Privacy Policy

Last updated: August 21, 2026

This English version is the authoritative one. A German translation is available at Datenschutz; it is provided for convenience only.

1. Who processes your information

Orchivia
1039 Coffeen Avenue, Suite 1200
Sheridan, WY 82801, USA
[email protected]

Orchivia is operated from the United States. Wherever you use the app: your information is processed by us and may be stored in the United States. Privacy questions go to [email protected].

2. What information we process

Everything listed here you either entered yourself, or it arises from running the app:

We do not sell information and we do not run ads. There is no ad network in Orchivia, no tracking across other sites, and no trade in data. This is not a statement of intent but the business model: Orchivia earns its money from subscriptions.

3. Chats are encrypted

Messages and attachments are stored encrypted (AES-GCM); the key is delivered only to members of your family. The operator does not read your chats.

To be honest about it: a residual technical means of access through the database exists as long as no client-side key exchange is implemented. We say so plainly instead of promising more than we can keep.

4. Location information

Location sharing — family map, location in chat, tracking devices — is expressly opt-in, can be switched off per person, and is visible only within your family.

During an active trip (the way to school, the way home, a pickup) the Android app also transmits the location while the screen is off — but only for as long as the trip runs: it is started explicitly, ends at the stated time at the latest, and can be cancelled at any moment. No route history is stored, only the most recent position for the family map; it expires after a few minutes.

On a child’s device the app additionally shows a remaining-distance map during a trip (“400 m to go”). The position used for this stays on that device: it is neither transmitted nor stored. Parents still see only that a trip is running and when it ends — no route.

Weather, place and travel-time lookups run through our own servers, so the providers behind them see neither your IP address nor your device; coordinates are rounded in the process. One exception we name openly: your device loads the map tiles directly from OpenStreetMap. In doing so, OpenStreetMap learns your IP address and, from the map section, the approximate area you are looking at.

5. Photo storage and faces

Photo storage keeps photos encrypted: resizing, thumbnail and encryption happen on your device, our storage contains ciphertext only. The same limitation applies as with chats (section 3): the key belongs to your family but resides in our database so that you do not lose it when changing devices — so a residual technical means of access exists as long as no client-side key exchange is implemented. At first a photo is stored only for you (“private”); it becomes visible to your own family only once you release it.

If you share a photo with a connected family, a separate copy is created on your device and re-encrypted to the shared key of those two families. The other family does not receive your family key. If you withdraw the release, the copy is deleted.

Face recognition can be switched off and is off by default. When it is on, it runs exclusively on your device: the app detects faces there and computes a numeric value per face that reaches us only encrypted — we can neither reconstruct a face from it nor compare two faces. The name you give a face is stored encrypted as well. None of this is used to train AI, neither by us nor by third parties. Faces without an assignment — people you do not name — are deleted after 30 days; if you switch the feature off, all face data is deleted immediately.

6. Artificial intelligence

For outing and class suggestions, text snippets and the assistant we use a language model, connected through our own gateway.

What is transmitted: pseudonymized profile details — age, level of supervision, interests, the location in rounded form. What is not transmitted: names, email addresses, photos, chat content, exact addresses, position histories.

The model providers process these requests on our behalf and are contractually barred from using them for training. Can be switched off under “Data & sharing” — the suggestions then go away, everything else stays.

Voice input: when you hold the Orbi button and speak, your device does the recognition itself where possible — the recording then does not leave it. If it cannot, you have two options, and both mean the recording is transmitted: in the browser to its own speech recognition (with Chrome, to Google), in the app to our own gateway, which turns it into text and discards it afterwards. We do not store voice recordings. If you would rather not, type — the button is an offer, not a requirement.

What a language model outputs can be wrong, out of date or entirely made up. It is not educational, medical or legal advice and no assurance about the suitability or safety of an offering for your child. Check what matters.

7. Service providers we use

Notifications never carry content. No message text, no address, no coordinate — only the kind of event and a first name from your own family. A notification lands on a locked screen and is readable by anyone who sees it.

8. How long we keep information

Information stays stored for as long as your account exists. After a deletion request, account and family data are removed within 30 days; backup copies are overwritten after 35 days at the latest. The payment provider keeps billing records under the rules that apply to it; they contain no content from the app.

9. Your choices and rights

In the settings: “Export data” downloads all of your family’s data as JSON. “Close account” files a logged deletion request. Individual areas — location history, albums, a child profile — can also be deleted separately without giving up the account.

Without access to the account it works by email; how, is described under Delete account. Residents of California have additional rights under the CCPA/CPRA — access, deletion, correction and the right to opt out of a sale of their personal information. Since we do not sell information, the opt-out has nothing to apply to; the remaining rights you exercise through the same routes.

10. Children

Children do not have their own account in Orchivia. Child profiles are created exclusively by the legal guardians, and the details in them come from those guardians. We do not collect information from children directly and do not direct the app at children under 13 as independent users.

Photos of children are optional and visible only to your own family and to expressly connected families. If a legal guardian learns that a child was entered without their consent, we delete the details after a message to [email protected].

11. Security

Transmission is encrypted throughout (TLS), access to family data is restricted at the database level to your own family, passwords are stored only as a hash, chats are encrypted on top of that. No one can promise complete protection — anyone who does is not telling the truth.

12. Changes

We may change this policy. We announce material changes at least 30 days in advance in the app or by email. The date at the top tells you which version applies.

13. Governing language

The English version is binding; translations serve comprehension only. The law of the State of Wyoming, USA applies — see Terms of Service.

Terms of ServicePrivacyProviderRefundsDelete accountDeutsch

Privacy Policy – Orchivia