OUTIS ORDER
LEGAL

PRIVACY

What this website collects today, which is very little, and what the service will collect when there's a service to collect it.

DRAFT, NOT FINAL
This isn't a finished privacy policy and it hasn't been reviewed by a lawyer. It's a description of what's true today and what I intend, written so nobody has to guess. When there's a real policy it will replace this page and carry the date it took effect.

Why this page is a placeholder

Outis isn't sold yet and there are no customer accounts, so there's no processing to describe accurately. A full policy written now would describe practices that don't exist, and a policy somebody could rely on and shouldn't is worse than an honest gap.

What this website collects

Ordinary web server logs: the request, the time, an IP address and a user agent. No analytics, no advertising, no third-party scripts, and no cookies set by this site.

The site loads nothing from anywhere else. The fonts, the stylesheets, the scripts and the sprites all ship with it, and a test fails the build if any reference points off this origin. So visiting these pages tells no other company that you did.

What the preorder form collects

Nothing. It has no live endpoint behind it, so there's no list, no database row and no message. The preorder page says the same thing next to the button.

What the service will collect, when there is one

This is the intent, not a commitment, and it's here so the shape isn't a surprise later.

  • Account data: a name, an email address, an organization, and the authentication material for the account.
  • Operator data: which devices you hold, which actions you're eligible for, and the notification channel you chose.
  • Ceremony records: every request made, the payload as the integration supplied it, who staged, who committed, and the outcome.
  • Device telemetry: firmware version, battery level, signal strength, last contact time.
  • Operational logs: request metadata, IP addresses and user agents for the application and the API.

The parts designed not to be readable

Arming codes, device PINs, recovery codes and API tokens appear once, at the moment of use, and can't be retrieved afterward. Arming codes never reach a browser at all, and they're never stored as digits: the store keeps a keyed one-way index of each code, and matching what somebody types means computing the same index, not reading a code back.

What I'm not going to do

  • Sell personal data, or hand it to an advertiser.
  • Run third-party analytics on this site or in the application.
  • Train anything on the contents of your ceremonies.

Contact

There's no published privacy address yet, which is a gap rather than a policy. The disclosure page describes the same gap for security reports, and what happens in the meantime.