Off Earth Data — Legal
Privacy Policy
Version 1.10 — Effective August 25, 2026
Version 1.10 — Effective August 25, 2026
This Privacy Policy describes how Off Earth Data, a Delaware corporation ("Off Earth Data", "we", "us"), collects, uses, and shares information when you use our websites, dashboards, and APIs (the "Service"). It is incorporated into our Terms of Service.
1. Information We Collect
- Account information: your email address and authentication metadata, managed through Supabase, our authentication provider.
- Network and usage data: IP addresses, request timestamps, endpoints called, response codes, and volume — collected in usage logs for security, rate-limiting, billing, and service-quality purposes.
- Connector (MCP) access: when you connect the Service to an AI assistant or other client through our MCP server — either by authorizing it from a connector directory or by configuring an API key yourself — we collect the same network and usage data as for any other API request, plus a per-request count. That count is kept per account for connector authorizations — if you authorize more than one assistant, they share a single account-level tally rather than being counted separately — and per key where you configured an API key yourself. Authorizing a connector also stores the authorization itself — which client you approved, and when — with Supabase, our authentication provider.
- Connector analytics: where connector analytics is active for your account — by your choice in Settings → Privacy, or as a condition of trial access (see Section 3; connector requests have no browser, so no cookie or banner applies) — our analytics provider (PostHog) additionally records, per connector request: which tool the assistant called, how long the call took, whether it succeeded or failed (the category of failure, not the message), which client made the call, and — when the assistant chooses to supply one — a short statement of what it was trying to do. We do not record the parameters the assistant passed or the content of our responses: those are removed by an allowlist before anything leaves our systems, so the substance of what you asked the assistant to look up is still never stored. If analytics is off for your account, connector access is counted (previous bullet) and nothing more.
- Billing information: subscription tier, invoices, and payment status. Payment card details are collected and processed by Stripe; we never see or store full card numbers.
- Diagnostic data: when the Service encounters an error, our error-monitoring provider (Sentry) collects technical fault information — such as error messages, the page or request that failed, and browser and device type — so we can reproduce and fix the problem.
- Product analytics: where analytics is active (see Section 3 — in the EEA, UK, and Switzerland only if you agree first), our analytics provider (PostHog) records how the Service is used — pages viewed, features and navigation elements used, approximate location derived from IP address, and browser and device type — so we can understand which parts of the product are useful and improve them.
- Session recordings: on the same basis as product analytics above, PostHog also records a reconstruction of your session — the pages you visited and the clicks, scrolls, and navigation you performed. Recordings are captured with input masking: text you type into form fields, search boxes, and query inputs is replaced with placeholder characters before the recording leaves your browser, and we cannot recover it. Content that was already displayed on the page — including results, tables, and charts — appears in the recording as it appeared on your screen. Recordings are retained for 30 days and then deleted (Section 6). Session recording can be turned off on its own, without turning off product analytics (see Section 7).
- Account identification in analytics: where analytics or session recording is active (see Section 3) and you are signed in, we send your email address to PostHog as the label for your account, so that the usage and recordings above are attributable to a specific account rather than to an anonymous identifier. We do this so we can answer a support question about your own session, and tell one account's usage from another's — two people at the same email provider are otherwise indistinguishable. Signed-out visitors are not identified this way. Turning analytics off stops it for the future (Section 7), and you can ask us to delete what has already been captured.
- Correspondence: emails you send us (support, security reports, sales).
2. Information We Do NOT Collect
We do not log or store the content of your analysis in our own systems. Your queries, query parameters, and the analyses or integrations you build on top of the Service are treated as confidential to you: our logs record that a request occurred (for the purposes above), not the analytical intent or downstream use. We do not build a searchable store of your queries or results, we do not use them to train models, and we do not use them to inform anyone else's view of the market. One exception is described below: where session recording is active, a recording shows what was on your screen.
Four narrow exceptions apply, all described in Section 1:
- Automated fault diagnostics: when an error occurs, diagnostic data may incidentally capture technical details of the failed request, which we use solely to diagnose and fix the fault.
- Product analytics: where analytics is active under Section 3, we record that you used a given page or feature. Our analytics events record that a query happened and where in the product it happened, not what you asked.
- Session recordings: where session recording is active under Section 3, a recording reproduces what was displayed on your screen. Text you type — including search terms and query inputs — is masked before the recording leaves your browser and we cannot recover it. Results, tables, and charts that were already on the page are not masked and are visible in the recording. So while we do not log what you asked, a recording can show what you were looking at. Recordings are deleted after 30 days (Section 6), and you can turn session recording off on its own at any time, without turning off product analytics (Section 7).
- Connector analytics: where analytics is active for your account under Section 3, we record which tool the assistant invoked, its duration, its coarse outcome, the client, and any intent statement the assistant supplied — never the parameters passed or the content of our responses. No session recording is made for connector traffic — there is no browser session to record.
For connector traffic the core promise therefore now reads: we log that a request occurred and, where you allow analytics, which tool it used — never what you asked or what we answered. What happens to your question and our answer inside the assistant you connected is governed by that assistant's own privacy policy rather than this one; see Section 5. Note that an intent statement is text composed by your assistant, not by you; assistants sometimes echo parts of your request in it. If you do not want that recorded, turn analytics off (Section 7) — connector analytics stops immediately.
We do not sell any personal data, and we do not build advertising profiles.
3. Cookies
We use two categories of cookies, both first-party (set on our own domain):
- Essential cookies — always active. These include the Supabase session cookie required to keep you signed in, and a cookie recording your analytics choice below. They cannot be switched off without breaking the Service.
- Analytics cookies — optional. A first-party PostHog cookie gives you a pseudonymous identifier so we can tell whether two visits came from the same browser, which is what makes the usage measurement and session recordings in Section 1 meaningful. When you are signed in, that identifier is linked to your account email (Section 1).
Whether analytics starts on or off depends on where you are.
- In the European Economic Area, the United Kingdom, and Switzerland, analytics and session recording are off until you agree. On your first visit we ask you to accept or decline. If you decline — or simply ignore the request — no analytics cookie is set, no product-analytics events are collected, and no session recording is made. Declining is exactly as easy as accepting.
- Elsewhere, analytics and session recording are on by default and we show you a notice with a control to turn them off.
If we cannot confidently tell which of those applies to you, we treat you as being in the first group and ask for your agreement before collecting anything.
Either way, turning analytics off takes effect immediately: the analytics cookie is removed, no further product-analytics events are collected, and no further session recordings are made. Your choice is remembered on that browser, and you can change it at any time (see Section 7).
If your browser sends a Global Privacy Control (GPC) signal, we treat that as a decline everywhere, before any collection begins, and we do not ask.
Connector (MCP) requests have no browser, no cookie, and no banner, so the choices above cannot be asked for there. For standard accounts, connector analytics (Section 1) follows the analytics choice saved on your account from Settings → Privacy — off until you have turned it on there, everywhere, with no region-based default: no stored choice means no collection, and turning analytics off stops connector analytics immediately. During trial access, connector analytics is instead active as a condition of the trial: understanding how trial users work with the Service through their assistants is part of what we exchange for free access, the Settings → Privacy switches govern your browser analytics only for the duration, and the condition ends the moment your trial converts to a paid subscription (your stored choice then governs) or lapses. A GPC signal cannot accompany a connector request; if your browser sends GPC when you visit Settings → Privacy, that decline is saved to your account and applies to connector traffic on standard accounts — during a trial it takes effect when the trial ends.
We do not use advertising pixels, cross-site tracking, or third-party advertising cookies, and we do not share cookie data with advertising networks.
4. How We Use Information
We use the information above to operate and secure the Service, authenticate you, enforce rate limits and the Acceptable Use Policy, process billing, respond to support requests, and meet legal obligations. We may use aggregated, de-identified usage statistics to improve the Service.
5. Data Sharing
We share personal data only with the service providers needed to run the Service, and only for the purposes described here:
- Stripe — payment processing and billing.
- Supabase — authentication and application data storage.
- Resend — transactional email delivery.
- Hetzner — cloud infrastructure and application hosting (data centers in Germany).
- Cloudflare — DNS resolution for our domains.
- Sentry — error monitoring and fault diagnostics.
- PostHog — product analytics, session recording, and feature-flag delivery (PostHog Cloud US; data processed in the United States).
- Vercel — marketing-site delivery and web analytics.
AI assistants and connector clients are not on this list, because they are not our sub-processors. If you connect the Service to an assistant — through a connector directory such as Anthropic's or OpenAI's, or through a client you configure yourself — you are directing that assistant to call us for you. Your request reaches us through it, and our answer goes back the same way, so the operator of that assistant necessarily handles both. That handling is governed by your agreement with them and their own privacy policy, not by this one, and we have no visibility into it. We do not send your data to an assistant vendor on our own initiative, we answer only the requests you direct it to make, and we receive nothing back about you beyond the request itself. Choosing which assistants to connect — and reviewing their privacy terms before you do — is yours to decide.
We may also disclose information if required by law or to protect the rights, safety, or security of the Service, our customers, or the public. We do not sell personal data to anyone.
6. Data Retention
- Account data is retained for 7 years after account closure, to meet tax, accounting, and legal requirements.
- Usage logs are retained for 12 months. This includes the per-request counters recorded for API and connector (MCP) access, and the record of which connector clients you have authorized, which is kept while the authorization is active.
- Product analytics events — including connector analytics events (Section 1) — are retained for up to 7 years — the same period as account data — and are then deleted. That is the retention period our analytics provider applies to our plan, and its controls do not let us set a shorter one. Where you are signed in, these events carry your email address (Section 1); you can ask us to delete them at any point before that period ends and we will (Section 7).
- Session recordings are retained for 30 days and then deleted.
- Billing records are retained by Stripe per its own policies and by us as required by law.
- Payment and subscription event records we receive from Stripe — which may include your email address, subscription status, invoice amounts, and limited card metadata such as card brand and last four digits (never full card numbers) — are retained for 7 years to meet tax, accounting, and legal requirements, then deleted.
7. Your Rights
We support access, deletion, correction, and portability rights aligned with GDPR and CCPA, regardless of where you are located. To exercise a right, email <privacy@offearthdata.com> from your account email; we will verify the request and respond within the timelines required by applicable law. Deletion is subject to the retention obligations in Section 6.
Analytics and session recording. You control these independently of the rights above:
- On your first visit we either ask for your agreement (EEA, UK, Switzerland) or show you a notice with a control to turn analytics off (elsewhere) — see Section 3.
- If you have an account, Settings → Privacy lets you change your choice at any time, and lets you turn session recording off while leaving product analytics on. On standard accounts the same choice governs connector analytics (Section 3): turning analytics off stops connector analytics immediately. During trial access the connector condition in Section 3 applies instead, and your stored choice takes effect when the trial ends.
- Turning either off takes effect immediately and stops future collection — we do not continue recording after you opt out. To also delete recordings and events already captured, email <privacy@offearthdata.com> and we will delete them.
- Withdrawing your agreement is as easy as giving it, and does not affect anything collected lawfully beforehand.
- We honour the browser Global Privacy Control (GPC) signal everywhere: if your browser sends it, analytics and session recording are off from the start, without you having to do anything.
Connector (MCP) access. How you disconnect depends on how you connected:
- Disconnecting in the assistant — removing the connector in your assistant's own settings stops it from making further requests to us. This is the fastest way to stop connector access, and it is the only step most people need.
- API keys — if you connected by configuring a key yourself, Account → API access lets you revoke or rotate that key at any time, which takes effect immediately.
- Connector authorizations — we do not yet offer a self-serve control for revoking an authorization you granted through a connector directory. Email <privacy@offearthdata.com> and we will revoke it for you. We would rather tell you that plainly than describe a button that does not exist.
8. Data Protection Contact
Privacy inquiries: <privacy@offearthdata.com>. Our interim data protection contact is <engineering@offearthdata.com>; if we reach material volumes of EU customers we will designate a formal Data Protection Officer and update this policy.
9. Children
The Service is not directed at, and may not be used by, anyone under 18. We do not knowingly collect personal data from children. If you believe a minor has provided us personal data, contact <privacy@offearthdata.com> and we will delete it.
10. International Transfers
Off Earth Data is a US company. Our application is hosted in the European Union (Germany), and the service providers listed in Section 5 process data in the United States and the European Union. By using the Service you understand your data may be processed in both the United States and the European Union. Where personal data is transferred across borders, we seek to use providers that offer standard contractual clauses or equivalent transfer safeguards, and we work to put those terms in place with each provider. This policy is provided in English (en-US) only.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be announced by email or in-product notice with a new version number and effective date. The current version is always available at this page.
12. Contact
<privacy@offearthdata.com> for privacy matters; <security@offearthdata.com> for security or abuse reports.
Off Earth Data · Delaware, USA