Privacy Policy
Effective date: October 7, 2026
This Privacy Policy explains how Baek Doojin (trading name: dlab, Republic of Korea; "we") processes personal information when you use Orbit: the website orbit-lab.space, the Orbit macOS app, the Orbit PDF Reader browser extension, and related services. The privacy officer is Baek Doojin (orbit.lab.service@gmail.com).
1. Information We Process, Why, and for How Long
| Information | Purpose | Retention |
|---|---|---|
| Account: email address, name, user ID, sign-in method; with Google sign-in, your Google account ID and profile photo URL (kept by Firebase Authentication) | Creating your account, signing in, support, and service notices | Until you delete your account |
| Payments and credits: plan and subscription status, Paddle customer, subscription and transaction IDs, amounts and currency, credit balances and credit history | Billing, credits, refunds, and disputes | Until you delete your account. Payment event records (Paddle IDs, amounts, products, your user ID) are kept for 5 years under Korean e-commerce law, then deleted |
| Usage records: for each AI request, the model, token counts, cost, and time; app session identifiers; app version | Charging credits, usage history, abuse prevention, and troubleshooting | Until you delete your account |
| Device hash: a one-way hash of your Mac's hardware UUID (the UUID itself is not stored) | Granting welcome credits once per device | While welcome credits are offered. When you delete your account, its link to the hash is removed and only the hash and a granted flag remain |
| AI request content: document text and page images, questions, selected text, attachments, and earlier messages of the conversation | Producing AI answers, translations, and citation previews | Not stored by us (see section 2). Chat history is stored on your Mac |
| Windows waitlist: email address, language, and the page you signed up from | Telling you when Orbit for Windows is available | Until we send that notice or you ask us to remove it |
| Support: the messages you send us | Answering questions and handling complaints | 3 years (consumer complaint records under Korean e-commerce law), then deleted |
| Connection data: IP address, browser or app information, request times, and error logs | Security, fraud prevention, and troubleshooting | Up to 30 days in hosting logs |
We collect this information when you sign up or sign in, use the website, app, or extension, buy through Paddle, or contact us. We process it to perform our contract with you (account, payments, and the features you use), to meet legal obligations (keeping payment records), on our legitimate interests (security, fraud and abuse prevention, including the device hash), and with your consent (the Windows waitlist).
2. How AI Features Handle Your Content
- For document chat, the macOS app sends the PDF's text (with page numbers), page images when needed, your questions, selected text, attachments, and earlier messages of the conversation directly to OpenRouter, which forwards them to the provider of the model you chose. Older app versions send them through our servers.
- Translation (the selected text) and citation previews (a cropped image of the reference) are sent to OpenRouter through our servers. The browser extension sends text you translate the same way.
- We request OpenRouter's "deny" data-collection setting, which limits routing to providers that OpenRouter lists as not collecting user data. Providers process requests under their own terms and may keep them temporarily, for example for abuse monitoring or prompt caching.
- Our servers do not store your documents or the content of AI requests; they keep only the usage records in section 1. We do not use your content to train AI models.
- Looking up a paper's metadata sends only reference text such as a title or DOI to OpenAlex, Crossref, and arXiv.
- The browser extension opens PDFs on your device. It does not send the PDFs you open or your browsing history to us; it sends only text you choose to translate and the requests needed to sign in and show your credits.
3. Sharing with Third Parties
We do not sell personal information or share it for targeted advertising. We provide it to third parties only as described in this policy, with your consent, or when the law requires it. When you buy, Paddle collects your payment details directly as merchant of record under its own privacy policy, and we pass your email address and user ID to Paddle's checkout.
4. Service Providers and International Transfers
These providers process personal information for us. Information is transferred over encrypted connections when you use the related feature.
| Recipient and contact | Country | Information | Purpose | Retention |
|---|---|---|---|---|
| Google LLC (Firebase Authentication, Cloud Firestore, Gmail), privacy form | Database in Korea (Seoul region); authentication and email in the United States | Account, payment and credit, usage, and device hash records; support emails | Authentication, data storage, and support email | As in section 1 |
| Vercel Inc., privacy@vercel.com | United States | Connection data; requests passing through the website and API, such as translation text and citation images | Hosting the website and API | Logs up to 30 days |
| Paddle.com Market Ltd and its affiliates, privacy policy | United Kingdom, United States | Email address, user ID, and purchase details (Paddle collects payment details itself) | Payments, taxes, invoices, and refunds as merchant of record | As required by law, under Paddle's policy |
| OpenRouter, Inc., privacy policy | United States | AI request content and identifiers of your app's AI key | Routing AI requests and measuring usage | Under OpenRouter's policy |
| AI model providers reached through OpenRouter: OpenAI, Anthropic, Google, Fireworks AI, and other providers that OpenRouter lists as not collecting data; for older app versions, Z.AI (Zhipu AI) | United States; China for Z.AI | AI request content | Generating AI answers, translations, and citation previews | Under each provider's policy, which may include temporary retention for abuse monitoring or caching |
These transfers are needed to provide the Service. You can avoid transfers to AI providers by not using AI features, or stop all transfers by deleting your account; you can also contact us. Without transfers that core features rely on, those features cannot work. Transfers from the EEA and UK to us rely on the EU adequacy decision for Korea; onward transfers rely on the providers' Data Privacy Framework certifications or standard contractual clauses.
5. Deletion
When a retention period ends or the purpose is fulfilled, we delete the information without delay so that it cannot be recovered. When you delete your account, your account, credit, and usage records are deleted immediately, except records the law requires us to keep (section 1); copies remaining in logs or backups are deleted within 30 days.
6. Your Rights
You can ask to access, correct, delete, or stop the processing of your personal information, withdraw consent, or object to processing; in the EEA and UK you can also ask for a copy in a portable format. You can delete your account yourself in the dashboard, or email orbit.lab.service@gmail.com. We respond within 10 days. Someone you authorize, such as a legal guardian, can make a request on your behalf. We do not make decisions based solely on automated processing that significantly affect your rights.
7. Security
- All connections are encrypted (HTTPS).
- Access to systems that hold personal information is limited to the operator.
- Database rules let each user read only their own records; billing fields are written only by our servers.
- AI access keys are stored encrypted; passwords are handled by Firebase Authentication and not seen by us.
- Payment card details are handled by Paddle and never reach our servers.
9. Children
Children under 14 cannot create an account. If we learn that we hold a child's personal information, we delete it.
10. Privacy Officer and Complaints
Privacy officer: Baek Doojin, orbit.lab.service@gmail.com. In Korea you can also contact the Personal Information Dispute Mediation Committee (1833-6972, www.kopico.go.kr), the Personal Information Infringement Report Center (118, privacy.kisa.or.kr), the Supreme Prosecutors' Office (1301, www.spo.go.kr), or the Korean National Police Agency (182, ecrm.police.go.kr). In the EEA and UK you can complain to your data protection authority.
11. Changes to This Policy
We post changes at least 7 days before they take effect, or 30 days before for significant changes that affect your rights. This policy is available in English and Korean; for users in Korea the Korean version prevails.