ORBIT ยท EARLY BETA
Privacy
Orbit has no account system, analytics, advertising SDK, or remote AI API.
- Image editing, OCR, PDF processing, archives, rewriting, grammar correction, and summaries run on the Mac. Apple Intelligence must be available for text generation. Apple's translation service may download language packs.
- Image searches send the query and normal network request metadata to the selected provider, Google or Wikimedia. Images download directly from publishers over public HTTPS. Each download and redirect is checked for private/reserved addresses; the validated address is pinned for the connection with normal TLS verification. No publisher cookies, sign-in credentials, proxy settings or disk cache are used for these downloads. Some publishers may fail under this stricter policy. Google runs in an ephemeral offscreen WebKit session. Provider privacy policies apply to those requests.
- Favourite and recent image URLs are saved locally in
~/Library/Application Support/Orbit. These are links, not offline image copies. - Carry keeps one explicitly selected result and its source in memory, bounded to 64 MB. Carrying another result replaces the card; dismissing it clears that reference. Files retain local references. Dragging/chaining may create exports in an Orbit-owned temporary folder, capped at 128 MB. Exports stay available until normal quit, which removes them and clears the carried result. On startup and before creating temporary storage, Orbit removes marked session folders belonging to dead processes. Active sessions and unmarked folders are kept. A crash can leave files until a subsequent Orbit launch or system cleanup. Original files are never removed by dismissing a result.
- Clipboard history starts off. When enabled, recent entries stay in memory, bounded to 30 entries or 64 MB. Only items explicitly pinned are saved locally, encrypted with AES-256-GCM using a key in the macOS login Keychain. The key is not stored alongside the file or synchronized by Orbit. Existing plaintext pins are removed only after the encrypted replacement is read back and authenticated; a failed migration preserves the original. The storage directory is owner-only and files are mode 0600. If the file is corrupt or the key unavailable, saving pins is blocked; retry in Settings โ Privacy. There is no plaintext fallback. Marked concealed, transient, or automatically generated entries are ignored. Apps that do not mark sensitive copies cannot be identified reliably.
- Accessibility is optional and used to suppress pointer motion during an active edge gesture. Orbit does not log keystrokes.
- Automation is requested only when connecting a chosen Music or Spotify player. Track metadata is held in memory for display and seeking.
- Screen Recording is used for screen capture. Captures remain local until the user copies or saves them.
- Raw trackpad contacts are processed transiently and are not recorded. The explicit command-line diagnostic probe writes aggregate counts to
/tmp/orbit-gesture-status.json.
Quit Orbit to stop monitoring. Settings can pause gestures and disable clipboard recording. Recent clipboard items can be cleared while keeping pins. Unpin an entry before clearing to remove its persisted copy.
Encryption does not protect clipboard contents from an already-compromised Mac or every process running as you. Do not pin passwords or authentication codes. Keychain access may need your approval after an ad-hoc app update; Orbit never needs your Google password. Losing the encryption key makes saved pins unreadable.
This website
The website adds no analytics, tracking scripts, remote fonts or contact backend. The hosting provider receives normal web request metadata. The feedback form prepares a file locally in your browser; it does not submit your answers.