Sound Orbit — Privacy Policy

Effective Date: April 22, 2026

Last Updated: August 28, 2026

1. Introduction

Sound Orbit, LLC ("Sound Orbit," "we," "us," or "our") operates the Sound Orbit mobile application for iOS and Android (the "App") and the website soundorbitapp.com (the "Site"). We are a single-member limited liability company based in Jefferson County, Missouri.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. By using the App or the Site, you agree to the practices described here.

Some practices differ between the iOS and Android versions of the App, because the two platforms provide different underlying services. Where that is the case, this Policy says so explicitly.

If you do not agree with this Policy, please do not use the App or the Site.

2. Information We Collect

We collect only what we need to run the App, support our users, and measure whether our own advertising is working. We do not sell your information, we do not display advertising inside the App, and we do not use your information for cross-app tracking or to build advertising profiles.

2.1 Contact Information

Name — collected when you create an account or set up your community profile.

Email address — collected for account authentication, password recovery, support correspondence, and transactional notifications.

2.2 User Content

Saved mixes, Dream Journal entries, and community posts you create inside the App are stored so we can sync them to your account and (for community posts) display them to other users.

Artwork you generate for your saved mixes is stored with your account so it is available across your devices.

Verification documents (a government photo ID and an eligibility credential) that you upload during optional Service & Education Discount verification. These are handled as described in Section 5.

2.3 Identifiers

User ID — a unique identifier assigned to your account by Firebase Authentication.

Per-vendor device identifier — on iOS, Apple's Identifier for Vendor (IDFV); on Android, the App-set ID. Both are scoped to our apps only. We use them solely as part of our Discount Program anti-abuse system, to prevent repeat fraudulent verification attempts from the same device. We do not use these identifiers for advertising, profiling, or tracking across other apps or websites.

Advertising identifier (Android only) — see Section 2.7.

2.4 Usage Data

Product interaction data — analytics about how you use the App (for example, sessions started, features accessed, screens viewed, paywall interactions, and subscription events). Collected via Firebase Analytics for product improvement and to measure the effectiveness of our own advertising.

Diagnostics and crash data — crash reports and basic performance information (such as load times and error conditions), collected so we can identify and fix problems in the App.

Family Plan shared usage — for Family Plan subscribers (iOS only), Orbit AI question counts are tracked at the family-subscription level (a single shared counter keyed to the family's Apple-issued original transaction ID) rather than per-member. Individual question content is not shared between family members; only the aggregate count is shared.

2.5 Purchase Data

On iOS, subscriptions and in-app purchases are processed entirely by Apple through the App Store and StoreKit. On Android, they are processed entirely by Google through Google Play Billing. In both cases we receive a purchase receipt and subscription status from the platform, but we do not receive or store your payment card details.

In addition to subscriptions, you may purchase Artwork Tokens (consumable in-app purchases) through Apple or Google. As with subscriptions, these transactions are processed entirely by the platform; we receive confirmation of the purchase but not your payment details. Your Artwork Token balance is stored with your account so it is available across your devices and after reinstalling the App.

2.6 Professional and Eligibility Status

If you choose to apply for the Service & Education Discount, we retain a record of the professional or veteran status your verification confirmed — for example, that you are a verified law-enforcement officer, nurse, active-duty service member, veteran, or K-12 teacher.

We retain this because your discounted subscription entitlement depends on it and because status must be renewed annually. It is used only to grant and maintain your discounted pricing. It is not used for marketing, advertising, analytics, profiling, or any purpose outside the Discount Program, and it is never shared with third parties or displayed to other users.

The documents you submit to establish this status are handled as described in Section 5.

2.7 Advertising Measurement

We advertise Sound Orbit on platforms including Google Ads and Apple Search Ads.

On Android: when you install the App after selecting one of our advertisements, our analytics provider (Firebase) may access your device's advertising identifier to confirm that the installation, and any subscription that follows, resulted from that advertisement.

We use this solely to measure whether our own advertising is effective — for example, to learn which campaigns bring us users who find the App valuable enough to subscribe. We do not use it to build advertising or behavioral profiles, we do not display advertising inside Sound Orbit, and we do not share it with advertising networks or data brokers. We do not sell your data.

You can reset or delete your advertising identifier at any time in your device settings (Android: Settings → Privacy → Ads). Doing so does not affect your ability to use Sound Orbit or any of its features.

On iOS: we do not collect Apple's Identifier for Advertisers (IDFA), and we do not present App Tracking Transparency prompts. Install measurement on iOS uses Apple's privacy-preserving attribution framework, which reports campaign performance in aggregate and does not identify individual users.

2.8 What We Do Not Collect

We do not collect: precise location, health records (beyond the health-app data described in Section 6, which never leaves your device), contacts, photos outside of what you explicitly upload, audio recordings, browsing history, financial account numbers, or government ID numbers as structured fields (see Section 5 for how verification documents are handled).

We do not collect Apple's Identifier for Advertisers (IDFA) on iOS. On Android, our collection of the advertising identifier is limited to the campaign measurement described in Section 2.7.

3. How We Use Information

We use the information we collect to:

  • Create and maintain your account.

  • Sync your mixes, preferences, Dream Journal, session history, gamification progress, and Artwork Token balance across your devices and after reinstalling the App.

  • Power community features (sharing mixes, likes, reports, moderation).

  • Deliver answers through Orbit AI (see Section 4).

  • Generate AI artwork and AI-suggested descriptions for user-created mixes (see Section 4). AI-suggested descriptions are available only on paid subscription tiers.

  • Verify eligibility for the Service & Education Discount Program and maintain verified status (see Sections 2.6 and 5).

  • Process subscription entitlements and in-app purchases through Apple and Google.

  • Improve the App through usage analytics and diagnose problems through crash and performance data.

  • Measure the effectiveness of our own advertising campaigns (see Section 2.7).

  • Send transactional communications (account issues, verification status, subscription receipts).

  • Respond to support requests.

  • Enforce our Terms of Service and detect abuse.

  • Comply with legal obligations.

We do not use your information to build advertising profiles, sell data to third parties, or serve targeted ads. Sound Orbit contains no advertising.

4. Sharing & Third-Party Services

We share limited data with a small number of service providers, each bound by their own contractual and legal obligations. These providers process data on our behalf and are not permitted to use it for their own purposes beyond operating their services.

4.1 Firebase (Google LLC)

We use Firebase for authentication, backend database (Firestore), file storage, analytics, and crash reporting. Your account credentials, saved content, community posts, mix artwork, usage analytics, and diagnostic data are stored on Google-operated servers.

On Android, Firebase also processes the advertising identifier described in Section 2.7 for the sole purpose of attributing installs and subscriptions to our own advertising campaigns.

https://policies.google.com/privacy

4.2 Anthropic (Claude API)

Sound Orbit uses Anthropic's Claude API for two purposes: (1) Orbit AI — when you ask Orbit AI a question, the text of your question is transmitted to Anthropic for processing and a response is returned; and (2) Discount Program document analysis — when you submit verification documents, the document images are transmitted to Anthropic for in-flight analysis (see Section 5.2 for retention details). Per Anthropic's API terms, inputs and outputs are not used to train their models. Claude is not used for AI artwork or AI-suggested mix descriptions; those go through xAI Grok (see Section 4.3).

https://www.anthropic.com/privacy

4.3 xAI (Grok API)

Sound Orbit uses xAI's Grok API for two purposes: (1) AI artwork — when you generate artwork for a user-created mix, the text prompt describing your mix is transmitted to xAI and an image is returned; and (2) AI-suggested mix descriptions — when you request an AI-generated description for a saved mix, your mix metadata (name, sound layers, brainwave band, frequency) is transmitted to xAI and candidate descriptions are returned. AI-suggested descriptions are available only on paid subscription tiers; free-tier users enter mix descriptions manually and no data is sent to xAI for that flow.

https://x.ai/legal/privacy-policy

4.4 Apple (iOS)

Subscriptions and in-app purchases on iOS are processed by Apple through StoreKit. Apple handles all payment details. Apple also provides privacy-preserving install attribution for our Apple Search Ads campaigns, reported to us in aggregate.

https://www.apple.com/legal/privacy/

4.5 Google (Android — Play Billing and Google Ads)

Subscriptions and in-app purchases on Android are processed by Google through Google Play Billing. Google handles all payment details; we receive purchase confirmation and subscription status, not your payment card information.

We also run advertising campaigns through Google Ads. As described in Section 2.7, install and subscription events may be attributed to those campaigns through Firebase. We do not provide Google with your name, email address, or any content you create in the App for advertising purposes.

https://policies.google.com/privacy

4.6 Legal Disclosures

We may disclose information if required by law, subpoena, court order, or to protect our rights, users, or the public.

4.7 No Sale of Personal Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

5. Service & Education Discount Program — Verification Data Handling

The Service & Education Discount Program (the "Discount Program") offers discounted Premium subscription pricing ($1.99/month or $19.99/year) to verified members of eligible service and education professions: police and law enforcement; firefighters, EMS, and paramedics; 911 dispatchers; healthcare workers (including nurses, nurse practitioners, physician assistants, and physicians); active-duty military and veterans; and educators — specifically K-12 and state-licensed preschool/pre-K classroom teachers and teacher aides/paraprofessionals, at public or private schools.

Verification is required to access these discounted rates and is optional — you are never required to submit documents to use the App. Sound Orbit's stated goal is to offer Premium access to verified members free of charge as the program scales; until that goal is reached, the discounted rates above apply.

5.1 What You Submit

To verify, you upload two documents through the App:

  • A government-issued photo ID.

  • An institutional eligibility credential appropriate to your profession. Examples include: an employer- or department-issued ID card showing your name, photo, and the employer/department name; an active professional license with employer or licensing-board information visible; a state teaching license or teaching certificate; a school- or district-issued employee ID showing your name, photo, and the school or district name; a Common Access Card (CAC); or, for veterans, a DD-214 or a driver's license bearing a "VETERAN" designation.

5.2 How Documents Are Processed

Uploaded documents are analyzed in real time by the Claude API to confirm document type, match identity across both documents, and confirm qualifying employment or eligibility.

The document images themselves are never permanently stored. They are analyzed in-flight and discarded once analysis completes. They are not retained by us, are not written to our database or file storage, and are not used for any purpose other than the eligibility determination you requested.

5.3 What We Retain

After analysis, we retain only:

  • Perceptual hashes of each document (one-way mathematical fingerprints that prevent the same document from being reused by another applicant, but cannot be reversed to reconstruct the document).

  • A SHA-256 hash of extracted identity fields (also one-way and non-reversible).

  • The per-vendor device identifier (IDFV on iOS, App-set ID on Android) at the time of approval, for anti-abuse.

  • The professional or veteran status your verification confirmed, as described in Section 2.6.

  • Approval timestamp and re-verification due date.

  • A timestamped record that you agreed to the Discount Program verification terms.

5.4 Why We Retain It

These records exist solely to prevent fraudulent verification, to grant and maintain your discounted subscription entitlement, and to manage the annual re-verification cycle. They are not used for marketing, advertising, analytics, or any purpose outside the Discount Program.

5.5 Re-verification

Discount Program status is valid for 365 days plus a 30-day grace period. You'll be prompted in-app to re-verify before expiration.

5.6 Access Restrictions

Our Firestore security rules restrict access to Discount Program verification-hash collections to administrator accounts only. No user — including other verified members — can read or list another user's verification data.

5.7 Anti-Abuse Trial Records

To prevent repeated trial abuse, Sound Orbit retains a one-way SHA-256 hash of the email address used at signup, along with the timestamp the trial began. We additionally retain a SHA-256 hash of the platform-issued account identifier — the Apple user identifier for accounts created via Sign in with Apple, or the equivalent Google account identifier on Android — so the same protection applies if a user re-signs in without re-providing their email. These records:

  • Cannot be reversed to identify the user.

  • Survive account deletion (this is intentional, to prevent repeated trial fraud).

  • Are used only to determine whether a given email address or platform account identifier has previously consumed the 14-day free trial.

  • Are never used for marketing, analytics, advertising, or any purpose outside trial-eligibility verification.

By starting a free trial, you consent to the retention of this anti-abuse record. The same hash-based pattern is used for our Discount Program (see above).

6. Health Data

Health integration differs by platform. On iOS, Sound Orbit both reads and writes Apple Health data for the Profile wellness card. On Android, Sound Orbit only writes Mindful Minutes and reads nothing.

6.1 Apple Health (iOS)

Sound Orbit can read your heart rate variability, resting heart rate, sleep data, and Mindful Minutes from Apple Health, with your permission. We use this data only to display personalized wellness insights inside the app and pair sessions to your recovery state.

Sound Orbit writes Mindful Minutes to Apple Health when you complete a session, so your binaural beat practice is reflected in your daily Health app summary.

Apple Health data never leaves your device. We do not store it on our servers, share it with third parties, use it for advertising, or feed it into any AI service. You can revoke Sound Orbit's access to Apple Health at any time in the Health app under Sharing → Apps.

6.2 Health Connect (Android)

On Android, Sound Orbit integrates with Health Connect for a single purpose: writing Mindful Minutes. When you complete a session, Sound Orbit records that session's mindful minutes to Health Connect, with your permission, so your practice is reflected alongside the rest of your health data.

Sound Orbit does not read any data from Health Connect on Android. We do not read your sleep data, heart rate variability, resting heart rate, or mindfulness records. The Android version requests only the write permission for mindfulness and holds no read permissions.

The data Sound Orbit writes is limited to the duration and timing of sessions you complete in the app. It is written on-device only. We do not store it on our servers, share it with third parties, use it for advertising, or feed it into any AI service. You can grant or revoke Sound Orbit's Health Connect access at any time in the Health Connect app under App permissions, or from Settings inside Sound Orbit.

The Android wellness display that previously showed sleep and heart-rate trends has been removed. If we reintroduce a feature that reads health data on Android, we will update this Policy and request your permission before any data is accessed.

7. Data Retention & Deletion

  • Account and content: retained for as long as your account is active.

  • Discount Program hashes and status: retained for the duration of your verified status plus a reasonable period to prevent re-verification fraud.

  • Analytics, diagnostics, and advertising-measurement data: retained per Firebase defaults.

  • Health data: never retained by us on any platform. It stays on your device under the contract in Section 6.

  • Support correspondence: retained for up to 24 months.

Deletion

You can delete your account at any time from inside the App (Profile → Settings → Delete Account). Deleting your account removes your profile, saved mixes, mix artwork, Dream Journal entries, community posts, session history, gamification progress, Artwork Token balance, verified status, and associated data from our active systems. Discount Program verification hashes and anti-abuse trial records may be retained in de-identified, non-reversible form to prevent abuse, as described in Sections 5.3 and 5.7.

You may also request deletion by emailing support@soundorbitapp.com, or through https://www.soundorbitapp.com/delete-account. We will confirm receipt within 7 days and complete deletion within 30 days unless legal obligations require longer retention.

8. Your Rights

Depending on where you live, you may have rights to:

  • Access the personal information we hold about you.

  • Correct inaccurate information.

  • Delete your information.

  • Export a copy of your data.

  • Object to or restrict certain processing.

  • Withdraw consent where processing is based on consent.

To exercise any of these rights, email support@soundorbitapp.com. We will respond within 30 days.

9. Children's Privacy

Sound Orbit is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly. If you believe a child under 13 has provided us with personal information, please contact support@soundorbitapp.com.

Users between 13 and the age of majority in their jurisdiction should use Sound Orbit only with parental or guardian consent.

10. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what categories of personal information we collect and the purposes for collecting it.

  • Request access to or deletion of your personal information.

  • Correct inaccurate personal information.

  • Opt out of the sale or sharing of personal information — Sound Orbit does not sell personal information and does not share it for cross-context behavioral advertising. The advertising measurement described in Section 2.7 is limited to attributing installs and subscriptions to our own campaigns; it is not used to target advertising to you on other services.

  • Limit the use of sensitive personal information — the professional and veteran status described in Section 2.6 is used only to grant and maintain your discounted subscription and is not used for any other purpose.

  • Be free from retaliation for exercising any of these rights.

To exercise California rights, email support@soundorbitapp.com with the subject line "California Privacy Request." We may need to verify your identity before fulfilling your request.

11. International Users

Sound Orbit is operated from the United States. If you use the App or Site from outside the United States, your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those in your country.

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, the legal bases we rely on to process your personal information include: performance of our contract with you, your consent (where applicable), our legitimate interests in operating and improving the App and in measuring the effectiveness of our own advertising, and compliance with legal obligations.

12. Security

We use industry-standard security measures to protect your information, including:

  • TLS/HTTPS for all data transmission.

  • Platform secure storage for sensitive local credentials on your device (Apple Keychain on iOS; the Android Keystore system on Android).

  • Firestore security rules enforcing owner-only writes and restricted admin reads.

  • Firebase Authentication for credential handling.

No system is 100% secure. If we become aware of a data breach affecting your personal information, we will notify you as required by applicable law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. Material changes will be communicated via in-app notification or email. Your continued use of the App after changes take effect constitutes acceptance of the revised Policy.

Summary of the August 28, 2026 update: corrected Section 6.2. The prior revision stated that the Android version had no health integration; that was inaccurate — Android has written Mindful Minutes to Health Connect since July 2026. Section 6.2 now describes that write accurately. Separately, the Android read permissions (sleep, heart rate variability, resting heart rate, and mindfulness) and the Android wellness display that used them have been removed from the app; Android now holds a write permission only. iOS is unchanged.

Summary of the August 19, 2026 update: added Section 2.6 (professional and eligibility status) and Section 2.7 (advertising measurement, including the Android advertising identifier); added Google Play Billing and Google Ads as disclosed services; extended the Policy to cover the Android version of the App throughout, including per-vendor identifiers, purchase processing, anti-abuse hashing, secure storage, and the absence of health integration on Android; and added diagnostics and crash data to the usage-data disclosure.

14. Contact Us

Questions about this Privacy Policy or your information?

Sound Orbit, LLC Jefferson County, Missouri, USA Email: support@soundorbitapp.com