Own product

Orbit

How does “share approximately” become a verifiable technical boundary?

Orbit displays four sharing modes for a private circle: exact, approximate, on request and off.
iOS simulator state. The visible choices map to different data paths, not merely different labels.

Orbit shares location within private circles. Accuracy, recipients and duration are decided on device; the server distributes encrypted data.

Field
Private location sharing
Period
2026
Status
Test tracks · v0.3
Platforms
iOS, Android, Web viewer
Services
Flutter app, Native background engine, Backend, End-to-end encryption

Context

Location sharing is not one switch. People can share exact, approximate, requested or no location with different circles and need to understand the effective rule later.

Responsibility

Product and protocol design, Flutter interface, native background engine, end-to-end encryption, Node/Fastify backend, PostgreSQL model and test-track builds.

Outcome

Version 0.3 on test tracks with iOS and Android clients, device-specific keys, per-circle sharing, time-bounded accompaniment and a temporary web viewer.

Orbit displays who may request a location and which sharing rules are active.
“Who sees what?” makes recipients, requests and circle rules inspectable together.
Orbit people screen for a private location-sharing circle.
Real iOS simulator capture from project documentation. Names are test data.

Approximate cannot be a blurred exact marker

If an app sends exact coordinates and only draws a large circle later, the server still has the exact position. Orbit coarsens location on device before encryption and transport.

The implementation treats approximation as persisted state. A person leaves a coarse cell only after moving at least 250 metres past its boundary and remaining there for ten minutes. A heartbeat can confirm the current state after 15 minutes. This hysteresis avoids rapid cell changes that could reconstruct a more precise path from many coarse samples.

The intended scale is roughly three kilometres. It is a product compromise, not a mathematical anonymity guarantee. Boundaries, rare places and auxiliary information can still support inference.

Encryption follows recipient devices

Orbit encrypts location per recipient device. HPKE establishes keys, AES-GCM protects payloads and Ed25519 signs them. The server checks permissions, stores envelopes and distributes them without requiring locations, saved places or messages in plaintext.

People can own several devices, add a device or lose one. The engine therefore tracks recipient devices and key epochs. A new epoch separates future messages from an older key state, and the send path creates envelopes only for currently authorised recipients.

Metadata remains a separate privacy question, and a compromised endpoint can see decrypted data. The bounded claim is that domain payloads are encrypted on clients for authorised devices and are not plaintext for the distribution server.

Sharing is an ongoing, revocable decision

Each circle can receive exact, approximate, requested or no location. The “Who sees what?” screen combines circle rules, individual people and past requests so the effective decision remains visible after setup.

Pause and “stop everything” disable local sending immediately and queue the revocation for synchronisation. The device does not need to reach the server before it stops producing new locations. Previously delivered data cannot be recalled from other devices; that boundary is explicit.

New devices pair through a 25-character comparison code. Passwordless email codes prove account access, while device comparison confirms a cryptographic channel. They solve different trust problems.

Background behaviour outlives Flutter

Location and deadlines do not end when the visible Flutter interface pauses. Orbit uses a Swift and Kotlin engine connected through Pigeon. The shared interface expresses intent and presents state; native code owns background location, local keys and operating-system boundaries.

Accompaniment has a server-side deadline. A “not arrived” outcome therefore does not depend on the accompanied phone remaining active at that moment. The location payload stays separate and encrypted.

What this demonstrates for client work

Orbit turns privacy language into state machines, key boundaries and offline behaviour. Words such as approximate, paused and stopped only become meaningful through those rules.

CIDIX would not automatically reuse this protocol in another product. The transferable work is mapping a clear user decision to inspectable data processing: which device creates data, who can open it, how long permission lasts and what happens offline.

Technology and what it is for

Flutter
Shared interface
Riverpod
App state
Swift
Background engine on iOS
Kotlin
Background engine on Android
Pigeon
Typed Flutter ↔ native bridge
HPKE
Keys per recipient device
AES-GCM
Encrypted payloads
Ed25519
Device and account signatures
Fastify 5
Backend API
PostgreSQL
Data model
MapKit
Map on iOS
MapLibre
Map on Android and in the web viewer