Licence notices
BlueOcean Orbit is built on open source software. The components we use and their licences are listed here. The source code of Orbit itself is not open source.
Server service
| Component | Purpose | Licence |
|---|---|---|
| Python | Runtime environment | PSF-2.0 |
| FastAPI | Web service | MIT |
| Starlette | ASGI framework | BSD-3-Clause |
| Uvicorn | Application server | BSD-3-Clause |
| Pydantic | Data validation | MIT |
| httpx | HTTP client | BSD-3-Clause |
| cryptography | Encryption of stored keys | Apache-2.0 / BSD-3-Clause |
| dkimpy | Signing of outgoing email | BSD-2-Clause / Zope-2.1 |
| SQLite | Database | Public Domain |
| Ollama | Running the language model | MIT |
| SearXNG | Web search (separate service on our server) | AGPL-3.0 |
| Llama 3.2 | Language model | Llama 3.2 Community License |
| Gemma 3 | Image understanding (runs on our server) | Gemma Terms of Use |
| faster-whisper | Speech recognition (dictation, conversation) | MIT |
| Piper | Speech output (read aloud) | MIT |
| eSpeak NG | Phonetics for speech output (separate program on our server) | GPL-3.0 |
| FFmpeg | Conversion of audio recordings (separate program on our server) | LGPL-2.1+ |
Built with Llama. The language model is licensed under the Llama 3.2 Community License by Meta Platforms, Inc. — a licence of its own, not one of the usual open-source licences. It permits commercial use and requires this notice in return; we pass its terms on to you insofar as you use the model through us. The Gemma Terms of Use by Google apply likewise to image understanding, including the usage restrictions set out there. We provide both texts on request.
Windows application
| Component | Purpose | Licence |
|---|---|---|
| Qt for Python (PySide6) | User interface | LGPL v3 |
| httpx | Server communication | BSD-3-Clause |
| PyInstaller | Building the executable | GPL-2.0 with an exception for generated files |
On Qt for Python (LGPL v3): you may replace the bundled Qt library with your own build. We provide the information needed to do so on request at info@blueocean.report.
Website
| Component | Purpose | Licence |
|---|---|---|
| Inter | Typeface (self-hosted) | SIL Open Font License 1.1 |
| Spectral | Typeface (self-hosted) | SIL Open Font License 1.1 |
| MediaPipe Tasks Vision | Camera detection in the browser (self-hosted, no CDN) | Apache-2.0 |
| BlazeFace model | Face presence in the browser (self-hosted) | Apache-2.0 |
Messenger
These components carry the BlueOcean Messenger. They have been in operation since August 2026.
| Component | Purpose | Licence |
|---|---|---|
| Synapse | Matrix home server (standalone service on our server) | AGPL-3.0 |
| coturn | Relay server for voice and video calls | BSD-3-Clause |
| PostgreSQL | Database of the home server | PostgreSQL License |
| matrix-js-sdk | Matrix protocol in the browser (bundled by us, no CDN) | Apache-2.0 |
| matrix-sdk-crypto-wasm | End-to-end encryption in the browser | Apache-2.0 |
| matrix-encrypt-attachment | Encryption of attachments in the browser | Apache-2.0 |
On the AGPL component Synapse: we run it unmodified as a standalone service under its own domain and take no source code from it into Orbit. Only the configuration is adjusted. The source code is published by its maintainers; on request we will name the exact version we run.
We write the messenger interface ourselves — as an app for iPhone and Android and as a web client. We do not ship a third-party client. The Matrix protocol and the encryption underneath it are third-party libraries under Apache-2.0; they sit on our server and are loaded from there, never from a foreign network.
The apps for iPhone and Android
These components are delivered to your device with the app. That is why they are listed separately here — for a distributed program file the Apache-2.0 licence requires attribution, not just for operation on our server.
| Component | Purpose | Licence |
|---|---|---|
| matrix-rust-sdk | Matrix protocol and end-to-end encryption — the same core in both apps | Apache-2.0 |
| matrix-rust-components-swift | The Matrix core for the iPhone app (built by Matrix.org) | Apache-2.0 |
| Java Native Access (JNA) 5.18.1 | Connects the Matrix core with the Android app | Apache-2.0 OR LGPL-2.1-or-later |
| androidx.media3 (Transformer) | Shrinks videos before sending (Android) | Apache-2.0 |
| AndroidX, Jetpack Compose, Material Components | Interface of the Android app | Apache-2.0 |
| Kotlin standard library and coroutines | Programming language of the Android app | Apache-2.0 |
| androidx.security.crypto | Encrypted storage of the login in the Android Keystore | Apache-2.0 |
| rustls-platform-verifier | Verification of HTTPS certificates on Android | Apache-2.0 / MIT |
| Firebase Cloud Messaging (firebase-messaging) | Wake-up call for notifications on Android while the app is closed — no content in it, see privacy policy, section 7 | Apache-2.0 |
| Google Play Billing | Subscribing in the Play Store (Android) | Android Software Development Kit License |
| SwiftUI, Foundation | Interface of the iPhone app (Apple system libraries) | Apple SDK terms |
The full licence texts ship with the app and can be requested at any time at [email protected]. No source code from third-party projects sits in either app — what you install we wrote ourselves, apart from the libraries named here.
Embedded services
This site embeds two tools by BlueOcean Privacy. Both are operated by the same company that operates Orbit — they are not third-party providers:
- Consent tool (
blueocean.report) — collecting, documenting and managing consent, on every page. - Privacy policy embed (
embed.blueocean.report) — supplies the general part of the privacy policy, on the privacy page only.
A note on inspiration
While designing Orbit we studied publicly visible projects and drew on their concepts. Source code from those projects is not contained in Orbit. The ideas and principles underlying a computer program are not protected by copyright under Art. 1(2) of Directive 2009/24/EC.