Effective September 15, 2026

Privacy Policy

This policy explains how ItemOrbit handles information when you use the ItemOrbit mobile application, website, and support services.

Who this policy covers

This policy applies to ItemOrbit, an inventory organization app that lets you track belongings, record loans, and share selected inventory lists with other ItemOrbit users. Questions can be sent to itemorbit@gmail.com.

Information ItemOrbit collects

  • Account information: your email address, account identifier, optional display name, and authentication information needed to create and access your account. Passwords are handled by the authentication service; never send your password in a support email or report.
  • Inventory content: item names, categories, storage locations, notes, favorites, dates, condition, accessories, and related organization details you enter.
  • Loan and contact details: names or contact information you manually enter for people who borrow items, expected return dates, and return history.
  • Shared-list information: lists you create or join, membership records, invitations, and content you choose to make visible to other members of a shared list.
  • Safety and agreement records: the version and time of your agreement to the Terms and Community Rules; accounts you block; and reports you send, including the reason, description, account identifiers, and a limited copy of the reported item, list, or profile. Item reports include the item name, category, and notes; list and profile reports include the relevant name.
  • Purchase and entitlement information: subscription product, purchase status, renewal status, expiration date, and the account identifier needed to provide Personal or Family access.
  • Service and security information: authentication events, account and session identifiers, network request details, IP address, approximate location inferred from that address (such as city or country), and request timing and diagnostic logs used to operate, troubleshoot, and protect the service.

ItemOrbit does not request access to your device contacts, precise location, photos, camera, microphone, or health information. ItemOrbit does not receive your full payment-card or bank-account details; Google Play processes payments.

How information is used

ItemOrbit uses information to:

  • create and secure your account;
  • sync your inventory between signed-in devices;
  • organize, search, export, and display the content you add;
  • provide shared lists to people you choose;
  • confirm purchases, restore access, manage Family seats, and prevent subscription abuse;
  • respond to support and deletion requests;
  • review reports, enforce sharing restrictions, and record agreement to the Terms and Community Rules; and
  • detect problems, prevent misuse, and maintain service security.

ItemOrbit does not sell personal information and does not use it for advertising or cross-app tracking.

When information is shared

ItemOrbit uses Supabase for authentication, database hosting, secure synchronization, and subscription-entitlement records. Resend delivers account messages such as password resets and confirmation emails, and safety alerts to ItemOrbit support. Safety alerts contain a report reference and an administrator link, not the report description or reported content. RevenueCat helps ItemOrbit validate purchases and determine whether Personal or Family access is active. Google Play processes Android purchases and subscriptions under your Google account and its own terms and privacy policy. Google's Gmail service stores messages sent to and from the ItemOrbit support inbox. Cloudflare and ItemOrbit's website hosting provider help deliver and protect the public website. These providers process information to deliver their services. Inventory in a shared list is also visible to the ItemOrbit users whom the list owner chooses to add. ItemOrbit may disclose information if required by law or when reasonably necessary to protect users, the service, or the public.

Earlier Android versions, through Build 31, may check a connection to Google and to the sign-in service after a sign-in network error. Build 32 and later remove the Google check and only check the sign-in service. These requests do not include your entered password or inventory, but the receiving services receive ordinary connection information, such as your IP address. Google's handling of that connection information is described in its Privacy Policy.

Reports and blocking

Reporting and blocking are optional. A report is available to ItemOrbit support for review and is not shown to the reported user. Sending a report does not automatically remove content or suspend an account. The limited copy stored with a report can remain after the original item or list is edited or deleted. Please do not include passwords or unnecessary personal information in reports or support emails.

Blocking prevents sharing between the accounts and removes applicable shared-list access; it does not delete either person's inventory. Unblocking permits future invitations unless the other account still has a block in place. It does not automatically restore previous access.

Storage and security

Account and inventory data is stored in ItemOrbit's Supabase project and may also be cached on your device so the app can function smoothly. Network traffic is encrypted in transit. Database access controls restrict signed-in users to their own records and shared-list records they are permitted to see. No system can guarantee absolute security, but ItemOrbit uses reasonable technical safeguards appropriate to the information it handles.

Retention and deletion

ItemOrbit keeps account and inventory information while you maintain your account. You may delete individual items, categories, people, and lists in the app. You may permanently delete your account from Settings, or request deletion using the external process on the account deletion page. Uninstalling the app does not delete your account.

Completing account deletion removes your profile, inventory, owned shared lists, shared-list access, subscription-entitlement record, and authentication account from the live service. It also removes associated agreement receipts, block records, reports linked to the account, and their alert-queue records, and requests deletion of the matching RevenueCat customer profile. Items contributed by other users to your shared lists remain with their creators as private items. Deleting either account involved in a safety report removes that report from the live database; deleting only an item or list does not remove its report snapshot.

Deleting an account does not cancel a Google Play subscription. Subscriptions must be cancelled through Google Play. Google Play may retain purchase records under its own policies and legal obligations.

Support and safety records

We keep support correspondence and safety reports while a case is being handled. Routine support emails, resolved or dismissed safety reports and their saved content, and related alert records are deleted within 90 days after the case is resolved or closed. We review these records monthly and may remove them sooner. This is a retention limit, not a promise to resolve a case within 90 days.

Limited records may be kept longer when needed for an active dispute, security investigation, or legal requirement. We document the reason, restrict access, review the need regularly, and delete the records when that reason no longer applies. These exceptions do not change the live account-deletion behavior described above.

Support correspondence and safety-alert emails are stored separately from the app database and are not automatically erased by in-app account deletion. Contact itemorbit@gmail.com to request deletion of those records or other information you cannot remove in the app. We verify account control without asking for your password and handle valid requests under applicable requirements; requests do not have to wait for the routine 90-day cleanup. If information must be retained, we explain the reason unless prohibited by law.

Provider logs, backups, and separate copies

Service and authentication logs are separate from inventory records. Under our current Supabase Pro plan, routine project logs and daily database backups have a seven-day retention window. Resend, our email-delivery provider, retains email and delivery-log data for 30 days under our current plan, with backups persisting for seven days. These provider periods do not delete messages in our separate support inbox. Provider account, billing, and security records may follow different retention rules.

Deleting live data does not immediately erase copies in routine encrypted backups. Those copies expire through the provider's backup cycle and are not used for ordinary app operation. If a backup is restored, applicable deletions must be reapplied before restored personal data is returned to ordinary use. We may retain limited incident-related diagnostic records only while needed for the security or legal purposes described above.

Devices may retain offline cached data, and you can remove local app data through your device settings. Account deletion cannot remotely erase copies another person has exported or saved outside ItemOrbit. For details about provider-held records, see Supabase's privacy policy, Resend's retention information, RevenueCat's privacy policy, and Google's privacy policy.

Your choices

You control what inventory information you enter and which lists you share. You can update or delete records in the app, leave lists you do not own, reset your password, or permanently delete your account. For help accessing or correcting your information, contact ItemOrbit support.

Children's privacy

ItemOrbit is a general-audience household organization service and is not directed to children under 13. ItemOrbit does not knowingly collect personal information from children under 13.

Policy changes

This policy may be updated as ItemOrbit changes. The effective date at the top of this page will be revised when a material update is published.