Privacy notice
Who we are
Orbtile ("we"), made in Europe. Contact: [email protected].
What we collect
- Your email address.
- Which waitlist you joined: Windows, or other keypads.
- The keypad devices and AI coding agents you optionally select, and the short "other device" text if you type one.
- The time you gave consent and the version of this notice (wl-2026-09-29s).
- For 30 days only, a one-way keyed hash of your IP address, used to block abuse. We never store the IP address itself.
We do not collect your name through the waitlist. Announcement emails do not use tracking pixels or click tracking.
Why, and on what legal basis
To (a) email you when Orbtile is available for the platform or device you chose, including a beta invitation, and (b) count anonymous interest per device and agent to decide what we build next. Legal basis: your consent (GDPR Art. 6(1)(a)). The IP hash and the anti-bot check rely on our legitimate interest in keeping the form free of spam (Art. 6(1)(f)).
How the list works
You enter your email and submit the form. That is your sign-up; we do not send a confirmation email. We store your entry so we can write to you when the product, platform, or device you asked for is ready. We write at most once per announcement, and every email has an unsubscribe link.
Bot protection
The form uses Cloudflare Turnstile, which processes technical signals from your browser to tell humans from bots. See Cloudflare's privacy policy.
Who processes it for us
- Cloudflare, Inc.: hosting, the database (stored in the EU), and anti-bot checks.
- Email delivery provider (when announcement emails are sent).
- Google: optional website analytics, only after you allow analytics cookies.
Only the Orbtile operator can view waitlist email addresses in the private admin dashboard. We never sell your data. We share data with the processors listed here only to provide these services.
How long we keep it
- Waitlist entries: until the product is available plus 30 days, or at most 24 months from sign-up, whichever is sooner.
- IP hashes: 30 days. Rate-limit counters: 2 days.
- Unsubscribing deletes your entry immediately.
Your rights
You can withdraw consent at any time with the unsubscribe link in every email; this deletes your entry and does not affect earlier processing. You can also ask for access, correction, deletion, restriction or portability, or object, by writing to [email protected]. We answer within one month. You can complain to the Comissão Nacional de Proteção de Dados (CNPD, www.cnpd.pt) or to your local authority.
No automated decisions
No automated decisions or profiling are made about you.
This website
Our server counts page views and installer downloads. These server counters use no cookies or browser tracking script. Eligible page loads add to daily counters for the page, the country (from Cloudflare's network), the referring site (a short list of well-known sites by name; any other site is counted only as other), and the browser and operating system family. Installer download counters keep only the UTC day, version and country. Beta status fetches are counted separately by UTC day and app version, without a machine or visitor identifier. Bots, prefetches and requests beyond the counter budget can be omitted. Our counters store no IP address or visitor identifier. Cloudflare processes request addresses and technical headers to deliver and protect the service. The counts cannot tell visitors apart. We keep them for 13 months. Hourly cleanup removes counts once their UTC day is older than 395 days; failed or delayed runs can delay deletion.
Separately, if you choose Allow analytics, this website loads Google Analytics 4 to understand how visitors use it. Before you allow it, no Google Analytics script loads and no request is sent to Google Analytics. Analytics may collect pages visited, referring sites, approximate location, device and browser information, and interactions, including outbound link clicks and file downloads through enhanced measurement. Google processes this information for us. It uses cookies named _ga and _ga_* to distinguish browsers and sessions. We do not enable advertising consent: advertising storage, advertising user data and advertising personalization remain denied. The legal basis for this optional analytics is your consent (GDPR Art. 6(1)(a)). See Google's privacy policy.
Your choice is remembered in this browser's local storage. Use Cookie settings in any page footer to change it. Choosing No thanks withdraws permission, disables further Google Analytics collection on the current page and removes analytics cookies accessible to this website. Future page loads do not load Google Analytics unless you allow it again. Withdrawal does not affect earlier processing. The Orbtile Mac app does not use Google Analytics.
Feedback
When you choose to send feedback, we receive the message and category, whether it came from the app or website, and an optional email address if you want a reply. App feedback also includes the app version and the same pseudonymous machine ID used by usage reports, re-keyed on our server for abuse limits. The machine ID is not stored with the feedback item.
In the app you can choose to include diagnostics: app build, macOS version, keypad connection status, enabled built-in agents, theme, and four settings (automatic keypad takeover, key actions, background sessions and handover on sleep). You can review this before sending. Diagnostics contain no prompts, transcripts, paths, host names, or account names. Feedback messages contain what you type and are stored as submitted; please leave out secrets, personal information and private task text.
We use feedback to answer requests and improve Orbtile, based on our legitimate interest in maintaining and improving the product (GDPR Art. 6(1)(f)). Feedback, optional email, diagnostics and internal triage notes are kept for 365 days and deleted on the next hourly cleanup run. Keyed IP and machine abuse counters are kept for two days and deleted on the next hourly cleanup run; raw IP addresses are never stored. Cloudflare hosts the database in the EU. Website feedback uses Turnstile. Delayed or failed cleanup runs can delay deletion.
If an app submission cannot be delivered, the app keeps a local queued draft and retries hourly until the server accepts it. Contact [email protected] to request access or deletion; include your feedback reference if available.
The Orbtile app
The sections above cover the waitlist, website and voluntary feedback. This section covers the Orbtile app for macOS, which runs locally on your computer.
- What it reads: the end of each Claude Code session's transcript file on your Mac (the last 256 KB) to show the assistant's latest words on the key. For each subagent of a session it also reads the subagent's small metadata file (its name and type), the name of its workflow, and after a restart the end of its transcript, to label its key. These transcript reads stay local; automatic reports never include their text. For Codex, it reads local thread state and the ends of rollout files, including desktop threads and
codex execruns, to show state, tool labels and live text. When ZCode is installed, it also reads ZCode's local task database, read-only and, only while you have keypad approvals for ZCode turned on, ZCode's settings file ~/.zcode/cli/config.json. - How agent events arrive: over a private Unix-domain socket that only your user account can open. The app opens no network port. If you turn on keypad approval for Claude Code, Codex or ZCode, permission decisions return over that local socket. For Claude Code, selected question options also return over the socket.
- What it writes: its own settings and a small file of usage counters (kept until they are sent), stored on your Mac. Unsent feedback is also stored locally until accepted, and saving a keypad snapshot writes local images that can contain the text visible on the keys. These files are not automatically uploaded. When you connect an agent, it installs a small plugin (Claude Code) or hook entries (Codex) that send session events to the app over that socket; your own settings and hooks are kept, and removing the integration takes them out again. ZCode needs nothing installed; only if you turn on keypad approvals for ZCode, Orbtile adds one hook entry to ~/.zcode/cli/config.json (marked as Orbtile's, with a backup of the file kept in Orbtile's own folder) that sends ZCode's permission requests to the app over that socket, and it removes that entry when you turn approvals off. The rest of the file, including your MCP servers, is kept as it was. During the beta it stores nothing in the macOS Keychain.
- What it sends automatically: two kinds of request to orbtile.com, both without cookies. (1) A signed beta status check at orbtile.com/beta/status.json, at launch and once a day; it carries the app version and no identifier. (2) A usage report with cumulative counts for the UTC day: a machine ID, the app and macOS versions, the processor type, the interface language, whether a supported keypad was connected, how often the app started and how many minutes it ran and drove the keypad, for each built-in agent whether it is turned on, how many sessions and subagents it had, the most sessions at once and its busy minutes; for third-party adapters only how many are allowed, their session count and busy minutes; the names of the AI models they used with minutes per model, which features and settings were used, keypad approve and deny counts, error counts by type, and the number of unexpected exits. Settings choices (no personal text) are reported, including the current keypad theme (Frosted glow, Globules and Point cloud), minutes per theme for each UTC day, on/off switches, per-agent choices, exact numeric values and adapter/remote-host counts. Our server adds the country the request came from. A small usage summary is sent at most every 2 hours while Orbtile runs, only when it changed; the server keeps one row per Mac per day. Completed days and quit reports are also sent.
- The machine ID is a one-way keyed hash of your Mac's hardware UUID. It is pseudonymous: it lets us count Macs and see how use changes over time, it does not contain the hardware UUID, and we cannot turn it back into it. The same Mac gives the same ID, also after a reinstall. If the hardware UUID cannot be read, the ID is a keyed hash of a random ID stored on your Mac instead.
- What the report never contains: your name, email or account names, user or computer names, file or folder paths, project or session titles, prompts, transcripts, task text, tool commands, host names, IP addresses or the hardware UUID itself. Dates are kept by day, not by time.
- Why: to learn which Macs, agents, models and features are used, so we can decide what to fix and build next. Legal basis: our legitimate interest in keeping the product working and improving it (GDPR Art. 6(1)(f)). We keep usage reports for 13 months.
- How long: we keep usage reports for 13 months, then delete them. Hourly cleanup removes reports once their UTC day is older than 395 days. To limit abuse, a one-way keyed hash of the sender's IP address (for IPv6, of its /64 network) is used in short-lived rate counters. Hourly counters expire two hours after the window starts; new-machine daily counters expire two hours after the UTC day ends. Hourly cleanup normally removes these within 27 hours; the IP address itself is not stored. Cleanup runs independently of app traffic; delayed or failed runs can delay deletion.
- What it never does: it shows no macOS notifications. Automatic reports never send your transcript or task data.