Skip to content
OffsightAI
Sign In

Legal

Privacy policy

What we collect, what the AI does with it, who else sees it, how long we keep it, and how you get it back or get it deleted. Written for the person who has to sign off on the vendor review.

Last updated: August 7, 2026. This policy covers this website, the Offsight AI console at ai.offsight.com, the Offsight AI apps for iOS and Android, and the Offsight APIs. Published for information; it is not legal advice.

Protecting your information is a priority for Offsight Inc. (“Offsight,” “we”). This policy explains what we collect, why, who we share it with, and what you can ask us to do about it. By using the Offsight AI website or services, you consent to the practices described here.

1. Two different roles

Read this first, because everything else depends on it.

  • When you visit our website or contact us, Offsight is the controller. We decide what to collect from a demo request or a support message and what to do with it. This policy is the full description.
  • When a customer runs their factory on Offsight AI, Offsight is a processor. The customer decides what goes into their tenant — production records, photos, drawings, timesheets, inspections — and we process it on their instructions under our Data Processing Addendum. If you are an employee or contractor of an Offsight customer and you want to see, correct or delete records held about you in that customer’s tenant, contact that customer. We will help them respond; we will not act on their data without them.

2. Information we collect

Information you give us

  • First and last name
  • Email address
  • Phone number
  • Employer, job title and role
  • What you write in a demo request, sales enquiry or support message
  • Account details when a tenant is created for you: username, password (stored only in hashed form), role and permission assignments, and two-factor enrolment details
  • Billing contact details. Card details are collected and stored by our payment processor, not by Offsight

Information you put into the platform

This is Customer Data, and it belongs to the customer. It typically includes production and quality records, checklists and sign-offs, photographs taken on the floor, drawings, models and sheets, materials, inventory and purchase-order records, labor records and timesheets, delivery and shipping records, and messages exchanged with the Offsight AI assistant.

Information collected automatically

  • IP address, browser type and version, device type and operating system
  • Access times, pages viewed, referring URLs and, in-product, screens visited
  • Application and error telemetry used to keep the Service working and to diagnose faults
  • API usage metering — request counts and volumes against each API key, used to enforce limits and to bill accurately
  • AI credit consumption, recorded per request so an account can see where it went

Our sites and apps use cookies and similar technologies that are necessary to operate them — keeping you signed in, remembering a session, and understanding aggregate usage so we can fix what is broken. We do not sell your information, and we do not rent or lease customer lists.

3. How AI processing works

This is the section most vendor reviews are actually looking for, so it is specific.

What gets sent. When someone uses an AI feature, the content of that request and the records, documents or images relevant to answering it are sent over an encrypted connection to a third-party model provider, which processes them and returns a response. What is sent is scoped to the request. A question about one work order does not ship the whole database.

Who processes it. Model inference is performed by third-party model providers engaged as our sub-processors, under commercial API terms and under written data-protection obligations. Providers and model versions change as the technology changes. See section 7 of the DPA for how sub-processors are engaged and how customers get the identified list.

No foundation-model training. Offsight does not use Customer Data to train, fine-tune or develop general-purpose AI models, and inference requests are made under commercial API terms under which customer content is not used to train the provider’s models.

Permissions still apply. An AI request executes in the context of the user who made it. It is scoped to that user’s tenant and bounded by their per-module and per-user-group permissions. It cannot reach another tenant, and it cannot see a module the user cannot see.

It is logged. AI sessions — the request, the actions taken and the output returned — are stored in the customer’s tenant as part of the record, so an administrator can see what was asked, what the system did, and on whose behalf.

It is reviewed by people. AI output is decision support, not a professional opinion. The Terms of Service set out where human review is required before output is relied on.

4. How we use information

  • To operate, maintain, secure and improve the Service and this website
  • To provide the services you have requested, including a demo or support
  • To create and administer accounts, permissions and authentication
  • To bill accurately, including metered API and AI credit usage
  • To send transactional messages: alerts, notifications, confirmations, and service announcements
  • To tell you about other Offsight products and services. You can opt out of marketing email at any time using the link in the message or by writing to us
  • To comply with legal obligations and to enforce our agreements

We may also generate aggregated, anonymized data that cannot be linked back to you or to any individual, and use it to improve and test our products.

5. Sharing information

Offsight does not sell, rent or lease its customer lists to third parties.

We share information in four situations:

  • Sub-processors. We use sub-processors to perform part of the Service for us — hosting, model inference, design-file processing, transactional email, billing and edge delivery. Each is engaged under a written contract, is bound to use the information only to provide its service to Offsight, and is bound to confidentiality. Customers and their assessors can obtain the identified list under the DPA — see section 7 of the DPA.
  • Integrations you connect. If you connect Offsight AI to another system — an ERP, an accounting package or a design-file platform, for example — data moves between the two at your instruction and under that provider’s terms.
  • Legal process. We may disclose information if required by law, or in the good-faith belief that it is necessary to comply with legal process, to protect and defend our rights or property, or to act in exigent circumstances to protect someone’s personal safety.
  • Business transfer. If Offsight is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction, subject to this policy.

6. Security

Offsight secures information against unauthorized access, use, alteration and disclosure. The controls in place include:

  • Encryption in transit (TLS) and encryption at rest
  • Two-factor authentication
  • Per-module and per-user-group permissions, administered by your own admins
  • Tenant isolation, so one customer’s data is separated from another’s
  • Audited access, including logging of administrative and support access
  • API keys with rotation, live usage metering and enforceable limits
  • Managed cloud infrastructure in the United States: containerized services, a managed relational database with a read replica, a caching tier, and per-tenant data separation

No transmission over the internet or any wireless network can be guaranteed to be completely secure. While we work to protect your information, you acknowledge that there are security and privacy limitations inherent to the internet that are beyond our control. We will answer a written security questionnaire about the architecture, subject to confidentiality — ask us on the contact page.

7. Retention

  • Customer Data is retained for as long as the customer’s account is active, and then in accordance with the customer’s agreement. On termination, data can be exported and is then deleted on request. Data may be irretrievably deleted if an account is ninety (90) days or more delinquent.
  • AI session records — requests, actions and output — are retained in the customer’s tenant on the same basis as other Customer Data, because they are part of the audit trail.
  • Website and marketing information — a demo request, an enquiry — is retained for as long as needed to respond and to maintain a record of the relationship, and is deleted on request.
  • Logs and telemetry are retained for a limited operational period and then rotated out.
  • Billing records are retained for as long as required for tax and accounting purposes.

8. Your rights

Depending on where you live, you may have the right to request access to the personal data we hold about you, to have it corrected, to have it deleted, to restrict or object to how it is processed, to receive a portable copy, and to withdraw a consent you previously gave. You will not be treated differently for exercising any of these rights.

To make a request about data Offsight holds as controller — for example a demo request or a marketing contact record — write to support@offsight.com. We may need to verify your identity before acting.

To make a request about records held inside a customer’s tenant, contact that customer. They are the controller of that data, and we will support them in responding.

9. International transfers

Offsight is based in the United States and the Service is operated on infrastructure in the United States. If you access the Service from outside the United States, your information is transferred to and processed there. Where personal data is transferred out of a jurisdiction that restricts such transfers, we rely on the safeguards set out in our Data Processing Addendum.

10. Children under thirteen

Offsight does not knowingly collect personally identifiable information from children under the age of thirteen. If you are under thirteen, you must ask a parent or guardian for permission before using this website.

11. Email communications

From time to time we may contact you by email with announcements, alerts, confirmations, surveys and other general communication. Transactional messages about your account and the Service are part of the Service. Marketing email always carries an unsubscribe link.

12. Changes to this policy

Offsight may change this policy from time to time. We will notify you of significant changes to the way we treat personal information by sending a notice to the primary email address on your account, by placing a notice on this site, or by updating this page. Continued use of the site or the Service after a change constitutes acknowledgement of the modified policy and agreement to be bound by it.

13. Contact

Questions about this policy: support@offsight.com. Contract questions: sales@offsight.com.

Offsight Inc.
650 California St
San Francisco, California 94108

Bring the security questions to the call.

Your IT lead is welcome on the demo.