Last updated: 2026-09-22
Privacy Policy
1. Who is responsible for your data?
The data controller for Orbis Signal is Jan Wir-Konas (operating as Orbis Signal), established in Germany.
Address: Auf der Dorn 24, 40764 Langenfeld (Rheinland), Germany
Email: contact@orbis-signal.com
Orbis Signal is operated independently prior to incorporation. Until a registered company is formed, Jan Wir-Konas is the controller named in this policy. We will update this page if that changes.
We have assessed that appointing a Data Protection Officer (DPO) is not required for our current processing (Art. 37 GDPR / § 38 BDSG). You can still contact us at the email above for any privacy question.
2. What this policy covers
Orbis Signal is a website that publishes intelligence briefings on global politics, finance, and technology. You can read content without an account. Creating an account is optional and free. There is currently no paid subscription, checkout, or content paywall.
The service is intended for adults. It is not directed at children under 16, and we do not knowingly collect data from children.
3. Lawful bases
Under the EU General Data Protection Regulation (GDPR), we need a lawful basis for each use of personal data. We rely on:
- Contract (Art. 6(1)(b) GDPR) — creating and securing your account, sending sign-in and verification emails, and providing the website features you request.
- Legitimate interests (Art. 6(1)(f) GDPR) — running a secure, reliable website, preventing abuse, answering contact and support messages, and measuring anonymous usage and performance. You may object (see section 10).
- Consent (Art. 6(1)(a) GDPR) — where we ask you to opt in, currently the iOS TestFlight application form. You can withdraw consent at any time.
Storing information on your device or accessing information already stored there is also governed by § 25 of the German Telecommunications-Telemedia Data Protection Act (TDDDG). Strictly necessary storage does not require consent. Other storage requires consent unless an exception applies. See section 8.
We do not currently send marketing emails, product newsletters, or a briefing-by-email service. If a signup screen shows an optional mailing checkbox, that choice is not stored and no such emails are sent. If we introduce marketing later, we will ask for a separate opt-in and update this policy.
4. Personal data we collect
- Account data: email address, optional password (stored as a hash), verification status, last sign-in time, and authentication method (email link, password, Google, or Microsoft).
- Sign-in with Google or Microsoft: we receive an identifier and email address from the provider. The provider may also send a display name; we do not store that name. Google and Microsoft act as independent controllers for their own sign-in screens.
- Security tokens: hashed single-use tokens for magic links, email verification, and a short-lived cross-device sign-in handshake.
- Contact and support: topic, message, and optional reply email, plus any page URL or steps you include. You may submit without an email.
- iOS TestFlight applications: full name and email address (use the email on your Apple ID).
- Technical data: IP address used for short-lived in-memory rate limiting (not stored in our database). When you play a podcast, your device requests the audio file from our media host (see section 6).
- Cookies and similar technologies: see section 8.
We do not sell personal data. Editorial briefing text is not personal data about you. The public content API does not require a login and does not collect account data.
5. Why we use your data
- Provide the website and optional accounts.
- Authenticate you and keep sessions secure.
- Send transactional email (sign-in and verification links).
- Respond to contact and support messages when you ask us to.
- Invite you to the private iOS TestFlight beta if you apply.
- Prevent abuse (rate limits, honeypot fields on forms).
- Measure anonymous usage and site performance (Vercel).
6. Recipients and service providers
We use providers that process data on our instructions. Data-processing agreements are being finalized with each provider.
- Neon — database hosting (EU region: Frankfurt).
- Vercel — website hosting, scheduled jobs, and anonymous analytics and performance monitoring (functions region: EU Frankfurt).
- Brevo — transactional email (sign-in and verification).
- Mailjet — delivery of contact and support messages and internal operational alerts to us. We do not use Mailjet for marketing to you.
- Cloudflare — storage and delivery of podcast audio (Cloudflare R2). When you press play, your device connects to that host.
- Google or Microsoft — only if you choose to sign in with that provider.
- Apple (TestFlight) — if you apply for the iOS beta, we share your name and email with Apple so we can add you as a tester. Apple processes that data under its TestFlight terms.
Editorial production (research, writing, quality control, and spoken podcasts) uses tools such as Google, OpenAI, and ElevenLabs, and runs on Railway. Those systems process public news sources and briefing text. They are not used to process your account, contact form, or TestFlight data.
7. How long we keep data
- Account data: until you ask us to delete your account.
- Magic-link tokens: 15 minutes, then deleted.
- Email verification tokens: 24 hours, then deleted.
- Login handshakes: 15 minutes, then deleted.
- Contact and support submissions: as long as needed to handle your request and to document how we responded, typically up to 24 months, unless you ask us to delete sooner and we have no legal reason to keep the record.
- iOS TestFlight applications: until you withdraw the request or ask us to delete it, or until the beta programme ends.
- Server and platform logs: according to Vercel, Neon, and Cloudflare retention, typically rolling windows of days to weeks.
Database backups may briefly retain deleted data until rotated.
9. International data transfers
We are established in Germany. Primary application and database hosting for production is in the EU (Frankfurt).
Some providers are international companies. Support, infrastructure, or identity sign-in may involve access from the United States or other countries outside the EEA (in particular Vercel, Brevo, Mailjet, Cloudflare, Google, Microsoft, and Apple). When that happens, we rely on GDPR-approved transfer tools, typically Standard Contractual Clausesin the provider's terms, and we choose EU regions where the product allows it.
10. Your rights
Under the GDPR you have the following rights, subject to legal limits:
- Access — a copy of personal data we hold about you.
- Rectification — correction of inaccurate data.
- Erasure — deletion in certain circumstances.
- Restriction — limits on how we use your data.
- Portability — data you provided, in a machine-readable format, where applicable.
- Object — object to processing based on legitimate interests.
- Withdraw consent — where we rely on consent (currently TestFlight applications).
- Complain — lodge a complaint with a supervisory authority.
How to exercise your rights: email contact@orbis-signal.com from the address registered on your account where relevant. We respond within one month (extendable by two months for complex requests, which we will explain).
Self-service download and delete controls in account settings are not available yet. Until then, contact us at the address above.
11. Security
We use encrypted connections (TLS), hashed passwords and single-use tokens, signed session cookies, and database access controls. No method of transmission or storage is completely secure.
12. Supervisory authority
You may complain to the data protection authority where you live, work, or where an alleged infringement occurred. Because we are established in North Rhine-Westphalia, the competent authority for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW). You may also contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI).
13. Changes to this policy
We may update this policy when our service, providers, or legal requirements change. We will post the new version on this page with an updated date. If we introduce paid features, additional processors, or marketing email, we will revise this policy before those activities start.