Privacy Policy
Plain English. Short paragraphs. No dark patterns. If something here is unclear, email privacy@altorbit.app and we'll explain — and probably rewrite the section.
Who we are
AltOrbit is an independent project, currently pre-incorporation — operated by its founder. A legal entity (planned in the EU) will be established before public launch. When this policy says "we", it means AltOrbit. When it says "you", it means anyone whose data we handle — usually a user of an AltOrbit workspace, or a visitor to altorbit.app.
Two roles, depending on the data. For what's inside a workspace — time, pay, leave, chat, files — your organisation is the controller and we process it on its behalf under our DPA; questions about that data are best sent to your employer first. For your account, billing, this website, the early-access list and support, we are the controller.
What we collect
The things you give us, the things your workspace generates, and the things we measure to keep the service working.
| Bucket | Examples | Why |
|---|---|---|
| Account | Name, email, hashed password, profile photo | So you can sign in and your team can find you |
| Workspace content | Time blocks, projects, chats, leave requests | The product itself |
| Billing | Card last-4, billing address, invoice history | Charging, taxes, receipts. Card numbers are held by Stripe, not us. |
| Operational | IP, user-agent, error stacks, click events | Debugging, security, fraud prevention |
| Early-access list | Name, work email, company, team size, your note, IP address and browser | To email you once at public launch with your code |
| Support | Your message, name, email, company, IP address and browser | To answer you and follow up |
| Website chat | What you type into the support chat | An AI assistant answers your questions |
| Sign-in with Google | Name, email and profile photo, provided by Google | To create your account without a password |
| Mobile app | A push token for your device | To deliver notifications you've turned on |
| Website analytics | Pages viewed, clicks and scroll positions (heatmaps), session recordings with form fields masked, survey answers, browser and device type | To improve the website — only if you accept analytics |
Why we use it
Each purpose and the legal basis we rely on under GDPR:
- To run the product — sign-in, sync, notifications, billing. Basis: our contract with you or your organisation (Art. 6(1)(b)).
- To keep it secure — block brute-force attempts, detect compromised accounts, audit admin actions. Basis: our legitimate interest in keeping the service and its users safe (Art. 6(1)(f)).
- To improve the website and the apps — pseudonymous analytics via PostHog: which pages and screens are used and where onboarding stalls. On the website and in the web app this can also include clicks and scroll positions (heatmaps), page-speed measurements, short surveys, and recordings of how you move through the pages (session replay); what you type into form fields is masked in your browser and never recorded, and in the web app all text and images are masked as well, so a recording shows layout and clicks, never your content. Only if you accept analytics — in the cookie banner on the website, or when the web or mobile app asks (consent, Art. 6(1)(a)). If you accept on both the website and the web app, your earlier website visits are linked to your account. Plus anonymous page-speed numbers via Vercel Speed Insights, which uses no cookies (legitimate interest, Art. 6(1)(f)).
- To understand how the product is used — our servers record key actions in your account, such as signing up, creating a project, closing a ticket or changing a plan, and send them to PostHog (EU) with your account id and workspace id — never your name, email or anything you write, and without your IP address. This uses no cookies and does not depend on the analytics choice above. Basis: our legitimate interest in learning which parts of the product work (Art. 6(1)(f)). You can object at any time — write to privacy@altorbit.app and we stop.
- To talk to you — receipts, security alerts and account emails (contract); the early-access launch email and any product news only if you asked for them (consent).
- To answer you — support requests by email, form or chat. Basis: our contract with you, or our legitimate interest in helping visitors (Art. 6(1)(b)/(f)).
- To meet legal duties — billing and tax records. Basis: legal obligation (Art. 6(1)(c)).
We don't sell your data. We don't share it with advertisers. We don't use your workspace content to train AI models — ours or anyone else's. AI features call a third-party model provider only when someone uses them, and only providers whose terms exclude training on that data.
Who we share it with
A short, public list of sub-processors. We use them because building our own would be worse for your data, not better.
- OVHcloud — application servers, database and backups (Frankfurt, Germany).
- Cloudflare — DNS, CDN, DDoS protection, bot checks on our forms (Turnstile) and file storage (Western Europe).
- Vercel — hosting of the website and the web app, and anonymous page-speed measurement (Speed Insights).
- Stripe — payment processing. Card data never touches our servers.
- Resend — transactional email (receipts, password reset, invites).
- Sentry — error tracking. Configured with PII scrubbing.
- An AI model provider — AI features and the support chat assistant (USA).
- Expo — push notifications to the Android app, delivered through Google Firebase Cloud Messaging, and app updates (USA).
- PostHog — product analytics for the website and the apps, including heatmaps and session recordings on the website (form fields masked) and in the web app (all text, inputs and images masked), and usage statistics from our servers (EU; IP addresses are discarded).
- GIPHY — GIF search in chat (USA). Searches go through our servers without anything that identifies you; the Android app loads the GIF images from GIPHY directly.
The full list with current addresses and DPAs is at altorbit.app/subprocessors and is updated whenever it changes — we email Owners 30 days before adding any new processor.
Where your data lives
Your workspace data, files and backups are stored in the EU — the database in Frankfurt, files in Western Europe. Some processing happens outside the EU: the web app's servers run on Vercel in the USA and see requests in transit, Cloudflare's network is global, AI features call a US-based model provider, push notifications to the Android app go through Expo (US), and payments run through Stripe. These transfers are covered by the EU Standard Contractual Clauses or the EU-US Data Privacy Framework. A US region is on our roadmap, with no committed date yet.
Your rights
If you live under GDPR (EU/UK), CCPA (California), or a similar regime, you have the right to:
- Access — get a copy of your data. Self-serve in settings, or email us; very large histories are split into several files.
- Correct — fix anything wrong. Most of it is editable from your profile.
- Delete — delete your account: your personal data is erased right away and leaves backups within 90 days. Content you created in a workspace stays with that workspace.
- Port — download your personal data as JSON or CSV.
- Object — opt out of any non-essential use: marketing emails, analytics, and the usage statistics our servers record (write to us, see below).
- Restrict — ask us to pause using your data while a request or a dispute is being checked.
- Withdraw consent — for analytics or launch emails, at any time: use Cookie settings in the footer of the website, the analytics switch in the app's settings, or unsubscribe from the email. Processing before you withdraw stays lawful.
We don't make decisions about you based solely on automated processing. Workspaces can turn on overtime alerts that notify leads when someone logs approved overtime on most recent days; the alert informs a person, it decides nothing.
Reach us at privacy@altorbit.app. We reply within 2 business days and complete requests within one month, as GDPR requires.
How long we keep it
- Active workspaces — for as long as the workspace exists. Owners can choose to delete older chat and time records automatically after 12, 24 or 36 months.
- Inactive Free workspaces — a Free workspace nobody uses for 12 months may be deleted. Every Owner gets a warning email 30 days before, and any activity cancels the deletion.
- Deleted workspaces — access stops immediately and an Owner can restore the workspace for 30 days; then it's purged from primary storage and leaves backups within 90 days.
- Audit logs — 30 days on Free, 365 days on Pro, then deleted.
- Billing records — 7 years, because tax law says so.
- Early-access list — until we send the launch email. Ask us and we'll remove you sooner.
- Support requests and chats — as long as we need them to answer you and handle follow-ups.
Cookies
We use the smallest set of cookies that lets the product work — a session cookie, a CSRF token, short-lived sign-in cookies (two-factor, Google), and language and theme preferences. The support chat keeps a conversation id in your browser's local storage once a chat starts. On the website and in the web app we additionally use PostHog analytics (on the website this can include heatmaps and session recordings with form fields masked), which loads only after you opt in; you can change your choice any time via Cookie settings in the footer or in the app's settings. Vercel Speed Insights measures page-load speed without cookies. We don't use advertising or retargeting cookies.
Children
AltOrbit is not for children under 16. If you believe a child has signed up, email us and we'll delete the account immediately.
Changes to this policy
We change this document when our practices change, not for fun. Material changes get a 30-day notice email to all Owners. Cosmetic changes (typos, clearer wording) are made without a separate notice.
Contact
Privacy contact: Andrii Zhelezko, founder · privacy@altorbit.app. A Data Protection Officer will be appointed once AltOrbit is incorporated.
Registered address: published once AltOrbit is incorporated (planned in the EU)
UK representative: to be appointed at incorporation
You can complain to a data protection authority at any time — in the EU, usually the one where you live or work. We'd appreciate the chance to fix things first at the address above.