1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and password (stored securely using bcrypt hashing). If you sign up via Google or Microsoft OAuth, we receive your basic profile information from those providers.
Email Tracking Data
When you use Outsolvi to track emails, we collect metadata about email interactions — specifically open events (via tracking pixel) and click events (via link redirect). We do not read, store, or access the content of your emails.
Usage Data
We collect standard usage analytics: pages visited, feature usage, device type, browser, and IP address. This helps us improve the product.
2. How We Use Your Data
- To provide and operate the Outsolvi email tracking service
- To display engagement analytics on your dashboard
- To send transactional emails (verification, password reset, billing)
- To detect and filter bot/scanner activity from genuine opens
- To improve our product and fix bugs
- To enforce our Terms of Service and prevent abuse
3. Data Storage & Security
Your data is stored on secure cloud infrastructure (PostgreSQL on Neon, hosted in AWS US-East). All data is encrypted in transit (TLS 1.3) and sensitive fields (OAuth tokens, API keys) are encrypted at rest using AES-256-GCM.
Passwords are hashed with bcrypt (12 rounds). We support two-factor authentication (TOTP) for admin accounts.
4. Cookies
We use essential cookies for authentication sessions and CSRF protection. We do not use third-party advertising or analytics cookies.
5. Third-Party Services
We share limited data with these service providers:
- Stripe — payment processing (billing info only)
- Resend — transactional email delivery
- Neon — database hosting
- Cloudflare — DNS, CDN, and DDoS protection
We never sell your data to third parties or use it for advertising.
6. Data Retention
We retain your account data for as long as your account is active. Email tracking events are retained for up to 12 months. When you delete your account, we remove all personal data within 30 days.
7. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and associated data
- Export your data in a portable format
- Withdraw consent for optional data processing
If you are in the EU/EEA, you have additional rights under GDPR including the right to lodge a complaint with a supervisory authority.
8. Email Tracking Transparency
Outsolvi uses a 1x1 transparent tracking pixel to detect when recipients open tracked emails. We also wrap links to detect clicks. We employ bot filtering and confidence scoring to ensure accuracy — our system distinguishes between genuine human opens and automated security scans.
We do not access the body or subject of your emails. The tracking pixel only records: timestamp, approximate location (if available), device type, and a confidence score.
9. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or an in-app notice. The “Last updated” date at the top reflects the most recent revision.
10. Contact Us
If you have questions about this Privacy Policy or your data, contact us at support@outsolvi.com.