Privacy policy
Last updated: 1 October 2026
Who we are
Orba is practice-management software for Australian architecture studios. Aapo Group Pty Ltd (ABN 21 615 985 085) runs it. In this policy, "Orba", "we" and "us" mean Aapo Group Pty Ltd.
This policy covers the website at orba.team, the Orba web app and the pages your clients open from a share link. If we launch the Orba connector for Claude, ChatGPT or Grok, we will add it here before it starts.
Questions about privacy go to hello@orba.team, or by post to Aapo Group Pty Ltd, Suite 104/T111, 793 Burke Road, Camberwell VIC 3124.
We follow the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
The short version
- We collect what you put into Orba: your email, your studio details and your projects. Projects often hold client names, site addresses and meeting notes.
- We use it to run Orba for you. We don't sell it, and we don't use it for advertising.
- Some of it goes to service providers, several of them in the United States. The main one is xAI, whose Grok models write briefs and drafts.
- AI output is a draft for you to check. Renders are concept images, not for construction.
- You can ask us to show, fix, export or delete your data. Email hello@orba.team.
What we collect
About you and your studio
| What | Examples | Why we need it |
|---|---|---|
| Email address | you@studio.com.au | To sign you in and send the email you ask for |
| Studio profile | Studio name, ABN, address, logo, brand colour, letterhead footer, email sign-off, website, default fee settings | To put your studio's details on documents |
| Plan | Beta, Pro or Max, and renewal date | To switch features on and off |
| Waitlist details | Email, studio name, role, how you heard of us | To tell you when a place opens |
| Sign-in records | A one-time code (stored scrambled), your IP address and browser type | To keep accounts secure and stop abuse |
| Google connection (optional) | Your Google email and Drive access tokens, stored encrypted | For "Sign in with Google" and Drive import |
We never see your card number. When paid plans open, you pay through Stripe, and Stripe holds your card details.
What you put into projects
- Project name, site address, client name, project type and stage.
- Meeting notes, briefs, fee proposals, contract admin documents and follow-up emails.
- Tasks, dates, and the name or email of the person a task belongs to.
- Files you upload or link from Google Drive, such as drawings, photos and planning permits. We keep the text we pull out of them.
- Renders, and the prompts and drawings you used to make them.
- Your chats with the Orba project assistant.
- Voice sessions, if you use voice. We keep the transcript. We don't keep the audio.
- Leads, if you use the business development tools. If you connect a mailbox, its password and message content are stored encrypted.
About your clients and other people
Your projects will hold personal information about people who don't use Orba. Clients are the obvious case. Consultants, builders and neighbours named in permit conditions are others. You collect that information and you decide what goes into Orba. Read "Your clients and other people" below.
When a client opens a share link, we record:
- when they opened it, with a scrambled (hashed) form of their IP address
- any decision or comment they leave
- if they accept a fee proposal online: their name, email, stated authority to sign, the time, their browser type and a hashed IP address. We keep this as evidence of the agreement.
Collected automatically
- IP address. We use it to check that you are in Australia and to limit repeated requests. Rate-limit records expire within 24 hours.
- Server logs. Our host keeps request logs. They can include your IP address, the page you asked for and, for some errors, your email address.
- Product events. We record steps such as signing in, making a first project and creating a share link. These stay in our own database.
We use no third-party analytics and no advertising trackers.
How we use it
We use your information to:
- run Orba: sign you in, save your work, make documents and send the email you ask for
- run AI features when you ask for them
- look up planning data for a site address
- keep Orba secure and stop misuse
- answer you when you contact us
- see which features studios use, from our own event records
- bill you, once paid plans open
- meet our legal obligations.
We don't sell personal information. We don't use your projects to train AI models. xAI and OpenAI say they don't train on data sent through their business APIs.
Fee benchmarks are opt-in. If you opt in, we add your fee percentage to a band (for example, residential alterations in one cost range). We show a band only when at least 20 studios have contributed. No studio or client is named.
How Orba uses AI
When you ask for a brief, fee proposal, contract admin document, follow-up email, project pack, render or assistant answer, we send what the task needs to an AI model. That can be your notes, a site address, planning data, photos, drawings, uploaded documents and project details.
| AI provider | What it does in Orba | What we send |
|---|---|---|
| xAI (Grok) | Writes briefs and drafts, reads photos and drawings, answers in the project assistant, pulls actions from notes, runs voice | The text, images and project context for that task |
| OpenAI | Searches the NCC library, turns voice recordings into text and makes renders from a model image | Your search words, voice recordings and the model image you send for a render |
| fal.ai | Makes concept renders from your drawings | The drawing or image and the render prompt |
xAI and OpenAI keep API requests for up to 30 days to check for abuse, then delete them.
Please keep in mind:
- AI makes mistakes. Treat every output as a draft that a qualified person checks before anyone relies on it.
- Planning data and NCC references can be wrong or out of date. Check them against the planning scheme, the NCC and the council.
- Renders are concept images, not for construction. They are not drawings. They can show things that can't be built or approved.
- AI doesn't make decisions about people. It drafts and suggests. You decide.
Who we share it with
We share personal information with the service providers below, only so they can run their part of Orba.
| Provider | What they receive | Where it is held |
|---|---|---|
| Neon (database) | All account and project data | Sydney, Australia |
| Vercel (hosting, file storage, logs) | Everything that passes through the app, plus uploaded files, logos and renders | The app runs in Sydney; file storage and logs are in the United States |
| xAI | Material for AI features, as above | United States |
| OpenAI | Material for the features marked above | United States |
| fal.ai | Drawings and prompts for concept renders | United States |
| Resend (email) | Email addresses and the content of email we send, including invites to your clients | United States |
| Upstash (fast storage) | IP addresses for rate limits, usage counts, your plan, form drafts for up to 7 days and briefs queued overnight (including meeting notes) for up to 48 hours | Sydney, Australia |
| SiteLogic (planning data, a related Aapo service) | The site address you enter | United States |
| Only if you connect it: sign-in, and the Drive files and folders you choose | United States | |
| Stripe | Once paid plans open: your email, plan and the payment details you give Stripe | United States |
| Cloudflare R2 | Planned for file storage. We will update this row before it starts. | To be confirmed before it starts |
We may also share information:
- with our professional advisers, such as lawyers and accountants
- when the law requires it, or to protect someone's safety
- with a buyer, if we sell Orba. We would tell you first.
Sending information overseas
Several of our providers are in the United States, and they may process your information there. People anywhere in the world can open a client share page.
Before we send personal information overseas, we take reasonable steps to make sure the provider handles it in line with the Australian Privacy Principles. We do this through their data processing terms.
How we protect it
- All traffic uses HTTPS.
- Google tokens and mailbox passwords are encrypted, and the key is kept outside the database.
- Sign-in codes, share tokens and client IP addresses are stored only in scrambled (hashed) form.
- Each studio's data is kept apart. Every request checks that the project belongs to the person asking.
- Only Orba's founder, and the automated tools they run, can reach production systems.
Uploaded files and renders sit in file storage at unlisted web addresses. Anyone with the exact address can open the file, so share those addresses with care.
No system is perfectly secure. If you think your account is at risk, email hello@orba.team straight away.
How long we keep it
| Information | How long |
|---|---|
| Account, studio and project data | While your account is open. We delete it within 30 days after you ask us to close your account, apart from the items below. |
| Deleted projects | Removed from your account when you delete them. Some linked documents and files can stay in storage until your account closes. Ask us and we will remove them sooner. |
| Sign-in links and codes | Work for 15 minutes. The scrambled code record stays until your account is deleted. |
| Signed-in session | 30 days |
| Partly uploaded files | 2 hours |
| Form drafts | 7 days |
| Briefs queued overnight | 48 hours |
| Client share links | Stop working after 30 days, or sooner if you revoke them |
| Accepted fee proposals | At least 7 years, even if you delete the project, because they are evidence of an agreement |
| Voice sessions | Transcript kept with the project. A discarded session's transcript is deleted. |
| Copies held by xAI and OpenAI | Up to 30 days |
| Waitlist entries | Until you join, or until you ask us to remove you |
| Backups | Our database provider keeps a restore history of a day or less |
| Server logs | Our host keeps them for a day or less |
Cookies and browser storage
We use only the cookies Orba needs to work.
| Name | What it does | How long |
|---|---|---|
| orba_session | Keeps you signed in | 30 days |
| google_oauth_state, google_oauth_return, google_oauth_drive | Protect and complete "Sign in with Google" | 10 minutes |
Orba also saves a few settings in your browser: your theme, your last brief draft, a render in progress, your voice setting and your last upload label. They stay on your device.
We use no advertising or analytics cookies, so there is nothing to opt out of.
Your clients and other people
When you put someone else's personal information into Orba, you are responsible for it. You must have the right to collect it and to use Orba to handle it. You must also tell those people how you handle their information, as the Privacy Act requires of you.
We handle that information only to provide Orba to you and as this policy describes. If one of your clients asks us about their information, we will pass the request to you and help you answer it.
Seeing, fixing and deleting your information
You can see and edit most of your information in Orba yourself.
For anything else, email hello@orba.team. You can ask us to:
- give you a copy of your personal information
- correct it
- give you a copy of your projects
- delete your account and its data.
We confirm it's you by emailing your account address. We don't charge. We reply within 30 days. If we can't do what you ask, we explain why in writing and tell you how to complain.
Complaints
Tell us first, at hello@orba.team. We acknowledge a complaint within 5 business days and aim to resolve it within 30 days.
If you are not happy with our answer, or we don't reply within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC):
- online: oaic.gov.au
- phone: 1300 363 992
- post: GPO Box 5288, Sydney NSW 2001.
Data breaches
If a data breach is likely to cause serious harm, we will tell the people affected and the OAIC, following the Notifiable Data Breaches scheme. If a breach affects your clients' information in Orba, we will tell you quickly so you can meet your own obligations.
Changes to this policy
We will post any change on this page and update the date at the top. If a change matters, such as a new provider or a new use of your data, we will email account holders at least 14 days before it takes effect.