1. Scope and who we are
This Privacy Policy explains how BLUR TEC LLC (“Blurtec,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information when you use outward.dev, the Outward macOS application, or related services (collectively, the “Service”). BLUR TEC LLC is the controller of personal information described in this policy unless a section says otherwise.
This policy is a notice about our practices, not a request for consent, and it does not replace a separate consent mechanism where applicable law requires one. By using the Service, you acknowledge this policy. The Service may link to third-party websites or integrations whose privacy practices are governed by their own policies.
2. Information we may collect
Account and identity information
When you create or use an account, we may receive an email address, display name, nickname, profile image, identity-provider identifier, authentication timestamps, and account status. Some of this information may come from the identity provider you choose.
Device and security information
We may process an installation or device identifier, device name, platform, app version, session information, sign-in and sign-out events, revoked sessions, security events, and information needed to protect accounts and prevent abuse.
Crash reports and diagnostics
Crash reporting is enabled by default. If Outward crashes or freezes while it is enabled, we receive a report containing the stack trace, app version, macOS version, basic device characteristics, a timestamp, and a random installation identifier. Sentry processes crash reports on our behalf.
Before a report leaves your Mac, Outward rewrites file paths: anything under a home folder is replaced with “~/…”, so neither your macOS username nor the name of the project you were working on is included. Screenshot and view-hierarchy attachments are not used. You can turn crash reporting off at any time in Outward under Settings › Privacy.
Analytics and usage information
Usage analytics is enabled by default. While it is enabled, we record a fixed list of product events — for example that a terminal was created, a tab was opened, or a sync finished — along with counts such as how many terminals were open, the app version, the macOS version, and the same random installation identifier. PostHog processes analytics on our behalf.
The events Outward can send are a closed list built into the app. They never carry text you typed or content you stored. Session replay and automatic screen capture are not used. The exact list is shown in the app under Settings › Privacy › What gets collected, and you can turn analytics off in the same place. Turning it off also discards the installation identifier, so re-enabling it later starts a new, unlinked record.
The installation identifier is generated randomly on your Mac. It is not your account, your email, or your device serial number, and two installations by the same person are unrelated to each other.
Support and communications
If you contact us, we collect the information you choose to send, such as your email address, message, attachments, and support history.
Billing and subscription information
Stripe processes payments for Outward Pro. Stripe may collect your name, email address, billing address, payment-method information, tax identifiers, and transaction details. Blurtec receives limited billing records such as Stripe customer, subscription, checkout, and event identifiers; selected plan and billing interval; subscription status and dates; and payment or invoice status. Blurtec does not receive or store your full card or bank-account number.
Website and technical information
When you visit the website, our hosting and security systems may automatically receive technical information such as IP address, browser type, operating system, referring page, requested pages, timestamps, and basic security or error logs.
Outward.dev does not currently set advertising or website-analytics cookies. Our hosting and security provider may use strictly necessary cookies or similar identifiers when needed to deliver the website, maintain a session, prevent abuse, or respond to security threats. These technologies are not used to sell personal information or build advertising profiles.
3. Your project content stays local
Outward is designed so that project content remains on your Mac for now. This includes projects, files, notes, terminal commands and output, canvas layouts, Stack nodes and links, local assets, and locally stored bookmarks. Blurtec does not use this content for advertising, sell it, or upload it to our servers for general cloud storage under the current Service design.
Local content can still be sent outside your Mac when you intentionally use an integration or external action—for example, syncing content from a connected third-party service, opening a link, using a remote service from a terminal, or sending content to us in a support request. Those transmissions are controlled by the action you choose and the relevant provider’s policy.
Connected-account credentials are intended to be protected using the operating system’s secure credential storage. You should review connected accounts periodically and disconnect any integration you no longer use.
4. How and why we use information
We use information for the following purposes and legal bases. The legal basis that applies can depend on where you live:
- Contract: to create and manage your account, authenticate you, provide the Service, respond to service requests, process subscriptions, and provide paid features you request.
- Legitimate interests: to secure the Service, prevent abuse and fraud, diagnose crashes, improve reliability, understand use of features, improve performance and accessibility, provide support, and protect our legal rights. Our interests are operating a secure, reliable, useful software service with narrowly scoped diagnostics and analytics. You can object to this processing, and the in-app crash-reporting and usage-analytics switches provide an immediate opt-out for those activities.
- Legal obligations: to maintain records, respond to lawful requests, comply with tax, accounting, consumer-protection, and security obligations, and establish or defend legal claims.
- Consent: where we specifically ask for permission, such as for optional communications or where local law requires consent. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
We may also use limited information when reasonably necessary to evaluate or complete a merger, acquisition, financing, reorganization, or sale of some or all of the business, subject to appropriate confidentiality and legal protections.
Account and authentication information is required to create an account and provide signed-in features. Billing information is required only if you purchase Outward Pro. Crash reporting and usage analytics are not required to use Outward and can be disabled independently.
6. Retention
We apply the following retention periods or criteria:
- account, device, and subscription-access records are generally kept while your account is active and are removed through the account-deletion process;
- completed operational privacy-request receipts are retained for 30 days so we can verify that the deletion workflow finished, after which the automated retention process removes them;
- security records are kept only for the period reasonably needed to investigate abuse, protect accounts, and establish or defend legal claims, with access restricted to those purposes;
- support communications are kept while the request is active and afterward only while reasonably needed for follow-up, dispute resolution, security, or legal obligations;
- crash and analytics records follow the applicable provider project’s configured retention period, which we review and limit using the time reasonably needed for debugging, security, reliability analysis, and product trend analysis; and
- billing, tax, transaction, fraud-prevention, and dispute records are retained for the periods required by Stripe or applicable accounting, tax, payment, and legal rules; and
- transactional email records — that a message of a given type was sent to your account address, and whether it was delivered, delayed, failed, bounced, or reported as spam — are kept only as long as reasonably needed to investigate delivery problems and to evidence required billing, security, account, and legal notices. We do not retain the full text of sent messages for that purpose.
When you request account deletion, we revoke active sessions and begin the account-deletion workflow. If your account has a Stripe customer, we ask Stripe to delete it, which cancels its active subscriptions, before we remove the local billing mapping and account data. Stripe may retain transaction, invoice, tax, fraud-prevention, or dispute records when it acts as an independent controller or must keep them under law. We delete or de-identify other account data within a reasonable operational period, subject to documented legal, security, fraud-prevention, backup, and dispute-resolution needs.
Because project content is local, you control its retention on your Mac and should use the app’s local deletion controls or your operating system’s storage controls when you want to remove it. Billing processor behavior and retention exceptions are tracked in our processor inventory and reviewed before live payments are enabled.
Aggregated or de-identified information that can no longer reasonably identify you may be retained for reliability, security, and product-improvement purposes.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or obtain a portable copy of personal information; object to certain processing; withdraw consent where processing relies on consent; or appeal a decision about a privacy request.
You can exercise a privacy right by emailing contact@outward.dev. We may need to verify your identity before completing a request. We normally do not charge for a request. Where the GDPR or UK GDPR applies, we will respond without undue delay and normally within one month, subject to legally permitted extensions. We will not discriminate against you for exercising privacy rights, although some Service functionality requires information that is necessary to operate your account.
You can turn crash reporting and usage analytics off independently in Outward under Settings › Privacy. Each switch takes effect immediately and does not require restarting the app. You may unsubscribe from non-essential email communications by following the instructions in the message or contacting us. Service, security, transactional, and legal notices may still be sent when necessary.
Your right to object: where we rely on legitimate interests, you may object by contacting us. You can object to crash reporting or usage analytics immediately by turning off the applicable switch. We will stop the processing unless we have compelling legitimate grounds to continue or it is needed for legal claims.
We do not knowingly sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer characteristics about you.
8. Security
We use reasonable administrative, technical, and organizational measures designed to protect information, including access controls, secure authentication, encrypted connections where supported, limited access, and secure credential storage on supported devices.
No method of transmission, storage, or software is completely secure. You are responsible for protecting your devices, passwords, sign-in methods, backups, and local project data. If you believe there has been a security issue, contact contact@outward.dev.
9. Children’s privacy
Outward is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided information to us, contact us at contact@outward.dev so we can investigate and delete it where appropriate.
10. EEA, UK, and international users
Blurtec is established in the United States. Information may be processed in the United States and other countries where our providers operate, which may have different data-protection laws from your country.
For restricted transfers from the European Economic Area or United Kingdom, the available safeguards may include an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or another legally recognized safeguard. Some providers also participate in the EU-U.S. Data Privacy Framework and its UK Extension. We require the applicable safeguard to be in place before making a restricted transfer. You may request information about the safeguard relevant to your data by emailing contact@outward.dev.
If you are in the EEA, you may complain to the data-protection authority where you live or work, or where you believe a violation occurred. If you are in the UK, you may complain to the Information Commissioner’s Office. We encourage you to contact us first so we can try to resolve the concern.
We do not use personal information to make decisions based solely on automated processing that produce legal or similarly significant effects. If we appoint a data protection officer or an EEA or UK representative for our activities, we will publish the applicable contact details here.
11. Changes to this policy
We may update this Privacy Policy when the Service, our practices, or the law changes. We will post the updated policy and change the “Last updated” date. If a change materially affects how we use personal information, we will provide additional notice. Where law requires consent or explicit reacceptance, we will ask for it before the relevant new processing begins. Otherwise, your continued use after the effective date means you acknowledge the updated policy.
12. Contact us
Privacy questions and requests can be sent to contact@outward.dev.
BLUR TEC LLC · New York, United States