Privacy · Orbi Cloud
Privacy policy
What crosses the hosted-service boundary, and why. This policy describes the data Orbi Cloud uses to sign you in, run deliveries, measure usage, and bill subscriptions.
DATA WE USE
Only the records the service needs
When you connect Cloud, we receive GitHub account information and the repositories you authorize. For those repositories, the service handles repository metadata and delivery records such as Issues, pull requests, commits, and run outcomes. The control plane records tenant and repository configuration in Cloudflare D1, and records delivery usage for quota and billing operations. The website may record anonymous visitor events in its visitor_events table for site measurement.
Cloud delivery work temporarily runs on infrastructure we operate. A terminal delivery worktree is destroyed after a 120-minute quiet period; in-flight and recoverable worktrees are kept. Cloudflare D1 account, repository, usage, and visitor records have no automatic expiry and remain until they are no longer needed to operate the service or you request deletion. GitHub remains the source of truth for your Issues, pull requests, and releases.
SERVICE PROVIDERS
Processors that make Cloud work
Stripe processes subscription payments, invoices, and customer-portal actions; Orbi does not receive your full card number. The model provider you select receives the prompts, relevant repository context, and output needed for a delivery. Provider retention and processing are governed by that provider’s terms. GitHub receives the GitHub actions Cloud performs through the permissions you grant.
We do not sell personal information. BYOK model keys used by Cloud are stored encrypted in the control plane and exposed to the runner only when needed.
YOUR CHOICES
Access, deletion, and contact
You can revoke Orbi’s repository access in GitHub. To request deletion of your Orbi account and associated Cloud records, email privacy@orbi.build with the GitHub account or tenant to identify. We will explain what was deleted and what must remain in GitHub or Stripe’s systems. Questions about this policy can use the same address or GitHub Issues.
This policy describes the current Cloud implementation, including the tenants, repositories, delivery_usage, and visitor_events records. It does not promise deletion of data held independently by GitHub, Stripe, or a model provider.