Privacy

What we store, and what we don't

One form, six fields, no cookies, a page counter that cannot tell who you are, and one short function of ours in between that keeps nothing. The answer is short; this page is longer than the answer because saying exactly what happens takes more words than doing very little does. If the answer ever stops being short, this page changes before the practice does.

cookieless analytics no cookies no company we haven't named no database, no CRM deletion on request invoices kept as law requires

Last updated 4 August 2026. Written in plain English on purpose, and describing what the site actually does rather than what a template assumed it might. Every service that touches your message is named below.

The access form is the whole of it

There is nothing to sign into on this website and no other place on it that asks you for anything: the beta itself is something you request, and we set it up with you. If you don't submit the form, we have no record that you were here.

Every field, and why it's there
/#access6 fields + one tick
Your nameso a reply isn't addressed to an inbox
Emailthe only way we can answer
Company · optionalcontext for the reply
Where is it today? · optionalwhether a build helps you now
What would you build first?the actual reason for the form
Anyone asking you hard security questions? · optionalwhich of our limits matter to you
That you ticked the terms box, and whenso we both hold the same record

Three of the six are optional and the form works without them. We ask for a work email rather than a personal one because the conversation is a work conversation, not because we're building a profile.

The last row is the only thing on this list you don't type. Ticking the box before you send writes one line into the message: what you accepted, and the time you accepted it, so the record of your agreement sits in your sent folder as well as our inbox. That is the entire reason it exists, and it is not used for anything else.

What we'd rather you didn't send

The brief field invites you to describe an application, and people are generous with detail. Shape is enough. We don't need your schema, your customer names, your incident history or anything under an NDA to tell you whether a build is worth an hour of your time.

If a real conversation needs that detail later, we'll do it properly, under an agreement, not in a text box on a landing page.

Where it goes, named

"Trusted third parties" is not a list. These are the only services that touch what you send, and we'd rather name them than let the phrase do the work.

the form

One hop, and it's named

Pressing Request access posts what you typed to a short function of our own on Cloudflare, which does one thing: hand the message to Resend (Resend, Inc.) to deliver as an email, then forget it. It writes nothing down: no database, no queue, no CRM, no spreadsheet, and no copy kept on the way past. Resend holds it for as long as its own delivery log runs, and that is the whole journey. The form is gated by Cloudflare Turnstile, described below, which answers our function with one word, pass or fail, and no score, no profile and nothing about you attached.

the reply

Our mailbox

What arrives is an ordinary email in a founder's inbox on Zoho Mail, run by Zoho Corporation, which publishes its own privacy and data-processing terms. Once it lands, that is where it stays: it is not synced into a CRM, an enrichment tool, a sales sequencer or a shared spreadsheet. If you write to us directly instead of using the form, your own provider and ours are the only two in the path, and Resend is not one of them.

the page

The host

Serving a page produces a server log (IP address, time, path, user agent) held briefly by Cloudflare (Cloudflare, Inc.), the host that serves this page, for its own security and abuse handling, under its retention policy rather than ours. We do not read those logs, nothing joins them to an email you sent us, and the page counter described below runs beside them rather than on top of them. The one piece of our own code in the path is the form function above, which runs on the same host. Our DNS is operated by Spaceship, which sees lookups for the domain and nothing else.

How long we keep it

Twenty-four months from the last time we spoke, then the thread is deleted. A beta is a long conversation and we would rather not ask you the same questions twice, but "as long as it's useful" is not a retention period, so here is a number instead.

If you tell us you're not interested, that's the end of it and the thread goes sooner. We don't keep a list to revisit in six months.

Twenty-four months covers the conversation. It does not cover an invoice. If you've paid us, the payment record is kept for as long as tax and accounting law requires, which is years. It is the one piece of this page we don't control, and it is spelled out again next to the deletion promise so nobody meets it by surprise.

Getting it deleted

Email hello@oceantic.dev and say so. There is no form for this and no retention team to escalate through: the person who read your message is the person who deletes it. We'll confirm when it's done.

One thing that request cannot reach: if you've paid us, the invoice stays. Tax and accounting law sets how long, it is measured in years rather than months, and no company gets to waive it for you. Everything else about you goes, and we'll tell you exactly what was kept and why.

What this site does not do

Most of this page is about the form because the form is the only thing that collects anything about you. One page counter runs alongside it and cannot tell who you are. Everything else on the site is inert.

the counter

It counts pages, not people

One thing measures this site: Cloudflare Web Analytics, which counts page views and how quickly pages load. It sets no cookie and asks your browser for no identifier, so there is nothing for us to join up and nothing that follows you to another site. What we see is a number of views by page and country, never a person and never a session to replay. No tag manager, no tracking pixel, no session recorder, no heatmap, no chat widget, and no advertising network.

no cookies

One key, and it's yours

This site sets no cookies, which is why you were never shown a consent banner. The only thing written to your browser by us is your light/dark choice, under oceantic-theme in localStorage, when you click the sun or moon. Clearing site data removes it and nothing breaks. The page counter sets nothing at all, and the Turnstile check keeps whatever it needs inside its own frame on Cloudflare's domain, under Cloudflare's terms rather than ours, where we can neither read it nor join it to anything.

no third parties

The page loads from here

Type is self-hosted rather than pulled from Google Fonts, and there is no embedded video, external stylesheet, tag manager or third-party script. The page itself is served by Cloudflare, from its content delivery network, because every static host is one, so loading this page tells nobody but Cloudflare that you read it. Two things load from another address, and both are Cloudflare's: the Turnstile spam check on the two forms, from challenges.cloudflare.com, and the page counter, from static.cloudflareinsights.com. Different hosts, the same company, and no new name on the list. The rule that permits exactly those two is written into _headers in the open, and it permits nothing else.

Why we're allowed to hold it

Every privacy page has to say what entitles it to keep your details. Ours is short: you emailed us to ask a question, and we kept the email so we could answer it.

the basis

A reply you asked for

We hold what you sent on the basis of a legitimate interest in answering a request you started, and in the steps leading up to a possible working relationship. You wrote to us first, and the only thing we do with it is write back. If you go on to buy a paid package, what we hold for that is held to perform a contract with you, and the invoice behind it, to meet a legal obligation. If you disagree with any of it, that is what the objection right below is for.

entirely optional

Nothing here is required of you

No law and no contract obliges you to send us anything, and three of the six fields are optional. The only consequence of not sending it is that we cannot reply. Nothing on this site is withheld, and nothing degrades, because you left a box empty.

no machine decides

A person reads it

There is no automated decision-making and no profiling. Nobody is scored, ranked or filtered by software to decide whether they get a reply. We also don't buy lists, enrich what you send against a data broker, or infer anything about you from anywhere else: what we know is what you typed.

not for children

This is a tool for people building software at work, it isn't directed at children, and we don't knowingly collect anything from anyone under 18. If you believe a child has sent us something, mail hello@oceantic.dev and we'll delete it without asking you to prove anything.

Your rights, and who to ask

You gave us this because you wanted an answer about beta access. That's the basis we hold it on, a legitimate interest in replying to a request you started, and it's the only thing we use it for.

What you can ask for
hello@oceantic.devno ticket system
a copy of everything we holdask
a correction to anything wrongask
deletion, bar invoices we must keepask
us to pause while a question is settledask
an objection to us holding it at allask
a copy in a portable formatask
to stop hearing from usask
to complain to a regulatoryour local authority

One email does all eight. We'll answer within 30 days at the outside and usually the same week: there is no queue to join and no identity-verification process to survive first. Complaints go to the data protection authority where you live; once Oceantic is registered we'll name our own regulator here too.

Who is responsible

Oceantic is an unincorporated venture operated by its founders, and until it is registered the founders are personally the people answerable for anything you send. There is no exemption in this for being small or being early: the duties on this page apply to the people doing the processing, and we are those people.

The contact point for every one of them is hello@oceantic.dev, which reaches a founder rather than a queue. Ask for the registered name and address of the individual responsible and we'll give it to you. We'd rather answer that on request than publish a home address on a marketing site.

There is no data protection officer to route you to, and at this size no requirement to appoint one. When Oceantic is incorporated the company becomes the responsible party in place of the founders, this page is re-dated the same day, and the entity's name and registered address appear here. Nothing described on this page gets weaker in that handover.

the part people skip

None of this covers the application you build with it. That is generated by the compiler and lands as ordinary files on your machine; there is no Oceantic runtime in your production and the running application makes no call back to us, so your users' data is never ours to describe. Your brief is yours. We treat it as confidential, and if you need that on paper before you send it, ask and we'll sign something.

Keeping it safe, and telling you if we don't

The best security control on this page is how little there is to secure. There is no database of yours to breach, because we never built one: what exists is email, and a page that is the same file for everybody who loads it.

how it's held

Two-factor and a short list of people

Mail accounts that can read your message are protected with two-factor authentication, and the list of people with access is the founders. The site is served over HTTPS only, with a strict content security policy that forbids it loading anything from anywhere but the two Cloudflare hosts named above, which is also why the claim is enforced by the server rather than just promised here.

if it goes wrong

You hear it from us

If something you sent us is exposed and there is a real risk to you, we will email you directly and tell you what happened, what was in it, and what we did, and notify the relevant regulator where we're required to, within the 72 hours the usual standard allows. We would rather tell you about a small one than have you find out about a large one.

where it sits

Crossing borders

Email is international by construction: a message you send may be stored on servers in a country other than yours, and the same is true of the host serving this page. Where that happens we rely on the safeguards those providers publish for such transfers. Nothing is sent to a country because we chose to move it there, and we don't sell, rent or share it with anyone.

When this page changes

The date at the top changes with it, and the practice never changes before the page does, and that ordering is the whole point of the sentence in the header. If a change is material, whether a new processor, a new purpose or a longer retention, we email the people who have written to us rather than quietly editing the page and hoping.

Everyone who touches it, in one line

Cloudflare, Resend, and Zoho Mail. That is the complete list, not a representative sample, and not the start of one. Cloudflare serves the page, runs the one function we wrote and answers the spam check; Resend carries the message as email; Zoho holds it in the inbox. Nobody else is in the path, and nothing is stored between those three.

Buying a paid package does not lengthen it by itself: how you pay is agreed with you per package, and where that brings in anyone new, a payment provider or an accountant, they are named here before they touch anything, on the day they are added rather than in an update nobody reads.