Otto

Privacy Policy

Effective date: August 20, 2026

Last updated: August 20, 2026

This Privacy Policy explains how Otto ("we," "us," or "our"), the operator of the Service, collects, uses, stores, shares, and protects your personal information when you use the Otto AI assistant service. By using the Service, you agree to the practices described in this policy.

1. Information We Collect

1.1 Account Information. When you register for Otto, we collect your name, email address, and a hashed version of your password. We do not store your password in plain text — it is hashed using bcrypt before being stored.

1.2 Profile Information. You may optionally provide additional profile information such as a display name, timezone, or preferences. This information helps Otto personalize its responses.

1.3 Conversation Data. We store the messages you send to Otto and the responses Otto generates. This history is used to maintain context across sessions so Otto can reference prior conversations and provide more relevant assistance. You can delete conversation history at any time; deleted items sit in Trash for 30 days before they are permanently removed.

1.4 Memory Data. Otto's memory system allows the AI to save facts, preferences, and notes about you that you instruct it to remember (e.g., "remember that I prefer bullet points"). These memories are stored in our database and associated with your account. You can view, edit, and delete all memories from Settings → What Otto Knows.

1.5 Task and Routine Data. We store tasks you create and schedules/automations ("Routines") you configure, including their prompts, schedules, and execution history.

1.6 Integration Credentials. When you connect third-party services, we receive and store OAuth access tokens and refresh tokens. These tokens are encrypted using AES-256 encryption at rest. We use them solely to access the connected services on your behalf, when you direct Otto to do so.

1.7 Content from Connected Services. When Otto accesses connected services on your behalf (e.g., reads your email, checks your calendar), the content it retrieves is used to generate a response and is then saved as part of that conversation or routine record, so the exchange still makes sense when you return to it. In practice this means the text of emails, events, and documents Otto reads for you is stored in our database as part of your conversation history. We keep it for as long as you keep that conversation: deleting the conversation, the routine run, or your account deletes it.

1.8 Usage Data. We collect information about how you use the Service, including: features accessed, commands sent, message counts, session duration, and error logs. This data is used for billing, abuse prevention, and product improvement.

1.9 Device and Technical Data. When you access the Service we automatically record your IP address (used for security and rate limiting, and stored once with your consent record), your browser's user-agent when you sign in or when a page reports an error, a coarse device type (desktop, mobile, tablet, or extension), the pages you visit within Otto (path only, never query strings), and the site that referred you. This data is used for security, fraud prevention, and analytics.

1.10 Log Data. Our servers automatically record log data when you use the Service, including the date and time of requests, request details, and server response codes. Server logs are held by our hosting provider under its own retention schedule, typically under 30 days; we do not control that window. Inside Otto, records of the actions Otto took for you and usage and analytics events are kept for up to 180 days, and routine run history for up to 90 days, after which a scheduled job deletes them.

1.11 Cookies and Local Storage. We use session cookies to maintain your logged-in state. We use local storage for UI preferences (e.g., dark/light mode). We do not use tracking cookies or third-party advertising cookies. You can control cookies through your browser settings, but disabling session cookies will prevent you from logging in.

1.12 Legal Consent Records. When you agree to our Terms of Service and Privacy Policy, we record the timestamp, the version of the documents you agreed to, and your IP address at the time of agreement. This record exists for legal compliance; it is removed with the rest of your data when you delete your account.

1.13 Payment Information. If you subscribe to a paid plan, payment information (credit card numbers, billing address) is collected and processed by Stripe, our third-party payment processor. We do not receive or store your full credit card number. We receive only a payment token and basic billing details from Stripe.

1.14 Meeting Recordings. If you send Otto’s notetaker into a meeting, an audio recording of that meeting exists — audio only, never video — for as long as it takes to produce your transcript. The recording is created and held by Recall.ai on our instructions, not on our own systems, and Otto has it deleted once the transcript is saved. Section 4 describes exactly how this works and Section 7 describes exactly how long the recording lives.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the Service: Processing your requests, executing actions on connected services, maintaining conversation context, and running scheduled routines.
  • Personalization: Using your memories, preferences, and history to make Otto's responses more relevant and useful to you specifically.
  • Account management: Managing your account, processing payments, sending transactional emails (account confirmations, password resets, billing receipts), and enforcing plan limits.
  • Security and fraud prevention: Detecting, investigating, and preventing fraudulent transactions, abuse, and violations of these Terms.
  • Product improvement: Analyzing aggregated, anonymized usage patterns to improve the Service. We do not use individual conversation content for this purpose.
  • Legal compliance: Complying with applicable laws, regulations, and legal processes, including responding to lawful requests from public authorities.
  • Communications: Sending you service-related announcements, updates, and — with your consent — product news. You can unsubscribe from marketing communications at any time.
  • Support: Responding to your inquiries and providing customer support. Support staff may access limited account information to resolve your issue, only with your knowledge.

3. Google API Data — Limited Use Policy

This section is required by Google's API Services User Data Policy and describes exactly how we handle data obtained through Google APIs.

What we access. When you connect your Google account, Otto may access the following, solely when you direct it to:

  • Gmail: read messages, send messages, create drafts, search email. (Otto does not request permission to modify your mailbox, so it cannot mark messages as read or archive them.)
  • Google Calendar: read events, create events, update events, delete events, find free time.
  • Google Drive: search files, read file contents, create folders, create documents and spreadsheets.
  • Google Docs/Sheets: read and append content to documents and spreadsheets you own or have access to.
  • YouTube: read-only access to your channel and video information, only if you choose to connect YouTube.

Limited Use compliance. Otto's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide or improve user-facing features that are visible and prominent in the Otto interface.
  • We do not transfer Google user data to third parties except as necessary to provide the Service (e.g., transmitting to the AI model to generate a response), and only with your explicit direction.
  • We do not use Google user data for advertising, including retargeting, personalized advertising, or advertising-related analytics.
  • We do not allow humans to read your Google user data unless you have explicitly consented, or we are required to do so for security or legal compliance, or it is strictly necessary for technical support and you have affirmatively requested it.
  • We do not use Google user data to build user profiles for purposes unrelated to providing the Service.
  • We do not sell Google user data under any circumstances.

Storage of Google data. OAuth access and refresh tokens are stored encrypted in our database. When Otto reads an email, calendar event, or file to answer you, the content it read is saved as part of that conversation or routine record, so the answer still makes sense when you come back to it later. That means the text of emails Otto has read for you is stored in our database, up to roughly the first 6,000 characters of each message. It is your record: you can see it in the conversation, and it is deleted when you delete that conversation, that routine run, or your account. For email triage — the automatic sorting of your inbox — Otto stores only short metadata about recent threads: sender name and address, subject line, the category Otto assigned, and a one-line note explaining why. You can see and correct these, and deleting your account deletes them.

Records Otto derives from your mail. To do its job, Otto keeps a small set of its own records built from your email and calendar: People entries (name, email address, phone, company and role where Otto can infer them, and notes you or Otto add), plus relationship statistics Otto calculates automatically from your message history — how often each side starts a thread, typical reply times, and whether contact is speeding up or slowing down. It also keeps commitments it detects (a short description of the promise, who it involves, and its due date), reply-watch entries (recipient and subject line of a message you're waiting on), and — when you approve a scheduled or drafted email — the outbound draft itself until it is sent. These are your records: they are visible in the product, editable, and deleted with your account.

People who are not Otto users. Some of those records describe other people — the contacts you email and meet. They are held on your behalf, and they are visible and editable by you. If a user sends Otto’s notetaker into a meeting you attend, your voice is briefly part of the recording and your words are part of the transcript — the notetaker joins visibly and announces out loud that it is taking notes before anyone’s words are kept, precisely so this never happens to you without your knowledge (§4). If you are not an Otto user and you believe an Otto user's account holds information about you — a contact record, a transcript of something you said, anything — email team.ottohq@gmail.com and we will locate it and delete it.

Chrome extension. The Otto browser extension works only on mail.google.com and calendar.google.com. It reads the email thread or calendar event you have open (and the Google account address shown in the page header, to warn you if it differs from the account connected to Otto), and sends that context to your own Otto account over HTTPS to power summaries, drafts, triage and meeting preparation — nowhere else. It is authenticated by a revocable per-browser credential that you approve on an Otto-hosted authorization page after a plain-language disclosure; nothing is read or sent before that approval. The extension never composes and sends mail silently: a reply it drafts lands in Gmail for you to press Send. If you tap Approve on a pending action in the extension panel, Otto's server carries out the action you approved, which can include sending that message. The extension has no access to other websites, your browsing history, or your Google password. Disconnect any browser in Settings → Chrome extension; disconnecting revokes its credential immediately.

Revoking Google access. You can revoke Otto's access to your Google account at any time by: (a) disconnecting the Google integration from Settings → Connections in Otto, or (b) visiting your Google Account Security settings at myaccount.google.com/permissions and removing Otto's access. Upon disconnection, we immediately delete the stored tokens.

4. Other Third-Party Integration Data

Otto’s notetaker (a bot that joins your meeting). You can send Otto’s notetaker into a Zoom, Google Meet, or Microsoft Teams meeting. It only ever goes where you send it, one meeting at a time — there is no ambient capture and no standing schedule. It joins as a visible participant with a name like “Otto — Notetaker (recording)”, records audio only — never video — and announces itself out loud before anyone’s words are kept — the announcement is the first thing in the recording, so the record proves the disclosure rather than merely claiming it. Anyone who joins late is told too, because they never heard the opening line: when someone new joins, Otto pauses the recording until they’ve been told, and resumes only then. If the announcement cannot be delivered into the meeting, Otto does not record — and afterwards Otto checks the transcript for the announcement itself, treating any meeting whose transcript lacks it as one where consent was never verified.

Where the notetaker’s recording lives, and for how long. The recording exists for one purpose: to produce your transcript. It is created and held by Recall.ai (Recall Technologies, Inc., listed in §5.7), on Recall’s servers in the United States, and Recall — not Deepgram — performs the transcription on this path. Once the transcript is saved to your account, Otto instructs Recall to delete the recording; a timed backstop deletes it automatically even if that instruction never lands. Deleting a meeting in Otto also deletes any recording still on Recall’s servers, and so does deleting your account (§7).

Platform honesty. The notetaker is subject to each platform’s own rules, so it does not work everywhere: a Google Meet host must admit Otto from the knocking screen before it can join, some Microsoft Teams organizations block outside notetakers entirely, and Zoom support depends on the meeting’s settings and often requires extra setup we haven’t shipped. When the notetaker cannot join, nothing is recorded — Otto tells you rather than working around the platform.

Recording in your browser. Separately from the notetaker, audio you record in your browser or upload is sent to Deepgram for speech-to-text and the resulting transcript is stored in your account, along with notes, summaries, decisions, and action items derived from it. Deepgram also separates the voices it hears, so the transcript can mark who spoke which line; it labels them only as “Speaker 1”, “Speaker 2” and so on, and any real names come from you typing them in. Transcripts naturally contain the words of other people in the meeting. You are responsible for making sure everyone being recorded has agreed to it — many places require the consent of all participants before a conversation may be recorded. Otto shows a reminder before recording starts. Transcripts are yours: you can delete any meeting, and deleting your account deletes them all.

We never train on your meetings, and we hold our vendors to the same line. Otto’s own systems store no audio at all — not on disk, not in our database — and we do not train any model on your meetings, transcripts, or notes. What is new: when the notetaker joins a call, Recall holds the recording on its servers until your transcript is saved, then Otto has it deleted, with a timed backstop either way. Recall’s standard data-processing terms restrict it to processing recordings only to provide the service — not for its own purposes, and not to train models. Deepgram runs a Model Improvement Program under which it may otherwise retain customer audio and train its speech models on it; Otto sends an explicit opt-out on every single transcription request, live and uploaded, and pays a higher per-minute rate as a result.

What we can and cannot promise about that. We would rather be precise than reassuring. The opt-out we send applies to each individual request, and Deepgram’s standard terms separately reserve a broad right to use customer content for model training. We are seeking a signed agreement with Deepgram that removes that right for your audio; until we have one, what we can honestly promise is that Otto sends the opt-out on every request without exception, and that Otto never trains on your content itself. Separately, if a live meeting falls back to your browser’s built-in speech recognition (see above), that audio reaches your browser vendor under their terms, which we neither control nor can opt you out of.

Backup transcription uses your browser, which sends audio to its maker. If Otto cannot reach Deepgram during a live meeting, it falls back to the speech recognition built into your browser so the meeting is not lost. That fallback is not Deepgram and is not a sub-processor we control: your microphone audio is sent to your browser vendor — Google for Chrome, Apple for Safari — and is handled under that vendor’s own privacy policy, not ours. The fallback produces no speaker separation. Otto tells you on screen which engine is running and announces the switch when it happens, so you can stop recording if you would rather not use it.

Dictation (speaking to Otto instead of typing). The microphone buttons used to dictate a message or a quick note also use your browser’s built-in speech recognition, so that audio likewise goes to your browser vendor under its own privacy policy. Otto stores the resulting text, not the audio. Neither Otto nor Deepgram receives dictation audio.

Slack. When you connect Slack, Otto can read messages from channels and direct messages you authorize, and send messages on your behalf. We store your Slack OAuth token encrypted. We do not mirror or index your Slack history; the messages Otto actually reads to answer you are saved in that conversation record, as described in §1.7.

Notion. When you connect Notion, Otto can read and write pages and databases you authorize. We store your Notion OAuth token encrypted.

Other OAuth connections. Otto can also offer optional OAuth connections such as Spotify, Discord, and Instagram (availability varies). The same rules apply as for Slack and Notion: you grant access explicitly, the token is stored encrypted, Otto uses it only when you direct it to, and disconnecting revokes it.

Other integrations. For API-key based integrations, you provide an API key which we store encrypted. We use the key solely to make requests to that service when you direct Otto to.

General principle. For all integrations: we access only what is necessary to complete your request, we store credentials encrypted, we do not share your integration data with other users, and you can disconnect any integration at any time.

5. How We Share Your Information

We do not sell your personal information. We do not share your personal information with third parties for their marketing purposes. We share information only in these limited circumstances:

5.1 AI model providers. When you send a message to Otto, the content of that message (and relevant context from your conversation history and memories) is transmitted to Anthropic's Claude API to generate a response. Anthropic processes this data subject to their own privacy policy and Terms of Service. We do not send your Google/Gmail/Slack content to Anthropic unless it is directly relevant to fulfilling your request.

5.1a If you choose a non-Anthropic model. Otto lets you pick other AI models, routed through OpenRouter. If you do, the same context Otto would give Claude goes to that model instead: your name and email, relevant memories and open tasks, and your conversation history — which can include Gmail or Calendar content Otto fetched earlier in that conversation. Every request carries OpenRouter's do-not-collect flag. Precisely what that flag does: it restricts routing to model providers whose policies forbid collecting or training on prompts — it governs who may receive the request, and is not a promise from OpenRouter about its own systems, which operate under OpenRouter's own privacy policy. We would rather describe the mechanism exactly than imply a stronger promise than the flag makes.

5.1b Automatic backup processing. If Anthropic is unavailable, some Otto features retry through OpenRouter (with the same do-not-collect instruction) so the product keeps working. Your Gmail and Calendar content is excluded from this: features that process email or calendar content (inbox triage, reply watching, commitment extraction, meeting follow-up drafts, the browser extension's email tools) never fail over to a second provider — they wait for Anthropic instead. If a chat conversation is rerouted during a full outage, any content Otto previously read from your email, calendar, or web pages is withheld from the backup model. Features that don't involve Google content (for example meeting-transcript analysis or dictation cleanup) may use the backup.

5.1c Search embeddings. To power memory search and meeting search, Otto computes text embeddings of your saved memories (titles and notes, which can summarize facts learned from your email) and of your meeting notes (titles, summaries, and the note text Otto wrote — not the raw audio) through OpenRouter, with the same do-not-collect instruction. Embeddings are stored only in our own database.

5.2 Infrastructure providers. We use Railway for hosting and deployment. Railway hosts the database and the application, so your data resides on their infrastructure; access is restricted to the operator's account and to Railway's own personnel under their terms.

5.3 Payment processing. Stripe processes payments. They receive your payment card information and billing details. We do not receive or store full payment card information.

5.4 Legal requirements. We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, prevent fraud, or protect the safety of any person.

5.5 Business transfers. If the Service is ever transferred to another operator, your information may move with it. We will notify you before your information is transferred and becomes subject to a different privacy policy.

5.6 With your consent. We may share your information for any other purpose with your explicit prior consent.

5.6a Links you choose to share. Otto lets you create an unlisted link to a conversation or to a meeting's note document. Anyone who has the link can read that content — no Otto account required — until you revoke it. Meeting links include the written note only (title, date, summary, notes, decisions, and action items); they never include the recording, the transcript, the attendee list, attachments, or your private jottings. Share links are long random URLs that cannot be guessed, are marked so search engines do not index them, and can be revoked from the shared item at any time; revocation takes effect immediately. You are responsible for who you give a link to while it is active.

5.7 Sub-processors. The following third parties process personal data on our behalf to operate the Service. We select providers that publish data protection commitments and act as processors on our instructions. We do not currently hold a signed data processing agreement with every provider on this list, and we would rather say so than imply otherwise; obtaining them is work in progress and we will update this section as each is in place. All are located in the United States except where noted in the list below.

Anthropic, PBC

AI model provider — processes message content and relevant context to generate responses (Claude)

OpenRouter, Inc.

AI model routing — processes content when you select a non-Anthropic model, as automatic backup for non-Google content (§5.1b), and for memory-search embeddings (§5.1c); always with a do-not-collect instruction

Deepgram, Inc.

Speech-to-text — processes meeting audio you record or upload in your browser to produce transcripts, including separating one voice from another (§4)

Recall.ai (Recall Technologies, Inc.)

Meeting notetaker — when you send Otto's notetaker into a Zoom, Google Meet, or Microsoft Teams call, Recall joins it, records the audio (never video), transcribes it, and holds the recording on its servers in the United States only until the transcript is saved, when Otto has it deleted (§4, §7)

ElevenLabs, Inc.

Voice generation — processes short text snippets when you use Otto's spoken responses

Stripe, Inc.

Payment processing — handles card details and billing; we never receive full card numbers

Railway Corp.

Cloud hosting and infrastructure — stores the application database and server logs

Resend (Plus Five Five, Inc.)

Transactional and marketing email delivery

Postmark (ActiveCampaign, LLC)

Inbound email processing — receives messages you send or forward to your Otto address

Pipedream, Inc.

Managed third-party connections — if you connect an app through Otto's connector marketplace, Pipedream holds that app's authorization and relays the API calls Otto makes on your behalf

Telegram FZ-LLC

Message delivery — if you connect Telegram, Otto's bot delivers your briefs and alerts there, which can include email and calendar content from those briefs. Telegram is based outside the United States

Fastlane (usefastlane.ai)

Website visitor analytics on our marketing site (ottohq.app) — aggregate traffic data, not account data. Fastlane runs on Convex, Inc. hosting, so the analytics endpoint your browser talks to is a convex.site address

Otto operations monitor (self-hosted)

Receives operational error summaries, in-app feedback you submit (including your email address), and support email sent to Otto's own address, so we can fix failures and reply

If you connect optional integrations (e.g., Google, Slack, Notion, Telegram), those providers also receive data as needed to fulfill the requests you direct Otto to make. We update this list when we add or remove a sub-processor; material changes are communicated as described in the "Changes to This Policy" section. To request advance notice of sub-processor changes, email team.ottohq@gmail.com.

Not on this list, but it receives your voice: your own browser. When you dictate, or when a live meeting falls back to the browser’s built-in speech recognition (§4), the audio goes from your device to your browser vendor — Google for Chrome, Apple for Safari. That happens between you and software you installed, so those vendors are not our sub-processors and we have no agreement with them covering it, but you should know it happens. It is listed here rather than hidden because the effect on your privacy is the same either way.

Also not on this list: the meeting platform. When Otto’s notetaker joins a call, your voice reaches Recall (listed above) by way of the meeting platform — Zoom, Google, or Microsoft — which relays the call’s audio to the notetaker the same way it does to every other participant, under the platform’s own terms. You chose the platform, not us, so it is not our sub-processor — but on the notetaker path it is part of how your voice travels, and you should know that.

6. Data Security

We implement and maintain technical and organizational security measures designed to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:

  • AES-256 encryption for OAuth tokens and API credentials at rest;
  • bcrypt hashing for passwords with appropriate cost factors;
  • TLS/HTTPS encryption for all data in transit;
  • Session tokens with expiration and rotation;
  • Production database access restricted to the operator and protected by unique credentials;
  • Dependency updates and security reviews before significant releases;
  • Rate limiting and abuse detection systems.

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.

7. Data Retention

Active accounts. We retain your personal information for as long as your account is active. Conversation history, memories, and task data are retained indefinitely until you delete them, as they are core to the Service's functionality.

Items you delete inside Otto. Conversations, memories, tasks, routines, and meetings you delete move to Trash, where you can restore them for 30 days. After 30 days a scheduled job removes them permanently.

Meeting recordings (notetaker). A recording made by Otto’s notetaker is the shortest-lived thing in this section, on purpose. It lives on Recall’s servers (§4, §5.7) only until your transcript is saved, at which point Otto instructs Recall to delete it; a timed backstop deletes it automatically even if that instruction never lands. Deleting a meeting in Otto also deletes any recording still on Recall’s servers — that deletion does not wait out the 30-day Trash window, because a recording of other people’s voices should not sit on a vendor’s disk while a note document sits in Trash. Deleting your account does the same.

Deleted accounts. When you delete your account, all associated personal data — including account information, conversations, memories, tasks, integration tokens, and routines — is permanently deleted from our systems within 30 days. Where a vendor holds data for us, deletion reaches there too: account deletion instructs Recall to delete any meeting recording still on its servers.

Backups. Deleted data may remain in database backups for up to 60 days before being purged from backup systems. Those backups live on our own infrastructure with restricted access; they are compressed rather than separately encrypted.

Logs and activity records. Records of actions Otto took for you, and usage and analytics events, are kept for up to 180 days. Routine run history is kept for up to 90 days. Server and platform logs are held by our hosting provider under its own retention schedule, typically under 30 days.

Security events. A dedicated security log records sign-ins and failed sign-ins, password changes, session revocations, data exports, account deletions, and administrative actions, together with the IP address and browser information of the request. These records exist to investigate account compromise and abuse, and are kept for up to 400 days, then deleted automatically. Your entries are removed immediately if you delete your account.

Payment records. Billing records are retained for 7 years as required by financial regulations.

8. Your Rights

Depending on your location, you may have certain rights regarding your personal information. We honor these rights for all users, regardless of jurisdiction:

Right to access. You can access most of your personal data directly within the Service (conversations, memories, tasks, integrations). You may request a full export of your data by emailing team.ottohq@gmail.com.

Right to rectification. You can update your name and email from the Settings page. For other corrections, contact us at team.ottohq@gmail.com.

Right to deletion ("right to be forgotten"). You can delete your account from the Settings page, which initiates permanent deletion of all your data within 30 days. You can also delete individual conversations, memories, and tasks directly from the app.

Right to data portability. You may request an export of your data in a machine-readable format by emailing team.ottohq@gmail.com. We will fulfill this request within 30 days.

Right to withdraw consent. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.

Right to object / restrict processing. You may object to certain processing activities or request restriction. Contact us at team.ottohq@gmail.com to exercise these rights.

CCPA rights (California residents). California residents have the right to know what personal information we collect, the right to delete personal information, the right to opt out of sale (we do not sell data), and the right to non-discrimination for exercising these rights.

To exercise any of these rights, contact us at team.ottohq@gmail.com. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests.

9. Children's Privacy

The Service is intended for adults and is not directed to children. You must be at least 16 years old to create an account and use Otto.

COPPA (United States). Otto complies with the Children's Online Privacy Protection Act (COPPA). The Service is not directed to children under 13, and we do not knowingly collect, use, or disclose personal information from any child under 13. We do not knowingly create profiles of, or serve content to, children under 13. If we discover that we have inadvertently collected personal information from a child under 13, we will delete that information as quickly as possible and terminate any associated account.

We also do not knowingly collect personal information from minors aged 13 to 15. If we learn that a user is under 16, we will delete their information promptly.

If you are a parent or guardian and believe that a child under 13 has provided us with personal information, please contact us immediately at team.ottohq@gmail.com and we will take steps to delete it.

10. International Transfers and European Privacy Rights

Otto is operated from the United States. If you are located outside the United States, your information is transferred to, stored, and processed in the United States, which may not give it the same legal protection as your home country.

What makes that transfer lawful today. We currently rely on your agreement to this policy, given when you create your account, together with the data protection commitments our providers publish. That is a thinner basis than we want. We are putting data processing agreements incorporating the European Commission's Standard Contractual Clauses in place with each provider listed in §5.7, and we will name them here once they are signed.

Our lawful basis, purpose by purpose.

  • Contract — running the Service: answering you, carrying out the actions you ask for, running your routines, and maintaining your account.
  • Consent — the optional things you switch on: connecting a third-party service, recording and transcribing meetings — including sending Otto’s notetaker into a call, where a third party (Recall.ai, §4 and §5.7) records the voices of people in the meeting after the notetaker announces itself out loud — push notifications, and marketing email. You can withdraw consent at any time by turning the feature off, disconnecting the service, or emailing team.ottohq@gmail.com.
  • Legitimate interests — keeping the Service secure, preventing abuse, and measuring aggregate product usage so we can improve it. Our interest is operating a service that works and is not abused. You can object at team.ottohq@gmail.com and we will honor it.

Automated decisions. Otto sorts your inbox into categories, flags what looks like a commitment, and drafts replies, all automatically. None of this produces a legal or similarly significant effect on you, and nothing Otto drafts is sent without your approval. You can correct any classification in the product, and you can ask a person to review one by emailing team.ottohq@gmail.com.

Complaints. If you are in the EEA, the UK, or Switzerland, you have the right to lodge a complaint with your local data protection supervisory authority. We would rather you came to us first at team.ottohq@gmail.com, but you do not have to.

EU/UK representative. We have not appointed a representative under Article 27 of the GDPR. Otto is a private preview with a handful of users and is not marketed in the EEA or the UK. If that changes, we will appoint one and name them here.

11. Do Not Track

Some browsers transmit "Do Not Track" signals. We honor these signals for the Service (the logged-in Otto product) — we do not use tracking cookies or cross-site tracking there. Product analytics are based on aggregate usage data from our own systems, not third-party tracking.

Our public marketing site (ottohq.app) uses a third-party website analytics tool (Fast Lane, listed in §5.7) to measure aggregate visitor traffic — pages viewed, referral source, general location. This is not used for advertising, retargeting, or cross-site profiling, and it does not run inside the logged-in product.

12. Push Notifications

If you enable push notifications, we store your push subscription endpoint to deliver notifications from Otto (such as routine results, reminders, or alerts you have configured). You can disable push notifications at any time from your browser or device settings, or from the Settings page in Otto. Disabling notifications will cause us to delete your push subscription.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes we will show you the updated documents in the app and ask you to agree before you continue using Otto. The effective date at the top of this page always reflects the version currently in force.

If you do not agree to the updated policy, you can stop using the Service and delete your account from Settings. Your data remains yours to export or delete either way.

The version of this policy you agreed to at registration is recorded in our systems. If we make changes that require re-consent under applicable law, we will ask for your renewed agreement.

14. Contact Us

Otto is a private-preview project operated by an individual in the United States. It is not yet incorporated and is not offered commercially. For privacy questions, data requests, or a postal contact address, email team.ottohq@gmail.com — that mailbox reaches the person who operates the Service.

Otto — Privacy Contact

Email: team.ottohq@gmail.com

We aim to respond to all privacy inquiries within 5 business days.