← Outora

Outora Privacy Policy

Draft. This policy is published as a clearly-marked draft ahead of formal adoption. Bracketed placeholders — the entity name and the effective date — resolve when Outora LLC is formed and this policy formally takes effect. The substance is real: it describes how Outora works today.

Version: 1.0-draft
Effective date: [Effective date — set at publication]
Entity: [Outora LLC, a New York limited liability company — formation pending; “Outora,” “we,” “us”]
Contact: privacy@outora.app

The short version

Outora exists to make your outdoor history visible and meaningful — as an Explorer identity that belongs to you. That shapes how we treat your data:

The rest of this policy says the same things precisely.

1. Who we are

Outora is a motivation engine for real-world outdoor adventures, operated by [Outora LLC — formation pending]. This policy covers the Outora mobile and web app and the outora.app website.

2. What we collect

We collect only the categories listed here. If a future feature needs something new, we will update this policy and its version number first (see Section 10).

2.1 Account information

2.2 Check-ins and location

2.3 Adventure history you claim

If you add past completions (our honor-system claim flow), we store the adventures you claimed and the dates you provide.

2.4 Badges and momentum

We store the badges you earn and your momentum/progress records. By schema-level design, these only accumulate — nothing about them resets or is used to penalize you.

2.5 Usage records (analytics events)

The app records product events: adventure views and opens, check-ins (including the coordinates involved), searches (including the search text you type), badge awards, momentum updates, and share actions. These event records are linked to your account identifier when stored. What we may do with them beyond operating the service is governed by your consent choices (Section 5). If you delete your account, the link between these events and you is permanently severed (Section 7).

2.6 Reports you submit

If you report a data problem (“Explorers improve the map for Explorers”), we store your report and your account identifier. If you delete your account, the report is kept but permanently anonymized.

2.7 Error reports

If the app hits an error, a technical error report is sent to our error-monitoring provider (Sentry). We have configured this to be errors only: no user identity is attached, no session tracking, no performance tracing, no replays, and IP addresses are not stored. We process these reports on a legitimate-interest basis — keeping the service working — and they contain no personal profile of you by configuration.

2.8 Emails we send

We send transactional email only: confirmation links, password resets, email-change confirmations, and security notices (for example, “your password was changed”). These are delivered by our email provider (Resend) from no-reply@outora.app. We do not send marketing email. If that ever changes, it will be opt-in and this policy will be updated first.

2.9 Referral information

If you arrive through another Explorer's share link, we record which account's link brought you (so their sharing is honored) and the kind of link it was. If the referring Explorer later deletes their account, this link is automatically severed.

2.10 Data stored only on your device

Some data lives only in your device's local storage and is not transmitted to us as a record: your login session, an in-progress account-upgrade note (the email you're confirming), and convenience data like recently viewed adventures. Deleting the app removes it.

2.11 Map tiles (third-party requests)

The map is drawn using tiles from the OpenStreetMap Foundation's tile servers. When the map loads, your device requests those tiles directly, which — like any web request — exposes your IP address and the map area you're viewing to the OpenStreetMap Foundation, under their privacy policy. We do not receive or store this.

3. What we deliberately do not do

4. How we use your information

PurposeData usedBasis
Running Outora: accounts, check-in validation, badges, progress, maps, sharingAccount, profile, check-ins, claims, badges/momentumProviding the service you asked for
Keeping Outora working and secure: debugging, abuse prevention, backupsUsage records, error reports, account dataLegitimate interest (narrowly scoped; see 2.7 and 8)
Honoring referralsReferral informationProviding the service
Aggregate statisticsUsage records, check-insOnly with your consent (Section 5)
Individual pattern analysisUsage records, check-insOnly with your consent (Section 5)
Uses of your photos beyond your own check-in recordCheck-in photosOnly with your consent (Section 5)

5. Your consent choices

Outora asks three separate questions, each with its own switch. Each is genuinely optional: declining any or all of them changes nothing about your experience — check-ins, badges, momentum, journeys, and sharing work identically either way, and always will.

  1. Aggregate statistics — whether your activity may be included in anonymized, aggregated statistics (for example, “how many Explorers checked in on this peak this season”), where no individual Explorer is identifiable.
  2. Individual patterns — whether your activity may be analyzed as anonymized individual-level usage patterns (for example, how a single anonymous Explorer's activity develops over a season), with your identity removed.
  3. Photo licensing — whether photos you attach to check-ins may be used by Outora beyond your own account record.

The precise wording of each question, shown at the moment you're asked, is the authoritative scope of that consent. Mechanics:

6. Who we share data with (processors)

We share personal data only with the service providers that run Outora, only for the purposes above:

ProviderRoleWhat they process
SupabaseDatabase, authentication, and server functions (our backend)All server-stored data in Section 2
ResendTransactional email deliveryYour email address and the content of auth emails
SentryError monitoringError reports (configured PII-free; see 2.7)
NetlifyHosting for outora.appStandard web-server request logs for the website
PorkbunDomain/DNS for outora.appDNS queries (no personal data from us)
Microsoft OneDriveOff-site backup storageEncrypted backup archives only — ciphertext, encrypted before upload (see Section 8)
OpenStreetMap FoundationMap tile deliveryYour device's tile requests (see 2.11)

We may also disclose information if the law genuinely requires it, or in connection with a change of ownership of Outora — in which case this policy continues to apply to previously collected data and we will notify you of any successor.

7. Deletion — what actually happens

You can delete your account from inside the app, whether it's a guest or registered account. Deletion is immediate in our live systems and works like this:

Backups: we keep encrypted backups so Explorers' histories can survive a disaster. A deleted account disappears from live systems immediately, and from backups as archives age out of our 90-day backup retention period — so deletion also fully holds in backup depth on that schedule. [The 90-day retention schedule takes effect at publication.]

8. How we protect your data

9. Your rights, children, and jurisdictions

10. Changes to this policy

Each version of this policy carries a version identifier (this draft is 1.0-draft). Your consent answers are stored against the version you answered under. If we change this policy materially — new data, new use, new recipient — we will publish the new version, bump the identifier, and re-ask for consent where your answers were given under the older version. We will not quietly widen anything.

11. Contact

privacy@outora.app · [Outora LLC — formation pending]