Privacy Policy
Last updated August 5, 2026
This Privacy Policy explains how Orbit, a product of Pluto Insights Inc. (“Orbit,” “Pluto Insights,” “we,” “us”) collects, uses, and shares information when you use our website and product. By using Orbit, you agree to the practices described here.
Information we collect
We collect the information you provide directly, such as your name, email address, and the contacts and connections you choose to import. With your permission, we also process data from the accounts you connect (for example, your address book and calendar) to build your network and surface warm introduction paths.
Data protection
We treat contact, calendar, and email-header data as sensitive. Orbit protects that data with the following mechanisms:
- Encryption in transit: all data exchanged between your devices and Orbit travels over TLS.
- Encryption at rest: stored account data, imported contacts, calendar interactions, Gmail metadata headers, and OAuth tokens are encrypted at rest on our managed cloud infrastructure.
- Account isolation:each user’s data is isolated with row-level access controls so one Orbit account cannot read another account’s network.
- Least privilege: we request the narrowest OAuth scopes needed for the features you turn on. For Gmail, that means headers only (From, To, Cc, Subject, Date) via
gmail.metadata—never message bodies or attachments. - Access control: OAuth tokens and imported Google user data are stored on protected servers, used only to sync the features you authorize, and are not sold or shared with other Orbit users. Internal access is limited to what is needed to operate and secure the service.
- User controls: you can disconnect Google, revoke access in your Google account permissions, delete imported contacts, or delete your Orbit account at any time.
Additional detail is available on our Security page.
How we use information
We use your information to provide and improve the product, map relationships across your network, suggest introductions, secure your account, and communicate with you about your account and the service.
Research and search personalization
Orbit may use public sources to research your professional background and build your self-profile. That research stays private unless you turn on Share Profile; when sharing is on, Orbit may use it to complete your details for another Orbit user who already has you in their network. Orbit also derives private, owner-scoped signals from search actions, such as topics and results that appear useful, to improve ranking for your account. You can turn off the use of those signals for search personalization.
How we share information
We do not sell your personal information. We share data with service providers who help us operate Orbit (such as hosting, infrastructure, and analytics providers), and only as needed to deliver the service. We may disclose information if required by law.
Your network is private by default. If you explicitly turn on Share LinkedIn connections, people who already have you saved in Orbit may see which first-degree LinkedIn connections you both imported and use those shared connections for warm-introduction suggestions. Orbit shows names, roles, and companies for those shared connections, but not phone numbers, email addresses, notes, or your private address book. You can turn this sharing off at any time.
Orbit contacts who are also Orbit users may see your online and last-seen status. This setting is on by default and can be turned off under Privacy & security; when it is off, Orbit shows only an approximate activity range rather than your precise activity.
Connected accounts
When you connect a third-party account, we request only the access needed to import your contacts, the people you meet with, and—when you explicitly authorize Gmail metadata—the people you exchange email with. You can disconnect a connected account at any time, and we honor the data-handling requirements of each platform we integrate with.
Apple Calendar on iPhone
When you connect Apple Calendar in the Orbit iPhone app, we request full calendar access so we can scan the last 12 months of calendars available on your device, including event titles, dates, and attendee names and email addresses when available. We upload that data to your private Orbit account to create or match contacts and build a private meeting timeline. We do not create, edit, or delete calendar events, and we do not notify attendees. Calendar-derived data is not automatically sent to third-party AI or profile enrichment services or used to build shared identity links. You can stop future access anytime in iOS Settings; revoking access does not delete data you already imported.
Google user data
When you connect a Google account, Orbit requests read-only access to .../auth/contacts.readonly and .../auth/calendar.readonly. If you choose the Gmail metadata connection, Orbit also requests .../auth/gmail.metadata. We use Contacts (People API)to read your saved contacts and “other contacts” (name, email, phone, company, job title, and photo) so we can populate your private contact list. We use Calendarto read events on your primary calendar (event start time, title, and attendee name/email only) so we can identify the people you meet with and build a private “last met” interaction timeline. We request read-only access only and never create, edit, or delete your contacts, calendar events, or email.
With Gmail metadata, Orbit reads only the From, To, Cc, Subject, and Date headers of recent messages. We use those headers to identify people you exchange email with and add subject-and-date interactions to your private contact timeline. Orbit does not request, access, or store Gmail message bodies or attachments. Google OAuth tokens and imported header data are stored on Orbit’s protected servers so the connection can sync the features you authorize.
Orbit’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the user-facing features described above; we do not sell it; we do not use or transfer it for serving advertisements; we do not use it to develop, improve, or train generalized or non-personalized AI and/or machine learning models; and we do not allow humans to read this data unless we first obtain your affirmative consent, it is necessary for security purposes (such as investigating abuse) or to comply with applicable law, or the data has been aggregated and anonymized. Each user’s Google data is private to that user and is not shared with other Orbit users.
Google user data is never used to train generalized or non-personalized AI models. Gmail metadata is not used for advertising, sold, or shared with other Orbit users.
You can revoke Orbit’s access at any time from your Google account permissions. Disconnecting Google in Orbit or revoking access stops future collection. You can also remove imported contacts in Orbit or delete your Orbit account.
Apple Messages (Mac)
If you connect Messages in the Orbit Mac app (Pro), Orbit reads recent one-to-one iMessage and SMS threads from the Messages database on your Mac after you grant Full Disk Access. Short snippets and summaries are saved to your Orbit so people and timelines stay in sync on web and iPhone. We do not send messages on your behalf. You can disconnect Messages anytime from Connect; that stops future syncs. Group chats are not imported.
Autopilot Screen (Mac)
If you turn on Autopilot Screen in the Orbit Mac app (Pro), Orbit captures a downscaled frame to spot names and profiles. The image is sent to Orbit to detect people and is not saved. You choose who to add. You can turn Screen off anytime from Autopilot settings.
Instagram and Channels
If you connect Instagram, Fabric processes your Instagram export, including followers, following, and selected activity, so Orbit can import mutual connections and add private context to your self-profile. If you connect a Channel, Unipile provides read-only sync of LinkedIn, WhatsApp, Instagram, or Telegram chats. Orbit stores matched people, message snippets, and derived summaries or topics in your private network so they can appear in contact timelines and search. Orbit does not send Channel messages on your behalf. You can disconnect either connection to stop future syncs.
Data retention and deletion
We retain your information, including search prompts and Orbit chat history, while your account is active so you can revisit prior work and Orbit can provide the service. You can delete contacts at any time and delete your account and associated data from the product or by contacting us. Disconnecting a connected Google account stops future imports. If you choose “remove contacts” while disconnecting, Orbit removes contacts whose sole source was that Google connection; contacts also supported by another source are kept. Deleting your Orbit account deletes the associated Google-derived contacts, calendar interactions, Gmail metadata interactions, and stored connection tokens from our systems.
Your choices
You can access, update, or delete your information from within the product, and you can revoke access to connected accounts at any time.
Contact us
If you have questions about this Privacy Policy or your data, contact Pluto Insights Inc. at privacy@orbitmy.co.