Index/privacy

Privacy Policy

Last updated August 4, 2026

OrbitalWiki (“we”, “us”) is an early-access prototype operated by Marko Kovalevskis as an independent, unincorporated project at orbitalwiki.com. This policy explains what personal data we collect across our website, developer accounts, and the OrbitalWiki API, why we collect it, the legal basis for processing it under the EU General Data Protection Regulation (GDPR), and the rights you have. For details on cookies and similar technologies, see our Cookie Policy.

1. Who is responsible for your data

The data controller is Marko Kovalevskis, operating OrbitalWiki as an individual. We have not appointed a representative or a data protection officer, because the project is small and does not carry out large-scale or high-risk processing. You can reach us at hello@orbitalwiki.com.

2. Information we collect

Newsletter sign-up. The weekly “Today in Orbit” digest has a public sign-up form. We collect the email address you submit, and we send a confirmation email you have to click before you are subscribed, so an address entered by someone else is never added. We store when you confirmed and which categories you chose. Every digest carries a one-click unsubscribe link, and unsubscribing removes you from the send list.

Early-access form. When you join the launch list we collect the email address you submit.

Server and security data. Like any website, our servers receive standard request data such as IP address, user agent, request path, timestamp, and error logs. Forms on the site run anti-abuse checks such as origin validation, rate limiting, and a hidden honeypot field that only an automated submitter would fill in. The newsletter form can also use a Cloudflare Turnstile challenge, but that is switched off at the moment; if we turn it on we will update this policy first.

Analytics (opt-in, cookieless). We use PostHog to understand aggregate usage, for example pages viewed, basic events, approximate location derived from your IP address, and device and browser type. Analytics only run if you choose “Accept analytics” in the consent banner shown on your first visit; if you decline, no PostHog events are sent. Even when enabled it runs in cookieless mode: it sets no cookies and does not track you across other sites. Your choice is remembered with a single strictly-necessary entry in a first-party cookie so we do not ask again.

Referral counting (no cookies, no opt-in). On every visit our own server reads the Referer header your browser sends and adds one to a daily counter for the kind of place the visit came from, for example a search engine, an AI assistant, or a social network. That is the whole record: a date, one of nine fixed category names, and a number. No page address, no referring address, no IP address, no device or country information, no identifier, and never more than nine rows a day however much traffic arrives. Visits with no referrer, and visits that came from our own pages, are discarded before anything is written at all. It runs whatever you chose in the banner, because it is how we know whether anyone is finding the site. One thing to be clear about: because this happens on our server rather than in your browser, a tracker blocker does not stop it. Nothing is stored that could be traced back to you or joined to anything else. As of today none of this is switched on yet: nothing has been recorded, and the referrer your browser sends is discarded without being stored.

Error monitoring (opt-in). We use Sentry to diagnose crashes and failed requests only after you choose “Accept analytics”. Browser telemetry is not loaded before that choice, and request-linked server or edge events without an accepted consent cookie are discarded. Withdrawing consent stops new telemetry events.

Developer accounts and API keys. If you create an account, we store your email address and an authentication record. When you generate an API key we store a hash of the key (never the key itself). To prevent abuse, such as one person farming many free keys from multiple accounts, we also record, at the moment of key creation, the IP address and a device fingerprint (a value derived in your browser from your device and browser characteristics), together with per-key usage counts. The fingerprint is computed locally in your browser; we do not use a third-party tracking service for it.

How you found us (optional). The signup form asks, optionally, how you heard about OrbitalWiki, with a list of choices such as a search engine, GitHub, or a friend, and a short free-text box if you pick “something else”. You can leave it unanswered and the account is created exactly the same. We store your answer against your account, we only ever look at the totals, and we never publish or share it. If you sign up with Google, only the choice you picked is recorded, never the free-text box.

Sign-in and account security. When you sign in to a developer account, our authentication provider records security data such as the time of sign-in, the IP address the request came from, and session and token metadata. We use this to keep your account secure, to detect and investigate unauthorized access, and to support account recovery.

Billing data. When paid subscriptions are enabled, checkout, payment method details, invoices, tax handling, and subscription lifecycle events are processed by Lemon Squeezy, our payment provider and merchant of record. Your checkout details (including your email and the plan you choose) are submitted to and handled by Lemon Squeezy under its own terms and privacy policy. We store the account email, plan, subscription status, customer identifiers, and webhook events needed to grant or revoke access. We do not store full payment-card numbers.

Contributions and personal features. When you use the interactive features of a signed-in account we store what you create: your watchlists and collections (the satellites, operators, and other entities you follow or save, linked to your account id), any saved catalog queries or data stories you build, and your newsletter category choices. If you submit a mission or a developer-showcase entry for review, we store the details you provide, including the contact email you supply, plus limited anti-abuse metadata (a hashed IP address and user agent); a person reviews submissions before anything is published. If you vote on the public roadmap we store only an aggregate count and a salted, one-way hash of your account id, never your email, name, or IP, and one vote per account is enforced.

3. Why we use it and our legal basis

  • Manage the launch list and contact you. We send only the launch and product updates you asked for. Legal basis: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time.
  • Keep the service secure and prevent abuse. This covers origin checks, rate limiting, and bot detection. Legal basis: our legitimate interests in protecting the service (Article 6(1)(f) GDPR).
  • Provide developer accounts and API access. Creating an account, issuing and managing API keys, and counting usage against your plan. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
  • Secure your account. We process sign-in and account-security records, such as sign-in times, IP addresses, and session and token metadata, to protect your account and prevent unauthorized access. Legal basis: our legitimate interests in protecting accounts and preventing unauthorized access (Article 6(1)(f) GDPR), and, where applicable, performance of a contract with you (Article 6(1)(b) GDPR).
  • Prevent API-key abuse. We use the IP address and device fingerprint recorded at key creation to detect and block the same person creating multiple accounts to bypass free-tier limits. Legal basis: our legitimate interests in preventing fraud and abuse (Article 6(1)(f) GDPR). You can object to this (see your rights below); if a block is mistaken, contact us and we will review it manually.
  • See which channels bring people here. If you answer the optional “how did you find us” question at signup, we count the answers to decide where to spend our effort. Legal basis: your consent (Article 6(1)(a) GDPR), given by choosing an answer; leaving it blank means no answer is stored.
  • Understand and improve the product. This is what our cookieless analytics are for. Legal basis: your consent (Article 6(1)(a) GDPR), given through the consent banner, which you can withdraw at any time by declining analytics or contacting us. PostHog and Sentry are not loaded before you opt in.
  • Know how many people reach the site. Our own server counts referrals by category, with no cookie, no identifier stored in your browser, and no profile. Legal basis: our legitimate interest (Article 6(1)(f) GDPR) in knowing whether anyone is reading what we publish, balanced against a measurement that keeps no record capable of singling you out. You can object at any time by contacting us. Blocking it in your browser is not possible, because the counting happens on our side.
  • Process subscriptions and enforce paid access. This covers checkout, invoices, subscription status, plan changes, refunds where applicable, and access changes. Legal basis: performance of a contract (Article 6(1)(b) GDPR) and our legal obligations for accounting and tax records (Article 6(1)(c) GDPR).

We do not sell your personal data and do not use it for third-party advertising.

4. Service providers

We share data only with providers that process it on our behalf under appropriate agreements:

  • Vercel hosts the website and serverless API routes.
  • Supabase stores early-access email records and prototype catalog data, and handles developer-account authentication, storing sign-in security logs.
  • Cloudflare provides the optional Turnstile anti-bot check for the newsletter form. It is not enabled at the moment, so no data reaches Cloudflare.
  • PostHog provides cookieless product analytics.
  • Sentry provides opt-in error monitoring.
  • Resend sends confirmation or product emails when email delivery is configured.
  • Lemon Squeezy processes paid subscription checkout and billing when purchases are enabled.
  • Google Fonts serves the web font files used by the landing page.

5. International transfers

Some providers above may process data on servers outside the European Economic Area (EEA), including in the United States. Where that happens, the transfer is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision. Our analytics data is processed in PostHog’s EU region.

6. Retention and deletion

We keep early-access email records until the prototype access period ends, until you ask us to delete the record, or until the list is migrated to an explicit account or mailing-list consent flow. Security logs are kept only as long as needed to investigate abuse. Analytics data is retained according to our analytics provider’s configured retention period.

Developer-account data (your email and API-key hashes) is kept for the life of your account and removed when you delete the account or ask us to. The IP address and device fingerprint attached to a key are kept while the key exists and for up to 12 months after the key is deleted for abuse prevention, after which they are erased.

Some records must be kept after account deletion to meet legal obligations. In particular, billing and transaction records (such as subscription status, customer identifiers, invoices, and tax records) and related security or audit logs are retained for as long as applicable accounting, tax, and consumer-protection law requires (which can be several years), after which they are erased. Note that because Lemon Squeezy is our merchant of record, it retains the underlying payment and invoice records under its own retention policy.

To request deletion or correction, email hello@orbitalwiki.com.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to processing, including our analytics;
  • receive your data in a portable format;
  • withdraw consent at any time, without affecting processing carried out beforehand.

To exercise any of these, email hello@orbitalwiki.com. You also have the right to lodge a complaint with the data protection supervisory authority in your country of residence.

8. Cookies

We keep cookie use to a minimum. PostHog analytics and error monitoring are off until you opt in through the consent banner, and even then they run cookieless; the referral count described above sets no cookies either, which is why it needs no banner. The banner offers a genuine three-way choice: accept analytics, essential only (functional cookies for theme and language keep working, analytics and error monitoring are off), or decline all (the same, plus those functional cookies stop persisting past your current browsing session). Your choice is remembered in one strictly-necessary cookie so it applies across orbitalwiki.com and all its subdomains, not just the page you chose it on. The only other cookies that may be set are functional, security-related ones from the Cloudflare Turnstile check on the form. See the Cookie Policy for the full list.

9. Children’s privacy

OrbitalWiki is not directed at children, and we do not knowingly collect personal data from anyone under the age required for valid consent in their country (13 in Belgium, and up to 16 in some other EEA countries).

10. Changes and contact

We will update this policy before any new processing takes effect and revise the date above. Questions about this policy can be sent to hello@orbitalwiki.com.