Orbnit

  • Home
  • Settings

Legal

  • Terms of Service
  • Privacy Policy
  • Payment & Refund Policy
  • Community Guidelines

Company

  • cto@orbnit.com
© 2026 Orbnit
Orbnit · Representative Yeonju Shin · Business Reg. No. 135-62-00885
Privacy Policy
Privacy PolicyVersion 7.0.1 · Last updated: 2026-08-28
Contents
1. The short version
2. Data we collect
3. Why we use it (and the legal basis)
4. AI processing (Google Gemini)
Automated moderation decisions
Automated privacy protection (personal-data detection)
5. Who receives your data (sub-processors)
6. International data transfers
7. How long we keep data
8. Your rights and how to use them
9. Minimum age and children
10. Security
11. Cookies and similar technologies
12. Changes, contact, and authority info
13. United States — California (CCPA/CPRA)
14. Korea (PIPA) and Japan (APPI) specifics
Business information
Contact
1. The short version
Orbnit is a diary social platform. Orbnit collects what it needs to run the service, keep it safe, and meet legal obligations. You keep ownership of your diaries and other content, subject to the limited license in the Terms of Service. You can request a copy of everything Orbnit holds about you, delete your account, or change your mind about analytics cookies (web) at any time.This policy explains what Orbnit collects, why, who else sees it, how long it is kept, and the rights you have. It also covers cookies (Section 11). Questions: cto@orbnit.com.
2. Data we collect
Orbnit collects the following categories of data.
•
Account — email, display name, date of birth, country, and which social provider you signed up with (Google / Apple / Kakao / LINE / Facebook) together with that provider's account identifier.
•
Profile — avatar, bio, language preference, service country.
•
Content — diaries, media (images and video), comments, likes, friend lists, direct messages, blocks, reports. How AI review applies to content is described in Section 4.
•
Usage — device type, IP address, locale, app version, crash reports, and product-analytics events. In the consent audit log the IP is stored only as a SHA-256 hash; the analytics tools in Section 5 receive events under their own IP-minimization settings.
•
Derived / activity data — reading activity (which diaries you viewed, kept about 90 days), the detected language of your posts, and a personalization vector built from your activity (see Section 4). Search terms are processed transiently to run the search and are not stored as a history.
•
Privacy ledger — names, places, and contact details of other people you mention in diaries, detected automatically, with the pseudonym chosen for each. This ledger is private to you and you can edit or delete it (see Section 4).
•
Payments — subscription status, provider transaction ID, and the payment method's type, brand, and last 4 digits (as shown by the provider). Orbnit never stores full card numbers or CVCs.
•
Location-related — place names you choose to add to a diary (via Google Places). Orbnit does not collect your GPS coordinates.
•
Reports — when content is reported, Orbnit keeps a snapshot of the reported text at the time of the report so the review remains possible even if the content is later edited or deleted.
3. Why we use it (and the legal basis)
Orbnit processes your data on one of these legal bases (using GDPR terms, which Orbnit applies globally for clarity). Account, profile, and content data are needed to provide the service — without them you cannot use Orbnit.
•
Sign-in, profile, posting diaries, messaging — basis: Contract.
•
Security, fraud prevention, rate-limiting, account recovery — basis: Legitimate interest. Keeping you and the service safe.
•
Content moderation (Gemini) — basis: Legitimate interest and legal obligation. Required for safety and laws such as the EU Digital Services Act.
•
Automated privacy detection of other people's data in diaries (Gemini) — basis: Legitimate interest and legal obligation. Detecting and pseudonymizing personal data about third parties before a diary is shown publicly protects their rights; you can turn the pre-publication review off in Settings.
•
Analytics cookies on the web (GA-4, PostHog) — basis: Consent. Off by default; you opt in via the cookie banner. Orbnit does not send marketing emails.
•
Operational telemetry — basis: Legitimate interest. Independent of the cookie banner, Orbnit's own servers record key service events tied to your account ID — for example that a subscription was activated or refunded, a moderation decision was made, or an account was deleted — in the product-analytics tool (PostHog) to operate the service, investigate problems, and prevent abuse. These are server-side operational records, not browsing trackers, and they follow a strict property allowlist that excludes free-text content.
•
Age verification, tax records, law-enforcement requests — basis: Legal obligation.
•
AI translation of public diaries (Gemini) — basis: Legitimate interest (display); you can disable it per diary.
•
Personalization and meaning-based search — basis: Legitimate interest, applied transparently under GDPR Art. 5(1)(a) and Art. 13. Orbnit builds a 768-dimension preference vector from the posts you write and engage with to rank your home feed and power meaning-based search. This is profiling for ranking only; it does not produce legal or similarly significant effects under GDPR Art. 22.
For Korea (PIPA) users, the equivalent legal bases are consent, contract performance, legal obligation, and legitimate interest. Orbnit collects the minimum needed and asks for separate consent where PIPA requires it (for example, cross-border transfer).
4. AI processing (Google Gemini)
Orbnit uses Google Gemini for six purposes: translation (diaries and comments, plus book titles and descriptions, chapter headings, and profile bios shown to readers in another language), place-name translation for locations you attach to a diary, moderation of new content, language detection, embeddings for search and recommendations (including the 768-dimension interest profile in Section 3), and personal-data (privacy) detection described below.
•
Public and friends-only diaries and comments are sent to Gemini for these purposes. Your direct messages are not.
•
Visual moderation: uploaded images, avatars, book covers, and short-lived video frames from public and friends-only diaries are sent to Gemini to check for unsafe imagery. Video frames are sampled and deleted right after the check — except where child-safety law requires Orbnit to preserve evidence. Private-diary media is never sent to Gemini; private media is scanned only if and when you switch a diary to public.
•
Reported content is re-checked: when someone reports a diary or comment, its text (and images, for a diary) is sent to Gemini again for a fresh review, together with the reporter's stated reason.
•
Private diaries are never used to train external AI models.
•
You can opt out of automatic translation per diary in the editor.
•
Gemini processing happens under a data-processing agreement and follows the EU AI Act's transparency duties.
Automated moderation decisionsTo the extent this is automated decision-making, the following applies. Orbnit's AI automatically reviews content and may block it before any human sees it. Moderation runs across the 17 rule categories in the Community Guidelines; it is stricter on comments and more lenient on undirected profanity inside diaries. The system fails safe: if the provider returns an error, content is held for review rather than published. If your content is blocked, you receive a statement of reasons and can request human review with the in-app review action on the blocked content. The model used is Google Gemini (Flash model family).Automated privacy protection (personal-data detection)To protect the people you write about, Orbnit runs an automated privacy scan on every diary you make public or friends-only, in parallel with moderation. It never changes your original text; it only changes what other readers see.
•
What is sent to Gemini: only the diary's title and body text. Your privacy ledger (below) is not sent — matching a detected word against your existing entries happens inside Orbnit's own servers. No account identifiers, email, or separate contact records are attached either. Direct messages and private diaries are never sent for this.
•
What it finds: real names and honorifics, specific addresses or places, affiliations (a school, workplace, or clinic), contact or account identifiers, and other wording that would single out another person you mention. Your own name is not the target.
•
How it is used: when Orbnit shows your diary to someone else, the detected wording is replaced on screen with a pseudonym. Your own copy always shows your original words; the original wording of a detected item is never placed in another reader's copy, translation, or share preview.
•
Review before publishing: for a new diary the scan runs before it is published, in the writing screen. If anything is detected you see it as a list before the publish completes, and the diary goes out only after you have confirmed each item (apply the suggested pseudonym, keep the original, or edit it). Leave without confirming and nothing is published — the entry stays a draft. When you edit a diary that is already public, the scan runs just after you save, and the diary is hidden from others until it finishes.
•
Publication hold (fail-safe): if something is found on a diary that reached publication another way, or if the AI provider errors, the diary is held from others' view rather than published — the system fails safe, exactly like moderation.
•
No training, nothing retained by the provider: scan requests are stateless and are not used to train external AI models; Google processes them under the same data-processing agreement as the other Gemini calls (Section 5).
•
The privacy ledger (`privacy_entities`): Orbnit keeps a per-user ledger of the people, places, and contact details it has detected in your diaries and the pseudonym chosen for each, so the same person reads consistently across your diaries. This ledger is private to you, enforced by Row-Level Security, and it is your record — you can view, rename, merge, add, or delete any entry in Settings → Account → Privacy, and you can also switch an entry to show the original everywhere without deleting it. Deleting forgets the entry, so the next time that name appears it starts over as a new one; showing the original keeps the entry and only lifts the pseudonym. Either way your original wording reappears immediately. The ledger is deleted when you delete your account.
•
You stay in control: you can turn the pre-publication privacy review off in Settings; with it off, new public diaries — and any currently held — are shown with your original wording. Comments are not scanned for personal data.
5. Who receives your data (sub-processors)
Orbnit shares data with the service providers that help run Orbnit, each under a signed data-processing agreement. Apart from these providers and the seller below, Orbnit provides your personal data to no third parties, does not sell it to advertisers, and does not share it with data brokers.
•
Supabase — database, storage, real-time sync (Japan, Tokyo).
•
Google Cloud — hosting, background jobs, caching (Redis), secret storage, scheduled jobs, video transcoding (US and Japan, Tokyo).
•
OneSignal — push notifications; receives your device push token, linked to your account ID (US).
•
Sentry — error monitoring, PII automatically redacted (US).
•
Google Analytics 4 — pseudonymous usage statistics, only if you consent (US).
•
PostHog — product analytics and the operational telemetry in Section 3 (US).
•
Google Gemini — AI translation, moderation, language detection, embeddings, and privacy detection (US).
•
Google Places — place search for diary locations (US).
•
Paddle — the seller (Merchant of Record) for web subscriptions in both Korea and Japan (UK / US). Paddle is an independent seller rather than a processor acting on Orbnit's instructions: it receives the data needed to process your purchase and issues your receipt.
•
Apple — iOS app distribution, and in-app purchases if offered (US).
•
Google Play — Android app distribution, and in-app purchases if offered (US).
•
Cloudflare — DNS resolution (Global). Service traffic does not pass through Cloudflare.
6. International data transfers
Because Orbnit serves Korea and Japan and uses global infrastructure, your data may travel across borders. Orbnit's primary hosting region is Tokyo (Japan); analytics, notifications, AI processing, and payments use US or UK infrastructure as listed in Section 5.
•
From the EU / EEA / UK / Switzerland: transfers to each provider rest on an adequacy decision or on the Standard Contractual Clauses (SCC 2021, with the UK Addendum where applicable) incorporated in that provider's data-processing agreement.
•
From Korea: cross-border transfers follow PIPA Art. 28-8 (and Art. 28-9), based on the separate consent you give at signup or another lawful ground under that article. For each provider, Section 5 states who receives the data, in which country, what for, and Section 7 how long it is kept; transfers happen continuously while you use the service, over encrypted connections. This includes Korean users' payment data — the seller (Paddle) is in the UK and US, so payment-related information is transferred abroad.
•
From Japan: APPI Art. 28 — Orbnit transfers to countries with adequate protection or under written agreements ensuring an equivalent standard.
•
From other countries: Orbnit uses SCC-equivalent contracts and follows local rules.
7. How long we keep data
Orbnit keeps data for the following periods.
•
Active account — until you delete your account.
•
Deleted account, grace period — 30 days (you can change your mind and restore).
•
Diaries, media, messages after grace — permanently deleted. Comment text is erased, leaving a "[deleted]" placeholder so other people's threads stay readable.
•
Photos sent in direct messages, full-size original — 1 year from sending. After that Orbnit automatically deletes the full-size original; the message is not deleted and continues to display the smaller preview copy that was stored alongside it. This is irreversible, and it applies to both the sender's and the recipient's view of the message.
•
Administrative audit logs — kept permanently in a tamper-proof form, as the integrity record of administrative and data-protection actions (GDPR Art. 30).
•
Consent records — kept while your account exists (an append-only audit log proving what you agreed to and when); deleted when your account is erased. The log stores a SHA-256 hash of your IP, not the IP itself, plus user-agent, version, and country.
•
Payment records — Orbnit's own payment ledger is deleted with your account; the seller (Paddle) and the app stores retain transaction records for the periods their tax and commerce laws require.
•
Report records — the report and its content snapshot are kept as a permanent moderation record, also where the law requires it.
•
Translation caches — cached diary translations are removed after about 60 days without use; cached place-name translations after about 30 days.
•
Notifications — removed after about 90 days. Reading activity and reading positions are also removed after about 90 days.
•
De-identified analytics — per the retention configured in GA-4 (at most 14 months).
•
Personalization vector — kept while you use Orbnit; a daily job removes vectors of accounts inactive for over a year with almost no interactions, and deletion of your account deletes it.
•
Privacy ledger — kept while your account is active; you can delete individual entries or the whole ledger in Settings, Account, Privacy; deleted on account deletion.
When the purpose is fulfilled, Orbnit deletes data without undue delay, by a method that prevents recovery; an automatic job runs hourly to process accounts whose 30-day grace period has ended, and storage files are removed before the database records. Data kept under a legal duty — child-safety evidence, report records, administrative audit logs, and app-store billing identifiers needed to honor store subscriptions — is stored separately and kept only as long as that duty requires.
8. Your rights and how to use them
You have these rights, and they apply globally, regardless of which law grants them.
•
Know what we hold — email cto@orbnit.com and Orbnit sends you a copy of your data (GDPR Art. 15 / PIPA Art. 35 / CCPA).
•
Get a copy (portability) — email cto@orbnit.com; Orbnit provides your data in a portable, machine-readable format within the statutory deadline (GDPR Art. 20).
•
Correct mistakes — Settings, Edit profile, or email Orbnit for data not shown in-app (GDPR Art. 16 / PIPA Art. 36).
•
Delete your account — Settings, Delete account; 30-day grace, then permanent (GDPR Art. 17 / PIPA Art. 37).
•
Restrict or object — email cto@orbnit.com (GDPR Art. 18, 21).
•
Withdraw consent — cookie banner, or Settings → Account → Allow analytics cookies (web) (GDPR Art. 7(3)).
•
Manage detected personal data — view, edit, add, or delete the privacy ledger of other people you mention in diaries, in Settings, Account, Privacy (see Section 4).
•
Complain — to your local data-protection authority; see contacts in Section 12 (GDPR Art. 77 / PIPA Art. 62).
Orbnit responds to rights requests within 30 days (extendable by 60 days for complex cases, with notice). Where local law sets a shorter deadline — such as Korea's access-request timeline — the shorter deadline applies.
9. Minimum age and children
You must meet your country's minimum age to use Orbnit. The thresholds are set out in the Terms of Service, Section 3, and Orbnit checks your date of birth at signup against your country's minimum.
•
Korea — minimum age 14 (PIPA Art. 22-2; Orbnit does not process children under 14 there).
•
Japan — minimum age 16 (APPI sets no fixed children's-consent age; this is Orbnit's own minimum).
•
United States and elsewhere — Orbnit is not directed to children under 13 and does not knowingly collect their personal information (COPPA). If Orbnit opens a market that requires guardian consent (for example under GDPR Art. 8), the minimum age there will be set at or above that threshold before launch.
If Orbnit learns that a user is below the minimum age, Orbnit begins deleting their account. Parents or guardians can email cto@orbnit.com with concerns.
10. Security
Orbnit applies these security measures.
•
HTTPS everywhere, with HSTS (preload list enrollment in progress).
•
Authentication: short-lived JWT access tokens; admin accounts require TOTP MFA.
•
Database: Row-Level Security enforced on every public table; your data is invisible to other users by default, even at the database layer.
•
Payments: Orbnit stores no payment instrument. Your card is held by the seller of record, and Orbnit never sees your card number — only the method type, brand, and last four digits, so you can tell which card is on file.
•
Monitoring: source maps stripped from production builds; Sentry automatically redacts PII (emails, tokens, names) from error reports.
•
Vendors: signed data-processing agreements with every sub-processor and, for EEA-origin transfers, the safeguards in Section 6.
No system is perfectly secure. If a personal-data breach occurs, Orbnit reports it to the competent supervisory authority within the statutory deadline (72 hours of becoming aware under the GDPR; Korea's PIPA also sets a 72-hour standard), and where the breach is likely to put your rights at risk we notify you without undue delay by in-app notice and push notification.
11. Cookies and similar technologies
Orbnit uses a small number of cookies and similar tools on orbnit.com.
•
Essential — sign-in session (set by Orbnit's own servers), CSRF protection, and language preference. Always on; Orbnit does not function without them.
•
Analytics — pseudonymous usage statistics (Google Analytics 4, PostHog). Off by default; they run only after you accept.
•
On-device convenience storage — your cookie choice itself (`orbnit-cookie-consent`) and in-progress diary drafts are kept in your browser's local storage, on your device only.
Orbnit does not use advertising cookies, does not sell your data to ad networks, and does not track you across other websites.Consent (GDPR / ePrivacy / CNIL 2021). On your first visit, Orbnit shows a cookie banner with two equally prominent buttons: Accept all and Reject all (only essential; you keep full use of Orbnit). This follows the CNIL 2021 guidance that "Accept" and "Reject" be equally easy to choose. You can change your choice at any time in Settings → Account → Allow analytics cookies (web). Your choice is stored locally (`orbnit-cookie-consent`) and syncs across tabs. When you opt out of analytics, GA-4 Consent Mode reverts to `denied`.Third-party cookies: Google Analytics 4 (`_ga`, `_ga_*`) and PostHog (`posthog*`), both only after you accept. Sentry sets no cookies. No advertising platforms or social-media trackers are included.Mobile apps do not use browser cookies but use comparable technologies: Apple Keychain (iOS) or Android Keystore for the sign-in session and a locally stored push-notification token. IDFA (iOS) and the Android Advertising ID are requested only for App Store / Play compliance and are not currently used. The mobile apps have no analytics opt-in surface and send no analytics events from the app itself; analytics-cookie consent applies to the web only. The server-side operational telemetry in Section 3 applies to your account regardless of platform.
12. Changes, contact, and authority info
Changes. Orbnit tells you about material changes by in-app notice (and push notification, where enabled) at least 30 days before they take effect. The current version and date are always shown for this page. During the launch period, subscriptions and payments may be disabled in your market.Contact. - General privacy questions: cto@orbnit.com - Korea (PIPA) Privacy Officer (개인정보 보호책임자): Yeonju Shin (신연주), proprietor — cto@orbnit.com - EU GDPR representative (Art. 27): Orbnit does not currently target the EU market; a representative will be designated and published here before any EU launch. - UK GDPR representative: to be designated before any UK launch.Complain to a regulator. You can always complain about how Orbnit handles your data: - Korea — Personal Information Protection Commission (PIPC), or KISA. - EU member states — your national data-protection authority. - UK — Information Commissioner's Office (ICO). - US — California Privacy Protection Agency (for CCPA), or your state attorney general. - Japan — Personal Information Protection Commission (PPC).
13. United States — California (CCPA/CPRA)
This section applies to California residents under the CCPA/CPRA. The categories Orbnit collects and the purposes are those in Sections 2 and 3 — identifiers, customer records, internet and usage activity, commercial information, geolocation limited to place names you add (no GPS), and user-generated content.
•
No sale or sharing. Orbnit does not "sell" personal information and does not "share" it for cross-context behavioral advertising as the CCPA/CPRA defines those terms, so there is no opt-out of sale or sharing to provide.
•
Sensitive personal information. Orbnit does not use sensitive personal information to infer characteristics, so the right to limit its use does not apply.
•
Your California rights. You have the right to know, delete, and correct your personal information, and the right not to be discriminated against for exercising your rights — exercise them as described in Section 8. Orbnit does not discriminate in price or quality because you exercised a privacy right.
14. Korea (PIPA) and Japan (APPI) specifics
Korea (PIPA). Orbnit discloses, as PIPA requires: the items of personal information collected and the purpose (Sections 2 and 3); retention and destruction (Section 7), including that electronic files are destroyed by a non-recoverable method; recipients of consigned processing (the providers in Section 5); cross-border transfer under Art. 28-8 (Section 6); and your rights of access, correction, deletion, and suspension of processing (Section 8). The Privacy Officer (개인정보 보호책임자) is named in Section 12.Japan (APPI). Orbnit handles your personal information under the Act on the Protection of Personal Information. You may request disclosure, correction, or cessation of use of your retained personal data by emailing cto@orbnit.com. Third-party provision and cross-border transfers follow APPI Art. 27 and Art. 28 (Sections 5 and 6). The supervisory authority is the Personal Information Protection Commission (PPC).
Business information
•
Trade name: Orbnit
•
Representative: Yeonju Shin (신연주)
•
Registered address: 226 Dongpangyo-ro, Bundang-gu, Seongnam-si, Gyeonggi-do, Republic of Korea
•
Business registration number: 135-62-00885
•
Hosting providers: Google Cloud Platform, Supabase
•
Contact: cto@orbnit.com
Contact
Email: cto@orbnit.com