Privacy should be understandable before connection.
A plain-language view of the data boundaries the launch privacy notice must cover.
What the current product handles
Account authentication identifiers, one creator workspace, one Instagram connection, and the inbound DMs and comments delivered after that connection.
The inbound record can include sender handles, message or comment content, timestamps, connection references, and provider event identifiers needed to keep records separated and deduplicated.
What Orbit does not ask for
Orbit does not ask for a Google or Instagram password. Those credentials remain with their authentication providers.
The current checkpoint does not send Instagram replies, publish content, or create automation decisions.
Controls planned for launch
The final product surface is planned to make export, message retention, connection removal, and account deletion visible from Settings.
Those controls are disabled previews today. This page must be updated with approved retention periods, provider disclosures, legal bases, contact details, and request procedures before launch.