1. Introduction
Offline Protocol, Inc. (“Company”, “we”, “us”, “our”) operates this website at offlineprotocol.com (the “Site”). This Privacy Policy explains what information we collect through the Site, how we use it, who we share it with, and the choices you have.
This policy covers the marketing and informational Site only. It does not cover the Fernweh or MINE mobile applications, our developer SDKs, or the mesh network itself. Those products have their own privacy policies, which you can read at offlineprotocol.com/docs/legal.
We designed the Site to collect as little as possible. There are no user accounts, no logins, and no tracking of you across other websites. This policy is written to comply with the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and other applicable privacy laws.
2. Information We Collect
The Site has no sign-up. We collect information in three ways: analytics (only if you consent), information you send us directly, and standard server logs.
2.1 Analytics (only with your consent)
We use PostHog for privacy-respecting product analytics, gated behind a consent banner. Nothing is collected until you make a choice on the banner, and if you ignore it, nothing is collected. In the banner’s preferences, product analytics is pre-selected on, so you can accept, open preferences to turn it off, or reject all, and your choice is remembered. When analytics is enabled, we collect:
| Data | Purpose |
|---|---|
| Pages viewed, referring URL, and clicks on links/buttons | Understand which content and calls-to-action are useful |
| Browser type, device type, operating system, screen size | Ensure the Site works across devices; aggregate reporting |
| Approximate location (country/region, derived from IP by PostHog) | Aggregate geographic reporting; the raw IP is not stored in our analytics |
| A random analytics identifier stored in your browser | Distinguish one visit from another; not linked to your real-world identity |
We configure PostHog to create anonymous profiles only. Because the Site has no login, we never attach your name, email, or any personal identifier to your analytics. We do not use PostHog session replay, heatmaps of your inputs, or third-party advertising features on the Site.
2.2 Information You Send Us
If you contact us or book a call, you provide information directly:
| Where | Data you provide | Handled by |
|---|---|---|
| Contact form | Name, email address, company (optional), and your message | Web3Forms (form relay) → our email inbox |
| “Book a pilot call” button | Name, email, and scheduling details you enter to book a meeting | Calendly (scheduling), on calendly.com |
| Direct email | Your email address and anything you include | Our email inbox |
We use this information only to respond to you, schedule and hold requested meetings, and follow up about your inquiry. We do not add you to marketing lists without your consent.
2.3 Server Logs
Like all websites, our hosting and content-delivery providers automatically log basic technical information when your browser requests a page: your IP address, user-agent string, the page requested, and a timestamp. These logs are used for security, abuse prevention, and reliability, and are retained for a short period by our providers (Cloudflare and Railway). We do not use them to build a profile of you.
4. How We Use Your Information
We use the limited information described above to:
- Respond to inquiries submitted through the contact form or by email
- Schedule and conduct pilot calls and meetings you request
- Understand, in aggregate, how the Site is used so we can improve it (only with your analytics consent)
- Keep the Site secure, prevent abuse, and diagnose technical problems
- Comply with legal obligations
We do not:
- Sell or rent your personal information
- Share your information for cross-context behavioral advertising
- Run third-party ad networks or retargeting pixels on the Site
- Use your information to train artificial-intelligence or machine-learning models
5. Third-Party Services and Sub-Processors
We rely on a small set of vendors to operate the Site. Each processes data only to provide its service to us:
| Service | Provider | Role | Data involved |
|---|---|---|---|
| Railway | Railway Corp. (US) | Website hosting | Server request logs (IP, user-agent, timestamp) |
| Cloudflare | Cloudflare, Inc. (US) | DNS, CDN, and security/DDoS protection | Request metadata (IP, user-agent, timestamp) |
| PostHog | PostHog, Inc. (US) | Product analytics (consent-gated) | Anonymous usage events, approximate location |
| Web3Forms | Web3Forms | Contact-form delivery to our inbox | Name, email, company, message you submit |
| Calendly | Calendly, LLC (US) | Meeting scheduling | Name, email, scheduling details you enter |
Some pages link out to services with their own privacy policies, including our documentation (docs.offlineprotocol.com), our shop (shop.offlineprotocol.com), GitHub, and X (Twitter). When you follow those links or interact with those services, their privacy policies govern.
5.1 Legal Disclosure
We may disclose information if required to do so by law or in response to a valid request by a public authority (for example, a court order). We may also disclose information to protect our rights, safety, and property, or those of others.
6. Legal Bases for Processing (GDPR)
If you are in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:
- Consent: for analytics via PostHog. You may withdraw consent at any time, and withdrawal does not affect processing already carried out.
- Legitimate interests: to keep the Site secure, prevent abuse, and maintain reliability (server logs), and to respond to inquiries you initiate.
- Performance of a contract / steps at your request: to schedule and hold a meeting you ask for, or to reply to your inquiry.
- Legal obligation: where we must retain or disclose information to comply with the law.
7. Data Retention
| Data | Retention |
|---|---|
| Analytics events (PostHog) | Retained per PostHog’s data-retention lifecycle; used only in aggregate |
| Contact-form messages and email correspondence | Kept as business records for as long as needed to handle your inquiry and for a reasonable period afterward, then deleted |
| Scheduling data (Calendly) | Retained by Calendly and in our calendar for the life of the meeting record |
| Server / CDN logs | Short-term, per Cloudflare and Railway defaults (typically days to a few weeks) |
| Consent choice (local storage) | Stored in your browser until you clear it |
8. International Data Transfers
We and our vendors are based primarily in the United States, so information collected through the Site may be transferred to and processed in the U.S. and other countries. Where personal data is transferred out of the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses provided by the relevant vendor.
9. Your Privacy Rights
9.1 Everyone
- Decline analytics, or withdraw your consent at any time (see Section 3)
- Ask what personal information we hold about you
- Ask us to correct or delete information you have sent us
9.2 EEA / UK Residents (GDPR)
You additionally have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your local data protection authority.
9.3 California Residents (CCPA/CPRA)
You have the right to know what personal information we collect and how we use it, to request deletion, to correct inaccurate information, and not to be discriminated against for exercising these rights. We do not sell your personal information and do not share it for cross-context behavioral advertising.
9.4 How to Exercise Your Rights
Email us at [email protected] or use our contact page. We will respond within the timeframe required by applicable law (generally 30–45 days). Because the Site has no accounts, we may need to verify your identity or ask for details (such as the email you contacted us from) to locate your information.
10. Children’s Privacy
The Site is a business-oriented, informational website intended for a general professional audience. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at [email protected] and we will delete it.
11. Security
The Site is served over HTTPS/TLS and sits behind Cloudflare’s edge security. Because we collect so little, and store no accounts or passwords, the Site presents a small attack surface. No method of transmission or storage is completely secure, but we take reasonable measures to protect the limited information we handle. To report a security issue, see our security page or email [email protected].
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Material changes will be reflected here; your continued use of the Site after an update constitutes acceptance of the revised policy.
13. Contact Us
For any privacy question or request, contact Offline Protocol, Inc. at [email protected], through our contact page, or at offlineprotocol.com. EEA/UK residents may also contact their local data protection authority.
Questions? Reach us at [email protected] or through our contact page.