Privacy Policy

Last updated: August 8, 2026

Effective: August 8, 2026 for anyone who applies on or after that date. If you already had an Orbt account, or had already submitted an application, on August 8, 2026, this policy takes effect for you on September 7, 2026 — 30 days after publication.

---

1. Who we are and what this policy covers

In short: Orbt Social Inc runs Orbt. This policy covers our website, our apps, the meetups we organize and the emails and notifications we send. We are a US service, currently live in Boston only.

Orbt is run by Orbt Social Inc, a Massachusetts corporation.

Detail
CompanyOrbt Social Inc
Address484 2nd Street, 6089, Everett, MA 02149, United States
Emailhello@orbt.social
Privacy requestshello@orbt.social — subject line Privacy Request, and tell us in the first line which right you are exercising

> One address, and it is monitored. hello@orbt.social is the only address we ask you to write to and the only one we publish. We do not run separate legal, privacy, DMCA or arbitration addresses, and we would rather tell you that than publish an address that bounces. (Our application and approval emails are sent from a company address rather than from hello@, and a reply to one of those reaches us too — but hello@ is the route we support and the one every deadline in this policy is measured from.) Use the subject lines given in each section and we will route it internally. You can also write to us at Orbt Social Inc, 484 2nd Street, 6089, Everett, MA 02149.

In this policy, "Orbt," "we," "us" and "our" mean Orbt Social Inc. "You" means the person using our services.

What Orbt does. You apply on our website. A person at Orbt reads your application and decides whether to approve it. If you are approved, you download our iOS or Android app, and we put you in a group of four — you and three other people — for a real-world meetup at a public venue: coffee, brunch, drinks or dinner. There is a group chat in the app so you can sort out the details.

> Approval is a fit decision, not a safety check. The person reading your application is deciding whether Orbt is a good fit for you, based only on what you told us. It is not a background check, not a criminal-records search, not an identity check, and not a judgment about whether any member is safe to meet. Section 6.1 says the same thing, and our Terms say it at greater length. Do not treat someone's approval as a reason to lower your guard.

What this policy covers. Everything we do:

Where we operate. Orbt is currently live in Boston only, and only in the United States. Our servers are in the United States. If you are outside the US, see section 13.

What this policy does not cover. It does not cover what a restaurant, café or bar does with information you give them directly, and it does not cover what the other people in your group do with things you tell them at the table. It does not cover other websites we link to.

---

2. The short version

In short: This is a plain-English summary of what follows. It is accurate, but it is short — where you need the detail, the numbered sections govern.

---

3. What we collect

3.1 What you give us when you apply

In short: This is the biggest single collection we do. Here is the complete list, exactly as the form asks for it.

Required — you cannot submit without these:

FieldWhat it is
First name
Email addressWe use it to contact you about your application and your meetups
Phone numberSee the note below this table
CityCurrently Boston only; if you pick "Other" we record the text you type so we know where to open next
Date of birthThe full date, not an age band. We use it to enforce our 18+ rule and, in a limited way, for matching
A photo of youRead by our review team, shown to the people you are matched with, and used as your picture in group chat
GenderMale, Female or Non-Binary
Agreement to our Terms and this Privacy PolicyWe record the exact time you ticked the box and which version of the documents you agreed to

About your phone number. We store it with your account and we write it to your sign-in record. Orbt does not send text messages — there is no SMS in the product, and we will tell you here before that ever changes. We use the number to reach you about a meetup if email fails, and for account recovery. We never give it to a venue, and we never show it to another member on any screen — but read the profile-response warning in section 5.1, because it is currently in a response a signed-in member can obtain.

Optional — you can skip all of these, and your application is still reviewed:

FieldWhat it is
Last nameLeave it blank if you would rather we did not have it — see section 5.1
NationalityA country, from a list. We ask for it after the matching questions — if you take the early-exit option before them, we never ask, and your application is reviewed anyway
"What kind of people would you love to meet?"Free text, 10–280 characters. You can skip this along with the matching questions
Instagram handleIf you give one, the people you are matched with can see it
Languages you speak
Job title, career field, alma mater
BioUp to 200 characters
"Why you're here"Preset tags, plus any tag you type yourself
Neighborhoods you'd travel to, cuisines you love, when you're usually free
Dietary informationYour general diet (for example omnivore, vegetarian, vegan, pescatarian, halal, kosher), restrictions (for example gluten-free, dairy-free, nut allergy, shellfish allergy), and a free-text box for anything else. See section 3.4

The matching questions. These are grouped into social intent (what kind of outing you want, how often, group size, whether you want to see the same people again), matching preferences (whether you would rather be matched with people of a similar or different age, career, interests, energy, life stage or cultural background), personality (how you warm up to people, talk style, humor, energy, planning style, how you handle disagreement, how quickly you open up), and life context (your life stage, relationship status, how long you have lived in your city, and your living situation).

You can skip the whole quiz, and here is exactly where the button is. On the "Add matching preferences?" step, the left-hand button exits without the matching questions and submits your application straight away. In a city where you can book a meetup — which today means Boston — that button reads "Find my people"; everywhere else it reads "Skip for now." Either one submits immediately. The other button, "Add matching," takes you into the questions. If you skip, we still review your application; we just have less to match on.

If you do start the matching questions, three of them cannot be left blank — see section 3.4, rule 1. The relationship-status question has a "Prefer not to say" answer; choosing it tells us nothing about you.

What the form sends that you do not type. Your country (currently always "US"), whether the city you picked is one we have launched in, a referral code if you arrived through someone's link, and the timestamps for your Terms and Privacy consent.

3.2 What you give us when you book a meetup

If you apply in a city we have opened, we also ask:

This is a record of where you plan to be, and when. We treat it accordingly: it is not shown to anyone outside the group you are matched into, and it is not shared with any advertiser or data broker, because we do not have any.

3.3 What you give us in the app

Once you are approved and signed in:

3.4 Sensitive information — and how we handle it

In short: Some of what we collect is treated as sensitive by US state privacy laws. Here is what it is, what we do with it, and the one place it goes that you might not expect.

What we collectWhy it is sensitive
Dietary answers such as halal, kosherCan reveal religious belief
Nut allergy, shellfish allergy, gluten-free, dairy-free, and the free-text diet boxHealth information
Nationality and the languages you speakCan reveal national or ethnic origin, citizenship
The "cultural background" matching questionA preference about ethnic or cultural similarity
Relationship statusMarital and family status
Living situation ("I live alone")Personal safety
Your photoAn image of your face
Your full date of birthAge
The contents of your group chatWe are not the intended recipient of what you write to your group, but it is stored for us and we can read it

Our rules for this information:

  1. Most of it is optional, and here is exactly which parts are not. A photo, your gender and your date of birth are required — we cannot review an application without them. Your nationality is required only if you go through the matching questions; take the early exit before them and we never ask for it. Three answers are all-or-nothing rather than field-by-field: once you start the matching questions, the cultural-background question, your relationship status and your living situation each have to be answered before the form will move on. Relationship status has a "Prefer not to say" option; living situation and cultural background do not. Your only way to withhold all three is to take the early exit before the matching questions, which skips the whole set. Everything else in the table above you can genuinely leave blank — your last name, diet, bio, interests, languages, job, career field, alma mater and Instagram — and your application is still reviewed; we just have less to match on.
  2. We use it for a narrow set of purposes: checking you are 18 or over, deciding whether to approve your application, forming groups, and choosing a venue that can accommodate the group. One exception you should know about: a profile summary that includes your dietary preference, your nationality, your languages, your relationship status and your living situation is currently sent to our AI provider, which writes the short "what you have in common" text your group sees. Section 6.2 lists the whole payload — please read it. We instruct the model not to mention religion, health, politics, income or relationship status, and we are cutting that payload back to what the summaries actually need. Until we have, treat those answers as things the summary could touch on.
  3. We do not use it to advertise to you, we do not sell it, and we do not give it to anyone for their own purposes.
  4. We do not try to work out your religion, health, sexual orientation or politics from what you tell us, and we do not ask about sexual orientation or political opinion at all. Some answers — a halal or kosher diet, an allergy — can reveal those things by their nature. We treat them as sensitive and use them only as described above.
  5. You can withdraw it. Email hello@orbt.social with "Remove optional fields" in the subject and tell us which optional fields to remove, including all of your dietary information, and we will remove them from your profile and from our matching data without closing your account. We do this by hand today, so allow us up to 30 days. Summaries that were already written and shown to a past group are not rewritten — but the underlying answer is removed and is not used again.

Please do not put sensitive information in free-text boxes. The bio, the "who you'd love to meet" box, the "other" diet box and group chat are open text. Whatever you type there is stored as you typed it. The "who you'd love to meet" box is the one people over-share in most — you can skip it entirely. Do not put medical details, financial details, your home address or anyone else's personal information in any of them.

3.5 What we collect automatically

In short: Read this section. It is the part of our data handling that is furthest from where we want it to be, and we would rather you knew exactly what happens.

What we store in your browser.

We show a cookie banner the first time you visit. Accept and Decline are given equal weight, and no analytics identifier and no advertising technology is stored on your device until you choose.

Separately from analytics, the site stores a few things in your browser so it works at all. These are not analytics and they are not shared with anyone:

What we storeWhereWhat it holdsWhen it goes away
Your cookie choiceLocal storageWhether you accepted or declinedWhen you clear site data for orbt.social
A referral codeSession storageThe code from the link you arrived on, stored as soon as you land so the referral is still credited when you finish applyingWhen you close the tab
Your application detailsLocal storageYour first name, email address and city, so that when you come back the site shows you your status instead of the application form againWhen you clear site data
Your membership flagLocal storageYour first name and city, written once we have confirmed your application was approved, so the site greets you instead of showing the application form. It replaces the row aboveWhen you clear site data, or when you use "change city" on the home page
Your application confirmationSession storageYour first name, email address, application ID, city, and the web address of the photo you uploaded, so the confirmation page can show you what you bookedWhen you close the tab

> If you are on a shared or public computer, clear your site data for orbt.social before you walk away. Your email address and a link to your photo are in your browser's storage until you do.

Analytics.

Bot protection. On our RSVP and invite pages we use Cloudflare Turnstile to check you are not a bot. Cloudflare receives your IP address as part of that check.

Server logs. Our website runs on Vercel and our backend runs on Amazon Web Services. Both keep request logs. Those logs contain IP addresses, timestamps, the page or endpoint requested, and browser information — and, in some places, your email address and the web address of your profile photo, because our own code writes them there while handling your request. We use logs for security, debugging and abuse prevention. They are not used for analytics or marketing and they are not shared. We are removing the photo address from those log lines.

In the app. The app talks to our AWS backend, and those requests are logged the same way. We do not run session replay in the app.

In our emails. Our emails are HTML, and each one also carries a plain-text version for mail apps that prefer it. Most of what we send is transactional — a direct answer to something you did (we have your application; you have been approved; your booking is live). We have also invited a small number of people we met through events we hosted or helped host, using the email address they gave us at that event. Our emails contain an invisible tracking image, so we can tell whether and when you opened one, and the links inside them are rewritten through our email provider, so we can tell which of those links you clicked and when. We use that only to know whether our email is reaching people and whether it is useful to them.

Two different systems send that mail, and you should know which is which. Our application, approval and booking emails go out through Postmark. Separately, when we create your sign-in account, Amazon Cognito sends you an invitation email containing a temporary password; that one comes from Amazon, not from Postmark or from our own sending code. Postmark records that a message was sent, delivered, bounced or was marked as spam, that it was opened, and that a link inside it was clicked. Cognito records delivery and bounce events. We use all of that only to know whether our email is reaching people. Our transactional email carries no unsubscribe link; section 9 explains what that means and what you can still stop.

3.6 What we collect from your device, with your permission

PermissionWhat we do with it
Camera / photo librarySo you can upload or change your profile photo. We only access what you choose. On our website, your photo is resized and re-encoded in your browser before it is uploaded, which removes EXIF metadata including any GPS coordinates and the original timestamp. In our apps we are adding the same step and it is not finished — until it is, if that matters to you, upload a photo you did not take at home, or turn off location tagging in your camera settings first
Push notificationsIf you allow them, we store a device token so we can send you notifications about your group, your booking and your matches. Push tokens go to Google Firebase Cloud Messaging on both iOS and Android. You can turn notifications off in your device settings at any time

We do not collect precise device location. We do not ask for GPS access and we do not track where you are. The only location information we hold is the city and neighborhood you tell us, an approximate location that analytics providers derive from your IP address, and — on the app upload path until the fix above lands — any location data embedded in a photo file you choose to upload.

3.7 What we collect from other people, and what other people can see through us

3.8 What we do not collect

To be explicit, because our previous policy got some of this wrong:

---

4. How we use your information

In short: To review your application, form groups, run the meetup, keep people safe, talk to you, and make the product better. Nothing else.

PurposeWhat we use
Deciding whether to approve youYour whole application. A person reads it. This is a fit decision, not a background check or an identity check — see section 1 and section 6.1
Checking you are 18+The date of birth you give us
Forming groupsYour activity, week and neighborhood choices, and the matching answers listed in section 6.1
Running the meetupYour booking, and a first name and party size for the venue
Choosing a venueDietary requirements, so we can pick somewhere with suitable options. We do not communicate your allergy to venue staff on your behalf — see section 5.2
Group chatYour member ID, display name and profile photo
Safety and moderationReports, feedback, blocks, booking records, account records — and, where a report or a safety concern requires it, the contents of the relevant group chat
ReliabilityYour booking and cancellation record, to enforce the show-up-or-cancel rule in our Terms
ReferralsThe referral code you arrived with and the link between your account and your referrer's
Talking to youEmail and push notifications about your application, your approval, your booking, your group and your meetup
PaymentsNothing today. When we start charging, we will use your email and subscription record. See section 4.1
Making the product betterAnalytics, in the form described in 3.5
Security and abuse preventionLogs, IP addresses, the honeypot field on our forms, and the bot check on our RSVP form — see section 8 for what we do not have
LegalComplying with the law, responding to lawful requests, and establishing or defending legal claims

We do not use your information to make decisions about credit, employment, housing, insurance, or anything else with a legal or similarly significant effect on you.

4.1 Payments — what's true today

Orbt is free right now. We are not charging anyone, and we hold no payment details.

Our website says a paid membership is planned, and the checkout for it is built and switched off — it does not appear, and nothing can be charged while it is off. If and when we switch it on:

---

5. How we share your information

5.1 With other Orbt members

In short: This is the part worth reading twice, because it is the sharing that actually matters — and two things in it are not yet what we want them to be.

Some of your profile is visible to the three people we match you with, and — where the app offers a profile view — to other approved Orbt members. We do not publish a member directory and we do not show your profile to anyone who is not an approved member. Treat what follows as visible to the membership rather than only to your table.

What we intend them to see, and what the app is built to show:

> About your name — please read this. We want other members to see only your first name and last initial ("Alex K."). That is not what happens today for members who applied through our website: the account we create for you in group chat is registered with the full name you gave on the application, so your first and last name is what appears there. We are changing this and will backfill existing chat accounts. Until we have: if you would rather the people you meet did not see your surname, leave the last-name field blank when you apply — it is optional — or email hello@orbt.social with "Remove optional fields" in the subject and we will remove it.

> The profile our app hands out is wider than the list above — please read this. The profile endpoint our app calls currently returns your whole profile record to any signed-in Orbt member who requests it — including your email address, your phone number, your date of birth, your dietary information, your relationship status, your living situation, and how long you have lived in your city. Those fields are not laid out on any screen we designed, but they are in the response, and a member who looked could obtain them. We are cutting that response back to the fields listed above, and we will update this paragraph when we have. Until then, treat everything on your profile as something another approved member can get hold of.

What no member can see, on any surface:

What they may see that you might not expect. The "what you have in common" summary is written by an AI model that currently receives your dietary preference and your life-context answers, including your relationship status and living situation. We instruct the model not to mention religion, health, politics, income or relationship status, and we are cutting those fields out of what we send it — but an instruction to a model is not the same as not sending the data. Until that change ships, treat your dietary and life-context answers as things the summary could touch on. Section 6.2 lists exactly what is sent.

One thing to know about links. Some Orbt pages work without signing in, so that people who do not yet have an account can use them. Anyone who has the exact link to your profile photo, or to an invite you created, can open it — see sections 3.7 and 8.

Blocking — and what it does not do. When you block someone, we ask our chat provider to stop that member being able to message you.

> A block stops messages. It does not stop you being put in the same group as someone. Our matching system does not read block lists today, so blocking on its own will not keep the two of you off the same table, and neither an automatically formed group nor a group put together by hand is checked against block lists. If you do not want to be matched with someone again, email hello@orbt.social with "Do Not Match" in the subject and a person will exclude them by hand. We are building the automatic exclusion and we will update this paragraph when it is live.

Blocking also works inside Orbt only. It cannot reach anything that has already left our app — if you shared your Instagram handle, your phone number or any other contact detail with your group, in the app or at the table, blocking will not stop that person contacting you there. If someone is contacting you off Orbt, block them on that platform, and if you feel unsafe contact local law enforcement. Report it to us as well at hello@orbt.social. If you are placed in a group with someone you blocked, leave and tell us — you should not have to sit through it.

Deleted accounts. If you delete your account, you disappear from your group's member list. Your name can still appear in records written before you left, and nothing renames it automatically — we remove it by hand when you ask (email us with "Delete Everything" in the subject). Summaries that were already written and shown to your group are not rewritten.

5.2 With venues

We book a table at a public venue — a café, a bar, a restaurant. Venues are not our service providers. They are independent businesses, and what they do with what we tell them is governed by their own policies, not this one.

What a venue gets: a first name for the reservation, the party size, and the date and time.

What a venue does not get: your last name, email address, phone number, date of birth, photo, profile or matching answers.

> We do not routinely pass your allergies or dietary requirements to venue staff, and you should not rely on us to do so. If you have a food allergy or any other dietary requirement that matters to your safety, tell the venue staff yourself when you arrive and before you order. We collect dietary information so we can choose a venue with suitable options — not to manage your allergy for you. Our Terms say the same thing.

Once you are at the venue, anything you tell the staff directly — a card at the till, a loyalty number, your own conversation about what you can eat — is between you and them. Orbt does not control that, and this policy does not cover it.

5.3 With our service providers

These are the companies that run pieces of Orbt for us.

ProviderWhat they receiveWhat they do with itWhere
Amazon Web ServicesEverything: your application record, your profile, your photo, your sign-in account, our logsHosting, database, file storage, sign-in (Cognito)United States (us-east-1)
VercelOur website and admin dashboard; your application passes through when you submit it; request logs including IP address, and in places your email addressWebsite hostingUnited States
PostHogWebsite usage events, page addresses, approximate location from IP — before and after you accept cookies — and, after you accept, a browser ID and a masked session replayProduct analyticsUnited States
Google AnalyticsPage views, device and browser, approximate location from IP, GA cookies. Only after you accept cookiesTraffic measurementGoogle (US and global)
PostmarkYour name and email address; the contents of the emails we send you; delivery, bounce, spam-complaint, open and link-click events. The internal notification we send ourselves when you apply goes through the same pipe, and it contains your name, email address, phone number, date of birth, a link to your photo, and your bio, interests and dietary answersSending our emailUnited States
Amazon CognitoYour email address and the temporary password it generatesRunning sign-in, and sending the invitation email when we create your accountUnited States
CometChatYour member ID, display name, profile photo URL, group name, and the contents of your group chat messagesIn-app group chatUnited States
Anthropic's Claude — reached either through Anthropic's own API or through Amazon Bedrock, Amazon's hosted version of the same modelProfile details for you and the people you are matched with — see section 6.2 for the exact listWriting your group's "what you have in common" summary and pairwise blendsUnited States
Google Firebase Cloud MessagingYour device push token and the content of the notificationDelivering push notifications on iOS and AndroidGoogle
CloudflareYour IP address and a bot-check token, on invite and RSVP pagesBot protectionGlobal
Our company mailbox providerAny email you send us, including a privacy request, a deletion request or a report, and our reply to itReceiving and answering your mailUnited States
Google FormsWhatever you type into the contact form linked in our website footerOur contact formGoogle
StripeNothing today. In future: your email address, your card details (which go to Stripe, never to us), your application ID and the identifiers of the meetups you booked, and your subscription recordPayments, once we start chargingUnited States
Apple / Google PlayIn future: purchase and subscription recordsIn-app purchases, once we start chargingApple / Google

We choose providers who commit to protecting your information. We do not authorise any provider in this table to sell your information, to use it for their own advertising, or to combine it with information they hold about you from anywhere else. To be straight with you about the paperwork: a signed written data processing agreement is not yet in place with every provider listed here, and putting that right is work in progress. We are also reducing what goes into the internal application email so that it carries a link to the application rather than a copy of it.

5.4 For safety, legal and law-enforcement reasons

We will share information outside the list above when we honestly believe it is necessary to:

We review these requests. We push back on ones that look overbroad or unlawful. Where we are legally allowed to tell you about a request for your information, we will try to.

5.5 If the business changes hands

If Orbt is acquired, merges, raises money in a way that requires disclosure, or sells part of the business, your information may transfer as part of that. If it does, we will tell you, and the buyer will be bound by this policy until they give you notice of a different one.

5.6 What we don't do

We do not sell your personal information for money or for anything else of value.

We do not run advertising. There are no ads on our website or in our app, no ad networks, no advertising pixels, no retargeting, and no ad-tech SDKs in the app.

We do not use your information for cross-context behavioral advertising, and we do not give it to anyone else to use that way. We use Google Analytics to measure traffic. Depending on how that product is configured, some state laws can treat the use of it as "sharing" for cross-context behavioral advertising. If you would rather that did not happen at all, decline cookies — Google Analytics is then never loaded — or email us with "Privacy Request" in the subject and we will make sure it does not.

---

6. Matching, AI and automated processing

6.1 How matching actually works

In short: A person decides whether you are approved. Software forms the groups, and a person can adjust them.

Approval is a human decision. Someone at Orbt reads your application and decides. It is not automated.

Group formation is partly automated. Our software puts you in a pool with the people who chose the same activity, the same time window and the same neighborhood, then scores candidate groups of four and picks the strongest. What it actually reads about you is: the activity, time of day, neighborhood and days you selected; the kind of outing you said you want, your social energy and your interests across music, books, film, arts, hobbies and sport; and your conversation style, your sense of humor, your life stage, how long you have lived in the city, your career field, and your age, calculated from your date of birth. The week you asked for, the city on your booking and the availability on your profile are stored but are not read by the matching system today. A person can and does adjust groups.

What our matching system does not use. We do not use race, ethnicity, national origin, religion, disability, sex, gender identity or sexual orientation to decide who is in a group or who is left out of one. We also want to be precise about one question we ask: the apply form asks whether you would rather be matched with people from a similar or different cultural background, and our matching system does not read that answer at all — it sits on your application record and nothing scores it. Your nationality, your languages, your dietary practice, your relationship status, your gender and your school are not matching inputs either. Your age is an input, as set out above — where you have asked to be matched with people of a similar or different age we use it to balance the mix of a group, and it is never used to exclude anyone from Orbt or from a meetup. Not being a matching input is not the same as not leaving your device: several of these answers are still sent to our AI provider when it writes your group's summary, and section 6.2 lists exactly which.

Approval is not a background check. It is a judgment about fit, based on what you told us. It is not a criminal-records search, not an identity verification, and not an assessment of whether anyone is safe to meet. Our Terms say the same thing, at greater length.

6.2 What AI we use, and what it receives

Our AI provider is Anthropic, and the model is Claude. The request is served in the United States, either through Anthropic's own API or through Amazon Bedrock — Amazon's hosted version of the same model, which keeps the request inside our existing cloud provider. We do not use OpenAI.

Claude is used for two things:

  1. Your group's "what you have in common" summary — a short piece of text shown to everyone in a group before they meet.
  2. Pairwise "blends" — a compatibility summary between two members, shown to those two members.

What Claude receives about you. One limited profile per person, used for both the group summary and pairwise blends. Today it contains: your first name; the account identifier we hold for you; your bio; your interests and favorites; your languages; your city; your job title and career field; your school; your life stage; your gender; your nationality; your dietary preference; your relationship status; your living situation; how long you have lived in your city; the availability you gave us; and your full set of personality, matching-preference and social-preference answers, including free-text items such as your quirks, values and current curiosity.

What Claude does not receive: your surname, your email address, your phone number, your date of birth, your address, payment information, or anything you wrote in a report or in post-meetup feedback.

We instruct the model not to mention religion, politics, income, weight or relationship status in what it writes. That is an instruction to a model, not a data boundary. We are cutting the payload back to what the summaries actually need — when that ships we will update this list and section 5.1.

Your choice. Today this processing applies to every approved member, and there is a permission flag in our system that governs it which is set on for you at approval and which we have never shown you. That is not a real choice and we are not going to pretend it is. We are adding a control in the app's settings so you can turn this off, and we will update this section when it is live. In the meantime, email hello@orbt.social with "No AI summaries" in the subject and we will exclude you by hand — you will be left out of the "what you have in common" summary and out of pairwise blends, and nothing else about your account changes. Be straight with us about the timing: honouring that request is a manual step a person takes before your next group is formed, not something the system enforces, so tell us before you are matched.

6.3 No automated decisions with legal effects

We do not use automated processing to make decisions that produce legal effects for you or affect you in a similarly significant way. Nobody is approved, rejected, suspended or removed by an algorithm alone — a person makes those calls. If you think a decision about your account was wrong, email us: a person will look at it again, tell you what information we used, and correct anything that was wrong.

---

7. How long we keep your information

In short: We keep information for as long as we need it for the purpose we collected it for. We are being straight with you about where we are: scheduled, automatic deletion is not running yet.

Where we actually are. We do not yet run scheduled deletion jobs across our systems. Rather than publish a retention schedule we do not honour, here is the honest position:

CategoryTarget
Application from someone we didn't approve (declined, or never finished)12 months from the decision, then deleted — including the photo. We keep a minimal record that the email address applied, so the same application is not reviewed twice and so someone we removed cannot reapply
Application from someone we approvedFor as long as you have an account, plus 12 months
Profile, matching answers, dietary information, photoFor as long as you have an account. Removed when you delete your account — see section 10
Your matching and personality answers held separately for our matching systemFor as long as you have an account
Booking and meetup requests24 months after the week they were for
Group records and the "what you have in common" summary24 months after the meetup
Post-meetup feedback and notes about other members24 months, unless part of a safety report
Safety reports, blocks and enforcement records3 years after the account closes, and longer where we reasonably need it to keep someone off the platform or to comply with the law
Group chat messages held by our chat providerFor the life of the group. Target: removed automatically when you delete your Orbt account — today we remove the chat account and its messages by hand when you ask
Referral records linking the person who invited you to your accountCurrently kept indefinitely. Target: 24 months after the referral is claimed, then reduced to a link between two member IDs with no other details
Records of privacy and deletion requests, including the email address that made them24 months — we are required to keep a record of what we were asked and what we did
Email records, including delivery and click events24 months
Device push tokensUntil you turn notifications off, uninstall the app, or delete your account
PostHog analytics events12 months; session replays 30 days
Google Analytics14 months
Server and application logsBetween 1 and 6 months, depending on the system
Records we need for tax, accounting or legal reasonsAs long as the law requires — generally up to 7 years for financial records, once we start charging

When we pause deletion. If we know of, or reasonably anticipate, a legal claim, an investigation, a regulatory request, a safety report or a law-enforcement preservation request, we will suspend the deletion of information relevant to it for as long as we reasonably need to preserve it, and delete it when the matter is resolved. This is the one circumstance in which the periods above may be extended.

Backups. We are not going to publish a backup retention window we have not verified. We do not operate a database backup or point-in-time-recovery configuration that we can describe to you here today, and putting one in place — with a stated window — is work in progress. Where any snapshot held by our cloud provider does contain a copy of deleted information, it is not used for anything and it is not readable by the product. Files such as photos are not backups — they are live objects that have to be deleted directly, and section 10 explains where we are on that.

---

8. How we protect your information

In short: Here is what we actually do, and where the gaps are.

What we do:

Written information security program. Massachusetts regulation 201 CMR 17.00 requires a written information security program from anyone holding a Massachusetts resident's name together with a Social Security number, driver's licence number, or a financial account or card number. We do not hold any of those, so the regulation does not currently apply to us — and to be plain about it, we do not have a written information security program today. We will put one in place before we ever collect any of that information, and we will say here when it exists. We are not going to claim a program we have not written.

Breach notification. If personal information about you is breached in a way that requires notification, we will notify you and the regulators required by the law of the state you live in — for Massachusetts residents, the Attorney General and the Office of Consumer Affairs and Business Regulation — as soon as practicable and without unreasonable delay, and we will not delay notice because our investigation is not finished. We will not condition any notice on you giving up any right.

> About your profile photo — read this.

>

> Your photo is stored in Amazon S3 at a randomly generated address and served directly from Amazon S3 — there is no content delivery network in front of it. We do not link to it publicly and we do not publish an index of it. But it is not password-protected, and the address does not expire: anyone who has the exact address can open it, and browsers and networks in between are told they may keep a cached copy for up to a year. That is a deliberate design choice — the same address is what makes your photo appear as your avatar in group chat and on your profile.

>

> The address also appears in our own server logs, in the internal notification email our review team receives, and in your browser's storage after you apply.

>

> Deleting your account does not remove the stored photo file. Our deletion routine does not reach into file storage yet. Until it does, email hello@orbt.social with "Delete Everything" in the subject, saying it is the photo file you want removed, and we will delete it by hand and confirm we have.

>

> What that means for you: treat your profile photo as something the people you meet will be able to keep a copy of. Do not upload a photo you would be unhappy for someone to have permanently. We are moving profile photos onto signed, expiring addresses so that this is no longer true.

THE HONEST CAVEAT: NO SYSTEM IS COMPLETELY SECURE. WE WORK HARD TO PROTECT YOUR INFORMATION, BUT WE CANNOT GUARANTEE THAT UNAUTHORIZED THIRD PARTIES WILL NEVER DEFEAT OUR SECURITY. YOU SEND US INFORMATION AT YOUR OWN RISK, AND YOU SHOULD ONLY ACCESS OUR SERVICES ON A NETWORK AND DEVICE YOU TRUST.

---

9. Your choices

In short: You do not need to make a formal legal request for most of this. Every email route below goes to hello@orbt.social.

What you wantHow to do it
Change or correct your profileIn the app, under your profile
Remove an optional field — including all your dietary informationEdit it in the app, or email us with "Remove optional fields" in the subject and tell us which ones. We do this by hand today, so allow us up to 30 days, and we will confirm when it is done
Stop your answers being used in AI summariesEmail us with "No AI summaries" in the subject. We are building an in-app control — see section 6.2
Change or withdraw your cookie choiceToday: clear your site data for orbt.social and the banner will ask again. We know that is not good enough — clearing site data also wipes the details that let the site recognise you — and there is no "Cookie settings" control on the site yet. We are adding one to the footer of every page so that switching your choice takes one click. If you would rather not wait, email us with "Cookie choice" in the subject and we will record your choice on our side. Declining stops Google Analytics from loading and turns off PostHog's browser storage and session replay; see section 3.5 for what is still sent
Stop emails from usWe do not send marketing campaigns or newsletters. Almost everything we send is about your application, your account, your booking or your group; it is transactional, and it carries no unsubscribe link — while you have an account you cannot opt out of the messages that are necessary to run your membership, because they are how the service works. The exception is an invitation to join Orbt, which we have sent to a small number of people we met through events; if you received one and would rather not hear from us, reply with "Unsubscribe" and we will stop. You can still email us with "Unsubscribe" in the subject and we will stop anything that is not necessary to operate your membership. If we ever start sending anything promotional, it will go on a separate stream with a working unsubscribe link. To stop all email, delete your account
Stop push notificationsTurn them off in your device settings, or in the app's notification settings
Ask not to be matched with a particular memberEmail us with "Do Not Match" in the subject. Blocking someone does not do this today — see section 5.1
Skip the matching questionsOn the "Add matching preferences?" step, choose the left-hand button — labelled "Find my people" if you booked a meetup, "Skip for now" if you did not. Either one submits your application without the questions. Do not choose "Add matching"
Ask a human to look at a decision againEmail us with "Review my decision" in the subject
Delete your accountSee section 10

---

10. Deleting your account and your data

In short: You can delete at any time. Here is exactly what the automatic routine removes today, what it does not yet reach, and how to get the rest removed.

How to do it:

  1. In the app — log in, go to Settings, choose Delete Account, and confirm. You will be asked to re-authenticate, because we do not want anyone else deleting your account.
  2. By email — write to hello@orbt.social from the address on your account with "Delete Everything" in the subject. If you applied but were never approved — so you never had an account to log in to — write from the address you applied with and use "Delete My Application" instead. Either way, we will email you back to confirm the request and will not delete anything until you confirm it from that address, because an email address on its own is not proof of identity and we will not delete someone else's data on a stranger's say-so.

orbt.social/delete-account carries a short summary of the in-app route. Where that page and this section differ, this section governs — we are rewriting the page to match it.

How long it takes. We aim to complete deletion within 30 days of verifying your request, and we will always complete it within the 45 days set out in section 11.6.

10.1 What deletion removes

Deleting your account today automatically removes:

Everything else that holds your information we remove by hand when you ask — see 10.3. It is the same deletion; it is just not yet automatic, and we would rather tell you which is which.

10.2 What we keep, and why

10.3 What we still remove by hand

We would rather tell you this than let you find out later. Our automatic deletion routine does not currently reach any of the following, and we remove each of them by hand when you ask:

Email hello@orbt.social with "Delete Everything" in the subject and we will do all of it by hand and confirm in writing exactly what was removed. We are building these into the automatic routine and this list will shrink as we do.

What we cannot reach at all. Copies held by our providers roll off on their own schedules — Postmark holds sent-email records, Amazon holds the Cognito invitation records, Google and PostHog hold analytics events, and any snapshot our cloud provider holds rolls off on its own cycle. And if someone in your group screenshotted your photo or wrote your number down, we cannot do anything about that.

---

11. US state privacy rights

Depending on where you live, state law gives you specific rights. We extend the core rights below to everyone in the United States, regardless of state, because maintaining two tiers is not worth it at our size.

11.1 Your rights

11.2 What we collect, by legal category

This table uses the categories from the California Consumer Privacy Act.

CategoryDo we collect it?What, specifically
A. IdentifiersYesName, email address, phone number, IP address, account and application IDs, device push token, Instagram handle
B. Personal information under Cal. Civ. Code §1798.80(e)YesName, phone number, date of birth, a photograph of you (physical description), and medical information in the limited form of the allergies and intolerances you tell us about. No Social Security number, licence or passport number, card number, bank account or insurance information
C. Protected classification characteristicsYesAge and date of birth, gender, nationality, citizenship and national origin, marital and relationship status. Dietary answers can reveal religious belief or a health condition; we treat those answers as sensitive information and use them only as described in 3.4 and 6.2
D. Commercial informationYesRecords of the meetups you booked. No purchase or payment history yet, because we do not charge
E. Biometric informationNoWe store a photo. We do not generate a faceprint, face-geometry scan or any biometric template from it, and we do not use it to establish identity
F. Internet or other electronic network activityYesPage views, in-app activity, application-funnel events, session replay with inputs masked (after consent), email delivery and click events
G. Geolocation dataYes — coarse onlyThe city and neighborhood you tell us, and an approximate location derived from your IP address by our analytics providers. No precise or GPS location. The one exception is location data embedded in a photo uploaded through our apps until the fix in 3.6 lands
H. Audio, electronic, visual or similar informationYesYour profile photo. No audio, no video, no voice recordings — we have no microphone or call feature
I. Professional or employment-related informationYes — optionalJob title, career field, and your life-stage answer. All optional, all self-reported
J. Education informationLimitedThe name of your school, if you choose to give it. We hold no records from any educational institution and nothing covered by FERPA
K. InferencesYesA matching and personality profile built from your quiz answers, plus AI-written summaries about you and the people you are matched with
L. Sensitive personal informationYesSee 11.4

Where each category comes from, why we have it and who we share it with is set out in sections 3, 4 and 5.

11.3 What we do with each category

We use every category above for the purposes in section 4, and we share them only as described in section 5. We have not sold personal information in the twelve months before the date at the top of this policy, and we have not shared it for cross-context behavioral advertising — subject to what section 5.6 says about how Google Analytics can be treated.

11.4 Sensitive personal information

The sensitive personal information we hold is:

We do not collect precise geolocation, genetic data, biometric data used to identify you, health records, financial account details, your sign-in credentials, or information about your sex life or sexual orientation.

What we do with it. We use it to review your application, to check your age, and to choose a venue that can accommodate the group. Your dietary preference, nationality, languages, relationship status and living situation are also currently included in the profile summary we send to Anthropic's Claude, which writes the text your group sees — see 3.4 and 6.2. As section 6.1 explains, our matching system does not use your nationality, your languages or your cultural-background answer to form groups. We do not sell any of it, we do not disclose it for anyone else's purposes, and we do not use it for advertising.

Your right to limit it. Because one of those uses goes beyond the narrow set of purposes state law treats as automatically permitted, you can tell us to stop. Email hello@orbt.social with "Limit sensitive information" in the subject and we will exclude your dietary, nationality and language answers from the summaries we send to Claude, and delete those answers on request. If you gave us a nationality, we will still hold it for as long as your application record exists, because it is part of that record — ask us to delete the record under section 10 and it goes with it.

Consent. Several states require your separate, specific consent before sensitive information is processed. Ticking the box that says you agree to our Terms and this Privacy Policy is not that consent, and we do not treat it as such. We are adding a separate, unticked control on the screens where we ask the dietary, nationality and cultural-background questions, so you can decline that use and still apply. Until it is live, use the "Limit sensitive information" route above — we will action it, and withdrawing does not close your account or change anything else about your membership.

11.5 Opt-out preference signals and Global Privacy Control

Some browsers and extensions send an automatic signal — most commonly Global Privacy Control (GPC) — telling websites you do not want your information sold or shared.

Our site does not read that signal yet. We are implementing support for it, and we will describe it here, in the present tense, when it is live. Until then, use the Decline button on our cookie banner — it is the control that works today, it is weighted the same as Accept, and declining stops Google Analytics from loading and keeps PostHog's browser storage and session replay off. Section 3.5 explains exactly what declining does and does not stop.

We do not respond to the older "Do Not Track" browser header, because no standard was ever agreed for what it means.

11.6 How to exercise your rights

How to reach us. Email hello@orbt.social with "Privacy Request" in the subject and tell us in the first line which right you are exercising — access, copy, correct, delete, limit sensitive information, or appeal. You can also write to us at Orbt Social Inc, Attn: Privacy, 484 2nd Street, 6089, Everett, MA 02149. For deletion you can also use the in-app route in section 10.

Verification. Before we act on a request about your information, we have to be reasonably sure it is you. We will normally do this by asking you to send the request from the email address on your account and confirming it through a one-time link, or by asking you to confirm details we already hold. For deletion in the app, we require re-authentication. We will not ask you for a government ID or any document we do not already hold. Anything you send us purely to verify your identity is used for that and nothing else, and we delete it from our mailbox once the request is closed.

Authorized agents. You can use an authorized agent. We will ask for written proof that you gave them permission, and we may still ask you to confirm the request directly.

Timing. We will acknowledge your request within 10 business days of receiving it and respond within 45 calendar days. If we need longer we will tell you before the 45 days are up, explain why, and take up to a further 45 days. There is no charge. We will not respond to more than two access requests from the same person in a 12-month period, and a request to know what we hold covers the 12 months before the request unless you ask for longer and we are able to provide it.

11.7 If we say no — appeals

If we refuse a request, we will tell you why in writing and tell you how to appeal.

To appeal, reply to our decision with "Appeal" in the subject line, or write to hello@orbt.social. We will review the decision afresh — where more than one person at Orbt is able to do so, someone who was not involved in the original decision will handle it. We will respond in writing within 45 days with our decision and the reasons for it.

If we deny your appeal, we will include in that response a current link for complaining to your state's Attorney General. You do not have to wait for us — you can complain at any time:

Each of those offices publishes a consumer complaint form on the site above. If your state is not listed, search for your Attorney General's consumer complaint form, or email us and we will send you the link.

11.8 California-specific

---

12. Age requirement and minors

Orbt is for adults. You must be 18 or over to apply, to have an account, or to attend a meetup.

We ask for your date of birth when you apply, and we check it twice — once in your browser, and again on our servers when the application arrives, so the check cannot be skipped by submitting directly to our systems. Applications from anyone under 18 are rejected.

> We do not verify your age. We do not ask for a driver's licence, a passport or any other document, and we do not use an age-estimation service. The date of birth you give us is the date of birth we rely on, so someone who gives us a false one can get through. Giving us a false date of birth breaks our Terms, and we remove the account when we find out.

We do not direct Orbt at children, and we do not knowingly collect information from anyone under 18. If we find out that someone under 18 has an account, we deactivate it and delete their information promptly. If you believe someone under 18 is using Orbt, tell us at hello@orbt.social and we will act.

California residents under 18. California law gives a registered user under 18 the right to ask us to remove content they posted. Since our service is 18+ this should not arise, but if it does: email us and we will remove or hide the content. Removal makes the content invisible to other users and to the public; it may not be complete or comprehensive, because copies may remain in backups, on another user's device, or where the law requires us to keep them. This right covers only content you posted yourself — not content someone else posted about you, and not reposts.

---

13. Where your information is held, and international users

Orbt is a United States service. Our servers, our databases and our staff are in the United States, and our service providers are almost all US-based. Everything you give us is stored and processed in the United States.

Orbt is currently available only in Boston, and it is built for people in the United States. We do not offer or advertise Orbt in the European Economic Area, the United Kingdom or Switzerland, we do not organize meetups there, and we do not open cities there. Our application form offers only the cities we have launched in, plus a free-text box for people who want to tell us where to open next. We do not block what you can type into that box, so an application naming a European city can reach us. We do not act on one — and if you would like us to delete it, email us with "Privacy Request" in the subject and we will.

Our website is reachable from anywhere, and if you visit it from outside the United States our analytics tools record that visit in the same way they record any other — see section 3.5 for exactly what they record and how to turn them off. If you are in the EEA, the UK or Switzerland and you would like us to delete anything we hold about your visit, email hello@orbt.social with "Privacy Request" in the subject and we will.

If you access Orbt from outside the United States, you are sending your information to the United States, where the privacy laws are different from — and in most respects less protective than — the laws where you live. If you are not comfortable with that, please do not use Orbt.

We have not set up the machinery — a European representative, Standard Contractual Clauses, a designated data protection officer — that European data protection law would require of a service aimed at Europe. We would rather say that plainly than claim compliance we cannot deliver. If we open a city outside the United States, we will put that machinery in place and update this policy before we do.

Canada. We are not live in Canada. If we open a Canadian city we will update this policy for PIPEDA and the applicable provincial laws before launch.

---

14. Changes to this policy

We will update this policy when what we do changes. When we do:

Changes take effect on the "Effective" date at the top of this policy. For this version that is August 8, 2026 if you apply on or after that date, and September 7, 2026 — thirty days' notice — if you already had an account or a submitted application on August 8, 2026. Using Orbt on or after the date that applies to you means the updated policy applies from then on. If you do not agree with a change, you can delete your account under section 10.

> Information we already hold. If a change would mean using information we already collected from you in a materially different way from what we told you when we collected it, we will ask you to agree first. We will not apply a new use to old information on the basis that you carried on using the service.

Which version applies. The version of this policy in force at the time of the event in question is the version that applies to that event. When you agreed to this policy we recorded the date, the time and the version number. We keep the versions we have superseded — if you want to know which one you agreed to, or to read it, email us with "Previous policy version" in the subject and we will send it.

A correction to an earlier version. The version of this policy dated July 3, 2025 named OpenAI as an AI provider. That was inaccurate. Our AI provider is Anthropic, as described in section 6.2.

---

15. How to contact us, and how to complain

Talk to us first — it is the fastest way to fix something.

Orbt Social Inc

484 2nd Street, 6089

Everett, MA 02149

United States

hello@orbt.social

We aim to respond to privacy questions within 10 business days, and to formal requests within the timelines in section 11.6.

If we have not resolved it, you can complain to a regulator:

This policy lives at orbt.social/policy.

---

16. This policy and our Terms

This Privacy Policy is part of, and is incorporated into, our Terms and Conditions at orbt.social/terms.

Any dispute, claim or controversy arising out of or relating to this policy, to our handling of your information, or to any statement in this policy — whether based in contract, tort, statute or any other theory — is governed by the Terms, including the Dispute Resolution section (informal resolution, individual arbitration, and the class, collective and representative action waiver) and the Limitation of Liability section, on the same terms and with the same exceptions and opt-out rights set out there.

You have 30 days to opt out of arbitration, and opting out does not affect your membership. The 30 days run from the date the Terms take effect for you: if you already had an Orbt account or a submitted application on August 8, 2026, your window closes on October 7, 2026; if you apply later, it closes 30 days after you accept.

To opt out, email hello@orbt.social with "Arbitration Opt-Out" in the subject line, or write to Orbt Social Inc, Attn: Arbitration Opt-Out, 484 2nd Street, 6089, Everett, MA 02149. Include the four things Section 13.5 of the Terms asks for: your full name; the email address and phone number on your Orbt account; your mailing address; and a clear statement that you do not wish to resolve disputes with Orbt through arbitration. There is no separate opt-out address and no form to fill in. We will confirm your opt-out in writing within 14 days — and if you do not hear from us, write again; your original opt-out still stands.

Nothing in this policy or in the Terms waives, limits or restricts any right or remedy you have under the Massachusetts Consumer Protection Act, M.G.L. c. 93A, or any other right that cannot lawfully be waived.

Where this policy and the Terms conflict on how we handle your information, this policy controls. On everything else, the Terms control.

---

Related documents