Last updated · August 9, 2026
1. Overview
This policy explains what information Orbioom LLC (“Cyborb,” “we”) processes when you use the Cyborb desktop application, CLI, mobile apps, websites (cyborb.ai), and site hosting (cyborb.app) (together, the “Service”), and what rights you have. The short version: Cyborb is local-first. Your code and conversations live on your machine; prompts are passed through to AI providers to answer your requests, not stored by us; and the records we do keep are metering, account, and hosting metadata, not content. We are the controller for the processing described here. Contact: orbioomtech@gmail.com.
2. What stays on your machine
The desktop app stores your projects, code, chat threads and messages, attachments, scheduled prompts, settings, logs, and local diagnostics on your device (under ~/.cyborb), protected by your operating-system permissions; authentication tokens are stored in files restricted to your user account. We cannot access any of this. Your code and files leave your machine only as context included in a request you make. For example, when you send the agent a message or publish a site.
3. Prompts, code, and generated media: pass-through, not storage
When you use the managed Cyborb Agent, generation, or voice features, your prompts, included code context, images, or audio are transmitted through our proxy to the AI model or media provider serving your request, and the response streams back to you. Our proxy does not store or log the content of your prompts, messages, code, images, or audio. What we durably record about each request is metering metadata only: your account ID, the feature kind, the model alias and provider, token counts, an internal cost weight, a status, and a timestamp. No content, no IP address, no device fingerprint. Voice audio is passed to the speech provider and streamed back without being persisted by us.
4. Account, billing, and entitlement data
Authentication is provided by Clerk, which processes your email, sign-in identity, and session cookies. Payments are processed by Clerk Billing and Stripe; we never see or store your card number. We keep a minimal entitlement record (your user ID, plan tier, plan slug, subscription status, its source, and a timestamp) to unlock your plan across the website, desktop app, and CLI. If you purchase or connect a custom domain, we store the domain name, its status, provider references, and billing references (such as a Stripe subscription ID); registrant contact details are handled by the domain registrar (Cloudflare).
5. Published sites and their visitors
When you publish a site we store the site’s files (to serve them), plus metadata: site name, your user ID, size, file count, version, custom domain, and timestamps. For each published site we collect aggregate, privacy-preserving visitor statistics for the site owner: one record per page view containing the site name, path, referrer host, and a visitor identifier that is a truncated, salted hash which rotates daily; we never store visitors’ raw IP addresses, we set no cookies on published sites, and visitors cannot be tracked across days. Site owners see only totals and daily trends. If you publish a site, you are the party responsible for that site’s own content and any data it chooses to collect from visitors, including its own legal compliance.
6. Desktop app telemetry
The desktop/CLI app sends anonymous product-usage events to PostHog, our analytics processor, to help us understand feature usage and improve the Service. This telemetry is metadata only: it never includes prompts, code, file contents, or file paths. Events carry a pseudonymous ID (a one-way hash, not your name or email), platform and app-version details, feature and provider labels, and counts (for example, number of attachments). Telemetry is on by default; you can disable it at any time by setting the environment variable CYBORB_TELEMETRY_ENABLED=false. Diagnostic traces stay in a local file on your machine unless you explicitly configure an export destination. The cyborb.ai website itself uses Cloudflare Web Analytics, a cookieless, aggregate measurement service (page views, referrers, performance timings) that stores no personal information and does not track you across sites.
7. Remote access (P2P)
Remote access is off by default. If you enable it, devices connect peer-to-peer with end-to-end encryption; our relay stores only the signaling metadata needed to introduce your devices (a room ID, your user ID, and opaque encrypted handshake blobs we never parse), and these records are pruned automatically. We cannot see the content of remote-access sessions. Connection setup may use Cloudflare and Google STUN/TURN infrastructure, which processes IP addresses to establish the connection.
8. Who we share data with (sub-processors)
We use these categories of providers: Clerk (authentication and billing), Stripe (payments), Cloudflare (hosting, storage, domains, networking, aggregate analytics), PostHog (desktop telemetry), and AI model and media providers that serve your requests. Model and media providers currently include DeepSeek, Zhipu (Z.ai), OpenRouter, Google (Gemini), MiniMax, fal.ai, OpenAI, and ElevenLabs; the provider serving a given model or feature can change. Each provider processes data under its own terms; we do not sell your personal information, and we do not share it for cross-context behavioral advertising.
9. International transfers
Our infrastructure providers operate globally, and some model providers process requests in countries other than yours, including providers based in the People’s Republic of China (currently DeepSeek, Zhipu, and MiniMax), a country not covered by an EU/UK adequacy decision and where local law may permit government access to data. Prompts routed to such a provider are processed on its servers under its terms, which may include use for service improvement. Do not include personal or sensitive data in prompts if this concerns you. Where GDPR applies to a transfer we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or the provider’s certified transfer framework.
10. Purposes and legal bases
We process: account, billing, and entitlement data to provide the Service you signed up for (performance of a contract); prompts and content pass-through to fulfil the requests you make (performance of a contract); metering, abuse-prevention, audit, and security records to keep the Service fair and safe (legitimate interests); telemetry to improve the product (legitimate interests, with the opt-out above; where local law requires consent, we rely on your continued-use configuration choice and honor the opt-out). We make no solely automated decisions about you with legal or similarly significant effect; usage limits are applied automatically but affect only service throughput and can be reviewed by a human on request.
11. Retention
We keep data only as long as needed for the purpose: entitlement and billing-integrity records for the life of your account and as required for financial record-keeping; metering and audit records for as long as needed for billing accuracy and abuse prevention; published-site files and metadata while your site is published (unpublished or taken-down sites may be deleted; keep local copies); P2P signaling rows for days at most (pruned automatically). Data held by our providers (Clerk, Stripe, model providers) follows their retention schedules.
12. Your rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict the processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. We extend access, correction, and deletion requests to all users regardless of location. To exercise any right, email orbioomtech@gmail.com from your account address; we will verify and respond within the legally required time. We honor Global Privacy Control signals for the site by not selling or sharing personal information in the first place. If you are in the EU or UK you may also lodge a complaint with your supervisory authority or the ICO.
13. Security
We design for data minimization first: the most sensitive data (your code) never reaches us. Beyond that: transport encryption everywhere, end-to-end encryption for remote-access sessions, provider API keys held only server-side, local secrets stored with restrictive file permissions, and hashed, daily-rotating visitor identifiers for site analytics. No system is perfectly secure, and we cannot guarantee absolute security; we will notify affected users of a breach as required by law.
14. Cookies
cyborb.ai uses only strictly necessary cookies (Clerk’s authentication and session-security cookies), which do not require consent banners. We run no advertising or third-party tracking cookies. Published sites on cyborb.app receive no cookies from us; whether a published site sets its own cookies is the responsibility of its owner.
15. Children
The Service is for users 18 and older. We do not knowingly collect personal information from children; if we learn that we have, we will delete it and close the account.
16. Changes and contact
We may update this policy as the Service evolves; material changes will be announced by email or in-product, and the date above always reflects the current version. Questions, requests, and complaints: orbioomtech@gmail.com. See also our Terms of Service.