Privacy policy
Last updated 29 September 2026
This page explains what Outtest collects, why, who else handles it, and what you can ask us to do with it. Outtest is run by Sancar Media Ltd (company number 16010239, registered in England and Wales; registered office 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom), a UK company (“we”). Questions or requests go to outtest@sancarmedia.com.
There are two groups of people here. Customers are the businesses that sign up to Outtest. For their account data we are the controller. Visitors are the people who visit a customer's website after the customer adds the Outtest script. For visitor data, the customer is the controller and we handle it for them as their processor.
What we collect from customers
- Your account. Your email address, and your name if you give it. If you sign up with a password, Supabase (our login provider) stores a hash of it; we never see the password itself. If you use “Continue with Google”, Google tells us your name and email address.
- Your website. The address you give us, and the title, description, icon and tools (such as Stripe or Google Analytics) we find on its home page.
- Tools you connect. The access token or key for each tool, encrypted with AES-256 before we store it. From Stripe we read charges, refunds and subscriptions, and keep only daily totals such as revenue, refunds, recurring revenue and customer counts. We don't store your customers' names, emails or card details. The connect screen shows what each tool can see before you connect it.
- Billing. Stripe handles payments for your Outtest plan. We never see your card or bank details. We keep your Stripe customer and subscription IDs and which plan you're on.
- Agent chats. When you message an Outtest agent, we send your messages, your ship rules and a summary of your numbers (for example revenue and churn over the last 28 days) to Anthropic to write the reply. We don't save these chats.
- Settings. Your ship rules, autopilot choice and email preferences.
What the Outtest script collects from visitors
If a customer adds the Outtest script to their site, it records:
- a random ID, kept in the visitor's browser storage (
ot_vid), so repeat visits count as one person; - the page address, the page they came from, and events the customer chooses to track, such as a signup;
- the visitor's country, worked out from the request. We don't store IP addresses or browser details;
- a scrambled (SHA-256) copy of the visitor's email, only if the customer sends one to link visits to a signup.
The script sends nothing when the browser has Global Privacy Control switched on, or after the site calls outtest.optOut(). Customers who add the script must tell their visitors about it and get any consent their local law requires, for example through their cookie banner.
Cookies on useouttest.com
We use only the cookies Outtest needs to work. No advertising or analytics cookies.
sb-…-auth-token: keeps you signed in (Supabase), up to 400 days.ot_ws: remembers which workspace you're setting up, 400 days.ot_in: tells our pages you're signed in, 30 days.ot_oauth: protects a tool connection while you approve it, 10 minutes.ot-theme: your light or dark mode choice, 1 year.
Our home page shows posts from X, so your browser loads those images from X's servers.
Why we use it
- To run the service you signed up for: reading your numbers, suggesting and running tests, billing you. (Contract.)
- To keep Outtest secure, fix problems and improve it. (Legitimate interests.)
- To keep billing records the law requires. (Legal obligation.)
- To email you about your account and your tests. You can turn off the weekly email in Settings.
We don't sell data, and we don't use your data or your visitors' data to train AI models.
Who else handles it
- Supabase: database and logins.
- Vercel: hosting, in London.
- Stripe: payments for Outtest plans.
- Anthropic: writes agent replies.
- Resend: sends our emails.
- Google: only if you sign in with Google or connect a Google tool.
Each one only gets what it needs for its part. Some are based in the United States. Where data leaves the UK, we rely on the UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or the standard contract clauses each provider signs. We'll also share data if the law requires it, or with a buyer if Outtest is ever sold, under this same policy.
How long we keep it
- Account and workspace data: while your account is open. After you ask us to delete it, within 30 days.
- A connected tool's token and the numbers pulled from it: deleted as soon as you click Disconnect.
- Billing records: six years, because UK tax law requires it.
- Visitor events: 25 months, then deleted.
Your rights
You can ask to see, correct, export or delete your data, or object to how we use it. Email outtest@sancarmedia.com and we'll reply within one month. If you're a visitor to a customer's site, contact that business first; we'll help them answer you. If you're unhappy with our answer, you can complain to the Information Commissioner's Office.
Security
All traffic uses HTTPS. Tokens and keys for your tools are encrypted before they're stored, and only the Outtest server can read them. Only people who run Outtest can reach the database.
Children
Outtest is a business tool for adults. We don't knowingly collect data from anyone under 18.
Changes
If we change this policy in a way that matters, we'll email customers before it takes effect. The date at the top shows the latest version. See also our terms of service.