Privacy Policy
This is a convenience translation. The German version prevails.
In short: this website loads no third parties, does not measure visitors and sets no advertising cookies. The assistant itself runs on a server we operate — chat content is not sent to any external company by default.
1. Controller
BOP BLUEOCEAN PRIVACY LTD, Delphon 8, Livadia, Office 204, 7060 Larnaca, Republic of Cyprus.
info@blueocean.report
· +357 96915453. Further details in the legal notice.
2. Visiting this website
When pages are requested, the server processes the technically necessary connection data (IP address, time, requested path, status code, user agent). The legal basis is our legitimate interest in secure operation, Art. 6(1)(f) GDPR.
No analytics, advertising or social media services are embedded. Fonts are self-hosted.
Consent tool: To obtain, document and manage consent we load a script from
blueocean.report. This service is operated by the same company
as Orbit (BOP BLUEOCEAN PRIVACY LTD); it is not a third-party provider and no data is shared
with third parties. The tool stores your choice (consent or refusal) on your device so that
it applies on later visits. The legal basis for this technically necessary entry is our
legitimate interest in complying with consent obligations, Art. 6(1)(f) GDPR. Any other
cookies are set only with your consent, Art. 6(1)(a) GDPR; you can withdraw it at any time
with effect for the future via the tool.
3. Registration, login and session
- Registration: To open an account we process your e-mail address and send you a confirmation link (valid for 24 hours). The account only becomes active after confirmation and setting a password; unconfirmed registrations have no effect. Legal basis: steps prior to entering a contract, Art. 6(1)(b) GDPR.
- Credentials: e-mail address (as username) and password. The password is stored only as a checksum (scrypt with random salt), never in plain text.
- Session: After login the server stores a session token (as a hash only)
in its database, valid for 12 hours. In the browser it lives in
sessionStorageand is discarded when the tab closes. This is technically necessary, Art. 6(1)(b) GDPR. - Password reset: On request the server creates a one-time token valid for 30 minutes and sends it by e-mail to the address associated with the account.
4. Content in the workspace
- Chat: Your messages go to a language model running on our own server in the same internal network. It is not publicly reachable. The content is not transmitted to any other company.
- Profiles: name, role, brand list and personal working instructions.
- Observations: notes with source and confidence. Only confirmed observations enter the language model's context. Each observation can be deleted individually. Special categories of personal data within the meaning of Art. 9 GDPR are not automatically stored as facts.
- Media: optionally uploaded profile pictures and voice files are stored in the data directory of the same server.
- Services you connect (MCP): you can connect your own services to Orbit (Settings → "Connect services"). When Orbit uses a tool of such a service — always only after your confirmation — the necessary details go to that service; it is then a recipient within the meaning of Art. 13(1)(e) GDPR that you chose yourself. Your key is stored encrypted, never displayed, and deleted when you disconnect.
- Web search: if you let Orbit search the web, your search term goes through our own search engine (SearXNG, running on our server) anonymously to public search engines — without your name, without an account, without cookies. Our server fetches the pages found and summarises them for you; the sources are named.
- Files and images in chat: if you attach a file or an image to a conversation, it is stored and analysed on our server — text by a text extractor, images by a locally running vision model. The content does not leave our server and is not transmitted to any other company. Every attachment can be deleted individually and is deleted together with the chat.
- Speech (dictation): when you use the microphone, your browser records the audio and sends it to our server once. There, a locally installed speech recognition (faster-whisper) turns it into text. The recording is deleted immediately after the conversion and is not stored; only the recognised text ends up in your chat. There is no continuous listening — recording happens solely between the start and the end that you trigger yourself. The audio does not leave our server.
- Camera: if you switch on the camera (consent via your browser's prompt, Art. 6(1)(a) GDPR), the video image stays entirely in your browser. Presence detection (MediaPipe, hosted by ourselves, no third-party service) runs on your computer; nobody is identified and nothing is transmitted or stored. A picture is sent to our server in two cases only: as a single snapshot when you press the button yourself, or — if you switch on "Orbit may watch" — a current picture at intervals. For watching we first obtain your explicit consent (Art. 6(1)(a) GDPR) and record it with date and version; you can withdraw it at any time in the "Privacy" section of the settings. Transmitted pictures are treated like uploaded images (see "Files and images in chat") and do not leave our server.
- Conversation mode: if you switch on "Conversation", the microphone stays on until you switch it off again. Silence detection runs in your browser; only detected utterances are sent to our server one by one, converted to text there, and the recording is deleted immediately — just like dictation. There is no wake word and no hidden continuous listening: nothing listens without the visible switch. When you first switch it on we obtain your explicit consent (Art. 6(1)(a) GDPR) and record it with date and version; in the "Privacy" section of the settings you can withdraw it at any time and view the history of your decisions. The mode can also be turned off entirely there.
- Reading aloud: at the push of a button, a locally installed speech synthesis (Piper) turns the answer into audio. This also happens on our server and nothing is stored permanently. The voice is synthetic and therefore marked as artificially generated under Art. 50(4) of Regulation (EU) 2024/1689.
The legal basis is the performance of the usage contract, Art. 6(1)(b) GDPR.
5. Optional Claude premium factor
The premium factor is off by default. If the administration enables it and a user stores their own key for the Anthropic API, messages sent in this mode are transmitted to Anthropic PBC and processed there under their terms. The stored key is kept encrypted, never displayed and not logged; it can be deleted at any time. Without your own key no such transmission takes place.
6. Billing
The trial starts without payment details. Anyone who wants to continue afterwards stores their payment details with our payment provider Revolut. Card data is entered and stored exclusively there — we neither see nor store it. Our system only holds username, billing e-mail, subscription status and the payment provider's reference IDs. Legal basis: performance of contract, Art. 6(1)(b) GDPR, and statutory retention obligations under commercial and tax law, Art. 6(1)(c) GDPR.
2a. Visitor counts (reach measurement)
We count how often our public pages are opened and which buttons are clicked. No analytics script runs in your browser, no cookie is set, and nothing is stored on or read from your device — section 25 TDDDG therefore does not apply and no consent is required. No external provider is involved; the counting runs on our own server.
Your IP address is not stored. To distinguish visitors from mere page views, we derive a check value from IP address and browser identification, mixed with a random value that changes every day. Only that check value is stored. The random value is deleted after two days — after that the check value cannot be attributed to anyone, nor linked across days. There is no recognition across days, devices or websites.
Only numbers are stored: date, requested path, count. The legal basis is our legitimate interest in knowing whether our pages are found and understood (Art. 6(1)(f) GDPR). The numbers are deleted after 180 days. The signed-in workspace is not counted.
6a. Waiting list for the messenger
On the page /en/messenger/ you can put your name down for the planned BlueOcean Messenger. We store your name, e-mail address and country — nothing else. The sole legal basis is your consent (Art. 6(1)(a) GDPR); you see the full consent text before submitting, and we store its version alongside your entry so that it remains provable what you agreed to (Art. 7(1) GDPR).
We use these details solely to invite you at launch and to unlock the benefits promised to you. We pass them to nobody and send no advertising for other companies' products. Withdrawal: every message contains a link that deletes your entry immediately and in full; you need neither an account nor a reason. At the latest six months after the messenger launches we delete the list entirely.
Voluntary support for the project runs through Revolut (see section 7). We never receive your payment details.
6b. Reach measurement in our e-mails
When we send you a message about the waiting list or the messenger, we measure whether you opened it and whether you clicked a link inside. For that the message contains a small image file, and the links inside it lead via our server. We record the time of the first opening and of the first click — not your IP address, not your device, not your location. We do this to see which information gets through.
The legal basis is our legitimate interest (Art. 6(1)(f) GDPR). This measurement is expressly not part of the consent you gave when you joined the waiting list — that one says “name, e-mail, country. Nothing more.”, and it stays that way. We therefore do not base the measurement on your consent; we tell you openly here that we carry it out on a different basis. A note to that effect also appears in every measured message itself.
Object with one click. Every such message contains its own link for this (Art. 21 GDPR). You need neither an account nor a reason. After that we measure nothing more, and the times already recorded for your address are deleted. The unsubscribe link is separate from this and is never redirected — nobody is measured while leaving. After twelve months at the latest only totals per mailing remain, with no link to a person.
Who does this. Sending and measurement run on another platform of the same company. The controller in both cases is BOP BLUEOCEAN PRIVACY LTD. No outside mailing provider is involved, and your address is not passed to third parties.
6d. Documents to download
At /en/dokumente/ you can download documents. You need no account and no password — you enter your e-mail address, we send you a link, and the link opens the area. We store your e-mail address, the chosen language and the times you were there. Nothing else.
The legal basis is Art. 6(1)(b) GDPR: without your address we cannot send you the link, and without the link you cannot get in. The link is valid for 24 hours and works once; of the link and of your session we keep only a check value, never the key itself.
The tick “send me news” is optional and separate. Without it you get the documents just the same — it is not a condition for access (Art. 7(4) GDPR). If you set it, that is its own consent (Art. 6(1)(a)); we record its version and the time, and you can withdraw it at any moment without losing access.
Deletion: write to [email protected] and your access including the address is gone. We pass it to no third party.
6c. Messenger
The BlueOcean Messenger is a separate product, booked separately, built on the open Matrix standard. It runs on our own servers in Germany. The legal basis is performance of the contract (Art. 6(1)(b) GDPR).
What we never see:
- Message content. It is encrypted and decrypted on the devices of the people in the chat. Our server holds unreadable text only.
- Files, images and voice messages — likewise only as encrypted blocks.
- Your keys and your security phrase. They are created on your device and stay there.
What we do see — and why:
- Who is in which room with whom, and when. Every server needs this to deliver a message at all. End-to-end encryption protects content, not all traffic data — we say so openly because others leave it out.
- Room names and topics. Matrix encrypts the content of a room, not its master data. So do not put anything confidential into a room name.
- Whether you have read a message, whether you are typing, and when you were last here. Since 11 August 2026 the messenger shows ticks under your messages. To make that work, the devices send these three pieces of information to the server, and it passes them on to the others in the room. You can switch each of them off — in the browser under “What others see about you”, in the app under Settings. If you switch one off, you stop seeing it from others too. “When you were last here” starts switched off, because it says something about you and nothing about a message. The first tick (“delivered”) cannot be switched off: it only says that our server has the message, and it says nothing about you.
- Your profile picture. Since 15 August 2026 you can set a picture for yourself and for a conversation. A profile picture is not encrypted — unlike every message. It sits as an ordinary file on our media server, and anyone who knows its address can look at it, even without being in your conversation. That is how Matrix is built and not carelessness on our part: a picture has to be showable to someone who does not hold a key yet. This is why the same sentence also appears in the app, right under the button you use to choose one. A profile picture is optional — without one we only show the first letters of your name, and those are drawn on your own device.
- Storage use and file sizes — needed for the 2 GB guideline per account. The content stays invisible to us.
- IP address and number of devices, stored briefly to prevent abuse.
- Your e-mail address. Since 10 August 2026 you sign in to the
messenger with your e-mail address instead of a short name. For that the messenger
server has to know it — it stores the address with your account. Before, it only knew
the short name. We say so explicitly because it is one more piece of data on our side:
it changes nothing about the encryption, your messages stay unreadable to us. Your
address comes with a short name such as
@first.last:blueocean.report— that is what others use to invite you.
How long messages stay on our server: 30 days.
A messenger server is a holding area. It has to keep a message until every device involved has collected it — otherwise it would never reach a phone that is switched off. After that it is not needed, and we do not keep it either: after 30 days the server deletes every message and every attachment, for good and without anyone acting. Anything older lives only on the participants' devices.
What this means for you — please read this once: When you sign in on a new device, you will see nothing older than 30 days there. If you lose your only device, everything older is gone for good. We cannot restore it either; we no longer have it, and we could never have read it anyway.
Your keys are backed up separately from this, unless you switch that off — encrypted with your recovery key, unreadable for us. Without that backup, a new device could not open even the messages of the last 30 days.
A weakness we name openly: your account password opens the key backup.
So that you do not have to type 48 characters on a new device, your account password is also the security phrase of your key backup. That is convenient and has a price we will not hide from you:
- Anyone who knows your password can also open your key backup — and with it read old messages that are still on the server.
- When you sign in, your password travels encrypted (TLS) to our server. There it is visible at the moment of sign-in; it is never stored, only a checksum from which the password cannot be calculated back. We do not store it and we do not evaluate it — but we also do not claim that it would be technically impossible.
What you can do about it: Choose a password you use nowhere else. If you change it, all devices are signed out — anyone who had set themselves up with the old password gets no further. And the convenient route is not compulsory: you can switch the key backup off and work with the recovery key only. Then nobody can reach old messages through your password — not even you, if you lose that key.
Voice and video calls.
A call runs directly between the two devices wherever possible. Where that fails — on a mobile network or behind a corporate firewall — a server of ours relays the connection (a so-called TURN server). It stands in Germany and belongs to us; we put no third-party provider in between.
- Sound and picture are encrypted for that server too. It passes on data packets it cannot read itself. Listening in is technically impossible for it.
- Connection data does arise: the IP addresses of both sides, the time and the duration. This cannot be avoided — without it no connection finds its other end. We do not evaluate it. We build no connection overviews from it, no profiles and no statistics about who calls whom; we keep no call log.
The line that matters: we accept that connection data exists, because communication does not work without it. We do not evaluate content — neither messages nor calls, neither by hand nor automatically, and never to produce advertising, recommendations or analyses. This line holds without exception.
What this means for requests from authorities: we can hand over what we see — traffic data. We cannot hand over what we never hold: content and keys. That is a technical fact, not a promise.
Activation. We store when you were activated, whether an invitation or a voucher was used and who invited you. Invitation and voucher codes are held only as checksums. Your acceptance of the three texts (terms of service, privacy policy, code of conduct) is recorded with version and timestamp — the record required by Art. 7(1) GDPR.
Invited addresses. If you invite someone by e-mail, we store the address you type in — so that the person lands in your conversation after signing up and the invitation code is valid for them alone. If they do not sign up, we delete the address after 30 days, automatically. The invitation e-mail tells them so.
Sharing from other apps. When you share a photo, a video or a file from another app to the messenger, you choose the chat it should go to in the share window. So that this window can show your chats, the app keeps a list of your chats on your device — name, a small picture and when something last happened. This list stays on your device; the app does not send it anywhere, not to us either. The app deletes it when you sign out.
Your chats at the top of the share menu. When you write in a chat, the app gives the operating system of your device (iOS or Android) the name and picture of that chat, so that it appears at the top of the share menu the next time you share and you can pick it with one tap. It does not pass on message content. We receive nothing from this. What the operating system does with this information is determined by Apple or Google in their own privacy notices. If you delete a chat, the app withdraws its entry; if you sign out, it withdraws all of them. The legal basis is the performance of the terms of use (Art. 6(1)(b) GDPR) — you trigger the feature yourself.
“Delete for me”. If you delete a message only for yourself, it stays visible to the others in the chat; it is hidden on all your devices. To do this, we store the identifier of the message and the time in your account data — never its content, which we cannot read anyway. So we can see that you hid a certain message. At most the latest 1000 identifiers are kept. The legal basis is the performance of the terms of use (Art. 6(1)(b) GDPR).
Reports. If you report content through the code of conduct, you release that content to us; only then can we assess it. We process the report to meet our obligations under Art. 16 of the Digital Services Act (Art. 6(1)(c) GDPR) and delete it once the case is closed.
Deletion. If you cancel, we deactivate your messenger account. If you request erasure under Art. 17 GDPR, your uploaded files are removed as well.
6e. Finding contacts (matching at your request)
The app has a feature called “Find people”. If you use it and allow the app to read your address book, your device sends the e-mail addresses from your address book to our server — no names, no phone numbers, nothing else. The server does exactly one thing with them: it checks which of these addresses have a messenger account with us and answers with the matches. It does not store the addresses, does not write them to any log, and does not pass them on to anyone. After the answer they are gone from the server; all that is recorded is how often the feature was used — without any addresses.
You only see the matches: contacts who are already here. Of all other addresses we know nothing once the check is done. The matching runs by itself only if you switch it on in the app (“Check once a day by itself”): your device then repeats the same check once a day and shows you a notification when someone from your address book is newly here. Everything above still applies — and which matches you already know is remembered by your device alone, not by our server. Without that switch there is no background service and no automatic check at start; the permission to read your address book is granted solely by your device’s operating system, and you can switch the daily check off again at any time.
Legal bases: for you, the matching is part of the user contract (Art. 6(1)(b) GDPR) — you trigger it yourself. For the addresses of your contacts who do not (yet) have an account, we rely on the legitimate interest of enabling you to reach people you know (Art. 6(1)(f) GDPR). Our balancing: only the e-mail address is processed, only for seconds, only for this one purpose; nothing is stored or shared and no profile is created — no appreciable risk for the persons concerned arises. You can object at any time (Art. 21 GDPR): simply do not use the feature, or revoke the app’s address-book permission in your system settings.
6f. Feedback from the app (“Report something”)
In the app settings and in the workspace you can send us a bug, an improvement or a wish. This is voluntary and only happens when you type something and send it yourself — we have no automatic crash reporter that sends data without being asked.
What we store: your text, the chosen kind (bug, improvement, wish), the platform and app version, a ticket number and the time. If you are signed in, also your user ID. If you give an e-mail address — which is optional — we store it so that we can reply.
Device details only with your consent: we send the device model and operating system version only if you turn on the corresponding switch. It is off by default. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by leaving the switch off next time.
What we do not store: no message content, no screenshots, no logs from your device and no IP address alongside your report. We fetch nothing from your device — only what you write yourself is sent.
The legal basis for the text itself is our legitimate interest in a working product (Art. 6(1)(f) GDPR); without feedback we do not learn about faults. Retention: 24 months, then deleted. Recipients: none — reports stay in our system. If you delete your account we remove the user ID and e-mail address from your reports; the text stays anonymously, because it describes a fault, not a person.
7. Recipients
- Hetzner Online GmbH — server operation (data centre in Germany).
- Revolut — payment processing, only for paid use or voluntary support. On Revolut's checkout page, depending on your device, Apple Pay, Google Pay and the card networks Visa, Mastercard and American Express are also offered — providers based in the USA. That page is operated by Revolut; we never learn which payment method you choose there.
- Anthropic PBC — only with the premium factor active and your own key (section 5), processing in the USA.
- Cloudflare — name resolution and upstream protection of the domain.
- Apple Inc. (Apple Push Notification service) and Google Ireland Ltd. / Google LLC (Firebase Cloud Messaging) — for notifications only, and only if you allow them in the app. What we hand over is a wake-up call with no content in it: a room and event identifier, the device token and the point in time. No message text, no sender name, no phone number. Your device then fetches the text itself and decrypts it there — we could not pass it on even if we wanted to, because we never hold it in readable form. So both providers do learn something: that your device is being woken and when — but not by whom and not what. Processing also takes place in the USA (a third country); the basis is each provider's standard contractual clauses. Legal basis: Art. 6(1)(b) GDPR — without notifications a messenger cannot be used as agreed. If you do not allow notifications, nothing is transmitted at all.
No data is shared for advertising purposes. There is no sale of data and no profiling for advertising purposes.
8. Retention periods
- Sessions: 12 hours, then automatically invalid.
- Messenger messages and their attachments: 30 days, then the server deletes them by itself (section 7b).
- Invited e-mail addresses that never become an account: 30 days (section 6c).
- Registration tokens: 24 hours. Password reset tokens: 30 minutes.
- Profiles, observations and media: until deleted by the user or the contract ends.
- Billing records: until the statutory retention periods expire.
- Server connection data: short-term, for fault analysis.
9. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). You may withdraw any consent given at any time with effect for the future.
To do so, contact info@blueocean.report.
10. Right to lodge a complaint
You can complain to a data protection supervisory authority. Competent for us is the Commissioner for Personal Data Protection, 1 Iasonos Street, 1082 Nicosia, Cyprus (dataprotection.gov.cy). You may also contact the authority at your place of residence.