Orbit Privacy Policy
Last updated: September 2026
Orbit is a study planning app for IB Diploma students, built and run by Saturn Designs Studio (the "operator"). This policy explains what Orbit collects, why, and what you can do about it. Plain language on purpose.
What Orbit collects
Account: your email address and a password (stored only as a secure hash). You join with an invite code; Orbit does not run open registration.
Study data you enter: subject choices, confidence ratings, logged errors and any photos you attach, doubts, deadlines, ideas, assessment scores, settings, and your activity history (which powers the streak and review scheduling).
Google Calendar, only if you connect it: Orbit asks Google for two narrow permissions: to read and write calendar events, and to read the list of your calendars. It uses these to write its own events (your review blocks and deadlines) to a calendar you choose, your primary calendar by default, and to show your day's events in the plan. Orbit does not create a calendar for you and does not request full calendar access. It stores a refresh token to keep this connection alive, and it never stores your calendar contents beyond what is needed to render your plan.
Push notifications, only if you turn them on: a device subscription so Orbit can send you the morning digest, streak guard, and deadline alerts. You can turn these off per type or per device at any time.
Technical basics: timezone (so your day boundary is correct), and server logs that record errors and timings without page content.
What Orbit does not do
Orbit does not sell your data, show ads, share your data with advertisers, or use your data to train AI models. Your study data is visible only to you. The operator can access the database for maintenance and support, and does not browse individual accounts without a reason you have raised.
Google user data
Orbit's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Orbit requests only the minimum scopes it needs: calendar.events (read and write events) and calendar.calendarlist.readonly (read your list of calendars). Calendar data is used only to provide the calendar features you see in the app, is not transferred to anyone else except as needed to provide those features, and is not used for advertising. Disconnecting Google in Settings revokes Orbit's access and deletes the stored token.
How your data is protected
All traffic uses HTTPS. Data is encrypted at rest by our database provider. Google Calendar tokens are stored server side in a table no browser can read, accessible only to Orbit's server code, and are deleted the moment you disconnect Google. Access to production data is limited to the operator and protected by row level security, so each account can only ever reach its own rows. Photos live in private storage reachable only through short lived signed links. Orbit holds Google user data only while your connection is active and never shares it with third parties. If we ever discover a security incident affecting your data, we will notify affected users promptly.
Bot protection (captcha)
The login and signup screens use Cloudflare Turnstile, a privacy friendly captcha, to tell real students apart from bots. When you sign in or sign up, Turnstile runs in your browser and processes a small amount of technical information (such as your IP address and browser signals) to decide whether the request is human. Orbit uses this only to protect accounts; Cloudflare processes these signals on the operator's behalf and states that they are not used to build advertising profiles or to train models. For the specifics of what Turnstile processes, see Cloudflare's Turnstile Privacy Addendum, which supplements Cloudflare's Privacy Policy.
Where data lives
Data is stored with Supabase (database and photo storage, private buckets) and the app runs on Vercel. The login and signup captcha is provided by Cloudflare. Push delivery uses your browser's push service. These providers process data on the operator's behalf under their own security commitments.
Your controls
- Export your data from Settings at any time.
- Delete your account from Settings; this removes your data and stored photos.
- Disconnect Google or turn off notifications from Settings.
- Change or correct anything you entered directly in the app.
Students under 18
Orbit is made for IB students, many of whom are under 18. If you are under the age required in your country to consent to data processing, you should have a parent or guardian's permission to use Orbit. A parent or guardian can ask for an account and its data to be deleted by contacting the operator.
Changes and contact
If this policy changes in a meaningful way, Orbit will show a notice in the app. Questions or requests: hello@saturndesigns.art.
This policy is written by a student operator in plain language and is not legal advice; it describes practices truthfully and will be updated as the app grows.