Privacy

What we store, and what we never do

This page describes the data the running service actually holds. It is a plain-language summary, not a contract; the formal privacy notice is outstanding, and until it is published this is the accurate description.

What we store

What we never store

Retention

Ledger entries and invoices are kept for as long as the account exists, because they are what a bill is reconciled against. Deprovisioning a resource deletes its stored credentials immediately and leaves the record so history survives. Deleting a team removes its projects and memberships.

Sub-processors

Stripe for payments, and the provisioning services behind each resource type — a bucket you ask for is created at the provider that offers it. Budget alert email is sent by Resend.

Getting your data

Everything the dashboard shows is available from the API under your own token — /api/v1/resources, /api/v1/ledger, /api/v1/invoices and /api/v1/activity — so an export is a script, not a request. For deletion, or anything else, write to hello@extraorbital.dev.

See also the terms of service and the documentation. ExtraOrbital is operated at extraorbital.dev.