Effective September 3, 2026
Privacy Policy
You are trusting us with information about someone’s incarceration. We designed OutDate so we hold as little as possible, encrypt what we do hold, and never monetize it.
What we collect
- Account data: your email address, a password hash (argon2 — we cannot read your password), and an optional phone number for reminders.
- Case data you enter: sentence facts, dates, program participation, and optionally a name and register number for the person inside. Names and register numbers are encrypted at rest (AES-256-GCM). A real name is never required — aliases work everywhere.
- Mail data (if you use physical mail): your verified name and return address, and the contents of letters you approve for printing.
- Concierge documents (only if you ask us to enter a case for you): the photos or PDFs you upload — typically the sentence computation sheet, team sheet, or judgment — and the note you write with them. Files, filenames, and the note are encrypted at rest (AES-256-GCM) in our own database. To read them, we send each document and your note to an AI model through OpenRouter (see “Who we share data with”); the model transcribes the values on the page, and a person checks them. The values are held as an encrypted draft that never touches your case until you review and save it, and the model's per-document findings are deleted with the documents.
- Usage data: anonymous feature counters (e.g. “a calculation ran”) with no case content, plus standard server logs. We use Google Analytics across the site and the app to measure visits, traffic sources, and which features are used (pages viewed, a case saved, a calculation run); it sets its own cookies. We send it page paths and event names only — never names, register numbers, sentence facts, or any other case content.
- The anonymous calculator stores nothing server-side.
How we use it
To run the product: computing dates, sending the reminders and rules-change notifications you signed up for, processing payments, and (if you choose) printing and mailing letters. We do not sell or rent personal data, we do not use case content for advertising, and we do not train machine-learning models on your data.
Who else touches your data
- Stripe processes payments; card numbers never reach our servers.
- Mailgun delivers our emails (your address and message contents pass through it).
- A print-and-mail vendor prints and posts letters you explicitly approve — it receives the letter contents and both addresses, and nothing else.
- OpenRouter (AI assistance features) — the specific text each AI feature works on is processed by an AI model through OpenRouter, restricted to providers that retain nothing after responding and with no training on your data. Names and register numbers are never sent: the plain-language summary is written only from the calculation's own derivation steps, letter help sees only the template blanks and the notes you type, intake suggestions see only the statute or question you enter, and sheet scanning sends only machine-read text with names and register numbers stripped (the photo itself never leaves our server). The one exception is concierge setup: when you ask us to enter a case for you, the documents and note you upload are sent as-is — names and register numbers included, since they are printed on the paperwork — to a vision model through OpenRouter, restricted to providers that retain nothing after responding and do not train on your data. If that read leaves a required input missing or two documents in disagreement, we email you about it, quoting the values in question so you can answer. A reply to that email (text and any photos attached) is received by Mailgun and read the same way. AI assistance is on for every account; you can switch it off in your account settings, and with it off nothing about your case reaches any AI provider (a concierge request is then entered by hand).
- We disclose data beyond this only if legally compelled, and where lawful we will tell you before we do.
Sensitivity, retention, and deletion
- We treat everything about a case as sensitive — incarceration status is not a marketing attribute, and we will never use it as one.
- Deleting a case permanently removes every associated record: sentence facts, ledger history, documents, and mailing records. Deleting your account removes the account and all its cases.
- Concierge documents are deleted the moment you save the reviewed draft, when you cancel the request, or when we close it — and in every case within 90 days of upload. Requests left untouched for 60 days are closed automatically, which deletes their documents.
- Encrypted database backups are kept for a limited window for disaster recovery and age out automatically.
Security
TLS everywhere, field-level AES-256-GCM encryption for names and register numbers at rest (and for concierge documents, filenames, notes, and drafts), argon2id password hashing, single-use hashed tokens for password resets, and server-side access control on every route. Every time an operator opens a concierge document or note, or reveals a name or register number, an audit-log entry is written first — there are no unlogged views. No security is perfect; if we learn of a breach affecting your data we will notify you promptly at your account email.
Your rights
You can export your case data from the product, correct anything in place, and delete cases or your whole account yourself — no support ticket required. For access, portability, or deletion requests you cannot self-serve (or any privacy question), email [email protected] and we will respond within 30 days. We honor applicable rights under state privacy laws (including the CCPA) and, for anyone in scope, the GDPR. The Service is not directed to children under 18.