Privacy Policy

Last updated: March 5, 2026

TL;DR: outer.bot can be used three ways, and this policy describes each. In hooks mode, everything runs on your own machine, and we see nothing. In proxy mode, your requests pass through our servers on the way to a model, but nothing is stored afterward. In the cloud Workspace, your source code is cloned and stored on our servers, in full, so the Workspace can read, edit, and run it — that's the plain fact of this mode, not a side effect of it. Hosted working files are retained until explicitly deleted; inactivity does not remove them. Your project's memory — briefing, learned facts, rejections, skills, rules — lives in a git repository you own if you connect one, with a rebuildable cache on our side; without a connected repo, that memory lives directly on our servers instead. We only collect what's necessary to provide the service. We never sell your data.

1. Introduction

outer.bot ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Workspace, website, and related services (collectively, the "Service").

By using outer.bot, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

2.2 Information Collected Automatically

2.3 What Happens to a Connected Project

When you connect a project to the Workspace, we clone it to our servers, in full, so the Workspace can read, edit, and run it on your behalf — this is not optional for a connected project, and any page that has told you otherwise was describing an earlier, retired version of the product. If you'd rather your code never reach our servers at all, that option exists too: our hooks-based setup runs entirely on your own machine, with no proxy in the loop. Details are in our writeup on trust levels.

Hosted working files are retained until explicitly deleted. Automatic deletion after inactivity is disabled to protect uncommitted changes and unpushed commits. Disconnecting a project does not instantly delete its hosted files.

Hosted working files are not backed up. Commit and push changes to your connected git repository to keep a durable copy. Explicit workspace cleanup deletes the hosted copy, including any uncommitted changes and unpushed commits, and requires acknowledgment of that deletion.

Request and response bodies — what you send to a model and what it sends back — pass through our systems in the moment a request is made and are not persisted afterward.

2.4 Optional API Keys (Pro BYOK)

Pro members may optionally provide their own Anthropic or OpenAI API key for direct billing. If provided, your key is transmitted over TLS and stored encrypted (AES-256-CBC) on our servers. It is never logged, never shared with third parties, and only decrypted server-side to make API calls on your behalf. You can remove your key at any time from Account Settings.

3. How We Use Your Information

We use the information we collect to:

4. Data Storage and Security

4.1 Your Project's Memory: Two Modes

Your project's memory — its briefing, the facts it has learned, any fact you've rejected, its skills, and its compiled rules — has two possible homes, and you choose which:

Either way, all data is encrypted in transit (TLS 1.3) and at rest (AES-256) where it touches our servers, stored in secure data centers, with access strictly controlled and logged.

4.2 What Stays on Our Servers Regardless of Mode

Some things are ours to hold no matter how you've configured your project's memory, because they describe our side of the relationship, not yours:

You can export or delete your data at any time; see Section 7.

5. Data Sharing

We do not sell your personal information. We may share data with:

6. Third-Party Services

outer.bot integrates with third-party services that have their own privacy policies:

If you configure a custom OpenAI-compatible provider (Account Settings), you're directing your prompts, briefing content, and code to an endpoint of your own choosing — outside the service-provider list above. We relay your request there; we don't vet, control, or take responsibility for what that endpoint does with it. This is stated again at the point you configure one.

When you use your own API keys via the optional BYOK feature (Pro), your usage is also subject to the respective provider's terms.

7. Your Rights

You have the right to:

To exercise these rights, contact us at privacy@outer.bot.

8. Data Retention

When you delete your account, we remove your data within 30 days, except where retention is required by law.

9. Children's Privacy

outer.bot is not intended for users under 13 years of age. We do not knowingly collect information from children under 13. If you believe we have collected such information, please contact us immediately.

10. International Data Transfers

If you are accessing outer.bot from outside the United States, your information may be transferred to, stored, and processed in the US. We use appropriate safeguards for international transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by:

12. Contact Us

If you have questions about this Privacy Policy, please contact us: