Privacy Policy
Version 2026-09-20 · Effective September 20, 2026
This Privacy Policy describes what information Orrery collects, how it is used, and who can see it. Orrery is a social network built around a visual map of your relationships, communities, and the businesses you follow.
Account information
When you create an account we store your display name, username, email address, a hashed password, your role, and timestamps for account creation and activity.
Phone numbers & SMS
If you add a phone number — for two-factor authentication, or to verify a business — we store it and use a third-party messaging provider to send verification codes. We use your number for verification and security only, not for marketing.
Profile information
Your “Me” profile and how you present yourself — name, photo and its framing, bio, social links, and visibility preferences such as whether your orbit is public.
Contacts & nodes
The contacts, places, and businesses you add to your orbit, including how you arrange them (tiers, clusters, positions). Contacts who are not Orrery accounts exist only in your own orbit and are not shared with anyone else.
AI features in Search
All of this is optional and starts switched off. Orrery’s search works fully without it: finding people, messages, events, photos, notes and settings, and the answers Orrery writes itself from your own records. You turn AI on yourself in Settings → Privacy, after reading a short explanation, and you can turn it off at any time.
There are two separate switches, because they are two different things.
1. Semantic Search — stays inside Orrery. Orrery reads your own content on its own server and turns it into “meaning-vectors”: lists of numbers that let search find something when you remember the idea but not the words. No other company is involved, and no text is sent anywhere. These vectors live in Orrery’s database beside everything else, are only ever used for your own searches, and are deleted when the thing they describe is deleted — including when a Comet expires or is unsent — and when you switch Semantic Search off.
2. AI Answers — sends a few excerpts to Anthropic. When you ask a question Orrery can’t answer from its own records, and only if you have turned this on, Orrery sends your question together with a small number of relevant excerpts to Anthropic, which runs the Claude model that writes the answer. Orrery sends the smallest amount that can answer the question — at most a dozen short excerpts, never your whole account — and always shows you which sources the answer came from, so you can open them and check. Answers are generated by AI and can be wrong or incomplete.
Each excerpt goes with a short label. So the model can tell one excerpt from another, every excerpt is sent with a brief label naming what it is — for example “Note about Sam”, “Reminder · Sam · 14 Sep” or an event’s title and date. That means the names of people, events and places in your own records can reach Anthropic alongside the excerpt, as can a place you wrote into an event or a memory, since it is part of that record. Orrery never sends the underlying database ids, links or account ids — the model only ever sees “s1”, “s2” and so on.
What is never sent to Anthropic:
- Anything you aren’t allowed to open. Orrery only ever considers results you already have access to, and re-checks that before an excerpt is used.
- Anything from your connected Google or Microsoft Outlook accounts — calendar events, contacts and anything else those services provide. That data stays fully searchable in Orrery, but is kept out of AI processing entirely, including out of the meaning-vectors above.
- Your password, your two-factor secrets, and your payment or account credentials.
- Your device’s location, the coordinates Orrery holds for a place, and your saved places such as Home or Work. A place name you wrote into an event or a memory is part of that record and can travel with its excerpt, as described above.
- Photos, videos and audio. Only text is ever sent.
What Anthropic does with it. Anthropic acts as a processor for Orrery under its Commercial Terms and Data Processing Addendum. Its published terms state that Anthropic may not train models on customer content submitted through the API, and that inputs and outputs are deleted from its systems within 30 days. Anthropic also runs automated safety checks on API traffic and states that content flagged by those checks may be kept for up to two years, and that it may retain data longer where the law requires it. Those are Anthropic’s terms, not Orrery’s, and they may change; the links above are always the current version.
What Orrery does with it. Orrery does not sell AI data, does not use it for advertising, and does not use your private content to train any model of its own. Orrery keeps a count of how many AI requests were made and what they cost — never your question, the excerpts, or the answer. An answer may be held in memory for a few minutes so asking the same thing twice doesn’t repeat the work; it is never written to disk and disappears when you turn AI off.
AI never does anything on your behalf. It can suggest — “add a reminder to call Sam on Tuesday” — but nothing happens until you tap to confirm, and the action is then carried out by Orrery’s ordinary code, with the same rules and limits as if you had done it by hand. AI cannot send messages, change your privacy settings, move anyone in your orbit, or delete anything. Text found inside your own messages, notes or posts is treated as quoted material and can never instruct Orrery to do something.
Turning it off. Switching AI processing off in Settings → Privacy stops all of it immediately, deletes the meaning-vectors Orrery built for you, and clears any answer held in memory. Your content, and ordinary search, are unaffected.
Location information
When you add a place or set an event location, we store that location as part of your orbit and event data. Location search is powered by a third-party places provider; the text you type into location search is sent to that provider to return suggestions.
Leave-by and your location. If you turn on Leave-by, Orrery works out when you should leave for an in-person event you're going to — an Orrery event, or an event from a Google or Outlook calendar you connected. To do that it uses:
- Saved places you add (such as Home, Work or School). They are private to you: never shown on your profile, to hosts, guests or anyone else, and only used to work out travel times. You can remove them at any time in Settings.
- Your device's location, only if you choose “Use current location” (in Settings, or for one event). Orrery asks your browser for permission when you tap that option — never on its own. On the web, a location is only read while Orrery is open and only when a trip is coming up; Orrery does not track your location in the background.
We keep only your most recent reading, rounded to about a kilometre — never a history of where you've been. It is deleted 12 hours after it was taken, when you turn “Use current location” off, or straight away if you tap “Forget it now”. To estimate travel time, the starting point and the event's location are sent to our maps provider (Google Maps Platform), which returns a travel time; when an event only has a written address, that address is sent to a maps provider (Google, or OpenStreetMap as a fallback) to find it on a map. Short-lived travel-time results are cached in a form that doesn't reveal where a trip started.
Orrery does not sell your location, use it for advertising, or show it to other people, and it is never used for finding or suggesting people.
Comets
Comets are photo or video posts that disappear. A Comet shared with your audience expires one week after it is posted. A Comet sent directly to one person expires one week after they first open it, and never more than two weeks after it was sent. Comet content is permanently deleted after expiration. Orrery may retain minimal metadata that a direct Comet interaction occurred, such as the participants and date, for private relationship-history features. The Comet itself cannot be recovered.
This metadata is only kept for a Comet sent directly to one person — not for Comets shared with your wider audience, and not for viewing a Comet. It is private to the two people involved, is never shown to anyone else, is removed if the sender deletes the Comet before it expires, and is deleted with either person's account.
Business follows & memberships
When you follow or join a business, we record your relationship (follower, member, or staff). Followers are audience-only and are not exposed to other followers or shown a business’s internal members.
Connecting third-party accounts (Facebook, Instagram, and others)
Orrery lets you connect third-party accounts — including Facebook, Instagram, and other social platforms — so your public posts from those services can appear in your orbit, and so business owners can link their Facebook Pages.
When you choose to connect an account, the third party asks you to authorize Orrery and then gives us an access token. We use that token only to retrieve the specific information you authorized — such as your basic profile, your public posts or media, and (for businesses) the Pages you manage. We do not post on your behalf, and we do not access private messages or data you did not grant.
Access and refresh tokens are stored encrypted at rest and are never sent to your browser or to other users. We use them solely to fetch the content you connected.
You can disconnect a third-party account at any time from your profile settings. Disconnecting deletes the stored token and stops further syncing. You can also revoke Orrery’s access directly from the third-party platform’s own app settings.
To request deletion of data we obtained from a connected platform, disconnect the account in settings or email us at [email protected]; see “How to contact us & data deletion” below.
Our use of information received from Meta platforms follows Meta’s Platform Terms and Developer Policies, and our use of information from any other connected platform follows that platform’s developer terms.
Google sign-in and your Google data
Signing in with Google is optional. If you use it, Google tells Orrery your name, email address and profile picture so we can create your account or sign you in. It gives Orrery no access to your contacts, calendar or anything else.
Google Contacts and Google Calendar are separate, optional connections you choose to turn on in Settings; each is described below. Orrery uses what they provide only to power the features you see — never for anything else.
Orrery’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We don’t sell Google user data, share it with advertisers or data brokers, or use it for advertising.
- We don’t use Google user data to develop, improve or train generalized artificial intelligence or machine-learning models.
- No one at Orrery reads your Google data, except when you ask us to (for example, for support), when needed for security or abuse investigations, or when the law requires it.
- Your Google data is never shown to other Orrery users unless you choose to bring something into Orrery (such as adding a contact to your orbit, or bringing a Google event into Orrery).
Google Calendar
Connecting Google Calendar is optional. When you connect it, you choose on Google’s screen to let Orrery (1) see and edit events in your Google calendars, and (2) see the names of your calendars. Orrery uses this only for your own calendar experience:
Events you host in Orrery are added to the Google calendar you choose and kept in sync both ways — if you change the title, date, time, time zone or location in either app, the other follows. If both change the same thing, Orrery asks you which to keep instead of overwriting either one. Orrery writes only the event’s title, time, location, your own description of the event and a note that it’s synced with Orrery — never your guest list, RSVPs, chats, memories, private notes or anything about the people in your orbit. Events you’re invited to can be added to your calendar as your own copy; changes you make to that copy don’t change the host’s event.
Your other Google events (from the calendars you choose to show) are read so you can see them alongside your Orrery events. They are private to you: no one else on Orrery — not your friends, guests, profile visitors or public pages — can see them. Orrery keeps only what it needs to show them (title, time, time zone, all-day, location and repeat pattern) and does not keep their descriptions, attendee lists, video-call details or other information. A Google event becomes an Orrery event only if you choose “Bring into Orrery”; the new Orrery event then follows Orrery’s normal sharing rules, and its Google attendees are never imported, contacted or matched to Orrery accounts.
Your Google access tokens are stored encrypted, are never sent to your browser or to anyone else, and are used only for these purposes. Disconnecting Google Calendar stops syncing, deletes the stored tokens, your calendar list and every stored Google-only event, and asks Google to revoke Orrery’s access (if Google Contacts is still connected to the same Google account, Google’s permission stays in place for Contacts until you disconnect that too — Orrery keeps no Calendar token). It doesn’t delete events in Orrery or in Google (you can separately choose to remove the events Orrery added). Deleting your Orrery account does the same and revokes Orrery’s access to your Google account.
Google Contacts
Connecting Google Contacts is optional and read-only: Orrery can see your saved contacts so you can choose people to add to your orbit, and never changes or deletes anything in your Google contacts. Orrery reads each contact’s name, nickname, email addresses, phone numbers, photo, birthday and company, and shows them only to you on a review screen.
To help you review, Orrery points out contacts you already have in your orbit and checks which email addresses belong to people already on Orrery, so it can show “already on Orrery”. Only verified addresses of people who allow themselves to be found can match; nobody is told, and addresses that don’t match aren’t kept.
Nothing is imported until you pick it, and importing never messages, invites, follows or notifies anyone. Only the people you choose are added to your orbit, as private contacts, with the details you choose; Orrery remembers which Google contact each came from so a later re-import can offer updates. Google photo links aren’t stored. Everything else Google returned is discarded after the review.
Tokens are stored encrypted and never sent to your browser. Disconnecting deletes them and asks Google to revoke Orrery’s access (unless Google Calendar is still connected to the same Google account — then Google’s permission stays in place for Calendar, and Orrery keeps no Contacts token). People you already added stay in your orbit and remain yours to edit or delete. Google Contacts and Google Calendar are separate connections with separate permissions — connecting or disconnecting one doesn’t affect the other. Deleting your Orrery account removes the connection and revokes Orrery’s access.
Microsoft Outlook calendar
Connecting Outlook (Outlook.com or Microsoft 365, with a personal, work or school Microsoft account) is optional. When you connect it, you choose on Microsoft’s screen to let Orrery see your basic account details (your name and email address, so Settings can show which account is connected) and read and edit the calendars in your own mailbox. Orrery asks only for your own calendars — never your email, contacts, Teams, files, other people’s calendars, or any organisation-wide access — and keeps access while you’re away only so changes can sync. Orrery uses this only for your own calendar experience:
Events you host in Orrery can be added to the Outlook calendar you choose and kept in sync both ways, exactly as described for Google Calendar above: only the title, date, time, time zone and location sync; if both sides change the same thing, Orrery asks you which to keep; your guest list, RSVPs, chats, memories and private notes are never written to Outlook. If you connect both Google Calendar and Outlook, your Orrery events go to the ONE calendar you choose, so nothing appears twice.
Your other Outlook events (from the calendars you choose to show) are private to you: no one else on Orrery can see them. Microsoft sends Orrery each changed event in full, but Orrery keeps only what it needs to show it (title, time, time zone, all-day, location and whether it repeats) and immediately discards descriptions, attendee lists, organisers and meeting details — they are never stored or logged. An Outlook event becomes an Orrery event only if you choose “Bring into Orrery”; its Outlook attendees are never imported, contacted or matched to Orrery accounts.
Your Microsoft access tokens are stored encrypted, are never sent to your browser or to anyone else, and are used only for these purposes. Disconnecting Outlook stops syncing and deletes the stored tokens, your calendar list and every stored Outlook-only event; it doesn’t delete events in Orrery or in Outlook (you can separately choose to remove the events Orrery added), and it doesn’t affect a Google Calendar connection. Microsoft doesn’t offer a way for Orrery to withdraw its own access, so to remove Orrery from your Microsoft account entirely, open your Microsoft account’s app permissions (account.microsoft.com → Privacy, or for a work or school account, myapps.microsoft.com) and remove Orrery. Deleting your Orrery account deletes the stored tokens and cached Outlook events too.
Cluster & community memberships
Your membership and role within clusters/communities, and which clusters you can see, are governed by each community’s visibility settings and your role.
Feed posts & comments
Posts, comments, reactions, and bookmarks you create, and where they are shared (personal feed, a community feed, or both).
Comms / messages
Direct and group messages, including in community and business inboxes. Messages are visible to the participants of a conversation; community and business chats are visible to their members and to authorized moderators for moderation purposes.
Uploaded images & media
Profile photos and media you attach to posts or messages are stored so they can be displayed to the people permitted to see that content.
Audit & security logs
To keep accounts and communities safe we record security and administrative events (logins, role changes, moderation actions, ownership transfers) along with the actor, target, and time.
How we protect your information
We take reasonable measures to protect your information. Passwords are stored using one-way hashing and are never stored in plain text. Third-party access tokens are encrypted at rest. Accounts can enable two-factor authentication. No system is perfectly secure, but we work to protect your data and to limit who can access it.
Moderation actions
Actions taken by community owners, moderators, or platform admins — such as removing a post, muting a member, or removing a member — are recorded for accountability.
Service providers we share data with
We don’t sell your personal information. We share limited data with vendors who help us run Orrery, only as needed to provide the service:
- A hosting provider that stores our database and uploaded media.
- An email provider used to send verification, password-reset, and notification emails.
- An SMS provider used to send verification codes.
- A places/maps provider used for location search and, if you use Leave-by, to estimate travel times and find written addresses on a map.
- A product-analytics provider used to understand how the app is used (page views and interactions, with text and inputs masked — we don't send the contents of your posts, messages, or fields).
- The third-party social platforms you choose to connect.
These providers are permitted to use your information only to perform services for us.
What others can see
Visibility depends on roles and settings. For example:
- Your public orbit (if you enable it) shows a limited, PII-stripped view to anyone.
- Community content is visible per the community’s visibility tier (public / community / internal).
- Business followers see public content only; members and staff see more.
- Private contacts in your orbit are never shown to other viewers.
Your California privacy rights
If you are a California resident, you have the right to know what personal information we collect and how we use it, to request a copy of it, to request deletion, and to not be discriminated against for exercising these rights. We do not sell your personal information and do not share it for cross-context behavioral advertising. To exercise any of these rights, contact us at [email protected].
Children
Orrery is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
Account & data deletion
You can delete your account from Settings. Deletion removes your account record and orbit data, hands off or orphans communities you own so they are not destroyed, and deletes messages you sent. Some records may persist where required for security or legal reasons (for example, audit logs of moderation actions).
When you permanently delete your account, the photos, videos and other files you uploaded to Orrery are removed from Orrery's storage. This includes files you added to posts, messages, Comets, Events and your media library.
Other people may have kept a reference to one of your photos — for example in one of their albums, Memories, an Event gallery or a repost. Keeping a reference does not keep your original file: after your account is deleted, those places show a “Photo no longer available” placeholder or simply stop showing the photo, while the rest of that person's album, Memory or Event stays as it was.
Removing files from storage can occasionally take a little longer than deleting the account itself (for example, if our storage provider is briefly unavailable). To finish the job safely, Orrery keeps a small technical record of which files still need to be removed and retries until they are gone. These records contain a file identifier and retry status only — never the photo or video itself.
One limitation: a profile picture may have been copied into another person's own contact card for you in their Orrery (for example, from an older version of Orrery or when they set it themselves). Those copies are part of that person's contact card rather than a file you uploaded, so account deletion may not remove them. You can ask us to review a specific case using the contact details below.
How to contact us & data deletion
For privacy questions or to request deletion of your data — including data obtained from a connected platform such as Facebook — email us at [email protected], or delete your account from Settings. We will respond within a reasonable time and in accordance with applicable law.
Orrery is operated by Orrery (Christopher Barber).