Control infrastructurefor your AI ambitions.

Delegate valuable work to AI.
Retain authority over the outcome.

Read Oorbital without 3D.

Your browser does not have WebGL2 available. All the text, diagnostics and contact options are available in reading view.

Oorbital

Your next step.

This destination is reserved for the next build.

Intelligence · Example

Less repeated work.
The same care.

Oorbi keeps researching answers already approved by your team. Reusing those answers is an opportunity to reduce repeated work.

The suggested change leaves the £200 refund limit in place. It still needs testing before release.

A local example, not a measured performance or savings claim.

The AI Abundance Report

Preview from the supplied report introduction.

The legal office

The small print.
In plain sight.

Privacy, cookies and terms. Choose a document at the desk, read it in an expanded view and move between documents without losing your place.

Open privacy notice ↗

Read the Oorbital Privacy Policy here.

↓Explore what you can do with Oorbital.
Legal
↙ Back to the office
Eight questions. A clearer next step.
oorbital

Take your time. Oorbi has the next question.

Your work, saved

Your diagnostic results.

Developer quick start

Keep your stack.
Add an execution boundary.

Oorbital Privacy Policy

Last updated: 24 September 2026

1. Who we are and what this policy covers

OORBITAL AI LIMITED, a company incorporated in England under company number 17249767 ("Oorbital", "we", "us") provides the Oorbital web application at app.oorbital.ai, the Oorbital Chrome extension, and the services supporting them (together, the "Services"). This policy explains how we handle personal data when you use these Services or contact us about them.

Privacy contact: team@oorbital.ai
Business address: 1 Lancelot House, Hurcott Village, Kidderminster, Worcestershire DY10 3PG

We are the controller of personal data used to manage our accounts, customer relationships and business operations. Where we process personal data contained in an organisation's workspace on its instructions, we act as its processor under the applicable data-processing agreement. That organisation determines its purposes and lawful basis and may provide its own privacy notice. Actual responsibilities depend on the processing, not simply these labels.

2. Information we handle

The information involved depends on the features you use, the permissions you grant and your workspace configuration.

Category Examples and sources
Account and authentication Name, email, account and workspace identifiers, membership and permissions, sign-in information, session tokens, and credentials you deliberately provide when connecting a service. We receive these from you, your organisation and your sign-in or connection provider.
Your content and work Instructions, prompts, conversations, uploaded files, selected page content, generated responses, saved assets and memories, workflow inputs and outputs, approvals and execution records. These come from you, authorised workspace users, connected services and your use of the Services.
Browser and connected-app information Relevant page addresses and titles, selected text, page structure, email or chat content, meeting captions, document and calendar information, and supported AI-assistant activity and usage information. Section 3 explains when the extension accesses this information.
Technical and service information IP addresses, browser and extension versions, language and time-zone settings, request times, feature usage, errors, security events and operational logs. IP addresses can indicate approximate location; the extension does not request GPS location.
Billing and correspondence Billing contact details, subscription and invoice records, payment status and transaction references, and messages or attachments you send to support. Where an external payment service is used, its identity is shown at checkout.

Content may contain information about other people, including sensitive health, financial or other personal information. Do not submit sensitive or regulated information unless you are authorised and the relevant service configuration and agreement support that use. Providing us with information about another person does not, by itself, establish that person's consent or another lawful basis.

3. How the Chrome extension works

The extension's purpose is to help you understand, draft and carry out work in the apps and pages you choose, alongside your Oorbital workspace.

Site access. Installation enables connections needed for Oorbital's API and authentication. Access to third-party websites is separate: you can enable supported apps, grant access to other websites, or invoke the extension on a particular page. Chrome's permissions limit that access. Enabling a site allows local recognition of the app and its relevant interface; it is not permission to use unrelated browsing data for other purposes.

Page content and tasks. When you request a feature such as summarising an email, improving a prompt, adding tabs as sources or continuing a conversation, the relevant content and associated page information are processed to perform that request. Content needed for server-based processing is sent to Oorbital and the providers involved in that feature. Work you create or continue in your workspace can be saved there, including its source material. Server processing is not necessarily temporary or storage-free.

AI Activity and usage. AI Activity is optional and off by default. When enabled for supported assistants, it keeps local conversation metadata, including addresses, titles, model names, state, counts and timestamps. Its activity view covers records updated within the preceding three days. Opening or continuing an activity can read the conversation content from the relevant assistant page. Supported usage features can also read provider-displayed usage figures or maintain local counts of messages sent. This does not involve importing Chrome's complete browsing-history database, but the addresses, titles and activity just described are still browser-related personal data.

Meeting notes. When you start taking notes in Google Meet, the extension reads live captions, including available speaker names, text and timestamps. This feature does not record meeting audio or join as a separate participant. Captions and notes are kept locally unless you request processing, saving or sharing that sends them onwards. Inform participants and obtain any permissions or consent required for your use.

Dictation. Dictation uses Chrome's speech-recognition functionality after microphone permission. Chrome may send audio to Google's speech service to produce text. The extension places the resulting text in your draft; it is sent to Oorbital when you submit it. Google handles any audio it receives under its applicable terms and privacy notice.

Tab control. This separately authorised feature uses Chrome's debugger capability to operate the approved tab. Relevant page observations, proposed actions and execution results may be sent to Oorbital and its processing providers. Actions can include navigating, clicking, typing and submitting information, subject to session limits and applicable policy and approval checks. You can stop the session. Authorising tab control is not authorisation to monitor unrelated browsing.

Search. Searches entered in the extension’s ordinary new-tab search box are passed to your default search engine through Chrome. That search provider handles the query under its own privacy policy.

Your controls. You can change app access, turn off AI Activity, clear supported local data, sign out, revoke Chrome permissions or uninstall the extension. Broad "other websites" access and permissions shared by multiple apps may need to be revoked separately. The extension is not enabled in incognito mode. Local clearing or uninstalling does not delete work already saved to Oorbital or another service.

4. Why we process data and our lawful bases

We process information to provide requested features, authenticate users, manage workspaces and connections, perform and govern tasks, maintain service reliability, prevent misuse, provide support, administer subscriptions, and meet legal obligations.

Where UK or EU data-protection law applies and we are the controller, our bases are:

Processing Lawful basis
Providing a service you contract with us to receive Performance of that contract, including necessary steps requested before entering it.
Administering an organisation's account and supporting its authorised users Our legitimate interests in delivering and managing that business relationship, subject to individuals' rights.
Security, troubleshooting and measuring service reliability Our legitimate interests in operating a secure, dependable service, using proportionate information.
Optional processing requiring consent Your consent, requested separately for the relevant activity and withdrawable at any time.
Required accounting, regulatory disclosures and other legal duties Compliance with the relevant legal obligation.

Necessary account or authentication information is required to provide signed-in features. Other information is optional, although a feature may not work without the context or permissions it needs. Customer-controlled workspace processing follows the customer's instructions and lawful basis. A browser permission is not a blanket legal basis for every use of data.

5. AI processing and model training

AI features send the inputs needed for your request, which can include relevant conversation history, files, page context and tool results, to the model provider or infrastructure configured for that feature. Governance and safety checks may also process this information. The applicable providers are identified in our provider register and relevant product disclosures.

We do not use Customer Content to train general-purpose AI models, and we do not authorise our processing providers to do so. "Customer Content" means the prompts, communications, files, page content and work products processed through the Services. Customer-requested evaluation or optimisation remains confined to delivering that customer's service and any restrictions applying to the source data.

Inference, permitted abuse prevention and temporary provider storage are different from model training. Provider retention and permitted security review depend on the applicable service and configuration, as described in our provider register. We do not promise zero retention unless expressly agreed for a supported configuration.

6. Who receives information

Service providers. We use providers for hosting, authentication, storage, AI processing, integrations, service communications and, where applicable, billing and support. They receive only the information needed for their role and are subject to appropriate contractual restrictions where they process it on our behalf.

Provider register: [INSERT PUBLIC URL OF THE COMPLETED PROVIDER REGISTER]. The register forms part of this policy and identifies the actual providers, their functions, relevant data, processing locations and applicable retention information. A provider appearing in the register does not mean every request is sent to it.

Your organisation and chosen recipients. Workspace owners, administrators and authorised collaborators may access workspace information according to their roles, settings and the organisation's policies. When you request an action, we may send the information needed to your chosen app, website or recipient. Independently operated services also apply their own privacy terms. This does not remove Oorbital's responsibility for its own processing or permit transfers prohibited by section 7.

Legal and business circumstances. We may disclose information when required by law, as necessary to address security or abuse, or for a lawful business restructuring. Disclosures are limited to what is necessary and subject to section 7, including its prior-consent requirement for relevant business transfers.

7. Additional protections for extension and Google data

Oorbital complies with the Chrome Web Store User Data Policy and its Limited Use restrictions. Data obtained through the extension is used only for its disclosed purpose and directly related operation, security and improvement, not unrelated profiling or business activities.

We do not sell this data, use it for advertising, provide it to data brokers, or use or transfer it for creditworthiness or lending decisions. Transfers are limited to necessary delivery or improvement of the disclosed functionality, legal compliance, protection against abuse, or a merger, acquisition or asset sale with the user's explicit prior consent.

Human access is restricted to specifically consented assistance, necessary security or legal purposes, or aggregated and anonymised internal operations permitted by those rules. Raw, scraped, derived and de-identified data remain subject to the applicable restrictions.

Information obtained through Google APIs is handled in accordance with the Google API Services User Data Policy, including its Limited Use requirements where applicable. Google Workspace data is also subject to the Workspace user-data policy; it is not used to develop or train general-purpose AI models.

These protections take precedence over any broader language elsewhere in this policy or an agreement. Workspace settings and user instructions do not override them.

8. Storage, retention and deletion

We keep personal data only for the purposes described here and for the time justified by those purposes.

In your browser. Preferences and enabled-app settings remain until changed or cleared. Session data is held for the relevant browser session; choosing "Stay signed in" permits a renewal credential to remain in local extension storage until removed or invalidated. It is not placed in Chrome Sync by the extension. Local meeting notes remain until deleted. AI Activity uses the three-day activity window described above; expired cached entries are pruned when its stored activity is updated, rather than guaranteed erased exactly at 72 hours. Turning AI Activity off removes its saved metadata. Local usage records are pruned during updates or removed when you clear them.

In Oorbital. Account information is retained while needed to operate the account. Saved workspace content remains available until deleted, the workspace is closed, or an applicable retention rule removes it, subject to lawful exceptions. Routine technical records are kept only as needed to troubleshoot recent failures, measure reliability and investigate security events. Support records are kept through resolution and any necessary follow-up or dispute period. Billing and legal records are retained for applicable statutory periods or a specific legal claim, not to justify indefinite retention of unrelated content.

After deletion. Limited copies may remain in backups until their scheduled rotation, or where a specific legal obligation or security investigation requires retention. Those copies remain protected and are not repurposed. Applicable provider-specific periods are described in the provider register. Contact us to request deletion of server-held information. Disconnecting an integration stops future authorised access but does not itself erase information already received or delete the original information at its source.

9. Security and browser storage

We use measures appropriate to the information and risks, including encrypted connections, authentication, permission checks and access restrictions. No online service or device can be guaranteed completely secure. Browser-local storage should not be treated as a personal encrypted vault, particularly on a shared or compromised device.

The web application uses cookies or comparable browser storage for functions such as sign-in, security and settings. Where an additional storage or tracking purpose requires consent, we request it before that processing and provide a way to withdraw it. The extension does not use browsing content for advertising. Any optional analytics must be separately disclosed and remain subject to section 7.

10. International processing

Your information may be processed outside your country, depending on the providers and deployment used. Our provider register identifies relevant processing locations. We do not promise UK-only or EU-only processing unless agreed for the relevant service configuration.

Where a transfer of UK or EEA personal data requires safeguards, we use an applicable adequacy decision or an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses and the relevant UK Addendum or International Data Transfer Agreement. Contact us for information about the mechanism applicable to your data and a copy of relevant safeguards, subject to lawful redactions. Using the Services is not blanket consent to unrestricted international transfers.

11. Your rights

Depending on the applicable law and our role, you may request access, correction, deletion, restriction of processing, or a portable copy of your personal data. You may withdraw consent without affecting processing already lawfully undertaken.

Right to object: You can object to processing based on legitimate interests on grounds relating to your situation. Where personal data is used for direct marketing, you can object to that use at any time.

Send requests to team@oorbital.ai. We may reasonably verify your identity and authority, and will respond within the period required by applicable law. Rights are subject to lawful exceptions, including other people's rights and specific retention duties. For data controlled by your organisation, we may direct the request to it and assist in accordance with our obligations.

You may complain to the UK Information Commissioner's Office or your competent local supervisory authority, including the authority where you live or work in the EEA. You do not need to contact us first to exercise that right.

AI-generated recommendations and governance scores assist with work and action controls. They are not, by themselves, authority to make legally or similarly significant decisions about people. An organisation deploying such a use must establish an appropriate lawful basis, provide the necessary notice and safeguards, and respect applicable individual rights.

12. Children and changes

The Services are intended for professional and general productivity use, not directed at children. Contact us if you believe a child has provided personal data in circumstances requiring action under applicable law.

We may update this policy as the Services or legal requirements change. We will update its date and provide additional notice of material changes. Where required, we will obtain consent before introducing a new use of information. A policy update does not retrospectively authorise an otherwise prohibited use.

Questions about privacy: team@oorbital.ai.

OORBITAL AI LIMITED · Privacy PolicyOORBITAL · LEGAL
Oorbital

Share a private copy

Share your results.

Choose who receives your results. Nothing is published online.

Open an email draft ↗

Your email app handles sending. This page does not send messages.