Privacy Policy
Last updated: August 17, 2026
Who we are
Orbit is a product of Anyra, Inc.(“we”, “us”) — an AI-assisted outreach CRM that helps businesses research companies, find relevant professional contacts, and prepare outreach messages.
We are the data controller for your account and billing information. For the research and contact data inside your workspace, you are the controller and we act as your processor: you decide who is researched and what is sent, and we process that data on your instructions.
Data we process about you
Account data (name, email, password hash), the workspace content you create, usage and billing records (AI usage, credits, subscription state), and technical logs needed to operate and secure the service.
Data processed about third parties
Orbit holds business information about companies and the professionals who work at them — names, job titles, employer, and business contact details — together with why they may be relevant to what you sell.
We process this on the basis of legitimate interest in business-to-business communication, and we apply data minimization: we keep only what a business needs in order to make contact. We do not knowingly collect special-category data, and Orbit is not intended for consumer marketing.
Any person has the right to object to this processing. Where an objection is received, we stop processing and erase the record unless we are legally required to keep it.
Additional contact detail
A workspace user can ask Orbit to look for further contact detail for a single named person. It is always a deliberate, one-person-at-a-time action and never runs on its own.
What that returns can include personal as well as work contact details — a personal email address or mobile number alongside a work email — along with role and employment history, education, and the person’s general location at city, state and country level. We keep only what is useful for making business contact. Date of birth, sex and street addresses are the kind of detail we refuse to store at all.
The right to object applies here exactly as it does elsewhere. When a person objects or asks to be erased, this record goes with the rest of their data.
Automated processing
Orbit uses automated systems to prepare research and draft messages. Where any part of that runs with a provider under contract, it is processed only to return a result to us, nothing is retained beyond what is needed to do that, and your data is never used to train anyone else’s models.
Rights of the people in your workspace
Any person whose data is stored in Orbit may request access, correction, or deletion. Workspace users can permanently erase a person’s entire record — including generated messages, activity history, any additional contact detail and the research snapshots that mentioned them — with the built-in “Erase permanently” action.
Requests sent to us directly are honored without undue delay and within 30 days. Because the data sits inside a customer’s workspace, we may need to contact that customer to complete the request, and we will confirm to you when it is done.
Your rights as a user
You can permanently delete your account — your login, your workspace, and everything inside it — from Settings → Account at any time. Deletion is immediate and irreversible.
You can export your companies, contacts and messages as CSV from each campaign at any time. For a copy of anything not covered by those exports, or for any other access or correction request, write to us at and we will respond within 30 days. If you are in the EU or UK and are unhappy with our response, you may complain to your local supervisory authority.
Sub-processors
We rely on a small number of vetted providers to run Orbit. They fall into these categories:
- Cloud hosting, database and authentication infrastructure
- Automated processing used for research and drafting
- Business data providers
- Payment processing — card details never touch our servers
- Delivery of account email such as sign-up and password reset
- Single sign-on, if you choose to sign in with an existing account
Each is bound by contract to process data only on our instructions and never for their own purposes. They process data in the United States and other countries; transfers out of the EU and UK rely on Standard Contractual Clauses and, where applicable, Data Privacy Framework certification.
Business customers who need the current named list for their own compliance records can request it at .
How long we keep things
- Deleted items — projects, campaigns, companies, contacts and templates you delete are purged permanently 30 days later.
- AI usage records — kept 24 months, then removed. The credit entries they support remain, since they determine your balance.
- Message history — the ten most recent versions per contact.
- Working data behind a run — cleared 30 days after the run finishes.
- Additional contact detail— kept for as long as the contact it belongs to. It has no separate expiry: deleting the contact removes it 30 days later with the rest of that record, and “Erase permanently” removes it at once.
- Credit ledger and activity history — kept for as long as the account exists, because they underpin your balance and your pipeline reporting.
- Everything — removed immediately when you delete your account.
Security
Access is isolated per workspace with database-level row security. Secrets are held server-side only and are never exposed to the browser. Passwords are hashed, never stored in readable form, and checked against known-breached password lists at sign-up. Backups and point-in-time recovery protect against data loss.
Cookies
Orbit sets only the cookies required to keep you signed in. We do not use advertising cookies or cross-site tracking.
Changes
If we change this policy materially we will update the date above and notify account holders by email before the change takes effect.
Contact
For privacy requests about data held in a customer’s workspace, contact that workspace owner where you can, or reach us directly at .