Legal
Privacy Policy
Last updated August 7, 2026
This Privacy Policy explains what data OpenOut collects, why, and how you can control it. We built OpenOut to be GDPR-friendly by design: visitor analytics are aggregated and never tied to a real identity, we don't store raw IP addresses, and you can export or delete your data at any time.
It covers two groups of people: users who hold an OpenOut account, and visitors who open a public OpenOut page. Where a section applies to only one of them, we say so.
1. Controller
Tim Geithner
c/o IP-Management #9778, Ludwig-Erhard-Str. 18
20459 Hamburg
Germany
Email: TGEcom@email.de
For the content a user publishes on their own OpenOut page — and for any subscriber list they build with a newsletter block — that user is the controller and we act as their processor. For our own platform operations (accounts, billing, security, aggregate analytics) we are the controller.
2. Data we collect
- Account data: email address, authentication method, password hash (never the password itself), and profile details you provide (handle, display name, avatar, bio, social links).
- Sign-in data from Google or Apple: if you use social sign-in, we receive your email address, a provider user ID and — where the provider supplies it — your name and avatar. We never receive your password at the provider.
- Content: the pages, blocks, links, destinations, uploaded images, themes and settings you create, including scheduling and page-password settings.
- Visitor analytics: per page view, link click and breakout event we store an anonymous session identifier (generated in the visitor's browser, per browsing session), the event type, the page and link involved, a coarse device type (mobile/tablet/desktop), the referring host name (not the full URL), and a two-letter country code derived at our edge network. We do not store IP addresses, full user-agent strings, or cross-site identifiers, and we don't combine these events into visitor profiles.
- Breakout data: to hand a visitor off to their system browser we create a short-lived, single-use continuation token bound to the destination link. It expires automatically and is not linked to a visitor identity.
- Newsletter sign-ups: if a page owner has placed a newsletter block on their public page and a visitor submits it, we store that visitor's email address together with the page and block it was submitted from. We store it on the page owner's behalf and never use it for our own mailings.
- Abuse reports: when someone reports a page, we store the report, the reason, any message and email address they choose to give, and a salted, non-reversible hash derived from their IP address for rate-limiting and de-duplication. The raw IP is never stored.
- Page-password attempts: for pages protected by a password we briefly log failed attempts with a salted, non-reversible client hash to block brute-force attempts. These rows are deleted after 24 hours.
- Billing data: for paid plans, Stripe processes and stores your payment method; we only receive a customer/subscription identifier, plan, status and invoice metadata — never full card numbers.
- Support and admin records: messages you send us, plus an internal audit log of administrative actions (for example a suspension or a plan correction) used for accountability.
- Technical logs: our hosting and edge network process request metadata (including IP address) transiently to deliver and secure the Service. We don't build analytics from them.
3. How we use it, and our legal basis (Art. 6 GDPR)
- Operating your account, your pages and the breakout engine — necessary for performance of our contract with you (Art. 6(1)(b)).
- Billing and invoicing — performance of contract (Art. 6(1)(b)) and compliance with tax/accounting law (Art. 6(1)(c)).
- Transactional and auth email (sign-up confirmation, password reset, magic links, email-change confirmation, receipts, security notices) — performance of contract (Art. 6(1)(b)).
- Product and report emails you can switch off (for example the weekly performance summary and dashboard notifications) — legitimate interest in helping you use a paid product (Art. 6(1)(f)); you can turn them off in your settings at any time.
- Visitor analytics for the breakout engine — our legitimate interest, and the page owner's, in seeing what converts (Art. 6(1)(f)), balanced by using only an anonymous session identifier, coarse device type and country, and by never storing IP addresses.
- Storing newsletter sign-ups for a page owner — processed on that owner's instructions and on the basis of the visitor's own submission of the form (Art. 6(1)(a)); the page owner, not OpenOut, is the controller for their subscriber list and for anything they send to it.
- Handling abuse reports and moderating content — legal obligation and legitimate interest in a lawful, safe service (Art. 6(1)(c), Art. 6(1)(f)).
- Security, rate-limiting, fraud and abuse prevention — legitimate interest (Art. 6(1)(f)).
- Owner-configured third-party pixels on a public page — consent of the visitor (Art. 6(1)(a)), collected through the banner described in §7.
We don't sell your data or your visitors' data, and we don't use it to train AI models.
4. Where it's stored and who processes it
Account and content data is stored in our managed Postgres database with row-level security so only you can access your own records. We share data with the following categories of processors, each bound by a data processing agreement:
- Database, authentication and hosting: Lovable Cloud (managed Postgres database, authentication and file storage) and Cloudflare Workers, which may process and store data outside your country.
- Social sign-in: Google and Apple, where you choose that sign-in method; they act as their own controllers for the sign-in process.
- Payments: Stripe processes and stores payment methods and billing data; see Stripe's own privacy policy for details.
- Email delivery: our managed email provider sends auth and transactional email from our own sender domain and processes delivery events (sent, bounced, complaint, unsubscribe) so we can keep our sending list clean.
- Owner-configured outbound webhooks: on paid plans a page owner can have link-click and breakout-confirmed events forwarded to an HTTPS endpoint they choose. Where they do, the operator of that endpoint receives the event data and is responsible for it; we don't control that destination.
- Owner-configured analytics/advertising pixels: where a page owner enables Google Analytics, Meta Pixel or TikTok Pixel on their page, those providers receive visitor data directly and act as separate controllers; this only happens with the visitor's consent (see §7).
- Web fonts: this site loads its typefaces (Archivo, Inter, Space Grotesk, JetBrains Mono) at runtime from Google's font CDN (fonts.googleapis.com / fonts.gstatic.com). Loading these fonts transmits your IP address and technical browser data (e.g. user agent) to Google. This happens for every visitor, not only those who consent to analytics. Our legal basis is our legitimate interest in consistent, fast typography across browsers (Art. 6(1)(f) GDPR); Google acts as its own controller for this processing — see Google's privacy policy for details.
Business users who need a data processing agreement with us for the visitor data on their own pages can request one at TGEcom@email.de.
5. International transfers
Some processors listed above may process data outside the EU/EEA or UK. Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision covering the destination country. This includes the web font requests described in §4, which are transmitted to Google's global CDN.
6. Your rights
You can access, export, correct or delete your account data at any time from your dashboard settings — the export includes your profile, pages, links and the newsletter sign-ups collected for you. If you're in the EU/EEA or UK, you have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21) under GDPR, and you can withdraw any consent you've given at any time with effect for the future. To exercise these rights, email TGEcom@email.de; we respond within one month. You also have the right to lodge a complaint with your local data protection supervisory authority.
Visitors: because visitor analytics are stored against an anonymous session identifier only, we usually cannot connect an analytics event to you as a person and therefore cannot answer an access request for it. If you submitted a newsletter form or an abuse report, contact us and we can act on that record.
7. Cookies, tracking and consent
Essential. We use session cookies to keep you signed in, plus an anonymous session identifier we store in your browser to route breakouts and count aggregated page views. These involve no cross-site profiling and no ad networks, and are set on the basis of legitimate interest / strict necessity.
Owner-configured third-party trackers. Page owners can add their own Google Analytics 4, Meta Pixel and/or TikTok Pixel to their public OpenOut page. These ARE third-party analytics and advertising trackers, operated by those providers as separate controllers. They are off by default and load only after you explicitly accept them in the consent banner shown on that page (Art. 6(1)(a) GDPR consent); declining leaves them unloaded.
Withdrawal. Your choice is stored locally in your browser (per site) and can be changed at any time via "Cookie settings" in the footer of the page; withdrawing reloads the page so no tracker keeps running.
8. Data retention
- Account and content data: retained for as long as your account is active. Deleting your account removes your profile, pages and links promptly.
- Visitor analytics: retained in session-linked form for up to 13 months, then anonymized or deleted; anonymized/aggregated analytics may be retained indefinitely.
- Breakout continuation tokens: single-use and valid for minutes; expired tokens are removed by our nightly maintenance job.
- Page-password attempt records: deleted after 24 hours.
- Abuse reports: retained while the case is open and afterwards for as long as needed to detect repeat abuse and to document our decision.
- Newsletter sign-ups: retained for as long as the page owner keeps the newsletter block on their page. To have an address removed, contact the page owner or email us at TGEcom@email.de.
- Email delivery events: retained for a short diagnostic window by our email provider; suppression entries (bounces, complaints, unsubscribes) are kept as long as needed to avoid mailing an address that shouldn't be mailed.
- Billing records: retained for as long as required by applicable tax and accounting law after the underlying transaction (in Germany, generally up to 10 years).
9. Security
Data is transmitted over TLS and stored in a database with row-level security, so a request can only ever read the rows belonging to the account that made it. Passwords are stored as salted hashes by our authentication provider. Administrative access is limited to accounts with an explicit admin role and privileged actions are written to an audit log. Where we need an identifier derived from an IP address (rate limits, abuse dedup), we store only a salted, purpose-separated hash. No system is perfectly secure, so please use a strong, unique password.
10. Data protection officer
We have not appointed a data protection officer. Please direct any data protection questions or requests to TGEcom@email.de.
11. Providing your data
Providing your email address and choosing access credentials is required to enter into a contract with us: without them, we can't create or operate an account for you. Providing other content (page details, links, media) is optional and up to you.
12. Children
OpenOut is not intended for children under 16, and accounts require you to be at least 16 years old. We don't knowingly collect data from children under 16; if you believe a child has created an account, contact us and we'll delete it.
13. Automated decision-making
We don't carry out profiling or automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. Automated rate limits and abuse heuristics can temporarily block a request, but any account suspension is reviewed by a human and you can object to it.
14. Changes to this policy
We update this policy when our processing changes; the "Last updated" date above always reflects the current version. For material changes affecting account holders, we'll notify you by email or in the app.
15. Contact
Questions about this policy or a data request? Email TGEcom@email.de.