OutcomeAI LLC ("OutcomeAI," "we," "us," or "our") operates the website at outcomeai.io. This policy explains what information the website collects, why we collect it, who we share it with, and the choices you have. We keep collection to what the site actually needs — there is no account system, no login, and no payment processing on this site.
01Who We Are and What This Covers
OutcomeAI LLC is a United States limited liability company building an agentic infrastructure-as-code assistant for DevSecOps teams. For the purposes of the EU and UK General Data Protection Regulation, OutcomeAI LLC is the data controller for personal information collected through this website.
This policy applies to the outcomeai.io website only. It does not govern the OutcomeAI product when it is deployed into a customer's own cloud environment, or any custom engineering engagement — those are covered by the written agreement between OutcomeAI and that customer. See Section 13.
02Information We Collect
Information you give us directly
- Meeting bookings. The booking button on this site is an ordinary link to our scheduling page on Calendly. If you book there, you provide your name, email address, and time zone, plus anything you write into the optional notes or question fields. That information is collected and stored by Calendly on our behalf, and Calendly's own privacy policy also applies to your visit to their site.
- Correspondence. If you email us or connect with us on LinkedIn, we receive whatever you choose to send — your name, email address, company, role, and the content of your message.
- Discovery conversation content. If we speak, we may take written notes about your team's infrastructure workflow, tooling, and pain points. We use these notes to inform product design. We do not record calls without telling you first and getting your agreement.
Information collected automatically
- Server and CDN logs. Our hosting provider records standard request data: IP address, user agent string, referring URL, requested path, response status, and timestamp. This is used for delivery, security, and abuse prevention.
- Analytics data — only if you accept. We use Google Analytics 4 and Google Tag Manager, and they load only after you accept analytics cookies. If you accept, they set cookies and collect a pseudonymous client identifier, pages viewed, session duration, referral source, approximate location derived from IP address (city-level, with the IP itself truncated by Google), device type, browser, and operating system. If you decline or take no action, no Google analytics script is loaded and no request is made to Google.
- Third-party asset requests. None. Fonts, stylesheets, and scripts are served from outcomeai.io itself, so simply loading a page on this site does not expose your IP address or user agent to any third party other than our hosting provider.
What we do not collect
We do not collect payment card details, government identifiers, precise geolocation, biometric data, or special category data through this website. We do not run advertising pixels or cross-site retargeting tags, and we do not buy personal information from data brokers to enrich site visitors.
03Third-Party Services
The website depends on the following processors and providers. Each maintains its own privacy policy, which governs its handling of your data.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare, Inc. | Website hosting, CDN, DDoS protection | IP address, request metadata, security logs |
| Google LLC (Analytics 4, Tag Manager) Loaded only after you accept | Traffic measurement and tag management | Cookies, pseudonymous IDs, page and session events, truncated IP |
| Calendly LLC Reached only if you follow the booking link | Meeting scheduling | Name, email, time zone, booking notes, calendar event |
Outbound links on this site to LinkedIn, Credly, and Credential.net are ordinary hyperlinks. We do not share your information with those platforms; if you follow a link, that platform's own privacy policy applies from that point forward.
04How We Use Information
- To operate, secure, and maintain the website.
- To schedule, prepare for, and follow up on conversations you request.
- To understand which content is useful, in aggregate, so we can improve the site.
- To conduct product discovery — understanding the problems infrastructure teams face so we build the right thing.
- To respond to your questions and, where you have asked for it, to notify you about product availability.
- To comply with legal obligations and to establish, exercise, or defend legal claims.
We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not use website visitor data to train machine learning models.
05Legal Bases (EEA / UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under Article 6 GDPR:
- Consent — for all analytics cookies and analytics processing, which we do not begin until you accept, and for any optional communications you sign up for. You may withdraw consent at any time through Cookie Settings in the footer, without affecting processing carried out before you withdrew it.
- Legitimate interests — operating and securing the website, including server and CDN logs, and conducting business-to-business product research. We have assessed that these interests are not overridden by your rights.
- Performance of a contract or steps prior to a contract — arranging and holding a requested conversation, and negotiating any engagement.
- Legal obligation — retaining records where law requires it.
06Cookies and Analytics
Analytics are off until you turn them on. On your first visit we show a banner asking whether you accept analytics cookies. Until you choose "Accept," the Google Analytics and Google Tag Manager scripts are not loaded, no request is sent to Google, and no analytics cookie is set. Declining, or simply ignoring the banner, leaves analytics off.
If you accept, Google Analytics 4 sets cookies (typically _ga and _ga_<container>) to distinguish visitors and measure sessions. We use Google Consent Mode with advertising, ad personalization, and ad user data signals set to denied at all times — we do not run advertising or cross-site tracking cookies under any setting. Calendly may set its own cookies on their own site if you follow the booking link; that happens on calendly.com, not here, and is a functional part of booking a meeting.
We record your choice in your browser's local storage under the key oai-consent, so we do not have to ask again on every page. That record stays in your browser and is not transmitted to us.
Changing your mind
- Cookie Settings in the footer of any page reopens the banner. Switching from accept to decline clears the Google Analytics cookies we can reach and reloads the page so the already-loaded scripts are discarded.
- Clear your browser's cookies and site data for outcomeai.io to reset the choice entirely.
- Install the Google Analytics Opt-out Browser Add-on for a browser-wide opt-out.
Global Privacy Control
If your browser or extension transmits a Global Privacy Control (GPC) signal, we treat it as a decline and never show the banner or load analytics. We also treat GPC as a valid opt-out of any sale or sharing of personal information — though, as stated in Section 7, we do not sell or share personal information in the first place. You can still opt in explicitly through Cookie Settings if you want to.
Declining does not break anything. Every part of the site works with analytics off, including the booking link.
07Disclosure of Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months.
We disclose information only in these circumstances:
- To service providers listed in Section 3, acting on our instructions and bound to protect it.
- For legal reasons — when required by law, subpoena, or valid governmental request, or where disclosure is necessary to protect our rights, safety, or property, or that of others.
- In a business transfer — if OutcomeAI is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. We will provide notice before your information becomes subject to a materially different privacy policy.
08Data Retention
- Analytics data — retained per our Google Analytics configuration, which is set to a maximum of 14 months for user-level and event-level data. Aggregate reporting may persist longer.
- Server and security logs — retained by our hosting provider for a short rolling window, generally no more than 30 days.
- Booking records and correspondence — retained for as long as needed to maintain the business relationship or conversation thread, and generally no more than 24 months after our last contact, unless you ask us to delete it sooner or we are required to keep it.
- Discovery notes — retained while relevant to product development. On request we will delete notes attributable to you, or de-identify them so they can no longer be linked to you or your employer.
09Security
The website is served over HTTPS with modern TLS. Access to booking data and correspondence is limited to personnel who need it, protected by multi-factor authentication. We rely on our providers' infrastructure security controls for the systems they operate.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. Please do not send credentials, access keys, or confidential architecture details by email or through a booking form. If we need that kind of detail, we will agree an appropriate channel with you first.
10International Transfers
OutcomeAI is based in the United States, and our providers process data in the United States and other countries. If you are located outside the United States, your information will be transferred to and processed in a country whose data protection laws may differ from your own. Where required, such transfers rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or the EU-U.S. Data Privacy Framework as implemented by the relevant provider.
11Your Privacy Rights
If you are in the EEA, UK, or Switzerland
You have the right to access your personal data; to correct inaccurate data; to request erasure; to restrict or object to processing (including objecting to processing based on legitimate interests); to data portability; to withdraw consent at any time without affecting prior processing; and to lodge a complaint with your national supervisory authority.
If you are a California resident
Under the CCPA as amended by the CPRA, you have the right to know what personal information we collect and how we use and disclose it; to request deletion; to request correction; to opt out of sale or sharing (we do neither); to limit use of sensitive personal information (we do not collect it); and to be free from discrimination for exercising these rights. The categories we collect are identifiers, internet or network activity, and approximate geolocation, as described in Section 2. You may use an authorized agent to submit a request.
Other U.S. states
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws have comparable rights of access, correction, deletion, portability, and opt-out, including a right to appeal a denied request. To appeal, reply to our decision and we will review it and respond in writing.
How to exercise a right
Email us at the address in Section 15 with what you are asking for. We will verify your request by corresponding with the email address we hold for you, and we will respond within the time frame the applicable law requires — 30 days under GDPR, 45 days under U.S. state laws, each extendable where permitted. There is no charge unless a request is manifestly unfounded or excessive.
12Children
This is a business-to-business website not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
13Customer and Product Data
The OutcomeAI product is designed to deploy into the customer's own cloud account. Infrastructure templates, tickets, policy rulesets, and review records generated by the product remain in the customer's environment and are controlled by the customer, not by OutcomeAI. This website privacy policy does not govern that data — a separate services agreement and, where applicable, a data processing addendum do.
Where we act as a processor for a customer's data under such an agreement, we process it only on that customer's documented instructions, and the customer remains the controller.
14Changes to This Policy
We may update this policy as the product and the business develop. When we do, we will revise the "Last updated" date at the top of this page. If a change materially affects how we handle personal information, we will provide more prominent notice — for example, by email to those we hold an address for. Continued use of the website after an update means you accept the revised policy.
15Contact Us
Privacy questions, requests, and complaints go to:
OutcomeAI LLC
Email: privacy@outcomeai.io
Web: outcomeai.io
We do not currently have an EU or UK representative under Article 27 GDPR, as our processing does not meet the threshold requiring one. If that changes, we will name a representative here.