中文
前言
欢迎使用 Orbit 轨迹(以下简称"我们"或"Orbit"),这是一款由 Yanrong Chen 开发的记录型应用,致力于为用户提供回忆记录、好友互动、地图足迹、共享账单等服务。我们深知个人信息对您的重要性,并郑重承诺保护您的隐私和个人信息安全。
通过本《Orbit 轨迹隐私保护政策》,我们将向您说明我们如何收集、使用、存储、共享和保护您的个人信息,以及您所享有的权利。
主要内容概要:
- 为帮助您注册并使用 Orbit 的各项服务,我们可能需要收集相关个人信息,您有权拒绝或撤回授权。
- 您可以访问、更正或删除您的个人信息,改变授权范围,或注销账户,我们为您提供相应的操作途径。
- 我们采取合理的技术和管理措施保护您的个人信息安全。
- 账号注销后,您的数据将在 7 个工作日内被永久删除。
【特别提示】请您在使用我们的各项产品和/或服务前,仔细阅读并充分理解本政策。一旦您使用或继续使用 Orbit 产品/服务,即表示您同意我们按照本政策处理您的相关信息。如对本政策有任何疑问,您可以通过 Orbit 内"我的 → 左上角设置图标(齿轮)→ 帮助与客服"或发送邮件至 [email protected] 进行反馈。
如果您未满 18 周岁,请在监护人的陪同下阅读本政策,并在征得监护人同意后使用我们的服务。
一、处理个人信息的法律依据
我们将依据《中华人民共和国个人信息保护法》、《中华人民共和国网络安全法》及其他相关法律法规收集和使用您的个人信息。我们通常只会在征得您同意的情况下收集您的个人信息。
在以下情形中,根据法律法规及相关国家标准,我们收集和使用您的个人信息无需征得您的授权同意:
- 为订立、履行个人作为一方当事人的合同所必需的;
- 为履行法定职责或者法定义务所必需的;
- 为应对突发公共卫生事件,或者紧急情况下为保护自然人的生命健康和财产安全所必需的;
- 为公共利益实施新闻报道、舆论监督等行为,在合理的范围内处理个人信息的;
- 依照法律规定在合理的范围内处理个人自行公开或者其他已经合法公开的个人信息的;
- 法律法规规定的其他情形。
二、我们如何收集和使用您的个人信息
我们会遵循正当、合法、必要的原则,出于本政策所述的以下目的,收集和使用您在使用服务过程中主动提供或因使用 Orbit 产品/服务而产生的个人信息。如果我们要将您的个人信息用于本政策未载明的其它用途,我们将在使用前以合理的方式向您告知,并再次征得您的同意。
2.1 账号注册与登录
注册 Orbit 账号时,您需要提供以下信息:
- 邮箱地址:用于注册、登录、找回密码及接收服务通知。
- 密码:用于登录验证,以加密哈希方式存储,我们无法获取您的明文密码。
- 用户名:用于在应用内展示,您可随时修改。
如果您不提供上述信息,您将无法注册或登录账号。
2.2 个人资料
您可以选择性地设置或修改以下信息,不提供不影响核心功能使用:
- 头像:您可以从相册上传自定义头像,或使用系统生成的随机头像(DiceBear)。
2.3 位置信息
在您授权后,我们会收集您的设备位置信息,用于以下功能:
- 发布回忆时标记地点(经纬度、地名、详细地址)。
- 在"友情地图"上以图钉形式展示回忆足迹。
- 使用地点搜索功能查找并标记位置。
当您使用地点搜索功能时,您输入的搜索关键词将发送至 Apple MapKit JS 进行地理编码处理,Apple MapKit JS 可能会记录这些搜索查询。详情请参见 Apple MapKit JS 隐私政策(见第四条第三方服务表格)。
您可随时关闭位置权限(管理方式见下文「三、设备权限调用说明」),关闭后地图和地点标记功能将不可用,但不影响其他功能的正常使用。
2.4 相册与媒体文件
发布回忆时,您可以选择从相册上传照片或视频。
- 我们仅在您主动选择上传时访问相册,不会在未经同意的情况下扫描或收集您的相册内容。
- 上传的照片和视频存储在我们的云端服务器上,您可随时删除已发布的内容。
2.5 麦克风
当您使用语音评论功能时,需要授权麦克风权限。语音录制仅在您主动触发时进行,录制的语音将作为评论内容存储。您可随时关闭麦克风权限(管理方式见下文「三、设备权限调用说明」)。
2.6 设备信息
为保障应用正常运行和安全,我们会自动收集以下设备信息:
- 设备型号、操作系统版本
- IDFV(Identifier for Vendor,由 iOS 系统分配的厂商级设备标识符)——仅用于故障排查,不用于广告投放或跨 App 追踪。我们不收集 IDFA(广告标识符)。
- IP 地址、网络类型
- 应用版本号、崩溃日志
这些信息用于故障排查、性能优化和安全防护。
2.7 使用数据
为改善服务体验,我们可能会收集您在应用内的操作行为数据,包括功能使用情况、浏览记录等。这些数据经匿名化处理后用于功能改进和稳定性分析。
2.8 推送通知
当您授权通知权限后,我们会通过 OneSignal 服务向您发送以下类型的推送通知:
- 社交互动通知:好友在您的回忆下发表评论、点赞或 @ 您、发起好友申请或接受好友申请。
- 运营公告:由应用管理员发送的重要公告(点击通知后将在应用内以弹窗形式展示内容)。
为实现上述功能,设备注册 OneSignal 推送服务后将生成一个唯一的推送订阅 ID(OneSignal Player ID),该 ID 将与您的账号关联存储在我们的服务器上,仅用于向您准确投递通知,不用于广告目的。
您可以随时在系统设置中关闭 Orbit 的通知权限(管理方式见下文「三、设备权限调用说明」),或在应用内「我的 → 左上角设置图标(齿轮)→ 通知」中逐类关闭特定类型的通知。关闭后您将不再收到对应推送,但不影响其他功能。
2.9 好友与社交互动
Orbit 提供好友系统,以支持回忆互动和共享账单等社交功能。以下说明该功能涉及的个人信息处理:
- 邀请码:您登录后,系统会为您生成一个唯一邀请码并存储在服务器上。其他用户可通过输入您的邀请码查找并查看您的用户名和头像,并向您发送好友申请。邀请码不包含您的邮箱、密码或位置等敏感信息。
- 好友关系:当您与他人互相确认添加为好友后,双方的好友关系将存储于服务器。好友可以互相查看对方的用户名和头像。
- 回忆可见范围(基于标签,而非好友关系):Orbit 的回忆采用"标签制"可见性——某条回忆只有发布者本人以及被明确打标的好友才能看到。仅是好友关系并不赋予查看对方全部回忆的权限;未被打标的好友无法在自己的动态流中看到您的回忆。
- 回忆标签:发布回忆时,您可以将好友标记在该回忆中。被标记好友的用户 ID 将与该回忆关联存储,该好友可以在自己的动态流中看到并查看该回忆内容。
- 评论与互动:被打标的好友可以在对应回忆下发布文字评论或语音评论。评论内容(含语音文件)将存储在服务器上,对该回忆的发布者及所有被打标的好友可见。
- 共享账单:您可以将好友加入账单记录,被加入的好友可以查看相关账单内容。
- 虚拟好友(临时好友):您可以为尚未注册 Orbit 的真实联系人创建一个临时占位账号(仅包含您为其设定的用户名)。该虚拟账号存储在我们的服务器上。当该联系人注册后,可通过邀请码将其绑定为真实账号,届时过去打标的回忆和账单记录将自动与其真实账户关联。
- 删除好友关系:您可以随时在"我的"页面删除好友关系。删除后会发生以下变化:(1)您这边:该好友的关系记录被完全删除;(2)对方那边:您的账号在其好友列表中被自动降级为"虚拟好友",保留您的用户名作为占位显示,但已断开与您真实账号的关联;(3)已打标的回忆:历史上打标了对方的回忆中,对方的标签将显示为"已不是好友",但该回忆标签的关联记录(memory_tags)不会自动删除,被标记者仍可在其动态流中看到过去那条回忆。如需彻底撤回其访问权限,您需要手动编辑该回忆移除其标签,或删除该回忆。
三、设备权限调用说明
在提供服务的过程中,我们可能需要您开通以下设备权限。此处所称系统或设备设置指:iOS/Android 等操作系统自带的「设置」中,针对 Orbit 应用单独授予或关闭位置、相册、麦克风、相机等权限的界面(例如 iOS「设置 → Orbit」、Android「设置 → 应用 → Orbit → 权限」),并非应用内「我的 → 设置」菜单。若您通过浏览器访问本服务,相关权限通常由浏览器提供管理入口(如网站权限、站点设置、地址栏旁的站点信息等),具体以您所用浏览器为准。您可随时在上述位置关闭部分或全部权限,关闭后仅影响对应功能,不影响其他功能的正常使用。
| 权限 | 对应功能 | 使用场景 | 可否关闭 |
| 位置 | 地图、地点标记 | 发布回忆时标记地点;在友情地图上展示回忆足迹 | 可以 |
| 相册 | 照片/视频上传 | 发布回忆时从相册选择并上传图片或视频 | 可以 |
| 麦克风 | 语音评论 | 录制语音评论内容 | 可以 |
| 相机 | 拍摄 | 直接拍摄照片或视频用于发布回忆 | 可以 |
| 通知 | 推送通知 | 接收好友互动(评论、点赞、@ 提及、好友申请)及官方公告通知 | 可以(也可在应用内按类型关闭) |
四、第三方服务及 SDK 说明
为向您提供更好的服务,我们的应用中使用了以下第三方服务。我们已审慎评估其数据收集行为,确保符合合法、正当、必要的原则。
| 服务名称 | 提供方 | 使用目的 | 可能收集的信息 | 隐私政策 |
| Supabase |
Supabase Inc. |
数据存储、用户身份认证、文件存储 |
邮箱、用户名、用户生成内容、设备标识 |
查看 |
| Apple MapKit JS |
Apple Inc. |
地图渲染、地点搜索、地理编码 |
位置数据(经纬度)、IP 地址 |
查看 |
| Aegis Web SDK |
腾讯云 |
前端性能监控、错误日志收集 |
设备信息、网络信息、性能数据、崩溃日志 |
查看 |
| Vercel Analytics |
Vercel Inc. |
网页访问统计与用户行为分析 |
页面访问记录、设备信息、IP 地址、Referrer |
查看 |
| QuickChart |
QuickChart (开源服务) |
生成回忆海报中的二维码图片 |
分享链接 URL(含回忆 ID 等参数) |
查看 |
| OneSignal |
OneSignal, Inc. |
推送通知投递 |
设备推送令牌(APNs Device Token)、设备平台、推送订阅 ID;不收集 IDFA,不用于广告目的 |
查看 |
五、我们如何共享、转让、公开披露您的个人信息
5.1 共享
除本政策第四条所述的第三方服务外,我们不会与任何公司、组织和个人共享您的个人信息,除非:
- 获得您的明确同意。
- 根据法律法规、法院判决或政府主管部门的强制性要求。
- 在紧急情况下为保护用户或公众的人身及财产安全。
我们不会出售您的个人信息。我们不会将您的数据用于跨第三方应用或网站追踪您的行为,也不会与任何数据经纪商共享您的个人信息。
5.2 转让
我们不会将您的个人信息转让给任何第三方,但在涉及合并、收购或资产转让时,我们会要求新的持有方继续受本政策约束。如变更处理目的,将重新征得您的同意。
5.3 公开披露
我们仅会在获得您的明确同意,或基于法律法规要求的情况下,公开披露您的个人信息。
六、我们如何存储和保护您的个人信息
6.1 存储
您的个人信息存储在由 Supabase Inc. 提供的云端服务器上,服务器位于中国境外(主要为美国地区)。这意味着您的个人信息将被传输至境外并在境外存储。我们已依据适用法律法规采取必要措施,确保上述跨境数据传输合法合规,并要求境外存储方提供与本政策同等水平的数据保护。
为保障服务稳定性与公平使用,Orbit 当前对单个账户设置约 500MB 的上传存储上限。达到上限后,您仍可浏览既有内容,但新增媒体上传将被限制,直至您删除部分内容释放空间。
我们仅在实现本政策所述目的所必需的期限内保留您的个人信息。自动收集的信息(如设备信息、使用日志)最长保存 24 个月,超期后将删除或匿名化处理。
当我们的产品或服务发生停止运营的情形时,我们将以推送通知、公告等形式通知您,并在合理期限内删除或匿名化处理您的个人信息。
6.2 安全措施
- 使用 HTTPS/SSL 加密传输所有数据。
- 密码以哈希方式存储,我们无法获取您的明文密码。
- 实施行级安全策略(Row Level Security),确保用户只能访问自己有权查看的数据。
- 部署访问控制机制,确保只有授权人员可访问用户信息。
- 定期审查安全配置和访问权限。
管理员权限说明:应用设有经授权的管理员账号,管理员可基于维护平台安全、处理违规投诉、解决用户问题等合理目的,访问以下有限范围的用户信息:用户名、注册邮箱、最近登录时间、账号状态(是否被封禁)、已用存储空间及存储配额。管理员不能查看您的私密回忆内容、评论、账单数据或位置历史,也不能查看您的密码(密码以哈希方式存储,任何人均无法获取明文)。管理员可向全体或指定用户发送推送通知(公告、运营通知等)。上述操作均受内部访问控制约束,仅用于平台运营管理目的。
尽管我们已采取合理的安全措施,但互联网环境并非绝对安全,任何安全措施都无法做到万无一失。在不幸发生信息安全事件后,我们将按照法律法规的要求,及时向您告知事件情况及我们采取的补救措施。
七、您如何管理您的个人信息
7.1 访问与更正
- 在个人主页点击头像或昵称,修改头像和用户名。
- 在"我的 → 左上角设置图标(齿轮)→ 账户 → 更换邮箱"修改绑定邮箱。
- 在"我的 → 左上角设置图标(齿轮)→ 账户 → 更换密码"修改登录密码。
7.2 删除
- 删除您发布的回忆、评论、照片、视频、语音等内容。
- 删除好友关系。
- 删除账单记录。
7.3 账号注销
您可以在"我的"页面发起账号注销申请。提交申请后:
- 您将立即退出登录。
- 账号及所有相关数据(个人资料、回忆、评论、账单、好友关系、上传的照片/视频等)将在 7 个工作日内被永久删除。
- 此操作不可逆,数据删除后无法恢复。
7.4 撤回授权
您可以通过以下方式改变授权范围:
- 按本节「三、设备权限调用说明」所述,在操作系统或浏览器的应用/站点权限设置中关闭位置、相册、麦克风、相机等权限。
- 在应用内「我的 → 左上角设置图标(齿轮)→ 隐私 → 允许他人分享我的回忆」开关,控制您作为回忆发布者,是否允许回忆中被 @ 的好友进一步对外转发分享该回忆;关闭后,被 @ 的好友将无法分享您的回忆(应用内设置不能替代系统或浏览器对敏感权限的开关)。
- 当您主动发起分享时,所分享回忆的部分信息(包括回忆正文片段、地点、日期、照片链接及被 @ 好友的用户名)将被编码至分享链接中,任何持有该链接的人均可查看。请谨慎选择分享对象。
撤回授权后,我们将不再收集对应的个人信息,但这可能影响部分功能的使用。您撤回授权的决定不会影响我们此前基于您的授权而进行的信息处理。
7.5 数据可携
如您希望导出您在 Orbit 中存储的个人数据副本,可通过本政策第十二条所列联系方式提交书面请求,说明需要导出的数据范围。我们将在 15 个工作日内以常用可读格式(如 JSON 或 CSV)向您提供账号下的主要个人数据副本,包括您发布的回忆、评论及账单记录等。
八、未成年人保护
Orbit 面向 18 周岁及以上用户提供服务。我们不会故意收集未满 18 周岁未成年人的个人信息。
如果您未满 18 周岁,请在监护人的陪同下阅读本政策,并在征得监护人同意后使用我们的服务或向我们提供信息。
如果我们发现在未事先获得监护人同意的情况下收集了未成年人的个人信息,我们会设法尽快删除相关数据。若您是未成年人的监护人,当您对您所监护的未成年人的个人信息有疑问时,请通过本政策第十二条的联系方式与我们联系。
九、Cookie 和同类技术
本应用可能使用 Cookie 和本地存储技术来实现以下功能:
- 维持您的登录状态,免去重复登录。
- 保存您的偏好设置(如深色模式、字体大小等)。
- 保障应用的安全稳定运行。
- 已读/未读状态标记(如评论和点赞的未读计数),用于在页面顶部显示未读提醒。
这些数据存储在您的设备本地,不会被上传到服务器或与第三方共享。
十、本政策如何更新
我们可能会不时更新本隐私政策。更新后的版本将在本页面发布。未经您明确同意,我们不会削减您依据当前生效的本政策所应享有的权利。
对于重大变更(如服务模式变化、信息收集方式变化、用户权利变化等),我们会通过应用内通知等方式提醒您。继续使用本应用即视为您接受更新后的政策。
十一、争议解决
本隐私政策的解释和执行适用中华人民共和国法律。如因本政策或个人信息处理事宜发生争议,双方应友好协商解决;协商不成的,可向有管辖权的人民法院提起诉讼。
十二、联系我们
如您对本隐私政策有任何疑问、意见或建议,或您认为您的个人信息权利可能受到侵害,您可以通过以下方式联系我们:
一般情况下,我们将在 15 个工作日内回复您的请求。
English
Introduction
Welcome to Orbit ("we", "us", or "our"). Orbit is a memory recording application that provides services including memory publishing, friend interaction, map footprints, and shared expense tracking. We are committed to protecting your privacy and personal information.
This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the Orbit mobile application (the "Application"). By using the Application, you agree to the practices described in this Privacy Policy.
Key points:
- We collect only the information necessary to provide our services. You have the right to refuse or withdraw consent.
- You can access, correct, or delete your personal information, or delete your account entirely.
- We implement reasonable security measures to protect your data.
- After account deletion request, all data is permanently removed within 7 business days.
If you are under the age of 18, please read this policy with a guardian and obtain their consent before using our services.
0. Legal Basis for Processing
We process your personal information on the following legal bases:
- Consent — For data collected via device permissions (location, camera, microphone, photo library), we rely on your explicit consent. You may withdraw consent at any time as described in Section 6.4.
- Performance of a contract — To create and manage your account and deliver the core services (memory publishing, friend system, shared expenses), processing your account data is necessary to provide the service you requested.
- Legitimate interests — To maintain the security, stability, and integrity of the Application (e.g., crash diagnostics, fraud prevention, abuse detection), where such processing does not override your rights and freedoms.
- Legal obligation — Where required by applicable law or a lawful order from a competent authority.
1. Information We Collect and How We Use It
1.1 Account Registration
When you register, we collect:
- Email address — for registration, login, password recovery, and service notifications.
- Password — stored using cryptographic hashing; we cannot access your plaintext password.
- Username — displayed within the Application; you may change it at any time.
1.2 Profile Information
- Profile photo — optionally uploaded from your photo library or randomly generated by the system.
1.3 Location Data
With your permission, we collect your device location to:
- Tag locations when publishing a memory (latitude, longitude, place name, address).
- Display memory pins on the "Friendship Map".
- Search for and select locations.
When you use the location search feature, the search keywords you enter are sent to Apple MapKit JS for geocoding. Apple MapKit JS may retain these search queries. For details, see the Apple MapKit JS Privacy Policy in the Third-Party Services table (Section 3).
You may revoke location permission at any time; see Section 2. Device Permissions below for where to manage permissions.
1.4 Photos and Videos
When publishing a memory, you may upload photos or videos from your photo library. We only access your library when you actively select files. Uploaded media is stored on cloud servers and may be deleted by you at any time.
1.5 Microphone
Used for the voice comment feature. Recording occurs only when you actively initiate it. You may revoke microphone permission at any time; see Section 2. Device Permissions below.
1.6 Device Information
We automatically collect device model, OS version, IP address, network type, app version, and crash logs for troubleshooting, optimization, and security. On iOS, we collect the IDFV (Identifier for Vendor — a system-assigned, vendor-scoped device identifier) solely for diagnostics. We do not collect IDFA (the advertising identifier) and do not use any device identifier for advertising or cross-app tracking.
1.7 Usage Data
We may collect anonymized usage data to improve our services.
1.8 Push Notifications
When you grant notification permission, we use OneSignal to deliver the following types of push notifications:
- Social interactions: when a friend comments on your memory, likes it, @-mentions you, sends you a friend request, or accepts your friend request.
- Admin announcements: important notices sent by app administrators. Tapping such a notification opens the app and displays the message in a modal overlay.
To deliver notifications, your device registers with OneSignal and receives a unique push subscription ID (OneSignal Player ID). This ID is stored on our servers linked to your account and is used solely to route notifications to your device. It is not used for advertising.
You may disable notifications for Orbit at any time in your device's system settings, or manage notification types individually within the app: Profile → Settings (gear icon, top-left) → Notifications.
1.9 Friends and Social Interactions
Orbit provides a friend system to support social features such as memory interaction and shared expense tracking. The following describes how personal information is processed in this context:
- Invite code: After you log in, the system generates a unique invite code for your account and stores it on our servers. Other users can enter your invite code to find your username and profile photo, and send you a friend request. The invite code does not contain your email address, password, location, or other sensitive information.
- Friend relationships: When you and another user mutually confirm a friend connection, the relationship is stored on our servers. Friends can view each other's username and profile photo.
- Memory visibility (tag-based, not friend-based): Memories in Orbit use a tag-based visibility model — a memory is only visible to its author and the friends who are explicitly tagged in it. Being friends with someone does not grant access to all of their memories; untagged friends will not see a memory in their feed.
- Memory tags: When publishing a memory, you can tag friends in it. The tagged friend's user ID is stored in association with that memory, and the tagged friend will be able to see and view that memory in their own feed.
- Comments and interactions: Friends who are tagged in a memory can post text or voice comments on it. Comment content (including voice files) is stored on our servers and is visible to the memory's author and all tagged friends.
- Shared expenses: You can include friends in expense records. Friends added to a record can view the associated expense details.
- Virtual friends (temporary contacts): You can create a temporary placeholder account for a real contact who has not yet registered on Orbit (containing only the username you assign). This virtual account is stored on our servers. Once that contact registers, they can link their real account via invite code, at which point past memory tags and expense records will automatically transfer to their real account.
- Removing a friend: You may remove a friend connection at any time from your Profile page. When you do, the following happens: (1) On your side: the friend relationship record is fully deleted; (2) On their side: your account is automatically downgraded to a "virtual friend" placeholder in their friend list — your username is retained for display purposes, but the link to your real account is severed; (3) For memories with tags: in memories where you previously tagged the other person, their tag will display as "no longer a friend", but the underlying tag record (memory_tags) is not automatically removed — the tagged person can still see that memory in their feed. To fully revoke their access, you must manually edit the memory to remove their tag, or delete the memory entirely.
2. Device Permissions
We may ask you to grant the permissions listed in the table below. Operating-system or device settings means the permission screens provided by iOS, Android, or similar systems for the Orbit app specifically (for example, iOS Settings → Orbit, or Android Settings → Apps → Orbit → Permissions)—this is not the same as in-app Profile → Settings. If you use Orbit in a web browser, permissions are usually managed through the browser’s site settings, permissions panel, or lock icon next to the address bar; the exact UI depends on your browser. You can disable any of these permissions at any time in those places.
| Permission | Feature | Use Case | Can be disabled |
| Location | Map, location tagging | Tag locations when publishing; display pins on map | Yes |
| Photo Library | Photo/video upload | Select and upload media when publishing memories | Yes |
| Microphone | Voice comments | Record voice comments | Yes |
| Camera | Photo/video capture | Capture media for publishing | Yes |
| Notifications | Push notifications | Receive alerts for social interactions (comments, likes, @-mentions, friend requests) and admin announcements | Yes (also manageable per-type in-app) |
Disabling any permission will not affect other features of the Application.
3. Third-Party Services
The Application uses the following third-party services, each with their own privacy policy:
| Service | Provider | Purpose | Data Collected | Privacy Policy |
| Supabase |
Supabase Inc. |
Data storage, authentication, file storage |
Email, username, user content, device ID |
View |
| Apple MapKit JS |
Apple Inc. |
Map rendering, place search, geocoding |
Location data, IP address |
View |
| Aegis Web SDK |
Tencent Cloud |
Performance monitoring, error logging |
Device info, network info, performance data |
View |
| Vercel Analytics |
Vercel Inc. |
Web analytics and user behavior analysis |
Page views, device info, IP address, referrer |
View |
| QuickChart |
QuickChart (open-source service) |
Generate QR code images for memory share posters |
Share link URL (including memory ID parameters) |
View |
| OneSignal |
OneSignal, Inc. |
Push notification delivery |
Device push token (APNs Device Token), device platform, push subscription ID; IDFA is not collected and data is not used for advertising |
View |
4. Information Sharing
We do not sell your personal information. We do not use your data to track you across third-party apps or websites, and we do not share your personal information with any data brokers. Beyond the third-party services listed above, we share information only:
- With your explicit consent.
- As required by law, regulation, or court order.
- To protect the safety or rights of users or the public in emergencies.
5. Data Storage and Security
5.1 Storage
Your data is stored on cloud servers operated by Supabase Inc., located primarily in the United States. If you are located in China or another jurisdiction with cross-border data transfer requirements, your personal information will be transferred to and stored outside your home country. We have taken necessary measures under applicable laws to ensure that such transfers are lawful and that your data receives an equivalent level of protection as described in this Policy.
To ensure service stability and fair use, Orbit currently applies an upload storage cap of approximately 500MB per account. Once the cap is reached, you can still view existing content, but new media uploads will be restricted until you free up space by deleting content.
Automatically collected data is retained for up to 24 months, then deleted or anonymized. If we cease operations, we will notify you and delete or anonymize your data within a reasonable period.
5.2 Security Measures
- All data transmitted over HTTPS/SSL encryption.
- Passwords stored using cryptographic hashing.
- Row Level Security (RLS) policies ensure data isolation between users.
- Access control mechanisms limit data access to authorized personnel only.
- Regular security configuration reviews.
Administrator access: Orbit has designated administrator accounts authorized to access a limited set of user information for legitimate platform operations such as safety enforcement, handling abuse reports, and resolving user issues. Administrators may view: username, registered email, last sign-in time, account status (banned/active), storage usage, and storage quota. Administrators cannot view private memory content, comments, expense records, location history, or your password (passwords are irreversibly hashed). Administrators may send push notifications (announcements, operational notices) to all users, individual users, or filtered groups. All such access is logged and governed by internal access controls.
While we implement reasonable measures, no electronic transmission or storage method is completely secure. In the event of a security incident, we will notify affected users as required by law.
6. Your Rights
6.1 Access and Correction
View and update your username, profile photo, email, and password within the Application: Profile tab → Settings icon (gear, top-left) → Account → Change Email / Change Password.
6.2 Deletion
Delete your published memories, comments, photos, videos, voice recordings, friend connections, and expense records at any time.
6.3 Account Deletion
Request account deletion from the Profile page:
- You will be signed out immediately.
- All data will be permanently deleted within 7 business days.
- This action is irreversible.
6.4 Permission Withdrawal
You may change how permissions are granted as follows:
- Disable location, photo library, microphone, camera, and similar permissions using your operating system or browser as described in Section 2. Device Permissions.
- Toggle "Allow others to share my memories" under Profile tab → Settings icon (gear, top-left) → Privacy. As the memory author, this controls whether friends you have @-mentioned in a memory may further reshare it. When disabled, @-mentioned friends cannot share your memories (in-app settings do not replace system or browser controls for sensitive permissions).
- When you actively initiate a share, a portion of the memory's data (including a text snippet, location, date, photo URLs, and tagged friends' usernames) is encoded into the share URL. Anyone who receives that link can view this information. Please share thoughtfully.
Withdrawal does not affect prior processing based on your earlier consent.
6.5 Data Portability
You may request a copy of your personal data stored in Orbit by contacting us using the details in Section 10. Please describe the scope of data you need. We will respond within 15 business days and provide your principal personal data (such as your published memories, comments, and expense records) in a commonly used, machine-readable format (e.g., JSON or CSV).
7. Children's Privacy
The Application is intended for users aged 18 and above. We do not knowingly collect information from children under 18. If we discover such collection, we will promptly delete the data. Parents or guardians may contact us using the information in Section 10.
8. Cookies and Similar Technologies
The Application uses cookies and local storage to maintain login sessions and save preferences (e.g., dark mode, font size). This data is stored locally on your device and is not uploaded or shared. The Application also stores read/unread status markers (e.g., unread comment and like counts) locally to display in-app notification badges.
9. Changes to This Policy
We may update this Policy from time to time. For significant changes, we will notify you via in-app notifications. Continued use constitutes acceptance of the updated policy.
10. Contact Us
For questions, concerns, or suggestions:
- Email: [email protected]
- In-App: Profile tab → Settings icon (gear, top-left) → Help & Support
We will respond within 15 business days.