Privacy policy
Last updated August 17, 2026.
What we collect
What we collect depends on how you use the site:
- If you just browse — routine edge and origin access logs (IP address, user agent, URL, timestamp, and similar request metadata), kept for security, abuse prevention, and reliability. We do not use browse-only logs to build advertising profiles.
- If you create an account — your email address. If you sign in with Google or GitHub, we receive the name, email, and avatar those providers share. If you use email and password, Supabase stores a password hash. We never see your password in plain text.
- If you're granted alpha access — an access-status flag on your account
(
app_metadata.status), optional admin role (app_metadata.role), and build or configuration data you create in the workbench so you can return to it. - If you send a run request or email us — your email address and whatever you include (workload, power budget, form factor, environment, or other message content).
- If you use the build chat — the messages you type and the resulting build state, stored against your account as a transcript so the conversation survives a reload. Your messages are sent to an AI model to generate the reply; see AI features.
- If you upload a profile photo — the image file itself, stored in our
avatarsstorage bucket under a path derived from your account id. Objects in that bucket are readable by anyone who has the object's URL — it is a public-read bucket, which is what lets your photo render in the app. Directory listing is disabled, so the URL cannot be discovered by browsing, but treat an uploaded avatar as public rather than private. Don't upload an image you need kept confidential. - Bot and abuse checks — when Cloudflare Turnstile or bot products are enabled, Cloudflare may process short-lived challenge signals needed to tell humans from automated clients.
- Product analytics — first-party only. We record which pages and steps you reach, when a design run starts, completes, or fails, and whether you view the 3D model or export a bill of materials. Each record carries a session id that lives only until you close the tab, your account id when you are signed in, an id for the design run, the page path, and the version of our code and parts catalog that produced the result. No third-party analytics script is loaded — not PostHog, not Google Analytics, not Cloudflare Web Analytics — and none of this leaves our own infrastructure. We do not set an analytics cookie and we do not track you across sites or between visits. You can turn it off; see Cookies and local storage.
- Optional hardware benchmark bundle — if you opt in, you run documented local commands on your
machine and may upload a JSON file you produced. The MVP collects inventory and an optional live usage snapshot.
We do not mine a month of OS history after the fact. Without a forward sample, any personalized scores use that
snapshot plus a disclosed population-average baseline. See
docs / runbook
user-benchmark-bundlein the repo. Nothing leaves your machine until you choose to share the file.
How we use it
We use this information to operate accounts and alpha access, respond to run requests and email, keep the site secure and available, enforce invite and admin gates, and improve the product. If we add paid hardware or software checkout, we will use order information to fulfill and support that order, and we will update this policy before that goes live.
Processors and service providers
We do not sell your personal information. We use processors that only see what they need to provide their service:
- Cloudflare, Inc. — CDN, DNS, DDoS and bot protection, Pages hosting, and optional Turnstile.
May set strictly necessary security cookies such as
__cf_bmorcf_clearance. See Cloudflare's cookie documentation. - Supabase — authentication (GoTrue), account records, and related session storage for signed-in users.
- Amazon Web Services (AWS) — backend API, jobs, and data stores used by the platform when those services are enabled for your environment.
- Google / GitHub — OAuth sign-in when you choose those providers. We only receive the profile fields noted above.
- Email delivery — transactional mail (for example confirmation or invite messages) when SMTP is configured. Owner-alert mail from the edge Worker is sent via Amazon SES. Auth confirmation/reset mail uses whatever SMTP is configured on Supabase Auth for that environment (moving to SES; see the auth-email runbook in the repo). We do not use email for marketing.
- Anthropic — the AI model behind the build chat, reached through Amazon Bedrock or the Claude Platform on AWS. It receives the message content described under AI features.
- A future payment processor — not in use yet. Before checkout goes live, we will name the processor and describe what it sees.
We may also disclose information if required by law, or to protect the security of the site and our users.
AI features
The workbench build chat is powered by an AI model — Claude, made by Anthropic — which we reach through Amazon Bedrock or the Claude Platform on AWS. Both run inside our AWS environment; we do not send your messages to a consumer chatbot.
What is sent to the model: the message you type, the build configuration under discussion (workload, power budget, form factor, and similar constraints), and the relevant parts catalog. What is not sent: your password, your session tokens, or your payment details, since we hold none of those in the chat.
Under the AWS terms we use, your messages are not used to train Anthropic's models and are not retained by the model provider to improve their service. AWS may hold them briefly for abuse monitoring under its own terms.
The model can be wrong. Thermal figures, power budgets, part fit, and clearances it produces are generated output, not engineering sign-off, and the Terms disclaimer on preliminary specs applies to them in full. Check anything load-bearing against the documented figures before you buy parts or trust a build.
The chat is scoped to hardware. It is not a general-purpose assistant, and it is not a source of medical, legal, financial, or crisis support. If you tell it you are in distress it will stop and point you to a crisis line rather than answer — in the US and Canada, call or text 988 — but the safe assumption is that this tool is the wrong place to raise it. In an emergency, call your local emergency number.
We keep chat transcripts against your account so a conversation survives a reload. You can see them in the export described under your rights, and deleting your account removes them on the schedule described there.
Cookies and local storage
We don't run a cookie-preference banner, and our product analytics is why that is still honest rather than
convenient. It sets no cookie and creates no durable identifier: the only id in
your browser is a random session id held in sessionStorage, which the browser discards when you
close the tab, so we cannot recognise you on a later visit. Nothing is sent to a third party. If we ever add a
durable identifier or a third-party analytics tag, we will introduce a consent mechanism before it loads and
describe it here.
The same goes for fonts and scripts: pages load them from our own domain only, so simply reading this site does not announce your visit to a third-party font or tag provider. Our Content-Security-Policy header enforces that rather than leaving it to good intentions. The exceptions are named above — Cloudflare, which sits in front of the site, and Turnstile where a bot check is enabled.
When you create an account you accept our Terms, which cover analytics tied to that account. If we materially change those terms, we will email you and make it straightforward to review and accept the new version.
Categories today:
- Strictly necessary — always on. Auth session, edge access cookie, Cloudflare security cookies, related local storage, and error reports (a page that breaks has to be reportable, or we cannot fix it).
- Product analytics — on, first-party, no cookie, no cross-site or cross-visit tracking. To turn it off: enable Global Privacy Control in your browser (we honour it), or use the analytics toggle in Settings. Turning it off stops product measurement; error reports still run, since those are what tell us the site is broken.
First-party storage the site sets:
Cloudflare may also set processor cookies such as __cf_bm (bot management, typically about 30
minutes) and cf_clearance (after a challenge). Those are security cookies set by Cloudflare, not
advertising cookies. Details: Cloudflare
cookies.
Retention
Account data is kept while the account is active and for a reasonable period after closure for security, dispute, and legal compliance. Contact and run-request email is kept as long as needed to respond and for ordinary business records. Edge and security logs are retained according to Cloudflare and AWS defaults for the environment, typically on the order of days to weeks unless a longer window is required for an incident. Workbench project data, build chat transcripts, and uploaded avatar files are kept until you delete them or your account, or until we close the alpha program and notify you. Product-analytics records are kept for up to 400 days — a full year plus a month, so one period can be compared against the same period a year earlier. Deleting your account removes your account id from those records, leaving them anonymous rather than linked to you. When data is no longer needed, we delete or anonymize it.
Your rights and regional notices
outfra.ai is intended for users in the United States and Canada. We are not currently structured to serve the EU or UK under GDPR or ePrivacy. If you are outside the US or Canada, do not create an account until we expand this policy.
Self-serve export and deletion
If you have an account, the fastest way to review or remove your data is to do it yourself. Sign in and open the Data & privacy section of account settings, where you can:
- Download your data — a full export of what we hold on you: your identity record, account metadata, and the build and configuration data you created in the workbench.
- Delete your account — starts deletion, in two stages, described below.
How deletion actually works today. We would rather describe this precisely than imply an instant wipe:
- Immediately — your account is marked for deletion and sign-in and API access stop working. A restore window of 30 days is recorded on the account, so an accidental or regretted deletion is recoverable rather than final.
- After the 30-day window — the remaining records are erased: your login identity, account rows, build and configuration data, chat transcripts, and uploaded avatar files. Security and edge logs age out on their own schedule, and product-analytics rows are stripped of your account id rather than deleted, as described under Retention.
- Being straight about the current mechanism — that final erasure is presently run by us rather than by an automatic scheduled job, so it can complete some days after the 30-day mark. Automating it is tracked work, and we will drop this caveat from the policy when the scheduled job is live. If you want your erasure confirmed, or done sooner, email [email protected] and we will run it and reply.
If you can't sign in — say you've lost access to your email or OAuth provider — email [email protected] from an address you can verify and we will handle the request manually.
California residents (CCPA/CPRA)
Depending on revenue and data volume, California's privacy law may or may not formally apply yet. We still offer these rights. California residents may ask us to disclose, delete, or correct personal information we hold. The self-serve tools above cover disclosure (the export) and deletion directly. For corrections, or if you can't sign in, email [email protected]. We do not sell or share personal information for cross-context behavioral advertising today, so a "Do Not Sell or Share" link is not required for that purpose. If that changes, we will add the link and honor Global Privacy Control where required.
Canada (PIPEDA)
For users in Canada, we collect and use personal information for the purposes in this policy, with consent shown by creating an account or contacting us. You may see what we hold or delete it yourself with the self-serve tools above, or email us below if you can't sign in.
Children's privacy
outfra.ai is not directed at children under 13. We do not knowingly collect personal information from them. If you believe a child has created an account or sent us information, email us and we will delete it.
Security
We use HTTPS, processor access controls, and least-privilege service roles where configured. No method of storage or transmission is completely secure. We cannot guarantee absolute security.
Changes to this policy
If collection changes materially (analytics going live, checkout, new processors), we will update this page in plain language and refresh the date at the top before that change ships.
Questions
Email [email protected].