Legal · Privacy

Privacy Policy

Last updated · 25 May 2026 · Version 1.0


1. Who we are

This Privacy Policy explains how Orbie Labs (“Orbie”, “Orbie Labs”, “we”, “us”) — an independent team based in Stockholm, Sweden, and the controller of your personal data — collects, uses, shares, and protects it when you use the Orbie website, studio, APIs, and related services (the “Service”). As we are established in the EU, no separate Art. 27 representative is required. Data-protection contact: [email protected].

2. The data we collect

  • Account data: email, display name, authentication identifiers, and organisation details.
  • Billing data: billing name, country, VAT/tax identifiers, and payment tokens. Full card numbers are handled by our payment providers; we do not store them.
  • Customer Content: the Inputs you submit (prompts, images, audio, reference media, parameters) and the Outputs we generate for you.
  • Usage and technical data: device/browser data, IP address, timestamps, request and error logs, generation metadata, and feature usage.
  • Support and communications: messages you send us and related metadata.
  • Cookies and similar technologies: see section 12.

3. How and why we use data — and our legal bases

Where the GDPR applies, we rely on the following legal bases (Art. 6 GDPR):

  • Provide the Service (create your account, run generations, deliver Output, process payments) — performance of a contract (Art. 6(1)(b)).
  • Secure and operate the Service (fraud prevention, abuse detection, debugging, capacity planning using aggregated/de-identified data) — legitimate interests (Art. 6(1)(f)).
  • Comply with law (tax, accounting, responding to lawful requests, mandatory reporting of certain unlawful content) — legal obligation (Art. 6(1)(c)).
  • Model training on Customer Content — only with your consent (Art. 6(1)(a)); you can withdraw it at any time.
  • Marketing communicationsconsent or legitimate interests as permitted by law; you can opt out at any time.

4. Customer Content and model training

We process your Inputs and Outputs to provide and support the Service. We do not use Customer Content to train or fine-tune our generative models unless you give explicit, opt-in consent (for example, by enabling a per-project setting). We may use de-identified, aggregated operational metrics that do not identify you to maintain and improve the Service.

5. How we share data

We do not sell your personal data. We share it only with:

  • Service providers / sub-processors who process data on our behalf under contract (see our current sub-processor list, referenced in the Data Processing Addendum), including cloud/compute hosting, payment processing, email delivery, and error monitoring.
  • Your organisation, where you use a team or organisation account, and your authorised team members.
  • Legal and safety recipients — authorities or third parties where required by law, to enforce our terms, or to protect rights, safety, and the integrity of the Service.
  • Corporate transactions — an acquirer or successor in a merger, financing, or sale of assets, subject to this Policy.

6. International transfers

We may process and store data in the EEA and in other countries, including the United States. Where we transfer personal data outside the EEA/UK/Switzerland to a country without an adequacy decision, we use appropriate safeguards, principally the European Commission’s Standard Contractual Clauses (and the UK Addendum / Swiss amendments where relevant), and carry out transfer risk assessments. You can request a copy of the relevant safeguards from [email protected].

7. How long we keep data

  • Account data: for the life of your account and then up to 90 days after closure.
  • Customer Content: until you delete it or close your account, then removed from active systems within 30 days and from backups within 90 days.
  • Billing/tax records: retained for the period required by law (typically up to 7 years).
  • Logs and security data: retained for up to 12 months.

We retain data longer only where required to comply with law or to resolve disputes.

8. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit, access controls and least-privilege, network segmentation, logging and monitoring, and personnel confidentiality obligations. No method of transmission or storage is completely secure. We will notify affected users and regulators of a personal data breach where and as required by law.

9. Your rights

EEA/UK/Switzerland. You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time (without affecting prior processing). You may exercise these rights in the dashboard or by emailing [email protected]. You also have the right to lodge a complaint with your supervisory authority — in Sweden, the Integritetsskyddsmyndigheten (IMY).

California (CCPA/CPRA) and similar US state laws. Subject to limits, you have the right to know/access, to delete, to correct, and to opt out of “sale” or “sharing” of personal information, and the right not to be discriminated against for exercising these rights. We do not sell your personal information and do not “share” it for cross-context behavioural advertising. To exercise rights, email [email protected]; we will verify your request and may accept authorised-agent requests. The categories of personal information we collect, the purposes, and recipients are described in sections 2, 3, and 5.

10. Children

The Service is not directed to children under 13, and we do not knowingly collect personal data from them. Users aged 13–17 may use the Service only with verifiable parental or guardian consent and supervision; the consenting adult is responsible for that use. Where we learn we have collected a child’s data without the required consent, we will delete it. Schools and organisations that provision access for minors act as controllers (or, where agreed, as our customer under the DPA) and are responsible for obtaining consents required by law (including COPPA in the US and GDPR Art. 8 in the EEA). Parents/guardians and schools may contact [email protected] to review or delete a minor’s data.

11. Automated processing

The Service generates content algorithmically from your Inputs. We do not use your personal data to make decisions producing legal or similarly significant effects about you without a lawful basis and applicable safeguards.

12. Cookies and similar technologies

We use strictly necessary cookies to run the Service and, with your consent where required, analytics or preference cookies. You can manage non-essential cookies through our cookie controls or your browser.

13. Changes to this Policy

We may update this Policy. For material changes we will provide reasonable notice (for example, by email or in-product notice). The “Last updated” date reflects the current version.

14. Contact

Orbie Labs, Stockholm, Sweden. Privacy enquiries and data-subject requests: [email protected].