Last updated 29 July 2026. This page describes the engineering data map and product behaviour that must pass separate legal review before launch. It does not claim that Orbit holds no personal information.
Data we handle
Depending on the features you use, Orbit may handle opaque identity provider identifiers and approved public handles, wallet addresses, profile and social information, passkeys and session records, device and network security metadata, optional KYC references, uploads, product activity, audit events, and public-chain activity. The current OAuth flow requests only the approved identity scopes and is designed not to store raw provider responses.
We use this data to authenticate accounts, provide requested product features, protect users and the platform, operate and troubleshoot services, meet verified custody or compliance duties, and prevent duplicate claims. Data used for logs, analytics, and security is minimized and pseudonymized where the service permits it.
Processors and public infrastructure
Orbit uses service providers for hosting and backups, edge security, error and trace monitoring, identity, KYC, storage and media, communications, wallet connectivity, AI features, and blockchain access. Depending on the feature, these may include Railway, Cloudflare, Sentry, Google, Discord, X, Telegram, Sumsub, Pinata, Google Cloud, Reown WalletConnect, Coinbase, AI providers, and RPC or bundler providers. Each provider is limited to its registered product purpose and requester workflow.
Retention
Ordinary live account and session records are deleted or pseudonymized when their purpose ends. Current engineering ceilings are 30 days for requester-linked edge, telemetry, deployment-log, and private media expiry; 35 days for backup and recovery windows; and up to 365 days for pseudonymized security evidence. A shorter provider deletion may occur where supported.
Some records can remain under a named retention obligation. Examples include minimum encrypted custody material while assets, delegated authority, or pending transactions remain unresolved; restricted KYC references subject to a reviewed provider obligation; and a minimal append-only claim tombstone that prevents duplicate OOC claims. The product reports the affected class, reason, and review or expiry boundary instead of claiming full deletion.
Account deletion
Self-service account deletion is not currently enabled. The Settings control and deletion API remain launch-disabled until every required processor, custody boundary, and retained-data receipt passes the production enablement gate. Orbit does not represent this unfinished workflow as available.
When enabled, deletion will be an asynchronous request protected by recent step-up verification. Starting a request will not mean every system has already erased its records. Status will report each system as pending, running, retrying, failed, retained, or complete, with a full-completion message only after every required system reaches its disclosed terminal treatment.
If a managed wallet still holds assets, authority, or unresolved work, Orbit retains the minimum encrypted custody material until a reviewed export or evacuation and finalized readback can be proven. Public blockchain records are immutable and cannot be deleted; Orbit removes mutable off-chain profile links where applicable and identifies the remaining public-chain boundary accurately.
Requests and questions
While self-service deletion remains unavailable, use Orbit's published support channel for access, correction, provider, retention, or deletion requests. We may need to verify control of the account before acting on a request.