Orbit app icon
Orbit|@4XIOM_

Privacy

Privacy Promise

Last updated: August 9, 2026

Orbit is built around intentional context, not passive surveillance. Privacy is not a premium mode in Orbit. It is the default shape of the product.

Screen Recording

Orbit asks for Screen Recording permission so it can capture the visual state of your active display at the exact moment you activate it. The image is held in temporary memory for the active turn, used as context, and then discarded.

Orbit does not continuously record your screen. There is no background buffering.

Voice Data

Voice is local-first. Since 1.1, the default voice path needs no account and no API key:

  • Local Voice (default): On-device speech recognition and text-to-speech. All processing happens on your Mac — no audio ever leaves your device. No account or API key required.
  • Bring your own key (optional): Sends audio to OpenAI for higher-quality transcription and GPT TTS speech. Uses your own OpenAI API key, which Orbit stores in the macOS Keychain — never in plain text.

Telemetry and Tracking

We don't want your data. The native Orbit macOS app contains zero tracking SDKs, zero analytics engines, and zero crash reporters that “phone home” to our servers. Any crash logs are generated locally by macOS and stay on your machine.

API Key Storage

All API keys and credentials are stored exclusively in the macOS Keychain — the same secure enclave that Safari and other Apple apps use. Orbit never writes keys to plain text files, config files, or environment variables.

Third-Party Services

Depending on how you configure Orbit, it interacts with third parties:

  • ChatGPT / Codex: Powers the AI assistant. Handles your text, screen context, and the streamed work that follows. Uses your existing ChatGPT subscription.
  • OpenAI API (optional): Only if you bring your own key for cloud voice. Audio is sent to OpenAI for transcription and GPT TTS for speech, using the API key you provide.

Verifiability

Orbit is now public on GitHub, so the privacy claims on this page can be checked against the shipped code and release tooling directly: no bundled telemetry, no hosted backend, and intentional capture instead of passive recording.