Off Earth Data — Legal

Privacy Policy

Version 1.3 — Effective July 30, 2026

Version 1.3 — Effective July 30, 2026

This Privacy Policy describes how Off Earth Data, a Delaware corporation ("Off Earth Data", "we", "us"), collects, uses, and shares information when you use our websites, dashboards, and APIs (the "Service"). It is incorporated into our Terms of Service.

> Product analytics and session recording are not switched on yet. Sections 1, 3, and 7 describe how they will work, and the choices you will have, when we enable them. Until then we collect no product-analytics events and make no session recordings, and the analytics cookie described in Section 3 is not set. We are telling you in advance rather than changing this policy on the day it starts.

1. Information We Collect

  • Account information: your email address and authentication metadata, managed through Supabase, our authentication provider.
  • Network and usage data: IP addresses, request timestamps, endpoints called, response codes, and volume — collected in usage logs for security, rate-limiting, billing, and service-quality purposes.
  • Billing information: subscription tier, invoices, and payment status. Payment card details are collected and processed by Stripe; we never see or store full card numbers.
  • Diagnostic data: when the Service encounters an error, our error-monitoring provider (Sentry) collects technical fault information — such as error messages, the page or request that failed, and browser and device type — so we can reproduce and fix the problem.
  • Product analytics: where analytics is active (see Section 3 — in the EEA, UK, and Switzerland only if you agree first), our analytics provider (PostHog) records how the Service is used — pages viewed, features and navigation elements used, approximate location derived from IP address, and browser and device type — so we can understand which parts of the product are useful and improve them.
  • Session recordings: on the same basis as product analytics above, PostHog also records a reconstruction of your session — the pages you visited and the clicks, scrolls, and navigation you performed. Recordings are captured with input masking: text you type into form fields, search boxes, and query inputs is replaced with placeholder characters before the recording leaves your browser, and we cannot recover it. Session recording can be turned off on its own, without turning off product analytics (see Section 7).
  • Correspondence: emails you send us (support, security reports, sales).

2. Information We Do NOT Collect

We do not collect or retain the content of your analysis. Your queries, query parameters, and the analyses or integrations you build on top of the Service are treated as confidential to you: we log that a request occurred (for the purposes above), not the analytical intent or downstream use.

Two narrow exceptions apply, both described in Section 1:

  • Automated fault diagnostics: when an error occurs, diagnostic data may incidentally capture technical details of the failed request, which we use solely to diagnose and fix the fault.
  • Product analytics and session recordings: where analytics is active under Section 3, we record that you used a given page or feature, and a masked reconstruction of your session. Text you type — including search terms and query inputs — is masked before the recording leaves your browser. We record that a query happened and where in the product it happened, not what you asked.

We do not sell any personal data, and we do not build advertising profiles.

3. Cookies

We use two categories of cookies, both first-party (set on our own domain):

  • Essential cookies — always active. These include the Supabase session cookie required to keep you signed in, and a cookie recording your analytics choice below. They cannot be switched off without breaking the Service.
  • Analytics cookies — optional. A first-party PostHog cookie gives you a pseudonymous identifier so we can tell whether two visits came from the same browser, which is what makes the usage measurement and session recordings in Section 1 meaningful.

Whether analytics starts on or off depends on where you are.

  • In the European Economic Area, the United Kingdom, and Switzerland, analytics and session recording are off until you agree. On your first visit we ask you to accept or decline. If you decline — or simply ignore the request — no analytics cookie is set, no product-analytics events are collected, and no session recording is made. Declining is exactly as easy as accepting.
  • Elsewhere, analytics and session recording are on by default and we show you a notice with a control to turn them off.

If we cannot confidently tell which of those applies to you, we treat you as being in the first group and ask for your agreement before collecting anything.

Either way, turning analytics off takes effect immediately: the analytics cookie is removed, no further product-analytics events are collected, and no further session recordings are made. Your choice is remembered on that browser, and you can change it at any time (see Section 7).

If your browser sends a Global Privacy Control (GPC) signal, we treat that as a decline everywhere, before any collection begins, and we do not ask.

We do not use advertising pixels, cross-site tracking, or third-party advertising cookies, and we do not share cookie data with advertising networks.

4. How We Use Information

We use the information above to operate and secure the Service, authenticate you, enforce rate limits and the Acceptable Use Policy, process billing, respond to support requests, and meet legal obligations. We may use aggregated, de-identified usage statistics to improve the Service.

5. Data Sharing

We share personal data only with the service providers needed to run the Service, and only for the purposes described here:

  • Stripe — payment processing and billing.
  • Supabase — authentication and application data storage.
  • Resend — transactional email delivery.
  • Hetzner — cloud infrastructure and application hosting (data centers in Germany).
  • Cloudflare — DNS resolution for our domains.
  • Sentry — error monitoring and fault diagnostics.
  • PostHog — product analytics, session recording, and feature-flag delivery (PostHog Cloud US; data processed in the United States).
  • Vercel — marketing-site delivery and web analytics.

We may also disclose information if required by law or to protect the rights, safety, or security of the Service, our customers, or the public. We do not sell personal data to anyone.

6. Data Retention

  • Account data is retained for 7 years after account closure, to meet tax, accounting, and legal requirements.
  • Usage logs are retained for 12 months.
  • Product analytics events are retained for 12 months.
  • Session recordings are retained for 30 days and then deleted.
  • Billing records are retained by Stripe per its own policies and by us as required by law.

7. Your Rights

We support access, deletion, correction, and portability rights aligned with GDPR and CCPA, regardless of where you are located. To exercise a right, email privacy@offearthdata.com from your account email; we will verify the request and respond within the timelines required by applicable law. Deletion is subject to the retention obligations in Section 6.

Analytics and session recording. You control these independently of the rights above:

  • On your first visit we either ask for your agreement (EEA, UK, Switzerland) or show you a notice with a control to turn analytics off (elsewhere) — see Section 3.
  • If you have an account, Settings → Privacy lets you change your choice at any time, and lets you turn session recording off while leaving product analytics on.
  • Turning either off takes effect immediately and stops future collection — we do not continue recording after you opt out. To also delete recordings and events already captured, email privacy@offearthdata.com and we will delete them.
  • Withdrawing your agreement is as easy as giving it, and does not affect anything collected lawfully beforehand.
  • We honour the browser Global Privacy Control (GPC) signal everywhere: if your browser sends it, analytics and session recording are off from the start, without you having to do anything.

8. Data Protection Contact

Privacy inquiries: privacy@offearthdata.com. Our interim data protection contact is engineering@offearthdata.com; if we reach material volumes of EU customers we will designate a formal Data Protection Officer and update this policy.

9. Children

The Service is not directed at, and may not be used by, anyone under 18. We do not knowingly collect personal data from children. If you believe a minor has provided us personal data, contact privacy@offearthdata.com and we will delete it.

10. International Transfers

Off Earth Data is a US company. Our application is hosted in the European Union (Germany), and the service providers listed in Section 5 process data in the United States and the European Union. By using the Service you understand your data may be processed in both the United States and the European Union. Where personal data is transferred across borders, we seek to use providers that offer standard contractual clauses or equivalent transfer safeguards, and we work to put those terms in place with each provider. This policy is provided in English (en-US) only.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be announced by email or in-product notice with a new version number and effective date. The current version is always available at this page.

12. Contact

privacy@offearthdata.com for privacy matters; security@offearthdata.com for security or abuse reports.


Off Earth Data · Delaware, USA