Privacy
What this page does
This part is written, because it is a fact about the code rather than a policy: the Outpost is a static page. It runs no analytics, no tag manager, no embedded fonts and no third-party scripts of any kind. It sets no cookies, and stores nothing in your browser.
It does make one request per app, to that app’s own subdomain, asking whether you are already signed in there — that is what puts a “signed in” badge on a card. Those requests carry the cookie your browser already holds for that app and nothing else; this page cannot read that cookie itself. The reply is a single true or false, used to show or hide the badge and recorded nowhere. If an app does not answer, no badge appears.
Your browser's request for it reaches the web server, which keeps ordinary access logs. Say below what those logs contain and how long they are kept.
This page is not written yet. Everything below is a
scaffold describing what belongs in each section — it is not a statement of terms and has
no legal effect. Replace it before the site is public. The page carries
noindex until then.
Server logs
What the nginx access log records, how long it is retained, and who can read it.
The apps collect separately
Each app has its own privacy notice covering its own data. Following a card off this page takes you to a different service; nothing about you crosses from here to there.
Your rights, and who to ask
The applicable regime (GDPR, CCPA, whichever applies), what people can request, and how long you take to answer. See Contact.