OrbitexAIOVideo Downloader

Privacy Policy

What this service does and does not collect when you paste a link, how long anything is kept, and who else can see it.

Last updated

Nota: Este documento solo está disponible en inglés, y el texto en inglés es la versión vinculante.

Who we are

This service is operated by Orbitex, from Pakistan. It is a small independent tool rather than a company with a legal department, and this policy is written accordingly: it describes what the service actually does, in plain words, and it does not claim to have been reviewed by a lawyer or to comply with any statute by name. Privacy questions and data requests go to support@orbitexaio.com and are answered by a person.

What this policy covers

This policy covers this website and the download tools on it. It does not cover the third-party platforms whose content you link to: when you paste a link, the platform hosting that media has its own relationship with you and its own policies. It does not cover anything you do with a file after you download it, which is between you, the rights holder and the law where you are.

There are no accounts

There is no sign-up, no login, no password, no profile and no saved history. The service never asks for your name, your email address or any other identifying detail, and there is no facility to give one. This shapes everything below: there is no user record for anything to attach to. What the next section describes is request data, the technical traces any web server sees, and not a profile of you.

Information the service handles

Four things on the server, plus the Google Analytics data described under cookies below, and nothing else. First, the link you paste: it is read to work out which platform it belongs to and to extract that platform's own media identifier. It is not stored as text. Second, public metadata about the media - title, thumbnail, duration, the file variants the platform publishes - held briefly in a cache keyed by that media identifier rather than by your URL. Third, standard web-server access logs, which for this site as for any other record the client IP address, the user agent, the timestamp, the requested path, the response status and the referrer where your browser sends one. Fourth, anything you type into a contact or platform-request form, which is simply the message you sent. There is no account data, no payment data, no device fingerprinting and no location beyond whatever an IP address implies.

A specific note about the link you paste

Because it is the question people actually ask: the link is not written to a database or an application log as text, and the metadata cache is keyed by the platform's own media identifier, so what survives a request is a record about a public video rather than a record of your asking for it. One honest caveat. Web-server access logs record the requested path, so a link submitted inside a URL would appear in them like any other path; the application receives the pasted link in the request body instead, which keeps it out of those logs. There is one exception to the idea that your link goes only to the platform it belongs to, and it is set out in full under Independent resolvers below.

What each of those is used for

The link is used to answer the request you made with it, and for nothing else. The metadata cache exists so that two people asking about the same video within a few minutes do not cause two identical requests to the source platform; it is keyed by media identifier precisely so that it cannot double as a history of who asked for what. Access logs are used to keep the service running and secure - diagnosing faults, investigating abuse, understanding load. The client IP address is used for rate limiting, which is what stops one automated client consuming the capacity everyone else is sharing. Messages sent through a form are used to reply to you and, for platform requests, to decide what to build next. None of this builds a profile, none of it is sold, and none of it is shared for advertising.

Cookies, analytics and advertising

This site uses Google Analytics 4, provided by Google, to count visits and understand which pages are used. When a page loads, the site sends Google, through its own address, the address of the page, the page that referred you, your browser and device type, screen size, language, and your IP address, from which Google derives an approximate location. Google Analytics 4 does not log or store IP addresses. It sets first-party cookies named _ga and _ga_ followed by the property ID, which let it recognise a returning browser without identifying who you are. Google Analytics keeps event data, the record of individual page views and interactions, for two months. It keeps user-level data tied to that cookie for fourteen months, and that period restarts each time the same browser visits again. The link you paste into the downloader is never sent to Google Analytics. What you type into the site search does appear in the search page's address, and Google Analytics records that address. You can block it with any content blocker or with Google's own opt-out browser add-on. No advertising network is integrated either, and there is no ad slot on any page - the placeholders that once reserved space were removed. Apart from the Google Analytics cookies named above, no cookie is set for analytics, advertising or cross-site tracking. Storage used by the interface itself is limited to remembering choices you make on your own device, such as a display preference; it stays in your browser and is not an identifier. If a cookie or an analytics or advertising provider is ever introduced, this section will name it and say what it receives before the first request reaches it, not afterwards.

How long anything is kept

Specific periods, taken from the running configuration rather than from an intention. Web-server access logs are rotated by size, with at most five archived files kept and older ones deleted automatically. Cached media metadata expires after 10 minutes, after which it is fetched again if anyone asks. Download tokens are valid for 10 minutes and are useless once they expire. Backups get their own sentence, because a deletion commitment means nothing if a copy quietly survives in one nobody mentioned: there are seven daily and four weekly database backups, so nothing survives beyond about four weeks. The link you paste has no retention period because it is not retained. Messages you send through a form are kept as long as needed to deal with what they are about.

Who else can see any of this

The site runs on infrastructure operated by Contabo GmbH, with no CDN in front of it, which necessarily handles requests in transit and generates the access logs described above. The source platform you are downloading from also sees a request, because the service fetches the media from it - that request comes from the server rather than from your browser, so the platform sees the server, not you. For two platforms there is one further recipient, named individually in the next section. Google receives the analytics data described in the cookies section above, as the provider of Google Analytics; it processes that data under its own terms and may do so outside the country you are in. No advertising network receives anything. Personal data is not sold and is not shared for advertising. Information may be disclosed where the operator is legally required to do so, or where it is necessary to investigate abuse, and only to the extent actually required. Any new provider with access to request data will be named here before it is introduced.

Independent resolvers, and the one platform that uses one

For fifteen of the sixteen supported platforms the server works out the media address itself, so the link you paste goes nowhere except to the platform it names. For TikTok it does not: that one is resolved by asking an independent service for the media address, which means sending it the link you pasted. TikTok links go to TikWM, at www.tikwm.com. That request is made by the server, not by your browser, so what the resolver receives is the link together with this service's own network address - not yours, not your user agent, and no cookie or identifier belonging to you. Once it answers, the media is fetched directly and the resolver has no further part in it. That is a separate operator running its own infrastructure under its own terms, and this service cannot promise what it logs or for how long. The list above is exhaustive. If you would rather no third party saw a particular link, the honest answer is not to use that tool for it.

Where processing happens

Worth stating plainly, because it is not what most people would guess: the operator is in Pakistan, but the server is not. Requests are served and logged in France, in the European Union, which is where the hosting provider's machine physically sits, and the operator administers that machine remotely from Pakistan. So your request data is handled in Europe and can be seen by one person outside it. Separately, and unavoidably, fetching media means contacting the platform that hosts it, which may be anywhere in the world - that is inherent in asking for a video from a foreign service and is not something this tool can localise.

Your rights, and what can realistically be done with them

Depending on where you live, the law may give you the right to ask what personal data is held about you, to have it corrected or erased, to object to processing, or to receive it in a portable form. Requests of that kind are handled here whether or not a particular statute compels it, and the target for a substantive answer is 30 days. Send them to support@orbitexaio.com. There is a practical limit worth being honest about: with no accounts and no identifier connecting you to a request, the operator usually cannot find "your" data, because nothing recorded here identifies you. An access or deletion request will normally be answerable only for a narrow window of access logs, and only if you can identify the requests concerned - by IP address and approximate time, for instance. If you are unhappy with how a request was handled, say so at that address first; if that does not resolve it, the data-protection authority in the country where you live is the usual escalation route where one exists.

Children's privacy

The service is not directed at children and is not intended for anyone under 13. No age is collected, because nothing is collected in the account sense - there is nothing to register and nothing to fill in - so the operator has no means of verifying anyone's age and does not attempt to. If you believe a child has sent personal information through a contact form, write to support@orbitexaio.com and it will be deleted.

Security

Only what is actually done. Traffic is served over HTTPS. There are no user accounts, which means there are no passwords to store, no credentials to leak and no account database to breach - the strongest privacy measure here is simply the absence of collection. Download links are issued as opaque, short-lived tokens rather than by exposing the upstream URL, so a link cannot be reverse-engineered into something durable and stops working shortly after it is issued. Rate limiting keyed on the client IP address keeps automated abuse from degrading the service. No certification is claimed and no system is described here as secure, because no honest operator can promise that.

Changes to this policy

If this policy changes, the revised version is posted on this page with an updated date. Material changes - a new category of data, a new recipient, a longer retention period, the introduction of analytics or advertising - will be made clear rather than folded quietly into the text, and will be described here before the change ships rather than after it.

Contact

Privacy questions and data requests go to support@orbitexaio.com. Copyright complaints follow the separate process on the Copyright Notice and Takedown page, linked as "DMCA" in the footer. General questions about using the service go to support@orbitexaio.com. All three reach a person rather than a ticket system.