BlueOcean Orbit
Open Source

Licence notices

BlueOcean Orbit is built on open source software. The components we use and their licences are listed here. The source code of Orbit itself is not open source.

Server service

ComponentPurposeLicence
PythonRuntime environmentPSF-2.0
FastAPIWeb serviceMIT
StarletteASGI frameworkBSD-3-Clause
UvicornApplication serverBSD-3-Clause
PydanticData validationMIT
httpxHTTP clientBSD-3-Clause
cryptographyEncryption of stored keysApache-2.0 / BSD-3-Clause
dkimpySigning of outgoing emailBSD-2-Clause / Zope-2.1
SQLiteDatabasePublic Domain
OllamaRunning the language modelMIT
SearXNGWeb search (separate service on our server)AGPL-3.0
Llama 3.2Language modelLlama 3.2 Community License
Gemma 3Image understanding (runs on our server)Gemma Terms of Use
faster-whisperSpeech recognition (dictation, conversation)MIT
PiperSpeech output (read aloud)MIT
eSpeak NGPhonetics for speech output (separate program on our server)GPL-3.0
FFmpegConversion of audio recordings (separate program on our server)LGPL-2.1+

Built with Llama. The language model is licensed under the Llama 3.2 Community License by Meta Platforms, Inc. — a licence of its own, not one of the usual open-source licences. It permits commercial use and requires this notice in return; we pass its terms on to you insofar as you use the model through us. The Gemma Terms of Use by Google apply likewise to image understanding, including the usage restrictions set out there. We provide both texts on request.

Windows application

ComponentPurposeLicence
Qt for Python (PySide6)User interfaceLGPL v3
httpxServer communicationBSD-3-Clause
PyInstallerBuilding the executableGPL-2.0 with an exception for generated files

On Qt for Python (LGPL v3): you may replace the bundled Qt library with your own build. We provide the information needed to do so on request at info@blueocean.report.

Website

ComponentPurposeLicence
InterTypeface (self-hosted)SIL Open Font License 1.1
SpectralTypeface (self-hosted)SIL Open Font License 1.1
MediaPipe Tasks VisionCamera detection in the browser (self-hosted, no CDN)Apache-2.0
BlazeFace modelFace presence in the browser (self-hosted)Apache-2.0

Messenger

These components carry the BlueOcean Messenger. They have been in operation since August 2026.

ComponentPurposeLicence
SynapseMatrix home server (standalone service on our server)AGPL-3.0
coturnRelay server for voice and video callsBSD-3-Clause
PostgreSQLDatabase of the home serverPostgreSQL License
matrix-js-sdkMatrix protocol in the browser (bundled by us, no CDN)Apache-2.0
matrix-sdk-crypto-wasmEnd-to-end encryption in the browserApache-2.0
matrix-encrypt-attachmentEncryption of attachments in the browserApache-2.0

On the AGPL component Synapse: we run it unmodified as a standalone service under its own domain and take no source code from it into Orbit. Only the configuration is adjusted. The source code is published by its maintainers; on request we will name the exact version we run.

We write the messenger interface ourselves — as an app for iPhone and Android and as a web client. We do not ship a third-party client. The Matrix protocol and the encryption underneath it are third-party libraries under Apache-2.0; they sit on our server and are loaded from there, never from a foreign network.

The apps for iPhone and Android

These components are delivered to your device with the app. That is why they are listed separately here — for a distributed program file the Apache-2.0 licence requires attribution, not just for operation on our server.

ComponentPurposeLicence
matrix-rust-sdkMatrix protocol and end-to-end encryption — the same core in both appsApache-2.0
matrix-rust-components-swiftThe Matrix core for the iPhone app (built by Matrix.org)Apache-2.0
Java Native Access (JNA) 5.18.1Connects the Matrix core with the Android appApache-2.0 OR LGPL-2.1-or-later
androidx.media3 (Transformer)Shrinks videos before sending (Android)Apache-2.0
AndroidX, Jetpack Compose, Material ComponentsInterface of the Android appApache-2.0
Kotlin standard library and coroutinesProgramming language of the Android appApache-2.0
androidx.security.cryptoEncrypted storage of the login in the Android KeystoreApache-2.0
rustls-platform-verifierVerification of HTTPS certificates on AndroidApache-2.0 / MIT
Firebase Cloud Messaging (firebase-messaging)Wake-up call for notifications on Android while the app is closed — no content in it, see privacy policy, section 7Apache-2.0
Google Play BillingSubscribing in the Play Store (Android)Android Software Development Kit License
SwiftUI, FoundationInterface of the iPhone app (Apple system libraries)Apple SDK terms

The full licence texts ship with the app and can be requested at any time at [email protected]. No source code from third-party projects sits in either app — what you install we wrote ourselves, apart from the libraries named here.

Embedded services

This site embeds two tools by BlueOcean Privacy. Both are operated by the same company that operates Orbit — they are not third-party providers:

A note on inspiration

While designing Orbit we studied publicly visible projects and drew on their concepts. Source code from those projects is not contained in Orbit. The ideas and principles underlying a computer program are not protected by copyright under Art. 1(2) of Directive 2009/24/EC.