Effective: 08/28/2026 ·
Last updated: 08/28/2026
Orrery is a mobile application for reading the U.S. Centers for Medicare & Medicaid Services
(CMS) Open Payments dataset. This policy explains what we collect from you, why, and what you can do
about it.
1. Who we are
Orrery (“Orrery”, “we”, “us”) is published by HBit Technology. The app is distributed through the Apple App Store
and Google Play under the identifier com.hbittechnology.orrery.
We are the data controller for the personal information described here. This policy covers the
Orrery app and the backend service it talks to. It does not cover the CMS Open Payments programme
itself, or any third-party website we link to.
2. The short version
You can search and read Open Payments data without telling us who you are. If you sign in, we
hold your name, email address, and an account identifier so that your subscription and your saved
work follow you between devices. We do not sell your data, we do not run advertising, and you can
delete your account and everything attached to it from inside the app.
3. What we collect
Browsing as a guest
On first launch the app signs in to a shared, non-personal account so that search works
immediately. At that point we do not ask for your name, email address, or any other identifying
detail, and we do not build a profile of you.
Signed-in accounts and subscriptions
| What | Where it comes from | Why we hold it |
|---|---|---|
| Email address and display name | Your Google or Apple account, passed to us when you sign in | To identify your account, restore it on a new device, and contact you about the service |
| An account identifier (a Firebase user ID) | Created when you first sign in | The key everything else is stored against |
| Subscription status and purchase history | Apple, Google, and our subscription processor | To unlock the tier you paid for, and to honour restores and refunds |
| Daily usage counters | Generated as you use the app | To apply the free tier’s daily allowance. We record how many records you opened and which ones, so that re-opening the same record on the same day is free |
| Saved contacts, tags, and notes | Written by you, on the paid tier | To store your own working notes and show them back to you |
| Diagnostic and crash information | Collected automatically when something fails | To find and fix faults. Includes device model, operating system version, app version, and the technical detail of the failure |
Sign in with Apple. If you choose to hide your email address, Apple gives us a
relay address instead of your real one. That works fine — we never see the address behind it,
and mail we send to the relay reaches you.
What we never collect
- Payment card numbers or bank details. Purchases are handled entirely by Apple and Google; we
are told only whether a subscription is active. - Passwords. There is no email-and-password sign-in — authentication is delegated to Google
and Apple. - Your location, contacts list, photos, calendar, microphone, or camera.
- Advertising identifiers. There is no advertising and no cross-app tracking in Orrery.
4. The Open Payments data is not your data
Most of what Orrery displays is the CMS Open Payments dataset: a public federal record of payments
and other transfers of value made by drug and device manufacturers to physicians, other covered
recipients, and teaching hospitals. CMS publishes that data; we do not collect it.
If you are a covered recipient and you appear in the app:
- We reproduce what CMS publishes. We do not add to it, and we do not link it to any user
account. - We cannot correct a record. Disputes and corrections run through CMS at
cms.gov/openpayments; a
change made there reaches Orrery at our next import. - Names are not unique. Around a quarter of recipient profiles share a name with another profile,
which is why the app always shows a city, state, or specialty alongside a name.
5. How we use what we collect
- To run the service — sign you in, keep you signed in, and show you your
own saved work. - To apply your tier — confirm an active subscription and count the free
tier’s daily allowance. - To keep the app working — diagnose crashes, fix defects, and watch for
abuse of the service. - To communicate with you — service messages such as billing problems,
security notices, and material changes to this policy. - To meet legal obligations — tax and accounting records for purchases,
and responses to lawful requests.
We do not profile you for advertising, and we do not use your saved notes or your search history
to train machine learning models.
6. Our legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we process your personal data on
these bases:
- Performance of a contract — account creation, sign-in, subscription
entitlement, and your saved contacts and notes. - Legitimate interests — diagnostics, security, fraud prevention, and
enforcing the free tier’s limits, balanced against your interests. - Legal obligation — retaining transaction records and responding to
lawful requests. - Consent — where we ask for it specifically, such as optional
notifications. You can withdraw consent at any time.
7. Who we share it with
We share personal data only with the service providers that make the app work, and only as far as
each one needs:
| Provider | What it handles |
|---|---|
| Google Firebase (Google LLC) | Authentication and account identifiers |
| Google Sign-In and Sign in with Apple | Verifying who you are at sign-in |
| RevenueCat, Inc. | Matching store purchases to your account and reporting subscription status |
| Apple App Store and Google Play | Taking payment, and handling billing, refunds, and renewals |
| [HOSTING PROVIDER] | Hosting the backend service and its database |
Beyond these, we disclose personal data only where the law requires it, to protect our rights or
someone’s safety, or — with notice to you — to a successor in a merger or
acquisition.
8. We do not sell your data
We do not sell your personal information, and we do not share it for cross-context behavioural
advertising, as those terms are used in the California Consumer Privacy Act and comparable state
laws. We have never done so.
9. How long we keep it
- Account data — for as long as your account exists.
- Saved contacts and notes — until you delete them, or until you delete
your account. - Daily usage counters — a short rolling window, long enough to apply the
daily allowance and detect abuse. - Diagnostics and crash reports — typically up to 12 months.
- Purchase and tax records — for as long as the law requires, usually
seven years, even after an account is deleted.
10. Deleting your account
You can delete your account from within the app, without contacting us. Deletion removes your
profile, your saved contacts, tags, and notes, and your usage counters. It cannot be undone.
Two things to know:
- Deleting your account does not cancel a subscription. Cancel that through the App Store or
Google Play, or it will keep renewing. - Backups and records we are required to keep may persist for a limited period after deletion,
and are not used for anything else in the meantime.
If you cannot reach the app, email hussain.murtaza@hbittechnology.com from your
account’s address and we will delete it for you.
11. Data stored on your device
So that the app is usable on a plane or a bad connection, it caches some data locally: your
sign-in session, app configuration, your current tier, records you have already opened, and your own
saved contacts and notes. This cache lives on your device, is removed when you sign out or uninstall
the app, and is not shared with anyone.
12. Security
Traffic between the app and our service is encrypted in transit with TLS. Sign-in tokens are held
in the operating system’s secure storage. Access to production data is limited to the people
who need it, and is logged.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the
relevant regulators as the law requires.
13. Children
Orrery is a professional reference tool. It is not directed at children, and we do not knowingly
collect personal information from anyone under 13 (or the equivalent minimum age where you live). If
you believe a child has given us personal information, contact us and we will delete it.
14. Your rights
Depending on where you live, you may have the right to:
- Know what personal information we hold about you, and get a copy of it.
- Correct information that is wrong.
- Delete your information.
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Withdraw consent you previously gave.
- Not be treated differently for exercising any of these rights.
To exercise any of them, email hussain.murtaza@hbittechnology.com. We will
verify your identity — usually by asking you to write from your account’s email address
— and respond within the period the law allows, normally 30 days. Using an authorised agent is
fine where the law provides for one.
If you are in the EEA or the UK you may also complain to your local supervisory authority. We
would appreciate the chance to address it first.
15. International transfers
We and our providers operate from the United States, so your information will be processed there.
Where data moves out of the EEA or the UK, it is transferred under the European Commission’s
Standard Contractual Clauses, the UK Addendum, or another approved mechanism.
16. Changes to this policy
We will update this page when our practices change, and revise the “last updated” date
at the top. If a change materially affects your rights, we will tell you in the app or by email
before it takes effect. Continuing to use Orrery after a change means you accept the updated
policy.
Orrery is an independent application. It is not affiliated
with, endorsed by, or sponsored by the Centers for Medicare & Medicaid Services or any U.S.
government agency. Open Payments data is published by CMS and reproduced here as public information.