Credentials stay with their provider
Google and Instagram handle their own credentials. Orbit never asks for or stores either password.
Trust & account safety
Trust starts by making the current boundary understandable: which account is connected, what Orbit receives, where the record lives, and what the product still cannot do.
Orbit can
Receive. Store. Show.
Orbit cannot
Reply. Publish. Guess.
These are product boundaries, not a security certification. Orbit will publish approved legal and security documentation before public launch.
Product boundaries
Google and Instagram handle their own credentials. Orbit never asks for or stores either password.
Creator reads are scoped to the active workspace and connected account before any inbound record is returned.
The current product receives and displays DMs and comments. It does not send replies or modify Instagram content.
Preview controls are disabled and illustrative data is labeled. Future behavior does not masquerade as a live backend.
Connect one creator workspace and keep every capability inside a visible permission boundary.