Outora Privacy Policy
The short version
Outora exists to make your outdoor history visible and meaningful — as an Explorer identity that belongs to you. That shapes how we treat your data:
- We collect what the product needs to work: your check-ins (including GPS location at the moment you check in), your badges and progress, your account details, and basic usage records.
- We don't sell your data. We don't show ads. We don't track you across other apps or websites.
- Anything beyond running the service — aggregate statistics, pattern analysis, use of your photos — happens only if you say yes, through consent choices you can change at any time. Saying no changes nothing about your experience.
- You can delete your account from inside the app, and deletion actually deletes.
The rest of this policy says the same things precisely.
1. Who we are
Outora is a motivation engine for real-world outdoor adventures, operated by [Outora LLC — formation pending]. This policy covers the Outora mobile and web app and the outora.app website.
2. What we collect
We collect only the categories listed here. If a future feature needs something new, we will update this policy and its version number first (see Section 10).
2.1 Account information
- Registered accounts: your email address and a password (stored only as a cryptographic hash by our authentication provider — we never see or store your plain password).
- Guest accounts: none of the above. A guest account is an anonymous account with a random identifier. If you later upgrade a guest account, your email attaches to the same account — your history stays yours and nothing is copied elsewhere.
- Profile: your chosen trail name (display name), an optional avatar image (stored as image data in your profile record), and the list of adventures you've joined.
2.2 Check-ins and location
- When you check in at an adventure, we record the GPS coordinates your device reports at that moment (latitude, longitude, and altitude if available), a timestamp, the adventure and check-in location involved, and whether the check-in was GPS-validated or self-reported.
- Location is used in the foreground only, when you're using the app — to show your position on the map and to validate check-ins. Outora does not collect background location. Location is never collected when the app is closed.
- You may attach an optional photo to a check-in. The photo (and, if your device includes them, its embedded timestamp and location) is stored as part of that check-in record. Photos are never required.
2.3 Adventure history you claim
If you add past completions (our honor-system claim flow), we store the adventures you claimed and the dates you provide.
2.4 Badges and momentum
We store the badges you earn and your momentum/progress records. By schema-level design, these only accumulate — nothing about them resets or is used to penalize you.
2.5 Usage records (analytics events)
The app records product events: adventure views and opens, check-ins (including the coordinates involved), searches (including the search text you type), badge awards, momentum updates, and share actions. These event records are linked to your account identifier when stored. What we may do with them beyond operating the service is governed by your consent choices (Section 5). If you delete your account, the link between these events and you is permanently severed (Section 7).
2.6 Reports you submit
If you report a data problem (“Explorers improve the map for Explorers”), we store your report and your account identifier. If you delete your account, the report is kept but permanently anonymized.
2.7 Error reports
If the app hits an error, a technical error report is sent to our error-monitoring provider (Sentry). We have configured this to be errors only: no user identity is attached, no session tracking, no performance tracing, no replays, and IP addresses are not stored. We process these reports on a legitimate-interest basis — keeping the service working — and they contain no personal profile of you by configuration.
2.8 Emails we send
We send transactional email only: confirmation links, password resets, email-change confirmations, and security notices (for example, “your password was changed”). These are delivered by our email provider (Resend) from no-reply@outora.app. We do not send marketing email. If that ever changes, it will be opt-in and this policy will be updated first.
2.9 Referral information
If you arrive through another Explorer's share link, we record which account's link brought you (so their sharing is honored) and the kind of link it was. If the referring Explorer later deletes their account, this link is automatically severed.
2.10 Data stored only on your device
Some data lives only in your device's local storage and is not transmitted to us as a record: your login session, an in-progress account-upgrade note (the email you're confirming), and convenience data like recently viewed adventures. Deleting the app removes it.
2.11 Map tiles (third-party requests)
The map is drawn using tiles from the OpenStreetMap Foundation's tile servers. When the map loads, your device requests those tiles directly, which — like any web request — exposes your IP address and the map area you're viewing to the OpenStreetMap Foundation, under their privacy policy. We do not receive or store this.
3. What we deliberately do not do
- No sale of personal data. We do not sell, rent, or trade your personal information. (This is also our answer to “Do Not Sell or Share” under state privacy laws: we don't.)
- No advertising. Outora shows no ads and shares no data with ad networks. This is a design commitment, not just a current state.
- No cross-app tracking. We do not track you across other companies' apps or websites, and we do not use third-party advertising or tracking SDKs. Because we don't track, browser “Do Not Track” and similar signals change nothing — there is no tracking to turn off.
- No cookies on outora.app. The outora.app website is a static page that sets no cookies and runs no analytics or tracking scripts.
- No background location. Location is used only in the foreground, as described above.
- No marketing email. Transactional messages only.
4. How we use your information
| Purpose | Data used | Basis |
|---|---|---|
| Running Outora: accounts, check-in validation, badges, progress, maps, sharing | Account, profile, check-ins, claims, badges/momentum | Providing the service you asked for |
| Keeping Outora working and secure: debugging, abuse prevention, backups | Usage records, error reports, account data | Legitimate interest (narrowly scoped; see 2.7 and 8) |
| Honoring referrals | Referral information | Providing the service |
| Aggregate statistics | Usage records, check-ins | Only with your consent (Section 5) |
| Individual pattern analysis | Usage records, check-ins | Only with your consent (Section 5) |
| Uses of your photos beyond your own check-in record | Check-in photos | Only with your consent (Section 5) |
5. Your consent choices
Outora asks three separate questions, each with its own switch. Each is genuinely optional: declining any or all of them changes nothing about your experience — check-ins, badges, momentum, journeys, and sharing work identically either way, and always will.
- Aggregate statistics — whether your activity may be included in anonymized, aggregated statistics (for example, “how many Explorers checked in on this peak this season”), where no individual Explorer is identifiable.
- Individual patterns — whether your activity may be analyzed as anonymized individual-level usage patterns (for example, how a single anonymous Explorer's activity develops over a season), with your identity removed.
- Photo licensing — whether photos you attach to check-ins may be used by Outora beyond your own account record.
The precise wording of each question, shown at the moment you're asked, is the authoritative scope of that consent. Mechanics:
- Each choice is recorded as not yet asked, declined, or granted — we distinguish “never asked” from “said no,” and we don't treat silence as consent.
- You can change any answer at any time in the app. Withdrawing consent stops future use; analysis already published in anonymized, aggregated form cannot be retroactively unpublished.
- Each answer is stored with the policy version you answered under and a server-recorded timestamp. If this policy materially changes, we re-ask rather than assume.
6. Who we share data with (processors)
We share personal data only with the service providers that run Outora, only for the purposes above:
| Provider | Role | What they process |
|---|---|---|
| Supabase | Database, authentication, and server functions (our backend) | All server-stored data in Section 2 |
| Resend | Transactional email delivery | Your email address and the content of auth emails |
| Sentry | Error monitoring | Error reports (configured PII-free; see 2.7) |
| Netlify | Hosting for outora.app | Standard web-server request logs for the website |
| Porkbun | Domain/DNS for outora.app | DNS queries (no personal data from us) |
| Microsoft OneDrive | Off-site backup storage | Encrypted backup archives only — ciphertext, encrypted before upload (see Section 8) |
| OpenStreetMap Foundation | Map tile delivery | Your device's tile requests (see 2.11) |
We may also disclose information if the law genuinely requires it, or in connection with a change of ownership of Outora — in which case this policy continues to apply to previously collected data and we will notify you of any successor.
7. Deletion — what actually happens
You can delete your account from inside the app, whether it's a guest or registered account. Deletion is immediate in our live systems and works like this:
- Deleted outright: your check-ins (including any photos attached to them), your badges, your momentum records, your profile (including trail name and avatar), your authentication data (email, password hash, sessions, identities) — the account itself.
- Kept, permanently anonymized: usage-event records and any data-problem reports you submitted have your account identifier permanently removed. The events stop being about you (an aggregate count stays honest; a map-fix report keeps improving the map), and the anonymization is irreversible by design.
- Self-healing links: if other Explorers arrived via your share links, the link to your deleted account is automatically severed on their records.
Backups: we keep encrypted backups so Explorers' histories can survive a disaster. A deleted account disappears from live systems immediately, and from backups as archives age out of our 90-day backup retention period — so deletion also fully holds in backup depth on that schedule. [The 90-day retention schedule takes effect at publication.]
8. How we protect your data
- Server-side data lives behind row-level security and least-privilege access rules: your records are readable by you, not by other Explorers. Check-in records can only be written by our server, never directly by any client.
- Backups are encrypted (AES-256, including filenames) before leaving our systems; the storage provider only ever holds ciphertext.
- Passwords are handled and hashed by our authentication provider; we never store plain passwords.
- No system is perfectly secure, and we don't promise otherwise — but if we learn of a breach affecting your personal data, we will notify affected Explorers and applicable regulators as the law requires.
9. Your rights, children, and jurisdictions
- Access: your data is visible to you in the app — your profile, check-ins, badges, and progress are the product. For a copy of your data beyond what the app shows, contact us.
- Deletion: in-app, as described in Section 7 — no email required, no waiting on us.
- Consent withdrawal: in-app, any time (Section 5).
- Correction: you can edit your profile in-app; for anything else, contact us.
- We honor these rights for everyone, not only where a statute compels it. Depending on where you live (for example, under state privacy laws like the California Consumer Privacy Act), you may have additional formal rights — including the right not to be discriminated against for exercising them, which is moot here: nothing in Outora is conditioned on consenting. We do not sell personal data or use it for targeted advertising, and requests can be sent to the contact above.
- Children: Outora is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn we have, we will delete it. We do not collect birthdates from anyone — the age requirement is enforced through these terms and through deletion upon actual knowledge, by design.
- Outora is operated from the United States and data is processed in the United States.
10. Changes to this policy
Each version of this policy carries a version identifier (this draft is 1.0-draft). Your consent answers are stored against the version you answered under. If we change this policy materially — new data, new use, new recipient — we will publish the new version, bump the identifier, and re-ask for consent where your answers were given under the older version. We will not quietly widen anything.
11. Contact
privacy@outora.app · [Outora LLC — formation pending]