1. What This Policy Covers

Orbt Networks connects to third-party platforms — including Gmail, Google Calendar, Microsoft 365, LinkedIn, Slack, CRM systems, and other relevant platforms — on behalf of our users. This Policy explains what data we access, how we use it, and how we protect it. It is addressed primarily to platform API providers reviewing our integration for approval.

2. Data We Access and What We Do Not

We access only what is necessary to build each user's private Relationship Graph: email metadata (sender, recipient, date, subject, thread ID) together with a short, provider-generated preview snippet (Gmail's message snippet or Outlook's body preview) — not the full message body; calendar metadata (event title, attendees, date, time, and event description); contact records (name, employer, title, contact details within granted permissions); interaction signals (frequency and recency of contact, derived from metadata only); and LinkedIn/Slack/CRM connection and membership data within permitted API scopes. We do not access full email or message body content, financial data, health data, minors' data, or geolocation. We do not use Platform Data for advertising, model training, or to build shared contact databases.

3. How We Use the Data

Relationship Graph: per-user, private map of professional relationships, stored in a logically isolated data store accessible only to that user. Network Queries: a user can search their own network and can search the network of people they are connected with on Orbt Networks' application. Connecting on our application also allows users to see the strength signals of relationships between someone the user is connected with and people that connection knows. In this process, no sensitive personal information is transmitted and users have control on which information people feel comfortable sharing with their different degrees of connections. Service improvement: aggregated, de-identified telemetry only; individual Platform Data is not used for model training without separate explicit consent.

4. Data Minimization and Scope

Orbt requests only the minimum OAuth scopes necessary for each function. Scope lists are reviewed before any product change and published on the website. When a user disconnects an integration, Orbt immediately stops using it and marks it inactive; formal revocation with the platform provider and deletion of previously collected raw data follow the retention target described in Section 6.

5. Third-Party Contacts

Persons appearing in a user's Platform Data who are not Orbt users have not directly consented to our processing. We protect them by using their data solely to generate relationship signals within that user's private graph, and never selling their data. They may submit requests to us if they want their data to be removed.

6. Security and Retention

We intend to use AES-256 at rest and TLS 1.3 in transit for encryption. Access controls: role-based; internal access logged and audited. Retention: derived signals are retained for the account lifetime. Our retention target for raw Platform Data is deletion within 30 days of processing, with backups purged within 90 days of account deletion; automated enforcement of this target is in progress, and deletion requests submitted under Section 7 are honored manually in the meantime. Incidents: Platform Providers notified within 72 hours of a confirmed breach. Compliance target: SOC 2 Type II.

7. User Rights and Governance

Users may access, correct, export, restrict, or delete their data by contacting us at the email below; in-app self-service controls for these actions are planned but not yet available. Users may opt out of Network Queries entirely or configure which connections may query their Orbt. Orbt intends to comply with CCPA for California residents and applicable regulations for EU/UK users.

Orbt

The private network intelligence layer for direct and second-degree professional relationships.

© 2026 Orbt Networks

Tufts Venture Accelerator · Summer 2026