This notice describes the current data boundary of the MMT Orbit Web product and its Google Play application. It is not a legal-compliance certification.
A draft prepared on the work start page before sign-in is not added to the URL. It stays in session storage for this browser tab for at most 24 hours and is not sent to Firebase unless you continue into the workspace. You can remove it sooner by clearing browser data.
When you continue with Google or create an email account, Google and Firebase process your account identifier and secure session information for authentication. An email account must be verified before it can submit a work command.
After sign-in, profile preferences, membership status, work drafts, job state and verification records may be stored in account-scoped Firestore paths. Security rules prevent another user from reading or changing your account and work. Private model and service keys are not placed in the Web or Android application.
Your file is not read until a real file path is enabled and you select it. Drive or a similar connection is not treated as connected unless it is separately established and its scope is shown. Public sales and real payments are not currently active; creating an account does not create a paid membership.
Your submitted public-guide question and conversation context of up to the last six questions are sent to OpenAI to prepare the answer. The guide does not access your account, files or work status, or take action on your account. The conversation stays in this browser tab; you can clear it from the tab.
A submitted guide question waits temporarily in the service. Its text is removed when the answer completes or expired requests are cleaned up while the service is connected. An outage can delay cleanup. Limited operation identifiers, a content hash and provider usage records may remain for verification instead of the question text; the provider’s data processing terms also apply.
When you ask for an answer or work in the workspace, your description, relevant messages and decisions, necessary context from earlier outputs and needed parts of files selected for use may be sent to OpenAI. Attaching a file does not mean its entire contents or all your work history are immediately sent to that service.
Current-source research uses OpenAI’s search tools in the present product path. Search uses a validated public-topic query separated from the work; private file and message contents are not added directly to the search query. Share sensitive data only with the required rights, permission and purpose. This processing is separate from product-measurement events.
Web hosting and authentication infrastructure may produce standard technical records such as IP address, user agent, requested page and time for security and operations. Full work descriptions, sensitive files and private access keys are not sent in product-measurement events.
Use the account-deletion steps for the account and associated application data. The request is processed after identity verification; limited records that must be retained for legal, security or dispute purposes may be separated and kept only for the required purpose and period.
Questions: topalogllu@gmail.com