Designed with boundaries

Your inventory is personal. We treat it that way.

ItemOrbit uses authenticated access, encrypted network connections, and list-level permissions to keep personal and shared information in the right hands.

Private by default.
Shared by choice.

Personal items are restricted to the signed-in account. Family content becomes visible only through lists the owner chooses to share with registered ItemOrbit users.

Account protection

ItemOrbit uses Supabase authentication for account sessions and secure password-reset links. Passwords are not stored in the ItemOrbit app or database as readable text.

Access controls

Database row-level access rules restrict users to their own records and shared-list records they are authorized to view. Anonymous inventory requests are rejected.

Secure connections

App, authentication, purchase, and website traffic uses encrypted HTTPS connections while moving between your device and service providers.

Payment separation

Google Play processes Android purchases. ItemOrbit and RevenueCat receive purchase status needed to unlock a plan, not your full card or bank details.

Deletion controls

You can delete individual records or permanently delete your ItemOrbit account. The public deletion page is available if you no longer have app access.

No advertising profile

ItemOrbit does not sell personal information and does not use inventory content for targeted advertising or cross-app tracking.