The private pilot

Privacy policy.

Last updated September 9, 2026

Go OffCourse helps a small invited group choose where to eat and remember their visits. This policy explains how MZ Technology Solutions LLC handles information in the pilot app and on getoffcourse.app.

For privacy questions or an account or data-removal request, email matt@mattzimmerman.io. Please do not include your password or a sign-in or password-reset link.

InformationGroups & photosVoice recapsLocation & GoogleYour choices

What the app handles

We use this information to run the app, keep the correct account and group in sync, support your requests, protect access, investigate problems and manage the pilot's usage limits. The pilot has no ads, advertising trackers or purchases.

Who can see your memories

Personal-workspace restaurants and visits are restricted to your account. Records saved in a group are shared with that group's authorized members. Your personal cuisine preferences stay with your account; switching groups does not copy another group's visits, spending or notes into the new group.

Group members can see identifying profile information, including names, email addresses and any profile picture. Decision participants can see progress and the result. Own-phone voting does not reveal another participant's individual ballot. In pass-phone mode, the organizing phone records the named participants' choices, so its user can access those entries.

Restaurant covers, visit photos and dish photos you upload use private storage and the account or group access of the related record. Leaving a group removes your access to its shared records, but does not itself delete those records for the people who remain. Authorized service administration also supports maintenance and troubleshooting.

Profile pictures are different: the current pilot serves them through publicly accessible image links. Anyone who has a profile-picture link may view that image. Choose a picture you are comfortable sharing this way, or leave it unset.

Only upload photos and information you have permission to share. Group members may save or share information they can see outside the app; OffCourse cannot control those copies. There is no public discovery feed or public list-sharing feature in this pilot.

Optional voice recaps

When enabled for your pilot account, you can record a visit recap of up to two minutes. Microphone permission is optional, and recording starts only when you choose it. Leaving the app stops recording. You can keep entering visits manually without using voice.

Stopping a recording does not send it for AI processing. If you choose Create draft, our Supabase service sends the recording to OpenAI for transcription, then sends the transcript and limited context, such as the date you recorded it, to OpenAI to suggest visit details. We do not send your other visits, group ballots or full dining history for this feature. Review and correct the suggestions before applying them to your draft and saving the visit.

Pending recordings and recap results are kept in the app's private device storage, separated by account and workspace. They expire after 24 hours and are cleared when the app next checks them. Applying or discarding a recap, or signing out, also starts local cleanup. OffCourse does not keep uploaded audio in server file storage. A private server cache retains the transcript and suggestions for up to 30 minutes so an interrupted request can retrieve its result; expired results are scheduled for removal every five minutes. Minimal request identifiers, hashes and usage reservations remain to enforce limits and prevent duplicate processing.

OpenAI processes API content on our behalf and does not use it to train models by default. Its audio-transcription endpoint currently lists no retained application state or abuse-monitoring logs. Text processing has different retention: standard abuse-monitoring logs can retain content for up to 30 days, subject to stated exceptions. We disable stored Responses API results, but this does not eliminate provider abuse-monitoring or applicable temporary caching. See OpenAI's API data controls and retention details.

Once you apply and save a recap, its transcript becomes part of your visit notes and follows the personal or group access of that visit. Record your own summary, with permission for any other person's information you include. Do not use this feature to secretly record conversations. You can revoke microphone permission in your phone's settings.

Location, restaurant search and Google

When enabled for your pilot account, Google Maps Platform provides maps, restaurant search, current place details and default restaurant photos. A nearby search sends the chosen coordinates and search area through our server to Google. Typed searches send what you enter, including an area or restaurant name. Detail and photo requests send the relevant Google place or photo identifier.

Location permission is optional. You can type an area instead. OffCourse requests location while you use a location feature; it does not request background location or build a continuous location history. You can change permission in your phone's settings.

The map and provider images also connect your device to Google. Google can receive technical information such as your IP address, device information and the content requested. We do not add your OffCourse account email, private notes, group ballots or cuisine preferences to Google search or photo requests.

Google place facts and photos are loaded for temporary display and may expire or become unavailable. We keep saved place identifiers and your own dining records separately. Google photos are not added to your private uploaded-photo collection. Your own cover photo can replace the default shown in OffCourse without changing Google's listing.

The Google Privacy Policy applies to Google's processing and is incorporated here for Google-powered features. See also the Google Maps Additional Terms. Google Maps and contributor credits identify provider content in the app; they do not mean that Google can read your private dining notes.

Services that help run the pilot

Supabase hosts authentication, the app database and uploaded files on our behalf. See Supabase's privacy notice and data-processing terms. Vercel hosts this website and may process website request information for delivery and security; see Vercel's privacy notice.

Apple TestFlight distributes the iPhone pilot and processes installation, diagnostic and feedback information under TestFlight & Privacy. Feedback you choose to send through TestFlight can be made available to us.

Service providers may process information in the United States and other places where they operate. We may also disclose information when needed to comply with applicable law, respond to lawful requests, or protect people and the service.

On your device and this website

The app keeps sign-in state, settings and some drafts or pending actions on your device so you can resume work. Images you choose or capture may also remain in your device's photo library. Camera or photo access is requested when needed for the action you choose.

This website stores your Light, Dark or System appearance choice in browser storage. It has no account-signup or payment form and loads no advertising or analytics scripts. The password-reset page helps you open the installed app; it is not a website account-management area.

Your choices and removal requests

You can change your profile and cuisine choices, edit records where the app permits, remove an uploaded cover, leave groups and change phone permissions. To request access to, correction of or deletion of account information, contact matt@mattzimmerman.io. We may need to verify account ownership and discuss how a request affects shared group records.

Signing out or deleting the app from your phone does not delete hosted records. A decision round or discovery allowance ending does not automatically erase your dining history. Removing or resetting a cover stops its use as that restaurant's cover; it does not promise immediate erasure of every underlying file or backup.

Account deletion does not establish that all uploaded files, shared information, backups and technical logs have been removed. Contact us for help with a complete removal request. Retention depends on the information, its use in shared records, service-provider backup and log handling, and applicable legal requirements. We do not promise a fixed deletion or support turnaround during the pilot.

Pilot scope and changes

This pilot is intended for invited adults in the United States. Optional AI voice recaps may be enabled for selected accounts within a limited allowance. The pilot does not include AI restaurant recommendations, automated receipt reading or gift-card tracking. Contact us if a child has supplied personal information or if you believe information was shared without permission.

We will update this page as the pilot's data practices change. The date above identifies this version. Review the pilot terms for use of the service and support page for help.