMEI, MAC address, advertising ID).
• Geolocation data — Orbit does not collect your location. Location permissions, if present, exist solely to allow websites you visit to request location access through the standard browser permission mechanism, after your explicit approval. This is the website's location access, not Orbit's.
• Personal profiles or behavioural data.
• Automatic crash reports or diagnostic logs — these are not uploaded by the app. A bug report is something you choose to submit voluntarily through this website.

2. Orbit Android App — Data Stored Locally on Your Device

To function as a browser, Orbit stores certain data locally on your device only:

• Bookmarks & Tabs: Saved in the app's local sandbox.
• Cookies & Local Storage: Stored per-domain to keep you logged into sites you choose.
• Autofill & Form Data: Kept on-device; not synchronised to any cloud server by Orbit.
• Settings & Appearance: Theme preference, search engine choice, and other preferences.
• Browsing History: Stored locally; you can clear it at any time in Settings.

This data remains under your direct control on your device. Clearing app data or uninstalling Orbit removes it from your device.

3. Orbit Website — Voluntary Support Submissions

The Orbit website provides a voluntary support form at orbitbrowser.com/support. Submitting the support form is voluntary, but once a user chooses to submit it, report_type and description are required fields. Other listed personal/support fields remain optional as implemented.

What is collected when you submit a report:
• Report type (required) — e.g. bug report, feedback, feature request.
• Description (required) — the text you type.
• Name (optional) — only if you provide it.
• Email address (optional) — only if you want a reply.
• Platform (optional) — selected from a list by you (Android, macOS, etc.).
• App version (optional) — typed by you; not automatically detected.
• Steps to reproduce (optional, shown for bug reports) — text you provide.
• Screenshot attachment (optional) — a file you choose to upload (JPEG, PNG, WebP, or GIF; maximum 5 MB).
• Submission timestamp — the time you clicked "Submit".

Nothing beyond the above is collected. Your IP address, device fingerprint, browser user-agent, browsing history, cookies, or session data are not recorded by this form.

How this data is used:
Solely to read, investigate, and respond to your report. It is not used for advertising, profiling, or sold to any third party.

Service provider — Supabase:
Form submissions are stored in Supabase (supabase.com), a hosted database and storage service. Supabase stores data on infrastructure in the region configured for this project. By submitting a report, your data is processed by Supabase in accordance with Supabase's Privacy Policy.

Private Screenshot Storage:
If you attach a screenshot, it is stored in a private Supabase Storage bucket. Attachments are not publicly readable, indexable, or accessible via public URL. Only authorized project maintainers can access stored attachments. Please avoid including sensitive personal information (passwords, payment details, private messages) in screenshots.

Retention & Deletion Requests:
Support submissions and attachments are retained while under review or until resolved by the project maintainer. If you wish to have a previously submitted report or attachment deleted, you may submit a request through GitHub Issues or directly to the project lead (Section 10), specifying the description or email used in the report.

4. Orbit Website — Infrastructure & CDN Logs

The Orbit website is hosted on Vercel's CDN. Standard ephemeral web server access logs (IP address, user agent, timestamp, URL) are automatically recorded by CDN infrastructure for DDoS mitigation, infrastructure health monitoring, and network security. These logs are controlled by Vercel and subject to Vercel's Privacy Policy.

The Orbit website does not use third-party advertising cookies, analytics SDKs, tracking pixels, or behavioural profiling tools.

5. Third-Party Search Engines & External Websites

When you submit a search query in Orbit, it is transmitted over HTTPS directly to the search provider you have configured (e.g. DuckDuckGo, Brave Search, Google). That communication is governed by the search provider's own privacy policy. Orbit does not inject tracking parameters, affiliate tags, or referral codes into your searches.

Websites you visit through Orbit may collect data according to their own privacy policies. Orbit does not intercept or modify that data.

6. GDPR & CCPA / CPRA

Orbit Android app: Because the app does not transmit personal data to our servers, we hold no server-side user databases or telemetry for the app. Under GDPR Articles 15–22, all browsing data resides under your direct custody on your device.

Website support submissions: If you reside in the European Economic Area (EEA) or California and have submitted a support report, you may have rights to access, correct, or request deletion of that data. Contact us using the details in Section 7.

We do not sell personal data as defined under the CCPA/CPRA.

7. Children's Privacy

Orbit does not knowingly solicit or collect personal information from children under 13 (or under 16 in the EU). If you believe a child has submitted a report through this website, contact us and we will delete the submission promptly.

8. Security

We take reasonable technical measures to protect support submissions stored in Supabase, including row-level security policies that prevent one user's submissions from being accessed by another, and access controls limiting who can view stored data.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we implement appropriate safeguards given the sensitivity and volume of data involved.

9. Changes to This Policy

If we make material changes to this policy, we will update the effective date at the top of this page. Continued use of the website or app after changes constitutes acceptance of the revised policy.

10. Contact the Data Controller

For privacy questions, data deletion requests, or security disclosures:

Parveen Kumar
Project Lead, Orbit Browser
GitHub: github.com/parveenengg/Orbit
Issues & Disclosures: GitHub Issues

TRANSPARENCY IN CODE

Verify for yourself.

Orbit's source code is public and open for review. Inspect how privacy is built into the architecture.