Privacy · pilot access

Your request stays bounded.

When you request pilot access, ObserverFlow records your email address, your selected starting point, your selected monthly-value range, your explicit request, an opaque receipt, and the time of the request. The two selections use fixed choices; there is no free-form profile. We count first-party document requests to the canonical landing page, venture-operations field guide, pilot form, and the fixed guide-to-pilot entry path so we can distinguish missing traffic from missing conversion. Those counters retain no IP address, user agent, referrer, cookie, visitor identifier, or raw request. We do not use advertising analytics, tracking cookies, visitor profiles, or third-party marketing pixels on this site.

Protection

Your email is encrypted before it is stored. The production service holds only the public encryption key; decryption custody remains outside the public runtime. A keyed fingerprint prevents duplicate records without storing a searchable plaintext email.

Purpose and retention

We use the email only to send one transactional confirmation and, after you confirm control of the address, to evaluate and follow up about ObserverFlow pilot access. We use the fixed selections to understand which pilot experience matters and whether the product creates enough value to support a sustainable price. Operations receive only aggregate counts. The record expires after 90 days, and withdrawing it removes its selections from the active confirmed-intent aggregate. Historical aggregate operating counts may remain without the email or receipt.

Confirmation

The confirmation email comes from ObserverFlow Pilot at pilot@mail.observerflow.com. Confirm and delete capabilities are placed after the link fragment so they are not sent in the initial page request, and each action still requires a button press. Unknown email-provider outcomes are not automatically retried.

Download or delete your request

Your browser stores a private withdrawal receipt after a successful request, and the confirmation email contains an equivalent fragment-only capability. Use the data-control screen to download the data associated with your request or delete the encrypted record immediately. Export requires the matching email and returns it only to your browser; it is not written into aggregate operations or a general evidence store. Deletion saves a receipt containing no email, ciphertext, or keyed fingerprint.

Control

Requesting pilot access does not create an ObserverFlow account, connect a service, grant authority, authorize spend, or begin autonomous action.