Privacy policy

Last updated: 1 October 2026

Who we are

Orba is practice-management software for Australian architecture studios. Aapo Group Pty Ltd (ABN 21 615 985 085) runs it. In this policy, "Orba", "we" and "us" mean Aapo Group Pty Ltd.

This policy covers the website at orba.team, the Orba web app and the pages your clients open from a share link. If we launch the Orba connector for Claude, ChatGPT or Grok, we will add it here before it starts.

Questions about privacy go to hello@orba.team, or by post to Aapo Group Pty Ltd, Suite 104/T111, 793 Burke Road, Camberwell VIC 3124.

We follow the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

The short version

  • We collect what you put into Orba: your email, your studio details and your projects. Projects often hold client names, site addresses and meeting notes.
  • We use it to run Orba for you. We don't sell it, and we don't use it for advertising.
  • Some of it goes to service providers, several of them in the United States. The main one is xAI, whose Grok models write briefs and drafts.
  • AI output is a draft for you to check. Renders are concept images, not for construction.
  • You can ask us to show, fix, export or delete your data. Email hello@orba.team.

What we collect

About you and your studio

WhatExamplesWhy we need it
Email addressyou@studio.com.auTo sign you in and send the email you ask for
Studio profileStudio name, ABN, address, logo, brand colour, letterhead footer, email sign-off, website, default fee settingsTo put your studio's details on documents
PlanBeta, Pro or Max, and renewal dateTo switch features on and off
Waitlist detailsEmail, studio name, role, how you heard of usTo tell you when a place opens
Sign-in recordsA one-time code (stored scrambled), your IP address and browser typeTo keep accounts secure and stop abuse
Google connection (optional)Your Google email and Drive access tokens, stored encryptedFor "Sign in with Google" and Drive import

We never see your card number. When paid plans open, you pay through Stripe, and Stripe holds your card details.

What you put into projects

  • Project name, site address, client name, project type and stage.
  • Meeting notes, briefs, fee proposals, contract admin documents and follow-up emails.
  • Tasks, dates, and the name or email of the person a task belongs to.
  • Files you upload or link from Google Drive, such as drawings, photos and planning permits. We keep the text we pull out of them.
  • Renders, and the prompts and drawings you used to make them.
  • Your chats with the Orba project assistant.
  • Voice sessions, if you use voice. We keep the transcript. We don't keep the audio.
  • Leads, if you use the business development tools. If you connect a mailbox, its password and message content are stored encrypted.

About your clients and other people

Your projects will hold personal information about people who don't use Orba. Clients are the obvious case. Consultants, builders and neighbours named in permit conditions are others. You collect that information and you decide what goes into Orba. Read "Your clients and other people" below.

When a client opens a share link, we record:

  • when they opened it, with a scrambled (hashed) form of their IP address
  • any decision or comment they leave
  • if they accept a fee proposal online: their name, email, stated authority to sign, the time, their browser type and a hashed IP address. We keep this as evidence of the agreement.

Collected automatically

  • IP address. We use it to check that you are in Australia and to limit repeated requests. Rate-limit records expire within 24 hours.
  • Server logs. Our host keeps request logs. They can include your IP address, the page you asked for and, for some errors, your email address.
  • Product events. We record steps such as signing in, making a first project and creating a share link. These stay in our own database.

We use no third-party analytics and no advertising trackers.

How we use it

We use your information to:

  • run Orba: sign you in, save your work, make documents and send the email you ask for
  • run AI features when you ask for them
  • look up planning data for a site address
  • keep Orba secure and stop misuse
  • answer you when you contact us
  • see which features studios use, from our own event records
  • bill you, once paid plans open
  • meet our legal obligations.

We don't sell personal information. We don't use your projects to train AI models. xAI and OpenAI say they don't train on data sent through their business APIs.

Fee benchmarks are opt-in. If you opt in, we add your fee percentage to a band (for example, residential alterations in one cost range). We show a band only when at least 20 studios have contributed. No studio or client is named.

How Orba uses AI

When you ask for a brief, fee proposal, contract admin document, follow-up email, project pack, render or assistant answer, we send what the task needs to an AI model. That can be your notes, a site address, planning data, photos, drawings, uploaded documents and project details.

AI providerWhat it does in OrbaWhat we send
xAI (Grok)Writes briefs and drafts, reads photos and drawings, answers in the project assistant, pulls actions from notes, runs voiceThe text, images and project context for that task
OpenAISearches the NCC library, turns voice recordings into text and makes renders from a model imageYour search words, voice recordings and the model image you send for a render
fal.aiMakes concept renders from your drawingsThe drawing or image and the render prompt

xAI and OpenAI keep API requests for up to 30 days to check for abuse, then delete them.

Please keep in mind:

  • AI makes mistakes. Treat every output as a draft that a qualified person checks before anyone relies on it.
  • Planning data and NCC references can be wrong or out of date. Check them against the planning scheme, the NCC and the council.
  • Renders are concept images, not for construction. They are not drawings. They can show things that can't be built or approved.
  • AI doesn't make decisions about people. It drafts and suggests. You decide.

Who we share it with

We share personal information with the service providers below, only so they can run their part of Orba.

ProviderWhat they receiveWhere it is held
Neon (database)All account and project dataSydney, Australia
Vercel (hosting, file storage, logs)Everything that passes through the app, plus uploaded files, logos and rendersThe app runs in Sydney; file storage and logs are in the United States
xAIMaterial for AI features, as aboveUnited States
OpenAIMaterial for the features marked aboveUnited States
fal.aiDrawings and prompts for concept rendersUnited States
Resend (email)Email addresses and the content of email we send, including invites to your clientsUnited States
Upstash (fast storage)IP addresses for rate limits, usage counts, your plan, form drafts for up to 7 days and briefs queued overnight (including meeting notes) for up to 48 hoursSydney, Australia
SiteLogic (planning data, a related Aapo service)The site address you enterUnited States
GoogleOnly if you connect it: sign-in, and the Drive files and folders you chooseUnited States
StripeOnce paid plans open: your email, plan and the payment details you give StripeUnited States
Cloudflare R2Planned for file storage. We will update this row before it starts.To be confirmed before it starts

We may also share information:

  • with our professional advisers, such as lawyers and accountants
  • when the law requires it, or to protect someone's safety
  • with a buyer, if we sell Orba. We would tell you first.

Sending information overseas

Several of our providers are in the United States, and they may process your information there. People anywhere in the world can open a client share page.

Before we send personal information overseas, we take reasonable steps to make sure the provider handles it in line with the Australian Privacy Principles. We do this through their data processing terms.

How we protect it

  • All traffic uses HTTPS.
  • Google tokens and mailbox passwords are encrypted, and the key is kept outside the database.
  • Sign-in codes, share tokens and client IP addresses are stored only in scrambled (hashed) form.
  • Each studio's data is kept apart. Every request checks that the project belongs to the person asking.
  • Only Orba's founder, and the automated tools they run, can reach production systems.

Uploaded files and renders sit in file storage at unlisted web addresses. Anyone with the exact address can open the file, so share those addresses with care.

No system is perfectly secure. If you think your account is at risk, email hello@orba.team straight away.

How long we keep it

InformationHow long
Account, studio and project dataWhile your account is open. We delete it within 30 days after you ask us to close your account, apart from the items below.
Deleted projectsRemoved from your account when you delete them. Some linked documents and files can stay in storage until your account closes. Ask us and we will remove them sooner.
Sign-in links and codesWork for 15 minutes. The scrambled code record stays until your account is deleted.
Signed-in session30 days
Partly uploaded files2 hours
Form drafts7 days
Briefs queued overnight48 hours
Client share linksStop working after 30 days, or sooner if you revoke them
Accepted fee proposalsAt least 7 years, even if you delete the project, because they are evidence of an agreement
Voice sessionsTranscript kept with the project. A discarded session's transcript is deleted.
Copies held by xAI and OpenAIUp to 30 days
Waitlist entriesUntil you join, or until you ask us to remove you
BackupsOur database provider keeps a restore history of a day or less
Server logsOur host keeps them for a day or less

Cookies and browser storage

We use only the cookies Orba needs to work.

NameWhat it doesHow long
orba_sessionKeeps you signed in30 days
google_oauth_state, google_oauth_return, google_oauth_driveProtect and complete "Sign in with Google"10 minutes

Orba also saves a few settings in your browser: your theme, your last brief draft, a render in progress, your voice setting and your last upload label. They stay on your device.

We use no advertising or analytics cookies, so there is nothing to opt out of.

Your clients and other people

When you put someone else's personal information into Orba, you are responsible for it. You must have the right to collect it and to use Orba to handle it. You must also tell those people how you handle their information, as the Privacy Act requires of you.

We handle that information only to provide Orba to you and as this policy describes. If one of your clients asks us about their information, we will pass the request to you and help you answer it.

Seeing, fixing and deleting your information

You can see and edit most of your information in Orba yourself.

For anything else, email hello@orba.team. You can ask us to:

  • give you a copy of your personal information
  • correct it
  • give you a copy of your projects
  • delete your account and its data.

We confirm it's you by emailing your account address. We don't charge. We reply within 30 days. If we can't do what you ask, we explain why in writing and tell you how to complain.

Complaints

Tell us first, at hello@orba.team. We acknowledge a complaint within 5 business days and aim to resolve it within 30 days.

If you are not happy with our answer, or we don't reply within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC):

  • online: oaic.gov.au
  • phone: 1300 363 992
  • post: GPO Box 5288, Sydney NSW 2001.

Data breaches

If a data breach is likely to cause serious harm, we will tell the people affected and the OAIC, following the Notifiable Data Breaches scheme. If a breach affects your clients' information in Orba, we will tell you quickly so you can meet your own obligations.

Changes to this policy

We will post any change on this page and update the date at the top. If a change matters, such as a new provider or a new use of your data, we will email account holders at least 14 days before it takes effect.