Orbit Authority
Shaping Rooms LLC

Privacy Policy

Effective Date: July 19, 2026 · Version 2026-07-19

1.Introduction

This Privacy Policy describes how Shaping Rooms LLC ("Company," "we," "us," or "our") collects, uses, stores, and shares data in connection with the ORBIT runtime AI governance platform and related services (the "Service"). ORBIT is a developer and professional tool for governing AI agents, available to individuals and to organizations. This policy explains our data practices regarding our customers ("Customers") and the data processed through our platform. Questions regarding this policy should be directed to legal@orbitauthority.com.

2.Data We Collect and Store

To provide our cryptographic governance infrastructure, we collect and store the following limited categories of data: Account and Organization Data: Email addresses, organization names, and administrative contact information, managed through our authentication provider (Clerk). Governed Action Records: Action types, payload metadata (specifically, field names and values used for governance decisions), governance verdicts (allow/deny), denial codes, deciding component, and the cryptographic receipts generated by our ledger. API Key Metadata: API key prefixes, descriptive labels, and creation and last-used timestamps. We never store full API key values. Usage Metrics: Aggregated system telemetry including governed action counts, denial rates, latency measurements, and contamination verdicts. We do not intentionally collect any category of data beyond those listed above. Customer responsibility for sensitive data. Under our Terms of Service, Customers are prohibited from transmitting protected health information (PHI), payment card (PCI) data, or unhashed personally identifiable information (PII) within governance payload metadata. If a Customer transmits such data in violation of the Terms, we process it as generic governance metadata and assume no additional HIPAA, PCI-DSS, or other regulated-data compliance obligation with respect to that data. Customers are responsible for masking, tokenizing, or hashing sensitive data before it reaches the ORBIT API.

3.Data We Do Not Collect or Store

Because ORBIT operates as a privacy-preserving governance boundary, we explicitly do not store: Full Large Language Model (LLM) prompt content or completion content. ORBIT does not proxy the LLM conversation. Installed adapters send proposed action metadata to ORBIT for governance decisions; the customer-selected LLM provider receives prompt and completion content under the customer's separate provider relationship, not because ORBIT routes that content. Full payment card numbers or card verification codes (handled by our payment processor, Stripe). The standard governance path is not designed to collect personally identifiable information belonging to our Customers' end users; it processes action metadata, not end-user identity records. Personal data may nonetheless be present if a Customer embeds it in submitted field values, support tickets, or other Customer-submitted materials in violation of the Terms (see Section 2). We do not use such data for any purpose beyond generating the governance decision and receipt the Customer requested.

4.Third-Party Sub-Processors

We utilize the following third-party sub-processors, each under a written data processing agreement, to operate the Service: Clerk: identity and authentication management. Amazon Web Services (AWS): cloud hosting and infrastructure. Data is hosted in the United States. Stripe: billing and payment processing. Customer-selected services (not ORBIT sub-processors). LLM Providers (OpenAI, Anthropic, Google, Mistral, and Microsoft Azure) may receive query content through the Customer's own agent or application configuration. ORBIT does not select the LLM provider and does not route prompt or completion content as part of the Guardian hook path, so these providers are engaged by the Customer, not by ORBIT, and are governed by the Customer's independent agreements with them. We do not sell Customer data to any third party. Changes to sub-processors. We will provide advance notice of any new or replacement sub-processor that processes Customer personal data, and Customers will have a reasonable opportunity to object on legitimate grounds before the change takes effect. A Data Processing Agreement (DPA) governing our processing of Customer personal data is available on request at legal@orbitauthority.com.

5.How We Use Your Data

We use collected data solely to: Provide, operate, and maintain the ORBIT Service and cryptographic ledger. Generate, store, and authenticate tamper-evident receipts. Process billing and manage Customer accounts. Monitor system security, detect unauthorized access, and optimize performance. Comply with applicable legal obligations. We do not use your data for marketing, advertising, or AI model training.

6.Data Retention

We retain Customer data for as long as the Customer account is active and as needed to provide the Service and to support audit and compliance needs, or longer where required by applicable law. Account and organization data, governed action records and cryptographic receipts, and usage metrics are retained on this basis rather than on fixed deletion schedules. Upon account termination, Customers may export their governed action records and cryptographic receipts. We delete governed action records, usage metrics, and associated personal data upon Customer request or upon account termination, except where a longer retention period is required by applicable law. Cryptographic receipts already held by the Customer remain independently verifiable using the ORBIT public key after account termination and data deletion. Receipts and the right to erasure. Cryptographic receipts are designed to contain hashes and governance metadata rather than raw personal data, so that the tamper-evident ledger can be retained for its audit period without holding personal data in a directly identifiable form. Erasure and rectification requests apply to our mutable stores (for example, account and organization data), not to the append-only integrity of already-issued receipts.

7.EU Data Subject Rights (GDPR)

For purposes of the General Data Protection Regulation (GDPR), Shaping Rooms LLC acts as a Data Controller for Customer account and organization data, and as a Data Processor for governed action payload metadata submitted through the Service. EU residents have the right to: access, rectification, erasure, restriction of processing, data portability, and objection to processing of their personal data. To exercise these rights, contact legal@orbitauthority.com. We respond within the timeframes required by applicable law (generally about one month under the GDPR — which may be extended by up to two further months for complex or numerous requests — and about forty-five (45) days under the CCPA). Data transferred outside the European Economic Area to the United States is protected by the European Commission's Standard Contractual Clauses (SCCs). We do not rely on any data-transfer certification framework for these transfers.

8.California Privacy Rights (CCPA)

Under the California Consumer Privacy Act (CCPA), eligible California residents have the right to request access to the specific personal information we have collected, request deletion of their personal information, and opt out of the sale of personal information. Shaping Rooms LLC does not sell Customer or end-user personal information. To submit a CCPA request, contact legal@orbitauthority.com. We do not discriminate against users who exercise their rights.

9.Data Security

We implement industry-standard security measures including encryption in transit (TLS) and at rest, principle-of-least-privilege access controls, cryptographic signing of all governed action receipts using AWS KMS, and regular security reviews. No internet-based service can guarantee absolute security. In the event of a data breach affecting Customer data, we will notify affected Customers as required by applicable law.

10.Cookies

We use only strictly necessary session cookies via our authentication provider (Clerk) to maintain secure administrative logins. We do not use advertising, tracking, or marketing cookies. Do Not Track. Because we do not track visitors across third-party websites over time, we do not respond differently to browser "Do Not Track" signals. This disclosure is provided under the California Online Privacy Protection Act (CalOPPA).

11.Changes to This Policy

We may update this Privacy Policy periodically. We will notify Customers of material changes via email or in-platform notification prior to the changes taking effect. For material changes that expand how we use personal data, we may require your affirmative re-acceptance before continued use, consistent with Section 17 of the Terms of Service; otherwise, continued use of the Service after the effective date constitutes acceptance of the updated policy.

12.Contact

For privacy-related inquiries, data subject requests, or questions about this policy: legal@orbitauthority.com Shaping Rooms LLC PO Box 13508 South Lake Tahoe, CA 96151 California, USA
Questions? Contact us at legal@orbitauthority.com