Privacy Policy
Effective date: [EFFECTIVE DATE]
This Privacy Policy explains how [COMPANY LEGAL NAME] ("CommonOrbit", "we", "us") collects, uses, and shares personal data when you use the CommonOrbit web application (the "Service"). We are the controller of this data.
Draft notice: This is an early-stage draft, not legal advice, and must be reviewed by a qualified attorney before publication.
1. Data we collect
Account data
- Email address (required).
- Password, stored only as a secure hash (never in plain text). We never see your actual password.
- Optional display name and username, and an optional phone number (not verified by us).
Google sign-in data (if you use it)
- Your Google account identifier, email address, name, and profile picture URL, received from Google when you choose to sign in with Google.
Content you create
- Goals, sources you add (URLs and notes), agent definitions, skills, and other workspace content.
- Chat messages and conversation data.
- Files you attach to a chat message (images and documents), and the text we extract from a document so an agent can read it.
- Contacts and connection requests (who you are connected to, and pending requests).
Voice and video call data
- For calls between people, the audio and video streams flow directly between participants through our real-time provider (LiveKit) and do not pass through our own servers. We keep a call record (who called whom, start and end times, status, and whether it was audio or video).
- For voice conversations with an AI agent, your speech is converted to text and the agent's reply to speech by our speech provider (Deepgram). A transcript is saved to your chat thread only if you turn on "save transcript" in your voice settings; with that setting off, the transcript is treated as ephemeral and is not stored by us.
Usage and cost data
- A record of AI and infrastructure usage tied to your account (feature used, provider, model, token or second counts, and estimated cost), used for metering and future billing.
Technical data
- Your IP address and basic request information, used for security, rate limiting, and abuse prevention. We rely on a bot check (Cloudflare Turnstile) at sign-up.
We do not currently process payment card data. If and when paid plans launch, payments will be handled by a third-party merchant of record (Paddle); card details go to that provider, not to us.
2. How your content is protected, and its limits
Chat message bodies are encrypted at rest (AES-256-GCM) in our database, so a stolen disk or leaked backup shows only scrambled text. This is not end-to-end encryption. We hold the encryption key, and our servers decrypt messages to display your chats and so that your AI agents can read conversation history to respond. That means our systems, and in a live-server compromise an attacker, can read message content. Please do not share anything through the Service that you would not want a server operator to be able to access.
Files you attach to a chat (images and documents) are stored with our cloud storage provider, protected by that provider's own encryption and a private, non-public storage location. The text we extract from a document so an agent can read it is encrypted at rest the same way message bodies are, under our own key. The original uploaded file itself is not additionally encrypted under our own key — only by the storage provider's. We restrict what file types can be uploaded and check each file's actual content before accepting it, but we do not scan uploaded files for malware or review their content.
3. Why we use your data
We use personal data to:
- Create and secure your account, verify your email, and sign you in.
- Provide the Service's features (agents, goals, the self-update loop, chat, calls, contacts).
- Send your prompts, chat history, and source text to our AI provider so it can generate responses.
- Convert speech to text and text to speech for voice features.
- Meter usage and, in the future, bill for paid plans.
- Prevent fraud and abuse, enforce our Terms, and keep the Service secure.
- Communicate with you about your account and important service notices.
Where required by law, our legal bases are: performing our contract with you, our legitimate interests (security, service improvement, abuse prevention), your consent (for example, optional transcript saving), and compliance with legal obligations.
4. Who we share data with
We do not sell your personal data. We share it with service providers ("processors") who handle it on our behalf, only to run the Service:
- Google for sign-in.
- Our AI model provider (currently Anthropic / Claude), which processes the prompts, chat history, and source text you submit to generate responses. The AI provider is chosen by us and may change; the Service is designed to be provider-neutral.
- LiveKit for voice and video call transport and signaling.
- Deepgram for speech-to-text and text-to-speech in voice conversations with agents.
- Cloudflare Turnstile for the sign-up bot check.
- Resend for sending verification emails.
- Paddle for checkout and billing, if and when paid plans launch.
- Hosting and database infrastructure, where our application and data (Postgres, MongoDB, Redis) are hosted.
We may also disclose data if required by law, to protect our rights or users' safety, or in connection with a business transfer (such as a merger or acquisition).
5. International transfers
We and our providers may process your data in countries other than yours, including outside the Philippines and the European Economic Area. Those countries may have different data-protection laws. Where required, we rely on appropriate safeguards (such as the providers' standard contractual clauses) for these transfers.
6. Data retention
We keep personal data for as long as your account is active and as needed to provide the Service, then for [DATA RETENTION PERIOD] or as required to meet legal, tax, security, and dispute-resolution obligations, after which we delete or anonymize it. Verification codes are short-lived (they expire within minutes). Message content stays until the conversation is deleted by all participants.
Files and images you attach to a chat message are deleted 30 days after you upload them, by default. Basic, Pro, and Enterprise accounts can extend that in Settings (Basic up to 60 days, Pro and Enterprise up to 180 days), and anyone, on any plan, can shorten it to as little as 7 days. Changing this setting applies to files you've already uploaded, not just new ones, and takes effect within an hour. Transcripts and summaries from a recorded meeting call are deleted 30 days after the recording finishes, on every plan, and this is not adjustable — separate from the raw call audio itself, which is deleted within minutes of the transcript being generated, well before this 30-day window even starts. None of this reaches content derived from a file or a call, such as an agent's reply that quoted it, a memory distilled from that conversation, or a report that cited it — those are ordinary chat and memory content and are kept under this section's general rule, not this timer. A transcript you chose to save from a live voice conversation with an agent is likewise ordinary chat content, not a call recording, and is not on this timer either.
Deleting a file or a transcript removes it from the Service, but our database and storage providers keep their own short-lived backups for disaster-recovery purposes, independent of anything described above: our database provider retains a rolling backup window on the order of hours, and our file storage provider keeps no backup of a deleted file at all.
7. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. Some of these you can do yourself in the app (for example, editing your profile, deleting conversations, or turning off transcript saving). We do not yet offer self-service full data export or account deletion; to request a copy of your data or deletion of your account, contact us at [CONTACT EMAIL] and we will act on your request as required by applicable law. You may also have the right to complain to your local data-protection authority.
8. Children
The Service is not intended for children under 18 (or the applicable age of consent in your jurisdiction), and we do not knowingly collect their data. If you believe a child has given us personal data, contact [CONTACT EMAIL] and we will delete it.
9. Applicable privacy laws
Depending on your location, laws such as the Philippine Data Privacy Act of 2012 (RA 10173) and the EU or UK General Data Protection Regulation (GDPR) may apply to how your data is handled. We aim to honor the rights and principles in these laws, but we do not claim full or certified compliance with any specific framework at this early stage. We are working toward stronger data-protection practices as the product matures.
10. Changes to this Policy
We may update this Policy. Material changes will be signaled by updating the effective date and, where appropriate, by notifying you in the app or by email.
11. Contact
[COMPANY LEGAL NAME] [BUSINESS ADDRESS] [CONTACT EMAIL]