Privacy policy
In short
- The Orbari app keeps your people, notes and recordings on your device. We can’t see them.
- The app has no account, no advertising and no analytics.
- Recordings are turned into text on your device. Suggestions from Apple’s on-device artificial intelligence (AI) are made on your device too.
- Files you export, mirror or share leave the app. You decide where they go and who can see them.
- This website stores information only when you send a bug report or an idea, vote or comment on the roadmap, or sign up for email updates. It runs on Cloudflare, stores what you send in a Cloudflare database, and uses Resend for email updates.
- Visit counts on this website use no cookies. The site sets one cookie, and only if you vote or comment on the roadmap.
- We don’t sell your information or use it for advertising.
- To see, correct or delete anything you sent through this website, email support@orbari.app and we will do it.
This policy explains how Orbari (“Orbari”, “we”, “us”) handles information in two places: the Orbari app for iPhone, iPad and Mac, and this website, orbari.app. The two work very differently, so each has its own section.
The Orbari app
What the app keeps, and where
The people you add, with your notes, catch-ups, relationships, important dates, custom fields, photos, saved recordings and other details, are kept in a database on your device. The database uses SwiftData, which is part of Apple’s software for iPhone, iPad and Mac.
The app does not need an Orbari account. It does not send your records to us, and we have no way to see them. They stay on your device unless you use one of the features below that makes a copy somewhere else.
When you add a photo of someone, you pick it in Apple’s photo picker, and Orbari receives only the photo you choose. When you import people from a contact card file or a spreadsheet file, Orbari reads only the file you pick. The app does not ask for access to your Contacts. On iPhone and iPad, text, links and files you share to Orbari from other apps go straight to Orbari on your device.
On-device intelligence
When you paste text or record a catch-up, Orbari can suggest people, dates, details and follow-ups. It uses Apple’s Foundation Models, the language model built into devices that support Apple Intelligence (Apple’s AI features). This runs on your device. Your text is not sent to us or to any other company to be processed. You review the suggestions before Orbari saves them. On devices without Apple Intelligence, you can still add everything by hand.
Microphone and speech recognition
Orbari asks for microphone access only when you start a recording, such as a catch-up, an interview or how to say someone’s name. To turn a recording into text, Orbari uses Apple’s speech recognition on your device. The first time, your device may download Apple’s speech recognition model. Your recording is not uploaded to us or to anyone else. If you save a recording, it is kept on your device with your records.
Other permissions
Orbari asks for these only when you use a feature that needs them. You can change your answer at any time in your device’s settings.
- Reminders and Calendar: if you choose to add a follow-up or an important date to Reminders or Calendar, Orbari creates that item there. Those apps, and any account they sync with, such as iCloud, then hold a copy.
- Camera (iPhone and iPad): used only to scan the QR code (a square barcode) that pairs your device with your Mac.
- Local network: used only so your iPhone or iPad and your Mac can find and connect to each other. See “Sharing between your Mac and your other devices” below.
- Face ID or Touch ID: used only if you turn on App Lock. Your device checks your face or fingerprint, and Orbari learns only whether the check passed. Your App Lock PIN (personal identification number) is stored in a scrambled form in your device’s keychain, Apple’s secure storage for passwords. It stays on that device.
Maps and places
When you choose a place on the map, Orbari uses Apple Maps. The words you search for, or the spot where you drop a pin, are sent to Apple to find the place name. Orbari does not use your own location.
Markdown mirroring and exports
Markdown files are plain text files with simple formatting. Many notes apps can open them, including Obsidian. Markdown mirroring is off until you turn it on, and it needs the one-time unlock. When it is on, Orbari writes a readable copy of each person, including private notes and saved recordings, to a folder you choose. If you don’t choose one, Orbari uses its own folder in iCloud Drive when iCloud Drive is available.
These files are copies. They are not a complete backup of the app, and they cannot rebuild Orbari’s database on another device.
You can also export people and their connections as an Orbari file to send to someone else. You choose which details to include before the file is made.
Once a file leaves the app, it is outside Orbari’s control. Whoever stores or receives it, such as iCloud Drive, another storage service or the person you send it to, handles it under their own terms. Deleting a person, using Delete All Data or Reset App, or deleting the app does not remove exported files. Delete those yourself in Files, Finder or your storage service.
Sharing between your Mac and your other devices
The Mac app has an optional sync server, which lets your other devices connect to your Mac. It stays off until you turn it on in Settings, and at first only that Mac can reach it. If you make it reachable on your network, your iPhone or iPad can pair with it by scanning the QR code (a square barcode) that the Mac shows, and then copy people from the Mac. The connection is encrypted with the server’s token, a private key that you share only with your own devices. The information goes straight between your devices. It is not sent to us. Anyone who has the token can read your people through the server, so keep it private. You can make a new token in the Mac app’s Settings at any time.
iCloud
Today, Orbari does not sync its database through iCloud. Each device keeps its own records. Syncing between your devices with iCloud is being tested and is not yet a feature you can rely on. If that changes, we will update this policy.
The app uses iCloud Drive only for Markdown mirroring, when the folder is in iCloud Drive. Apple stores and syncs those files under its own terms. We have no access to your iCloud account. Read Apple’s privacy policy.
Purchases
Orbari is free for up to five people. The one-time unlock is sold through Apple’s App Store, and Apple processes the payment. We never receive your card or payment details. Apple gives us only combined sales figures that do not identify you. The app checks your purchase with Apple on your device.
No tracking, analytics or advertising
The app contains no third-party analytics, advertising or tracking code. It does not track you across other apps or websites, and it does not send us information about how you use it.
Your device has its own setting for sharing crash reports with app developers. If you turn it on, Apple may share crash reports with us. Apple controls this, and you can turn it off in your device’s privacy settings.
Your information in the app
We can’t see the information in the app, so we can’t look it up, change it or delete it for you. You control it directly:
- View, edit or delete any record in the app.
- Export copies, as described in “Markdown mirroring and exports”.
- In Settings, under Data Management, use Delete All Data to remove your records but keep your settings, or Reset App to remove your records and settings.
- Delete the app to remove its data from that device. Exported files are not removed, so delete those separately.
This website
When you visit orbari.app, we aim to collect as little as possible. This is every service you interact with on this website, and what each one does.
- Domain name (DNS)
- Cloudflare. Answers when your browser looks up orbari.app.
- Hosting
- Cloudflare Workers. Runs the site’s code on Cloudflare’s network, in the data centre nearest to you, and protects the site from attacks. It keeps a log of the requests the site’s code handles, and of any errors, for up to 7 days.
- Database
- Cloudflare D1. Stores bug reports, ideas, roadmap votes and comments.
- Spam protection
- Cloudflare Turnstile. Checks that a form is sent by a person. When you send a form, the site passes the check’s result and your Internet Protocol (IP) address to Cloudflare to confirm it.
- Email updates
- Resend. Sends the confirmation email and the occasional newsletter, and keeps the mailing list.
- Support email
- Cloudflare Email Routing. Forwards messages sent to support@orbari.app to our inbox.
- Visit counts
- Simple Analytics. Counts visits to the public pages without cookies: the page, the site that linked to it, and the browser, device type and country. Pages that don’t exist and the private owner console are never counted.
The website data notice links to each service’s own privacy policy.
How your data is stored
Everything you send through the website’s forms is stored in Cloudflare D1, Cloudflare’s database service. We ask Cloudflare to keep the database in its Oceania region (Australia and New Zealand). Cloudflare encrypts the data while it is stored and while it moves between its servers.
Only the site’s own code reads and writes the database. Private bug reports, ideas and comments that haven’t been approved can be seen only by the site owner, in a console that needs a passkey, a way to sign in with your device’s screen lock instead of a password.
When we delete something, Cloudflare keeps a recovery history of the database for up to 30 days. After that, the deleted information is gone.
Email addresses for updates are not stored in our database. Until you confirm your address, it isn’t stored anywhere: it travels inside the signed link in your confirmation email. Once you confirm, Resend keeps it on our mailing list, in the United States, with the products whose news you chose and the site you signed up on.
Simple Analytics keeps only visit counts, in the European Union, and says it does not store IP addresses. Cloudflare keeps standard request logs, including IP addresses, to run and protect its network.
What the website keeps, and for how long
- Bug reports and ideas: what you typed, plus any reply email, display name and device details you added. Kept in Cloudflare D1 until we delete them. Nothing you send is published automatically. If we turn an idea into a public roadmap card, we write the card ourselves, without your name or email address. We use your email address only to reply about what you sent.
- Roadmap comments: your display name and comment, kept in Cloudflare D1 until we delete them. A comment is shown on the roadmap, with its date, only if we approve it.
- Roadmap votes: a cookie (a small file your browser keeps) called
orbari_feedback_voter, which holds a random code and lasts up to one year, and a scrambled version of that code in Cloudflare D1, so the site can count one vote per browser. To remove your vote, select the vote button again. - Sending limits: to stop abuse, the site counts how often each form is sent, for example five bug reports a day. It stores a scrambled code made from your IP address and browser details, never the address itself, with the count. The count starts again after an hour or a day, and the record stays in Cloudflare D1 until we clear it.
- Email updates: your address, which products’ news you chose and the site you signed up on, kept by Resend until you unsubscribe or ask us to remove it. Our other apps share the mailing list, but you get news only about the ones you choose, and you can change that from the link in any email. Unsubscribing stops the emails. To have your address deleted too, email us. The confirmation link stops working after 48 hours.
- In your browser only: your light or dark theme choice (
orbari-theme); a bug report or idea you haven’t sent yet (orbari-draft:), which is removed when you send it or close the tab; and, if a page fails to load, that page’s address (__vinext_rsc_initial_reload__or__vinext_hard_navigation_target__), which is removed once a page loads. None of these is sent to us. - The owner console: only the site owner’s own sign-in records: passkey public keys, scrambled one-time recovery codes, sign-in sessions (which end after eight hours) and a log of the owner’s actions. Visitors can’t create accounts, and the site never asks you for a password.
No system is perfectly secure, so please leave other people’s names and private details out of what you send.
Your choices
You can ask to see, correct or delete anything you sent through this website. Email support@orbari.app and we will do it. Tell us the email address or display name you used so we can find it.
Votes and sending limits are stored under scrambled codes rather than names, so we may not be able to tell which ones are yours. You can remove a vote yourself, and clearing this site’s cookies in your browser removes the voting cookie. You can stop email updates at any time with the unsubscribe link in any email.
We don’t sell your information, and we don’t use it for advertising.
Children
Orbari’s planned App Store age rating is 4+. That rating describes the app’s content. The app is not made for children under 13. We do not knowingly collect personal information from children through this website. If you think a child has sent us information, email us and we will delete it.
Changes to this policy
We may update this policy when the app or the website changes. We will post the new version on this page and change the effective date at the top.
Contact
Questions about privacy, or a request about your information? Email support@orbari.app. To report a problem with the app, you can also use the private report form on the support page.