Oribin Privacy
Legally Effective • Standard Protocol

Oribin Privacy Policy

Your privacy is the core architectural tenet of Oribin. We provide high-speed email, unified identities, and cloud workspace tools without ever profiling your correspondence or monetizing your personal data.

Effective Date: October 2, 2026
Applies to: Oribin Mail, Accounts & Ecosystem Services
Jurisdiction: India (DPDP Act) & Global (GDPR Compatible)
🛡️

Zero Ad Scanning

We never scan, inspect, or analyze email contents or snippets to display advertisements.

🔐

Encrypted Transit

All email dispatches, webhook payloads, and web sessions use mandatory TLS 1.3 encryption.

👤

Data Sovereignty

You own your emails. You can export your data or delete your account with immediate database purging.

⚖️

Strict Confidentiality

We never sell, rent, or lease your user data or contact records to commercial data brokers.

Scope & Commitment

This Privacy Policy applies to all services, web applications, and developer interfaces provided under the Oribin brand, including Oribin Mail (mail.oribin.in), Oribin Accounts (accounts.oribin.in), and the central Oribin workspace hub (oribin.in).

At Oribin, our guiding philosophy is straightforward: communication tools should empower users, not exploit their personal conversations. We build software engineered for speed, minimalist elegance, and dependable security. This document details precisely what information is collected, how it is secured, and your sovereign rights over your data.

Core Guarantee
Oribin does not trade, rent, broker, or sell any personal data, email addresses, or message content to third-party marketing firms or programmatic advertising networks.

Information We Collect

We only collect data strictly necessary to deliver high-performance email transmission, authenticate your identity, and safeguard our network against malicious abuse.

1. Account Information Provided by You

  • Display Name: Your chosen full name or organization alias.
  • Oribin Handle / Username: Unique identifier chosen upon registration (e.g., username@oribin.in).
  • Authentication Credentials: Password strings are never stored in plaintext. They are irreversibly hashed and salted using industry-standard bcrypt before database persistence.

2. Communications & Mailbox Data

  • Email Messages: Subject lines, sender and recipient addresses, message body content (HTML and plain text), and message metadata.
  • Mailbox Folders & State: Status tags such as read/unread markers, star indicators, and folder allocations (Inbox, Sent, Starred, Trash).
  • Timestamps: Exact creation, dispatch, and delivery timestamps to provide reliable thread sorting.

3. Technical & Telemetry Information

To maintain server uptime, mitigate denial-of-service attempts, and prevent unauthorized account access, our edge gateways automatically record operational logs:

  • IP Address & User Agent: Used solely for security session verification, rate limiting, and brute-force protection.
  • Session Identifiers: Cryptographic bearer tokens issued upon successful authentication.

How We Process Your Data

We process personal and communication data on the legal bases of contractual necessity (fulfilling your request to communicate via email), legitimate security interests, and legal compliance:

Purpose Data Categories Used Legal Basis
Email Delivery & Relay Recipient email, subject, body, sender identity Service Contract (Performance)
Identity Authentication Username, email, bcrypt password hash, session token Contract & Security
Spam & Malware Defense Outbound volume rate, sending IP, header formatting Legitimate Security Interest
Account Storage Management Message counts, folder indexes, total storage footprint Service Fulfillment

Infrastructure & Delivery Relays

Oribin relies on audited, enterprise-grade cloud providers to run our global edge network, database clusters, and SMTP delivery pipelines:

  • Database Hosting (Supabase / AWS): Production data resides in secure, isolated PostgreSQL relational clusters protected by virtual private clouds (VPC) and strict firewall isolation.
  • Application Edge Network (Vercel): Frontend static assets and serverless API execution layers operate on global edge nodes with automatic DDoS mitigation.
  • Outbound Mail Relay (Resend / AWS SES): Outbound messages dispatched through Oribin Mail pass via authenticated, DKIM/SPF-signed REST pipelines to guarantee world-class inbox deliverability.
Subprocessor Governance
Every cloud provider utilized by Oribin is bound by rigorous Data Processing Agreements (DPAs) mandating confidential handling, encrypted transport, and zero secondary data harvesting.

Security Architecture & Encryption

We employ multi-layered technical controls to preserve the confidentiality and integrity of your messages:

  • Transport Layer Security (TLS 1.3): All browser-to-server and server-to-relay communications enforce modern TLS encryption with forward secrecy. Plaintext HTTP traffic is rejected.
  • Cryptographic Password Protection: Account passwords are salted with unique random entropy and hashed via bcrypt before reaching the storage layer. Plaintext passwords never touch disk logs.
  • Bearer Session Token Isolation: Sessions are authenticated via randomly generated high-entropy tokens. Signing out immediately terminates and invalidates the session in the central database.
  • Automated Rate Limiting & Brute-Force Safeguards: Inbound authorization attempts are throttled to thwart credential-stuffing and automated dictionary attacks.

Data Retention & Deletion

We retain your communications and account data only for as long as your account remains active and in good standing.

  • Active Mailbox Messages: Retained until you decide to delete them.
  • Trash Folder: Moving a message to the Trash designates it for removal. Emptying your trash executes an immediate and irreversible DELETE query against the database.
  • Account Closure & Deletion: If you request complete account closure, your profile, sessions, and all associated messages are purged completely from our active database records.

Storage & Cookies

Oribin utilizes browser localStorage solely for strictly necessary functional operations:

  • oribin_mail_token: Authenticated session key required to retrieve your inbox securely.
  • oribin_view_mode: Your UI layout preference (Full-Width table view vs. Split-Pane preview).
  • oribin_privacy_theme: Dark or light color mode selection.

Zero Ad Tracking: We do not load Google Analytics, Meta tracking pixels, behavioral advertisement SDKs, or invasive fingerprinting scripts.

Your Legal Rights

Depending on your geographical location, you possess statutory rights regarding your personal information under frameworks such as the Indian Digital Personal Data Protection Act (DPDP), the General Data Protection Regulation (GDPR), and California privacy statutes:

  • Right to Access: You may request a machine-readable summary of personal data held about you.
  • Right to Rectification: You can update or correct your profile display name directly in your account dashboard.
  • Right to Erasure ("Right to be Forgotten"): You have the right to request the permanent deletion of your account and communications.
  • Right to Grievance Redressal: You may submit complaints directly to our designated Grievance Officer.

Children's Privacy

Oribin is engineered for general audiences and professional workspace communication. We do not knowingly solicit, collect, or process personal data from children under the age of 13 (or under 18 in jurisdictions where consent of a legal guardian is required). If we discover that a minor has registered without verifiable parental consent, we will promptly terminate the account and purge related records.

Policy Amendments

As we introduce new features, protocols, and ecosystem services, we may periodically revise this Privacy Policy. Any updates will be published immediately on this portal (privacy.oribin.in) with an updated "Effective Date". For significant changes that materially affect your privacy rights, we will provide prominent notice via in-app banner or direct notification to your Oribin inbox.

Grievance & Contact Information

In accordance with the Information Technology Act and the Digital Personal Data Protection Act, our team is committed to addressing inquiries and resolving complaints swiftly:

Oribin Privacy & Compliance Desk

Email: privacy@oribin.in
Support Desk: support@oribin.in
Legal Notice Desk: legal@oribin.in
Domain: oribin.in