Outlet Privacy Policy
Last updated: August 21, 2026
Outlet is the safe socket between your AI account and the apps you use. This policy says what we collect, what we never collect, where it lives, and how to get answers. It covers useoutlet.dev, the approval screen at useoutlet.dev/grant, the Outlet vault, and the Outlet SDK. Questions: [email protected].
The short version
Direct mode never touches our servers, so there is nothing to collect. Your AI conversations never pass through Outlet in any mode. When you use Vault mode we hold the minimum: your sign-in identity, your keys stored encrypted, your connections, and their spend totals. We do not sell or share your information for advertising. No ads, no trackers, no analytics scripts.
What we collect, by the way you use Outlet
The website. useoutlet.dev has no analytics and no advertising trackers. Cloudflare hosts the site and, like any host, processes standard request data (such as your IP address) to serve pages and block attacks. We do not build profiles from it.
Direct mode. You paste your own API key into an app and the key is checked on your device. Nothing is sent to Outlet. We collect nothing in Direct mode. This is by construction, not by promise: there is no server call to send anything to.
Signing in. The approval screen signs you in through WorkOS, our sign-in provider. We store the account id WorkOS issues for you and, if the sign-in shares it, your email address. Your password lives with the sign-in provider, never with us. Sign-in sessions last at most 12 hours and the session token is stored only as a hash.
Connecting an AI account (Vault mode). When you connect a provider account, we store your provider admin key encrypted (AES-256-GCM). We use it for exactly four things: create a capped App key inside your own account for an app you approve, read your spend totals to enforce the cap, apply the limits you chose, and revoke keys when you say so or a cap is hit.
For each connection we also store: which app, which provider, the cap you set, the connection status, references the provider creates in your account (for example a project id), and that connection's App key, encrypted. We store month-to-date spend totals per connection as dollar amounts. Totals only. Never what you asked the AI or what it answered.
We keep an append-only security log of sensitive actions (for example: account connected, connection approved, key delivered, key revoked) with timestamps and ids. The log never contains keys or other secrets.
On actions like approving a connection, Cloudflare Turnstile runs a bot check so an automated script cannot approve access in your name. Cloudflare processes the technical signals for that check on our behalf.
Developers. If you register an app we store the app's name, its redirect addresses, and a hash of its secret. When paid billing starts, developer payment details will go directly to Stripe, our payment processor. We will not store card numbers.
What we never collect
Your prompts, messages, or AI outputs in any mode. Your AI talks to your apps. We just make the introduction. We also never hold your passwords, and we never collect payment card numbers ourselves. We do not track you across other sites.
Where your information lives and who touches it
We run on Cloudflare: the site, the vault, its database (stored in Cloudflare's Eastern North America region), the bot check, and the firewall. WorkOS handles sign-in and holds your sign-in identity. Your AI provider (for example OpenAI or Anthropic) receives the key management calls we make with your admin key at your instruction; your relationship and their data practices are governed by their terms. When billing starts, Stripe will process developer payments. We share information with these processors only so they can do these jobs, and with authorities only if the law requires it. We do not sell personal information and we do not share it for cross-context advertising.
How long we keep things, and deletion
Revoking a connection deletes its App key at your provider and the connection stops. Some providers take time to fully stop honoring a deleted key, so a revoked key can keep working briefly on the provider's side. Spend records are kept for accuracy and, for developers, billing. The security log is append-only and kept for security record keeping. To remove a stored admin key, disconnect a provider, or delete your account and its data, email [email protected] and we will complete it within 30 days, keeping only what the law requires us to keep.
Your choices and rights
You can see, correct, or delete your information by emailing [email protected]. You can revoke any connection at any time. Depending on where you live you may have specific legal rights (for example access, portability, correction, deletion). We honor these requests regardless of where you live. We do not sell personal information, so there is nothing to opt out of selling. Because we do not track you across sites, browser signals like Do Not Track and Global Privacy Control do not change how the service behaves; we treat everyone as if they were on.
Children
Outlet is not for children. You must be 18 or older to use it.
Changes
If this policy changes, we will update this page and the date at the top. If a change meaningfully reduces your privacy, we will say so plainly on this page, and by email where we have one for you, before it takes effect.