Privacy Policy
Effective date: 2026-08-14 Last updated: 2026-08-14
Outsample (“we”, “us”) is operated by Marios Stathakopoulos, a business established in Ontario, Canada. This policy explains what personal information we collect when you use outsample.com and app.outsample.com, what we do with it, who processes it for us, and the rights you have over it. It is written to meet the Canadian federal privacy law (PIPEDA) and, for users in the European Union and EEA, the GDPR.
The person accountable for privacy at Outsample is Marios Stathakopoulos, reachable at privacy@outsample.com. This is the address for every privacy question, request, or complaint in this policy.
What we collect
Account data. Email address, display name, hashed authentication credentials, plan tier, referral code if you use one. Collected when you sign up.
Billing data. Payments are processed by Stripe acting as merchant of record through its Managed Payments service. Stripe collects your payment card details, billing address, and transaction history. We never see your full card number. We receive transaction records (who bought what, when, for how much).
Content you submit. Your research queries, the papers you upload, and the outputs generated for you (syntheses, strategies, critiques). This is the core of the service and is processed as described in “AI processing” below.
Usage data. Product analytics about how the app is used (pages viewed, features used, timing). Configured as described in “Cookies and analytics” below.
Technical and error data. Server logs and error reports, which can include your IP address, browser type, and the state of the app when an error occurred.
Correspondence. Emails you send us, including support requests.
Why we process it, and on what legal basis
| Purpose | Data | GDPR basis |
|---|---|---|
| Providing the service: accounts, queries, syntheses, uploads | Account, content | Contract (Art 6(1)(b)) |
| Billing, subscriptions, credits | Billing (via Stripe) | Contract (Art 6(1)(b)); legal obligation for tax records |
| Security, abuse prevention, debugging | Technical, error | Legitimate interests (Art 6(1)(f)) |
| Aggregate product analytics | Usage | Legitimate interests (Art 6(1)(f)), configured as set out below; identified in-app analytics only with your consent |
| Product and marketing email | Account (email) | Consent (Art 6(1)(a)); for existing customers, the email rules of your jurisdiction (in Canada, CASL implied consent from an existing business relationship) |
| Responding to you | Correspondence | Legitimate interests (Art 6(1)(f)) |
Under PIPEDA, we collect, use, and disclose personal information with your consent, for purposes a reasonable person would consider appropriate in the circumstances: delivering the service you signed up for, billing you for it, keeping it secure, and improving it.
AI processing
This section says plainly what happens to your queries and uploads.
When you run a query, ask for a synthesis, or upload a paper, that content is sent to large language model providers to generate the output. Routing goes through OpenRouter, an LLM gateway. Our primary model provider is Anthropic (the Claude models); OpenRouter may route requests to other model providers we configure.
Neither Outsample nor OpenRouter uses your queries or uploaded documents to train AI models, and we configure OpenRouter to route requests only to model providers that state they do not train on customer data. Our primary model provider, Anthropic, states that it does not train its models on content submitted through its commercial API.
Model providers may retain request content briefly for abuse and safety monitoring. Anthropic states that API inputs and outputs are automatically deleted within 30 days, except where content is flagged for trust-and-safety review or retention is required by law. OpenRouter states that it does not retain prompt content unless prompt logging is explicitly enabled, and we do not enable it.
Outputs are stored in your account so you can return to them. Delete a project or your account and the stored outputs go with it, per “Retention” below.
Who processes data for us
We use a small set of service providers. Each processes personal data only to provide its function to us.
| Provider | Role | Data touched |
|---|---|---|
| OpenRouter | LLM gateway routing queries to model providers | Queries, uploaded paper text, outputs |
| Anthropic and other configured model providers (via OpenRouter) | Model inference | Queries, uploaded paper text, outputs |
| Render | Backend hosting | All data the backend processes |
| Neon | Postgres database hosting | Account data, content, usage records |
| Cloudflare | Frontend delivery and CDN | IP addresses, request metadata |
| Stripe | Billing, merchant of record | Billing data, transaction history |
| SuperTokens | Authentication | Credentials, session tokens |
| PostHog | Product analytics | Usage data (see “Cookies and analytics”) |
| Sentry | Error monitoring | Error reports, IP addresses, app state |
| Resend | Account and authentication email (password resets, verification) | Email address, message content |
Each of these providers processes data under the data-protection terms in their published agreements.
Where data goes
Outsample is operated from Canada. The European Commission has decided that Canada’s federal privacy law provides adequate protection for data transferred to commercial organizations covered by it, so data moving from the EU to us travels under that adequacy decision. Some of our providers process data in the United States; those transfers rest on the provider’s standard contractual clauses or their certification under the EU-US Data Privacy Framework, per each provider’s data-protection terms.
Retention
| Data | Kept for |
|---|---|
| Account data | Life of the account, then deleted within 30 days of account deletion |
| Content (queries, uploads, outputs) | Until you delete them or your account; then removed from live systems within 30 days |
| Billing records | 7 years, as Canadian tax law requires |
| Usage analytics | PostHog’s project retention period |
| Error reports | 90 days (Sentry’s default retention) |
| LLM-side copies | Per “AI processing” above: Anthropic states deletion within 30 days; OpenRouter states prompts are not retained without opt-in logging |
| Breach records | 24 months, as PIPEDA requires |
Your rights
Wherever you are, you can ask us to:
- tell you what personal information we hold about you and give you a copy (access);
- correct it (rectification);
- delete it (erasure);
- give it to you in a portable format (portability, for data you provided);
- stop or limit certain processing (objection and restriction);
- withdraw a consent you gave, without affecting what happened before withdrawal.
Send requests to privacy@outsample.com. We will verify that the request comes from the account holder, act within one month for GDPR requests and 30 days for PIPEDA requests, and tell you if a legal exception prevents any part of the request.
If you are unsatisfied, you can complain to the Office of the Privacy Commissioner of Canada, and, if you are in the EU/EEA, to your local supervisory authority.
Deleting billing data held by Stripe as merchant of record can also be requested through Stripe’s Link service; we act on the remainder.
Cookies and analytics
The marketing site (outsample.com) uses no analytics cookies. Analytics there runs in a cookieless mode that stores nothing on your device; visitors are counted through a daily-rotated server-side hash that cannot be reversed into your identity. That is why there is no cookie banner on the site.
The app (app.outsample.com) sets:
| Cookie / storage | Purpose | Type |
|---|---|---|
| SuperTokens session tokens | Keeping you signed in | Strictly necessary |
| Stripe checkout cookies | Completing payment when you buy | Strictly necessary |
| PostHog analytics storage | Product analytics across sessions | Only after you opt in |
In-app analytics that remembers you across sessions is off by default for EU users and starts only if you enable the analytics toggle in settings. You can turn it off there at any time.
Security
Data in transit is encrypted with TLS. Databases are encrypted at rest. Access to production systems is limited to the operator. Payment card data is handled by Stripe and never stored by us. No system is perfectly secure; if a breach creates a real risk of harm to you, we will notify you and the relevant authorities as the law requires (in Canada, the OPC as soon as feasible; under GDPR, the supervisory authority within 72 hours where required).
Age
Outsample is a research tool for adults and is not directed at anyone under 18. We do not knowingly collect personal information from minors.
Changes
We will post changes here with a new “last updated” date. For material changes, existing users get an email before the change takes effect.
Contact
Marios Stathakopoulos c/o AMT Tuning, 25 Edilcan Dr #6, Vaughan, ON L4K 3S4 privacy@outsample.com