CSACloudServeAPPS
HomeProductsAppsAboutContact
Join the Waitlist
HomeProductsAppsAboutContactJoin the Waitlist
Legal & Compliance

Orbio — Privacy Policy

How Orbio collects, uses, and protects your data.

Effective date: September 19, 2026
App: Orbio — AI Chat Hub
Operator: CloudServe Apps, a division of RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED (CIN: U62091KA2025PTC210162), Registered Office: #36, WeWork Prestige Central, Infantry Road, Mahatma Gandhi Road, Bengaluru, Karnataka 560001, India ("we", "us", "our")
Contact: [email protected]

This Privacy Policy explains what personal data Orbio collects, how we use it, who we share it with, and the rights you have.

1. What Orbio is, in plain terms

Orbio lets you chat with several third-party AI models — currently OpenAI's GPT-4o and GPT-4o Mini, Anthropic's Claude 3.5 Sonnet and Claude 3 Haiku, and Google's Gemini 1.5 Pro and Gemini 1.5 Flash — plus generate images with fal.ai's Flux 1.1 Pro and OpenAI's DALL-E 3, with your conversation history saved to your account. Every message you send passes through Orbio's own backend server before it reaches the AI provider, and Orbio stores the full text of your conversations — every message you send and every reply you receive — in our own database. This is true whether you're on the free tier, on Pro using Orbio's shared AI access, or on Pro using your own API keys (see §4) — Orbio's backend is always part of the path your messages take, and always keeps a copy.

2. Data we collect

2.1 Account data

  • Email address and, optionally, your name — collected and managed by Clerk, our authentication provider, when you sign up
  • A unique account identifier issued by Clerk
  • Subscription tier (free/Pro/team) and whether "Bring Your Own Keys" is enabled
  • Your cumulative message count

2.2 Your conversations — the core content of the app

  • Every conversation's title (auto-generated from your first message, or one you set), selected AI model/provider, and any custom system prompt you write
  • The full text of every message you send and every response the AI returns, stored as your conversation history until you delete it
  • Token counts and estimated cost for each AI response, and monthly usage totals per model
  • Files you upload (filename, content type, size — stored in Cloudflare R2 object storage)

2.3 Subscription & billing

  • Your subscription tier and entitlement status, synced from RevenueCat, our subscription-management provider, from your Apple App Store or Google Play purchase
  • Purchases themselves are processed entirely by the Apple App Store or Google Play; Orbio and RevenueCat never see your card number or other payment details — only an entitlement status and a product identifier

2.4 Bring Your Own Keys (Pro feature, optional)

  • If you're a Pro subscriber and choose to add your own OpenAI, Anthropic, or Google API key, we store it encrypted at rest (AES-256-GCM) together with a one-way hash used only to verify you're updating the right key. We never display your key back to you in plaintext, and Orbio's backend only decrypts it in memory at the moment it makes an AI request on your behalf.
  • Using your own key changes who is billed by the AI provider for that request. It does not change whether Orbio's backend sees or stores your message — see §4.

2.5 Device, analytics & crash data

  • Anonymised/pseudonymous product-analytics events (e.g. screen views, "chat sent," model selected, upgrade tapped, purchase events), tied to your Clerk account ID, collected via PostHog — unless you opt out in Settings → Privacy & Data, or (on iOS) decline Apple's App Tracking Transparency prompt, which disables analytics entirely on that device
  • Crash and error reports via Sentry, with authentication headers and email addresses automatically stripped before the report leaves your device; you can also opt out of crash reporting in Settings → Privacy & Data
  • Push-notification tokens, only if you enable notifications

2.6 What we do not collect

Orbio does not access your contacts, photo library (beyond a file you explicitly upload), precise location, or microphone.

3. Which AI providers your messages go to

ProviderModelsWhat's sent
OpenAIGPT-4o, GPT-4o Mini, DALL-E 3Your message text and recent conversation history for context, or your image prompt
AnthropicClaude 3.5 Sonnet, Claude 3 HaikuYour message text and recent conversation history
GoogleGemini 1.5 Pro, Gemini 1.5 FlashYour message text and recent conversation history
fal.aiFlux 1.1 ProYour image prompt

Each provider processes this content under its own privacy policy and terms. We encourage you to review OpenAI's, Anthropic's, and Google's data-use policies yourself, particularly around whether API traffic is used to train their models — provider terms can change.

4. Bring Your Own Keys — what it does and doesn't change

Pro subscribers can toggle "use my own API keys" and provide their own OpenAI/Anthropic/Google key. This is not a way to keep your messages from Orbio. In both modes:

  • Your message is sent from your device to Orbio's backend server first
  • Orbio's backend forwards it to the selected AI provider — using Orbio's shared key by default, or your own stored key if BYOK is enabled — and streams the response back to you
  • Orbio's backend saves the full message and response text to our database as your conversation history, regardless of which key was used

BYOK only changes whose API account is billed and rate-limited by the AI provider for that request. If keeping your message content entirely outside our infrastructure matters to you, Orbio — in its current form — cannot offer that; every message, BYOK or not, is relayed through and stored by our backend.

5. Other third parties we use

ServicePurposeData shared
ClerkAuthenticationEmail, name (if provided), session tokens
Neon (PostgreSQL)Primary application databaseEverything in §2.1–2.3
Upstash RedisCaching / background job queueTransient job data
Cloudflare R2File storageFiles you upload
RevenueCatSubscription/entitlement managementClerk account ID, subscription tier, product identifiers
PostHogProduct analyticsPseudonymous event data, tied to your account ID unless you opt out
SentryCrash/error reportingStack traces and app state, with auth headers and emails scrubbed

We do not sell your personal data.

6. Data retention

DataRetention
Account, conversations, messages, filesUntil you delete them, or until you delete your account
Monthly usage recordsRetained for the usage dashboard; deleted with your account
Stored BYOK API keysUntil you remove them or disable BYOK
Analytics eventsGoverned by PostHog's standard retention (posthog.com/privacy)
Crash reportsGoverned by Sentry's standard retention (sentry.io/privacy)

Deleting your account (Account → Delete Account) permanently deletes your user record and, through database cascade rules, your push-notification tokens, uploaded files, conversations, messages, usage history, and any stored API keys. This is immediate and cannot be undone.

7. Your rights & controls

In the app:

  • Settings → Privacy & Data — toggle analytics and crash reporting on or off
  • Account → Export My Data — returns your stored account and subscription information in a structured format. As of this writing, this export includes your account and billing status but does not yet include your conversation/message history — if you need a full copy of your conversations, contact us and we will provide it manually while we close this gap.
  • Account → Delete Account — permanently deletes your account and all associated data described in §6

You can also email [email protected] to request access, correction, deletion, or a copy of your data. We aim to respond within 30 days.

7.1 India residents (DPDP Act, 2023)

You have the right to access, correct, and erase your personal data, and to nominate another individual to exercise these rights on your behalf.

  • Grievance Officer: Santhosh Suryavanshi
  • Email: [email protected]

7.2 EU / UK / EEA residents (GDPR)

Our data controller is CloudServe Apps, a division of RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED. You have the right to lodge a complaint with your local supervisory authority.

7.3 California residents (CCPA / CPRA)

You have the right to opt out of the "sale" or "sharing" of personal data. Orbio does not sell personal data.

8. Children

Orbio is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has created an Orbio account, contact us and we will delete it.

9. Security

  • Encryption in transit — the app is configured to reject cleartext (non-HTTPS) network traffic on Android, and all API traffic uses TLS
  • Stored third-party API keys (BYOK) are encrypted at rest using AES-256-GCM
  • Orbio performs a root/jailbreak and emulator check at startup and shows a warning if your device appears compromised — this check runs entirely on your device and is not reported to us
  • Beyond the above, we rely on our infrastructure providers' (Neon, Upstash, Cloudflare) standard encryption-at-rest and access controls for data stored in their systems

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you as required by applicable law.

10. Changes to this policy

We may update this policy as the app evolves — for example, if a rate limit, provider, or data flow described above changes. We will update the effective date above when we do.

11. Contact

CloudServe Apps, a division of RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED
Registered Office: #36, WeWork Prestige Central, Infantry Road, Mahatma Gandhi Road, Bengaluru, Karnataka 560001, India
Email: [email protected]

Have questions about our policies? Contact us
← Back to Orbio
CSACloudServeAPPS

Consumer and prosumer SaaS — ToolsChef is live with 77+ tools. Four flagship products — invitations open Q4 2026, public launch Q4 2026.

A division of CloudServe Infotech

Products

  • ToolsChefLive
  • LAKSHYA
  • VantageVid
  • NexaSocial
  • AssetMaestro
  • All Products
  • All Apps

Company

  • About
  • Careers
  • Early Access
  • Contact
  • CloudServe Infotech

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Compliance
  • Security
  • SLA
  • Acceptable Use
  • Grievance
  • Site Map

Our Divisions

  • CSI

    CloudServe Infotech

    Enterprise software across AI, cloud, and SaaS — built to last

  • CSD

    CloudServe Digital

    Enterprise cloud solutions and digital transformation

  • CSL

    CloudServe Labs

    AI Innovation & EdTech

© 2026 RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED. All rights reserved.

CloudServe Apps is a division of RAMSIO CLOUDSERVE INFOTECH PRIVATE LIMITED

CIN: U62091KA2025PTC210162 | GST: 29AAPCR1639E1Z3

Registered Office: #36, WeWork Prestige Central, Infantry Road, Mahatma Gandhi Road, Bengaluru - 560001, Karnataka, India

DPIIT Startup India certificate verification QR codeDPIIT Recognized Startup (India)Certificate No. DIPP282517Scan or click to verify →