Privacy

Privacy policy

This policy covers the OrbitSSH desktop client, the optional Orbit Cloud service (sync, teams, subscriptions) and this website.

Last updated: 26 September 2026

In short

The desktop client

Data kept on your computer

What the client sends on its own

AI assistant

The AI assistant is off until you set it up with your own API key. Your messages and the command output the assistant reads are then sent directly from your computer to the AI endpoint you entered (for example OpenAI, Anthropic, Google or a local model), not through our servers. Common secret formats are masked before sending, but this cannot catch everything, so the provider's own privacy policy applies to what you send.

Orbit Cloud (optional)

An account is only needed for cloud sync and teams. If you create one, we store:

Payments

Subscriptions are paid through third-party payment services (currently NOWPayments, an Epay gateway and EPUSDT). They receive the order number, amount and description, not your email address. We keep the order records (amount, currency, status and the payment service's confirmation, including the IP address it was sent from) and your balance and points history, as needed for accounting and to prevent fraud.

This website

Service providers

Traffic to orbitssh.com goes through Cloudflare, which sees your IP address and the pages you request. Encrypted backups are stored with Bunny (object storage). Our web server and Cloudflare may keep standard access logs (IP address, time, requested address) for security and troubleshooting. We use your IP address in memory to limit abusive request rates and store it only in the payment records described above.

Keeping and deleting your data

Contact

Questions about privacy, or requests to see or delete your data: [email protected]

Changes

If we change what we collect, we will update this page and its date before the change takes effect.

Code signing policy · Back to home