Privacy Policy
Last updated September 4, 2026
This policy explains how Outer handles personal data. Keeping your memory private, durable, and under your control is part of the service—not an advertising model.
Controller and contact
The data controller for Outer is Goodvibe OÜ, registry code 14101638, at Sepapaja tn 6, Lasnamäe, Tallinn 15551, Estonia. Contact us about privacy or exercise your rights at hello@outer.run.
Data we collect
- Account and organization data — your email address, authentication records, organization, role, and account settings.
- Memory content — threads, notes, evidence, files, and machine-readable content created by you or an agent acting under your authority.
- Keys and authorization records — key name, scope, prefix, hash, use metadata, revocation, and records showing what a person or agent was allowed to access. We do not retain the plaintext agent key after it is issued.
- Billing records — plan, subscription and customer identifiers, billing status, purchase interval, transaction references, and reconciliation events. Link handles the payment transaction; we do not receive or store your full card number.
- Service, product-analytics, and security data — IP address, coarse deployment environment and page category, device and request metadata, timestamps, quota usage, audit events, errors, and diagnostic logs needed to operate, protect, and improve Outer. Our browser analytics does not collect memory text, form values, resource identifiers, full URLs, or session recordings.
- Support data — messages, contact details, and records needed to answer a request, complaint, withdrawal, or refund.
Why we use it
- Contract — to create your account, authenticate requests, store and return authorized memory, provide plan features, reconcile billing status, and provide support.
- Legitimate interests — to secure Outer, prevent fraud and abuse, investigate failures, maintain reliable operations, and improve the service using appropriately limited operational evidence. We balance these interests against your rights.
- Legal obligations — to keep required accounting, transaction, consumer-complaint, tax, security, and compliance records and to respond to lawful requests.
- Consent — only where we ask for a separate, optional permission. You may withdraw that consent at any time without affecting earlier lawful processing.
Agents and people you authorize
A person or agent with a valid scoped key can access memory within that key’s authority. You control that sharing by choosing scopes and revoking keys. If an organization manages your account, its authorized administrators may manage membership, billing, and access according to their role.
Service providers and payment data
We use providers for authentication, hosting, databases, object storage, email, security, monitoring, limited product analytics, and customer support. PostHog EU Cloud processes privacy-bounded page categories for product analytics. These providers process data only for the services they provide to us and under applicable data-protection terms.
Paid purchases are sold through Link using Stripe Managed Payments. Link is merchant of record and handles payment details, tax, receipts or invoices, transaction support, and related fraud prevention under the privacy information shown at Checkout. Outer receives the identifiers and status needed to provide Pro and reconcile cancellations or refunds. We may also disclose information when required by law, to protect legal rights or safety, or as part of a corporate transaction subject to appropriate safeguards.
International transfers
Some providers may process data outside Estonia or the European Economic Area. Where required, we use an adequacy decision, standard contractual clauses, or another lawful transfer mechanism together with appropriate technical and organizational safeguards.
Storage and security
Outer separates tenant data and encrypts data in transit. We use scoped authorization, hashed keys, access controls, backups, monitoring, and rate limits to protect the service. No system is perfectly secure; please revoke exposed keys and report suspected unauthorized access promptly to hello@outer.run.
Retention and deletion
We keep account data and memory content while needed to provide Outer and until the account or content is deleted. Deleted data can remain temporarily in restricted backups until those backups rotate. Security and audit records are kept only as long as reasonably needed to investigate abuse, preserve service integrity, or establish legal claims. Billing, accounting, refund, and complaint records are retained for the periods required by applicable law. We may keep a minimal record of a deletion request so we can prove it was completed.
Your rights
Depending on applicable law, you may ask for access, correction, deletion, restriction, or portability of your personal data, and may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it. We may ask for information needed to verify your identity and will normally respond within one month.
You may lodge a complaint with the Estonian Data Protection Inspectorate or another competent supervisory authority. Information is available from the Estonian Data Protection Inspectorate. You also have the right to seek a judicial remedy.
Automated decisions
Outer does not use personal data to make solely automated decisions that produce legal or similarly significant effects about you. Automated security checks, quotas, and rate limits protect the service; you can contact us if you believe one has affected your account incorrectly.
Cookies and browser analytics
We use cookies and similar storage needed to keep you signed in, preserve security, and operate the service. We do not use advertising or cross-site tracking cookies. Browser product analytics uses an in-memory, short-lived identifier rather than analytics cookies or persistent browser storage, respects supported Do Not Track signals, and is limited to coarse page categories. Autocapture, session replay, form and text capture, heatmaps, and automatic exception capture are disabled.
Content involving other people
Do not place another person’s personal data in Outer unless you have a lawful reason and authority to do so. Avoid special-category or highly sensitive data unless it is necessary, lawful, and appropriate for your use of the service.
Changes
We may update this policy when Outer or applicable requirements change. We will update the date above and give reasonable notice before a material change takes effect where required.
Contact
Goodvibe OÜ · registry code 14101638 · Sepapaja tn 6, Lasnamäe, Tallinn 15551, Estonia · hello@outer.run.