Orbit VPN — Privacy Policy
Last updated 2 October 2026. This policy covers the free Orbit VPN extension.
How the free VPN works
When you switch Orbit on, your browser connects directly to an exit proxy from Orbit's community pool. There is no Orbit server in between your browser and the exit: no account, no key, and no Orbit-side log of the sites you visit, because the traffic never passes through one.
The destination website sees the exit's IP address, not yours. The exit operator — a third party — sees your real IP address and the hostnames you connect to. That is true of every shared proxy service, and it is the trade you are making.
Clean exits only
Some public proxies intercept HTTPS: they terminate your TLS with a certificate they generated and can read what should be encrypted. Orbit tests every exit and refuses to route through exits that do this. Each exit must also pass a live HTTPS probe from your own browser before you are switched to it. An exit that cannot present a valid certificate is rotated out automatically. This is a safety property we consider non-negotiable, not a feature.
Even with that filtering, community exits are run by strangers. Treat the connection as hiding your IP, not as privacy from the exit operator: do not use it for banking, work systems, or anything you would not want a stranger to observe.
What Orbit collects (and does not)
a) Pool status. The extension downloads the list of available exits from Orbit's portal. This request reveals your IP address to the portal and that you use Orbit. It contains no browsing data.
b) No traffic logs. Because your traffic goes browser-to-exit directly, Orbit cannot and does not log your connections, destinations, or contents. There is no billing and no account.
c) Nothing about the pages you browse. The extension has no permission to read page content. It reads the proxy setting and its own configuration in chrome.storage.local on your device.
Sharing your IP (community exits)
Orbit is free because members share. If you tick Share my IP, Orbit registers your interest with the portal (your IP address, browser user-agent, and the time). Ticking the box does not let anyone route traffic through your connection yet.
Actual IP sharing requires a separate companion agent, an explicit enrollment, and a record of that consent. When it is active, other members' traffic may exit through your connection: destinations will see your IP as the source, and you are responsible for what your connection is used for. You can withdraw at any time — the toggle, the agent, or uninstalling the extension all stop it, and withdrawal takes effect before any new connection is routed.
Sharing is a two-way trade: while you share, you get the pool; if you do not share, the VPN stays free anyway.
WebRTC
While Orbit is on, the extension sets Chrome's WebRTC handling to disable_non_proxied_udp so WebRTC cannot reveal your real IP through STUN. It is restored to your browser's default when you switch Orbit off.
Turning it off
Flipping the toggle removes the browser proxy setting immediately: traffic goes out through your normal connection, and the WebRTC policy is restored. Nothing is retained on Orbit's side, because nothing about your traffic was ever sent there.
Abuse
Exits may block or rate-limit traffic that looks like abuse. Do not use Orbit for attacks, spam, or anything illegal — community exits that attract abuse get withdrawn, which hurts every member.
Contact
Questions, deletion requests (of the single signup row we hold), or abuse reports: the portal contact address on the portal.
Close