The short version
- Orbit never intentionally collects your source code, file names, terminal contents, prompts, conversations, or credentials.
- The desktop app sends a small, optional stream of anonymous product usage to a self-hosted server. It is on by default in release builds and can be switched off at any time.
- This website uses self-hosted, cookie-free analytics loaded only in production.
- There are no ads, no third-party trackers, and no cross-site profiling. Orbit works exactly the same with analytics disabled.
Desktop app analytics
Release builds can send a limited set of anonymous usage information to a self-hosted analytics server. This is on by default in release builds and off in development builds, and you can turn it off at any time in Settings → Privacy → Anonymous Usage Analytics.
When enabled, Orbit may send:
- a pseudonymous installation identifier — a random UUID generated on first run and stored locally in
~/.orbit-pi/analytics.json; - a session identifier — a new random UUID for each launch;
- the app version, operating system, CPU architecture, and interface locale;
- a small, closed set of feature events: the app started or closed; a project was added, opened, or removed; the terminal was opened; an agent run started, completed, or failed; an MCP server connected, disconnected, or failed; the command palette or settings opened; the theme or a setting changed; and an update was available or installed.
Event details are limited to coarse values — for example, a failure category such as provider, or a theme mode such as dark. No free-form text is ever sent.
The installation identifier is pseudonymous
The installation identifier is a random number. It is not derived from your email, username, account, hostname, MAC address, CPU serial, disk serial, or any hardware identifier. Because it is stable across launches it can be linked to one installation over time, so it is best described as pseudonymous rather than legally anonymous. Resetting it generates a new identifier and a new session and discards anything already queued.
What Orbit does not intentionally collect
- source code, file names, file contents, or project and repository paths;
- terminal commands or terminal output, or shell history;
- AI prompts or responses, or conversation contents;
- API keys, access tokens, passwords, MCP credentials, or auth cookies;
- environment variables or clipboard contents;
- your IP address as an analytics property, exact location, or private URLs;
- machine hostname, MAC address, serial numbers, or disk identifiers.
The analytics pipeline is designed so this is enforced structurally: every event is a variant of a closed type, and a privacy filter strips and detects sensitive keys as defence in depth.
Turning it off
Turning telemetry off in Settings stops new events from being collected, clears anything already queued, and persists the choice locally. Orbit never blocks, never errors when the network is down, and works exactly the same with analytics disabled. Data is sent over HTTPS only, and TLS verification is never disabled.
This website
orbit.rajeshwarkashyap.in loads a small, self-hosted analytics script only in production builds — never in development. It is used to understand, in aggregate, which pages and releases people read.
The script records:
- the page path, query string, and referrer;
- your browser language and screen size;
- a random visitor identifier stored in
localStorage— not a cookie.
It does not use advertising cookies, does not fingerprint your device, and does not track you across other websites. If you set your browser to block scripts or clear local storage, the site works normally without it.
Third-party services
- Downloads and issue tracking run on GitHub. Visiting GitHub links is governed by GitHub's own privacy policy.
- Model providers you configure in Orbit are your own accounts. Prompts you send to them are governed by those providers' terms and privacy policies, not this one.
Retention and sharing
Analytics is self-hosted on infrastructure operated by the project and is not sold, rented, or shared with advertisers or data brokers. Data is retained only as long as it is useful for aggregate product decisions. Because the data collected is coarse and pseudonymous, it is not used to identify you.
Changes to this policy
If this policy changes in a material way, the date at the top of this page will change. Continued use of Orbit after an update means you accept the revised policy.
Contact
Questions about privacy? Email [email protected]. For the implementation details behind the app telemetry, see the project's docs/analytics.md.