Privacy Policy

Last updated: June 29, 2026

DeepModel, Inc. ("DeepModel," "we," "us," or "our") operates the Orbit platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect information when you use the Service.

This policy applies to personal information processed through Orbit. If you are an enterprise customer with a Data Processing Agreement (DPA), the DPA governs processing of personal data to the extent of any conflict.

Contact: team@deepmodel.ai

1. Scope and roles

1.1 Who this applies to

This policy applies to users who access Orbit, including account holders, workspace administrators, and invited team members.

1.2 Controller and processor roles

  • For account registration, billing, and Service operation data, DeepModel is the data controller.
  • For personal data contained in Customer Content that enterprise customers submit to Orbit, DeepModel generally acts as a data processor on behalf of the customer (controller). Processing terms are set out in the DPA.

2. Information we collect

2.1 Information you provide

  • Account information: name, email address, company name, job title, password (for email/password sign-in, stored only in hashed form; we never store plaintext passwords)
  • Profile and workspace settings: preferences, team membership, role assignments
  • Customer Content: workflow descriptions, notes, documents, metadata, diagrams, TEL scores, and other materials you submit to the Service
  • Communications: support requests, feedback, and correspondence with us

2.2 Information collected automatically

  • Usage data: pages viewed, features used, actions taken, timestamps, session identifiers
  • Device and browser data: IP address, browser type, operating system, device identifiers
  • Cookies and similar technologies: see Section 8

2.3 Information from third parties

  • Authentication providers (e.g., Firebase/Google) may provide identity verification data
  • Your organization may provide account provisioning information if using enterprise access

We do not intentionally collect sensitive categories of personal data (health, biometric, etc.) through Orbit. Do not submit such data unless expressly agreed in writing.

3. How we use information

We use information to:

  • Provide, operate, maintain, and secure the Service
  • Authenticate users and manage workspaces
  • Generate AI-powered workflow specifications, diagrams, and related Output
  • Process transactions and manage billing (where applicable)
  • Communicate about the Service, including updates, security notices, and support
  • Monitor usage and diagnose technical issues
  • Comply with legal obligations and enforce our Terms of Use
  • Improve the Service (see Section 4 for enterprise vs. other users)

3.1 Legal bases (EEA/UK users)

Where GDPR applies, we rely on:

PurposeLegal basis
Providing the ServicePerformance of contract
Security and fraud preventionLegitimate interests / legal obligation
Service improvement (non-enterprise)Legitimate interests
Marketing communicationsConsent (where required)
Legal complianceLegal obligation

4. Use of Customer Content and AI processing

4.1 Enterprise customers

If you have an Enterprise Agreement and/or DPA with DeepModel, use of Customer Content, including restrictions on model training or use for service improvement — is governed by those agreements.

4.2 Other users

We may use Customer Content and usage information to operate, secure, and improve the Service, subject to this policy. We do not sell Customer Content.

4.3 AI subprocessors

To provide AI features, Customer Content may be transmitted to third-party model providers acting on DeepModel's behalf, including Google Gemini, Groq, and BaseTen. Under DeepModel's applicable provider terms and configurations, Customer Content is processed only as needed to provide inference services and is not used to train or improve shared foundation models. Providers do not receive ownership of Customer Content.

5. How we share information

We do not sell personal information. We may share information with:

5.1 Service providers (subprocessors)

ProviderPurpose
Google Cloud PlatformBackend hosting, databases (Cloud SQL), object storage, authentication (Firebase — OAuth token verification), and AI model APIs (Gemini)
Redis.io (Redis Cloud)Managed cache service (session cache and API performance)
VercelWeb application hosting and delivery
CloudflareDNS, DDoS protection, network edge
GroqLLM inference
BaseTenModel hosting and inference
LangfusePrompt management
Amazon Web Services (SES)Transactional email delivery

We may also use providers for payment processing and analytics where applicable to your subscription tier.

5.2 Your organization

If you use Orbit through a workspace, administrators may access information associated with that workspace in accordance with their role.

5.3 Legal requirements

We may disclose information if required by law, regulation, legal process, or government request, or to protect the rights, property, or safety of DeepModel, our users, or others.

5.4 Business transfers

If DeepModel is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction with appropriate protections.

6. International transfers

DeepModel is based in the United States. If you access the Service from outside the US, your information may be transferred to, stored, and processed in the US and other countries where our subprocessors operate.

For transfers from the EEA, UK, or Switzerland, we use appropriate safeguards such as Standard Contractual Clauses as set out in our DPA.

7. Data retention

We retain personal information for as long as necessary to:

  • Provide the Service and fulfill the purposes described in this policy
  • Comply with legal obligations
  • Resolve disputes and enforce agreements

Retention periods for enterprise customers may be specified in the DPA or SOW. Upon termination, we will delete or return personal data in accordance with the DPA, or by default within 90 days of termination, unless retention is required by law. Customers may request export of their data within 30 days of termination.

Customer Content retention follows your workspace lifecycle and applicable agreement terms.

8. Cookies and tracking

We use cookies and similar technologies for:

  • Essential operation: authentication, session management, security
  • Preferences: theme and UI settings
  • Analytics: understanding how the Service is used (where enabled)

You can control cookies through browser settings. Disabling essential cookies may affect Service functionality.

9. Security

We implement administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, access controls, and monitoring. DeepModel maintains a security program aligned with SOC 2 principles.

No method of transmission or storage is completely secure.

10. Your rights

Depending on your location, you may have the right to:

  • Access personal information we hold about you
  • Correct inaccurate information
  • Delete personal information
  • Restrict or object to certain processing
  • Data portability
  • Withdraw consent (where processing is consent-based)
  • Lodge a complaint with a supervisory authority (EEA/UK)

California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, and opt out of certain sharing (we do not sell personal information).

To exercise your rights, contact team@deepmodel.ai. We will respond within the timeframe required by applicable law. We may need to verify your identity.

If your organization is the data controller for workspace data, contact your administrator or refer to your DPA.

11. Children's privacy

The Service is not intended for individuals under 16. We do not knowingly collect personal information from children. If we learn that we have collected such information, we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy with an updated "Last updated" date and, where required, provide additional notice. Continued use after such changes take effect constitutes acceptance.

13. Contact us

DeepModel, Inc.
Email: team@deepmodel.ai
Web: https://www.deepmodel.ai

For data protection inquiries from enterprise customers, include your organization name and workspace identifier.