Privacy

Privacy policy

Last updated August 17, 2026.

outfra.ai is operated by Quant-H2 LLC, a California limited liability company ("we", "us"). This policy covers the marketing site on Cloudflare Pages, the alpha account system (Supabase Auth), workbench access, and contact or run-request email. This page is a working draft for an early-stage product. It is not legal advice. Have counsel review it before you rely on it for production sales or EU traffic.

What we collect

What we collect depends on how you use the site:

How we use it

We use this information to operate accounts and alpha access, respond to run requests and email, keep the site secure and available, enforce invite and admin gates, and improve the product. If we add paid hardware or software checkout, we will use order information to fulfill and support that order, and we will update this policy before that goes live.

Processors and service providers

We do not sell your personal information. We use processors that only see what they need to provide their service:

We may also disclose information if required by law, or to protect the security of the site and our users.

AI features

The workbench build chat is powered by an AI model — Claude, made by Anthropic — which we reach through Amazon Bedrock or the Claude Platform on AWS. Both run inside our AWS environment; we do not send your messages to a consumer chatbot.

What is sent to the model: the message you type, the build configuration under discussion (workload, power budget, form factor, and similar constraints), and the relevant parts catalog. What is not sent: your password, your session tokens, or your payment details, since we hold none of those in the chat.

Under the AWS terms we use, your messages are not used to train Anthropic's models and are not retained by the model provider to improve their service. AWS may hold them briefly for abuse monitoring under its own terms.

The model can be wrong. Thermal figures, power budgets, part fit, and clearances it produces are generated output, not engineering sign-off, and the Terms disclaimer on preliminary specs applies to them in full. Check anything load-bearing against the documented figures before you buy parts or trust a build.

The chat is scoped to hardware. It is not a general-purpose assistant, and it is not a source of medical, legal, financial, or crisis support. If you tell it you are in distress it will stop and point you to a crisis line rather than answer — in the US and Canada, call or text 988 — but the safe assumption is that this tool is the wrong place to raise it. In an emergency, call your local emergency number.

We keep chat transcripts against your account so a conversation survives a reload. You can see them in the export described under your rights, and deleting your account removes them on the schedule described there.

Cookies and local storage

We don't run a cookie-preference banner, and our product analytics is why that is still honest rather than convenient. It sets no cookie and creates no durable identifier: the only id in your browser is a random session id held in sessionStorage, which the browser discards when you close the tab, so we cannot recognise you on a later visit. Nothing is sent to a third party. If we ever add a durable identifier or a third-party analytics tag, we will introduce a consent mechanism before it loads and describe it here.

The same goes for fonts and scripts: pages load them from our own domain only, so simply reading this site does not announce your visit to a third-party font or tag provider. Our Content-Security-Policy header enforces that rather than leaving it to good intentions. The exceptions are named above — Cloudflare, which sits in front of the site, and Turnstile where a bot check is enabled.

When you create an account you accept our Terms, which cover analytics tied to that account. If we materially change those terms, we will email you and make it straightforward to review and accept the new version.

Categories today:

First-party storage the site sets:

Cloudflare may also set processor cookies such as __cf_bm (bot management, typically about 30 minutes) and cf_clearance (after a challenge). Those are security cookies set by Cloudflare, not advertising cookies. Details: Cloudflare cookies.

Retention

Account data is kept while the account is active and for a reasonable period after closure for security, dispute, and legal compliance. Contact and run-request email is kept as long as needed to respond and for ordinary business records. Edge and security logs are retained according to Cloudflare and AWS defaults for the environment, typically on the order of days to weeks unless a longer window is required for an incident. Workbench project data, build chat transcripts, and uploaded avatar files are kept until you delete them or your account, or until we close the alpha program and notify you. Product-analytics records are kept for up to 400 days — a full year plus a month, so one period can be compared against the same period a year earlier. Deleting your account removes your account id from those records, leaving them anonymous rather than linked to you. When data is no longer needed, we delete or anonymize it.

Your rights and regional notices

outfra.ai is intended for users in the United States and Canada. We are not currently structured to serve the EU or UK under GDPR or ePrivacy. If you are outside the US or Canada, do not create an account until we expand this policy.

Self-serve export and deletion

If you have an account, the fastest way to review or remove your data is to do it yourself. Sign in and open the Data & privacy section of account settings, where you can:

How deletion actually works today. We would rather describe this precisely than imply an instant wipe:

If you can't sign in — say you've lost access to your email or OAuth provider — email [email protected] from an address you can verify and we will handle the request manually.

California residents (CCPA/CPRA)

Depending on revenue and data volume, California's privacy law may or may not formally apply yet. We still offer these rights. California residents may ask us to disclose, delete, or correct personal information we hold. The self-serve tools above cover disclosure (the export) and deletion directly. For corrections, or if you can't sign in, email [email protected]. We do not sell or share personal information for cross-context behavioral advertising today, so a "Do Not Sell or Share" link is not required for that purpose. If that changes, we will add the link and honor Global Privacy Control where required.

Canada (PIPEDA)

For users in Canada, we collect and use personal information for the purposes in this policy, with consent shown by creating an account or contacting us. You may see what we hold or delete it yourself with the self-serve tools above, or email us below if you can't sign in.

Children's privacy

outfra.ai is not directed at children under 13. We do not knowingly collect personal information from them. If you believe a child has created an account or sent us information, email us and we will delete it.

Security

We use HTTPS, processor access controls, and least-privilege service roles where configured. No method of storage or transmission is completely secure. We cannot guarantee absolute security.

Changes to this policy

If collection changes materially (analytics going live, checkout, new processors), we will update this page in plain language and refresh the date at the top before that change ships.

Questions

Email [email protected].