Privacy policy
This policy covers the OrbitSSH desktop client, the optional Orbit Cloud service (sync, teams, subscriptions) and this website.
Last updated: 26 September 2026
In short
- The desktop client sends no telemetry, analytics or crash reports.
- Without an Orbit Cloud account, the only thing the client sends to us on its own is the update check.
- Cloud sync is end-to-end encrypted: we store your backups but cannot read your hosts, passwords or keys.
- We do not sell your data and show no ads.
The desktop client
Data kept on your computer
- Your vault is a local database. Passwords, private keys and the other secret fields are encrypted with a key held in your operating system's credential store.
- Host names, addresses, usernames, tags, snippets, connection history and command history are stored on your computer unencrypted. When you first connect to a server, the client also reads that server's
~/.bash_historyfor command completion. Commands that look like they contain credentials are not recorded. - Terminal session logs are off by default; when you turn them on they are encrypted. AI assistant conversations are stored encrypted.
- None of the above is uploaded, except the synced items listed under Orbit Cloud if you sign in.
What the client sends on its own
- Update check: about 20 seconds after start and then every 6 hours, the client asks
orbitssh.comwhether a newer version exists. The request contains your operating system, CPU type and current version, and no account or device identifier. You can turn this off in settings. - Connections to your own servers (SSH, SFTP, Telnet, serial) and the latency check go only to the hosts you configure.
AI assistant
The AI assistant is off until you set it up with your own API key. Your messages and the command output the assistant reads are then sent directly from your computer to the AI endpoint you entered (for example OpenAI, Anthropic, Google or a local model), not through our servers. Common secret formats are masked before sending, but this cannot catch everything, so the provider's own privacy policy applies to what you send.
Orbit Cloud (optional)
An account is only needed for cloud sync and teams. If you create one, we store:
- Account: your email address, your plan and its expiry, when the account was created and last used. Your master password never leaves your computer: the client derives a login key from it, and we store only a hash of that key.
- Two-step sign-in, if you enable it: the TOTP secret (stored encrypted), hashed one-time backup codes, and the public ID of a YubiKey. YubiKey one-time codes are verified with Yubico's servers.
- Devices and sign-ins: a random device ID, the computer's name and the time of its last sync. For each signed-in session: whether it is the app or this website, the device ID and computer name the app reports, when it signed in and when it was last active (updated at most every 10 minutes). This is what lets you see and sign out individual devices.
- Encrypted backups: your hosts, passwords, keys, identities, groups, port forwards, snippets and known hosts, encrypted on your computer before upload. We can see only their size, version and upload time. We keep previous versions so you can restore them.
- Teams: the team name, its members and their roles are visible to us; the shared team vault is encrypted and we cannot read it.
Payments
Subscriptions are paid through third-party payment services (currently NOWPayments, an Epay gateway and EPUSDT). They receive the order number, amount and description, not your email address. We keep the order records (amount, currency, status and the payment service's confirmation, including the IP address it was sent from) and your balance and points history, as needed for accounting and to prevent fraud.
This website
- No analytics and no third-party fonts. Your language choice is remembered in your browser's local storage.
- The sign-up and sign-in pages use Cloudflare Turnstile to block automated abuse. It runs in your browser, and we pass your IP address to Cloudflare to verify the result. Cloudflare may set its own cookies.
Service providers
Traffic to orbitssh.com goes through Cloudflare, which sees your IP address and the pages you request. Encrypted backups are stored with Bunny (object storage). Our web server and Cloudflare may keep standard access logs (IP address, time, requested address) for security and troubleshooting. We use your IP address in memory to limit abusive request rates and store it only in the payment records described above.
Keeping and deleting your data
- You can delete individual backup versions, or all of your cloud backups, yourself at any time on the account page.
- To delete your account, email us from the address you signed up with (see Contact). If you are in a team, leave it first. Deleting the account removes your account record, devices and all backups. Payment records and balance history are kept for accounting and fraud prevention.
- Data on your own computer is yours: uninstalling the client does not upload anything, and you can delete the local data folder.
Contact
Questions about privacy, or requests to see or delete your data: [email protected]
Changes
If we change what we collect, we will update this page and its date before the change takes effect.