Privacy policy
What OutcomeGuard collects, why, how long it is kept, and how you get rid of it.
Last updated: 2026-09-11
1. Who this applies to
This policy covers the OutcomeGuard website and service ("we"), operated by ProofWorks. It explains what we collect, why, how long we keep it, and how you remove it.
We act as the processor for the monitoring data we read from your automation platform. You remain the controller of that data.
2. Data you give us
- Account data: email address, password hash, workspace name, locale and timezone preference.
- Integration data: the base URL of your n8n instance and the API key you provide, stored encrypted.
- Configuration: which workflows you monitor, your Outcome Contracts, alert recipients and notification settings.
- Billing data: handled by our payment processor. We store the subscription state and a customer reference, not your card details.
3. Data we read from your automation platform
We call the n8n public REST API read-only and store execution summaries: status, start and stop timestamps, duration, item counts, the name of the last node executed, the workflow definition hash, and error messages with secrets redacted.
We do not store raw execution payloads. The contents of the records your workflows move — customer data, documents, message bodies — are never copied into OutcomeGuard.
4. Website and product analytics
We count page views and a small number of product events (for example, that a free scan was started and that it completed) to understand whether the product is usable. We set no advertising cookies and no cross-site trackers, and we honour the browser Do Not Track signal by skipping the event entirely.
5. Why we are allowed to process it
- Performance of a contract: operating the monitoring you signed up for.
- Legitimate interests: keeping the service secure, preventing abuse, and fixing faults.
- Consent: the free scan runs only after you confirm that you authorise a read-only scan of the instance.
6. How long we keep it
- Execution summaries and findings: 90 days.
- Free scan reports: 7 days, then deleted. The API key used for a free scan is discarded as soon as the scan finishes.
- Account and billing records: for as long as the account exists, and afterwards only where tax or accounting law requires it.
7. Sharing
We use service providers for hosting, transactional email and payments. They process data on our instructions only. We do not sell personal data and we do not share it for advertising.
8. Your rights
You can access, correct, export or delete your data. Disconnecting an integration removes the stored credential and the execution summaries for that integration. Deleting the account removes the workspace and its data.
Requests go to the support address on the contact page. Governing data protection authority: [to be confirmed].
9. Security
API keys are encrypted at rest with AES-256-GCM, transport is TLS, every query is scoped to a workspace, and administrative actions are written to an audit log. The security page describes this in more detail.
We make no certification claims. We are not SOC 2 or ISO 27001 certified.
10. Changes
If we change this policy in a way that affects you, we will update the date at the top of this page and notify account holders by email before the change takes effect.