Privacy Policy
Otto is an AI email assistant that operates your Gmail mailbox on your behalf. This policy explains exactly what data Otto accesses, what it stores, who it shares data with, and the rights you have over it. We collect as little as possible — we never store the full body or attachments of your emails, only the lightweight metadata needed to show your inbox.
1. Who we are
Otto (“Otto”, “we”, “us”) operates the Otto service at https://ottomail.app. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, we act as the data controller for the personal data described here. For privacy questions or to exercise any of your rights, contact us at privacy@ottomail.app.
2. Data we collect and store
We only collect what we need to run the service. The categories of data we store are:
- Account & identity
- Your Google account id, name, email address and avatar URL, obtained when you sign in with Google.
- Mailbox index (metadata only)
- So your inbox loads quickly and updates in real time, Otto stores lightweight message metadata — sender, recipients, subject, a short preview snippet, labels, dates and read/star flags. It never stores the full body or attachments of a message; those are fetched live from Gmail each time you open one. This index is kept until you delete your account.
- Google authorization tokens
- The OAuth access and refresh tokens that let Otto act on your mailbox on your behalf. They are held server-side only (never sent to your browser), encrypted at rest by our database provider, and kept only until you disconnect Google or delete your account.
- Assistant conversations
- Your chats with the Otto assistant. When you ask the assistant about an email, excerpts of that email (sender, subject, body text) become part of the conversation and are saved with it. Kept until you delete the chat or your account.
- Settings & prompt templates
- Your preferences (model, persona, signature, appearance) and any saved prompt templates.
- Mailbox change signals
- To deliver real-time updates we store your Gmail push-subscription state (your email address and a mailbox history cursor) and, when new mail arrives, log the message id — never its content — to ping your browser.
- Notification tokens
- If you turn on closed-tab or mobile notifications, we store the push subscription or device token for that device (web push, Apple APNs or Google FCM) so we can alert you to new mail. The alert is a content-free “new mail” signal. Removed when you turn notifications off or delete your account.
- Billing & subscription status
- Your plan tier, subscription status, billing cycle and the identifiers our payment providers (Paddle, RevenueCat) use to reconcile your subscription. We never store your card details — payment is handled by Paddle as merchant of record.
- Waitlist & email preferences
- If you join the beta waitlist or opt in to product updates, we store your email address, your marketing-email consent, and an unsubscribe token. We send product-update email only with your consent, and you can opt out at any time via the unsubscribe link in any such email. Kept until you unsubscribe or we close the waitlist.
- AI memory (only if you enable it)
- If you turn on Memory in Settings, Otto learns your writing voice: it keeps short samples of your own text from sent emails (never quoted replies) and distils them into a private style summary plus a few durable facts (e.g. your role, recurring contacts), stored as embeddings so the assistant can draft more like you. It is off by default, scoped to your account, never used to train any model, and you can clear it or turn it off at any time in Settings → AI → Memory (which deletes the samples, facts and style summary).
- Product-usage analytics
- Structural events about how you use Otto — which features you open, onboarding steps, errors you hit, device/platform, performance timings and subscription changes — tied to your account id and processed by PostHog (EU-hosted) so we can measure and improve the product. We also record session replays, but ONLY on non-inbox pages (the landing, sign-in, pricing and settings screens), with anything you type masked, to see where the sign-up and upgrade flows can improve. None of this ever includes your inbox, email content, subjects, recipients, attachments, search text or assistant messages. Used only to run and improve Otto, never to build an advertising profile or train models.
- Email tracking you turn on (opt-in)
- If you (a Pro user) opt an individual outgoing email into read receipts or link-click tracking, Otto stores — for that one message — its subject, recipients and send time, plus the resulting open count and timestamps and/or per-link click counts. This is off by default on every email and chosen per send. A read receipt records that the message was opened, not which recipient opened it, and won't register for inboxes that block remote images. Kept until you delete your account.
What we deliberately do not store
- Your full emails. Otto never stores the body or attachments of your messages — those are fetched live from Gmail each time you open them. We keep only the lightweight metadata index needed to show your inbox (see “Mailbox index” above), plus any email excerpts inside an assistant conversation you chose to have about a message, which are erased when you delete that chat or your account.
- Your Google password (sign-in is handled entirely by Google via OAuth).
- Your payment-card details — those go directly to our payment processor (Paddle), never to us.
- Third-party ad-network or behavioural ad-profiling data. Otto embeds no advertising trackers, builds no advertising profile of you, and never uses your email content or personal data to target ads. We do use a privacy-focused product-analytics processor (PostHog, EU-hosted) to understand which features are used and where the experience can improve — it records structural usage events, performance timings, and session replays limited to non-inbox pages (the landing, sign-in, pricing and settings screens, with anything you type masked). It never records your inbox and never receives your email content, subjects, recipients or attachments. See subprocessors.
3. The Google data we access, and why
When you sign in with Google you grant Otto the following access. You can review and revoke it at any time at myaccount.google.com/permissions, or by disconnecting from within the app.
gmail.readonly- Read and search your mail so the assistant can find, open and summarize it.
gmail.send- Send the emails and replies you ask Otto to send.
gmail.modify- Organize your mailbox on your instruction — mark read/unread, star, archive, label and trash.
gmail.settings.basic- Create and manage your mail filters (the rules that auto-label, archive or sort incoming mail).
openid, email, profile- Identify you and show your name and avatar in the app.
4. Google API Services — Limited Use
Otto’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, data obtained from Gmail is used only to provide and improve Otto’s user-facing features, and we:
- do not sell or rent your Google data;
- do not use it for advertising, profiling, or any purpose unrelated to the features you are using;
- do not use it to train generalized or foundation AI/ML models;
- do not allow humans to read it, except where you explicitly ask us to, where required for security or to comply with the law, or on data that has been aggregated and anonymized.
5. AI processing
Otto’s assistant is powered by third-party large language models (see Subprocessors below). When you use the assistant, the relevant content of your request — which may include text from emails you ask about — is sent to the model provider’s API (currently OpenAI, routed through the Vercel AI Gateway) to generate a response. If you use the assistant’s web-research tool, your research query — which can include details you provide from an email — is additionally sent to Perplexity to search the web. Each provider processes this only to return a result to you and, under its API terms, does not use it to train its models. We do not use your Gmail content to train any model ourselves. You are asked to consent to this AI processing before you first use the assistant.
6. How we use your data
- To authenticate you and keep you signed in.
- To read, search, compose, send and organize mail at your instruction.
- To power the AI assistant’s responses and actions.
- To deliver real-time “new mail” updates to your browser.
- To remember your settings and saved prompts.
- To keep the service secure and to comply with our legal duties.
7. Legal bases (GDPR)
Where the GDPR applies, we rely on:
- Consent — for connecting your Google account and accessing your mailbox. You may withdraw it at any time by disconnecting or deleting your account.
- Performance of a contract — to provide the features you request.
- Legitimate interests — to keep the service secure and working, balanced against your rights.
8. Subprocessors
We share data only with the service providers needed to run Otto. Each processes data on our behalf under its own terms:
- Google (Gmail API & OAuth)
- Sign-in and the mailbox itself. Otto reads, sends and modifies mail through the Gmail API using the access you grant. (Global)
- OpenAI
- Powers the assistant. When you use Otto's AI, the relevant message content (which can include email text you asked about) is sent to OpenAI's API to generate a response. OpenAI processes this as our data processor and, per its API terms, does not use API data to train its models. (United States)
- Vercel (hosting & AI Gateway)
- Application hosting and delivery. AI requests are routed to the model provider through the Vercel AI Gateway, which passes the request through and does not train on it. (Global)
- Perplexity
- Powers the assistant's web-research tool. When you ask Otto to research a topic, your research query — which can include details you provide from an email — is sent to Perplexity's API to search the web and return current information. Perplexity processes this as our data processor and, per its API terms, does not use the data to train its models. (United States)
- Convex
- Our managed database and real-time backend. It stores the data described above (account, settings, assistant chats, the mailbox metadata index, subscription status) and powers live mailbox updates. (Replaces the former Supabase backend.) (United States)
- Paddle
- Merchant of record for web/PWA subscriptions. Handles checkout, card processing, tax and refunds; receives your email and payment details directly (we never see your card number). (Global)
- RevenueCat
- Cross-platform subscription management. Reconciles entitlements and in-app purchases on iOS/Android; receives your subscription identifiers, not your payment card. (United States)
- Apple & Google (push delivery)
- If you enable notifications, a device token and a content-free “new mail” signal are sent through Apple's APNs, Google's FCM or your browser's web-push service to alert your device. (Global)
- Resend
- Sends transactional email (e.g. an account-deletion confirmation) from our no-reply address to your registered email. It receives only the recipient address and message content needed to deliver the email. (United States)
- PostHog
- Product analytics. Records structural usage events (which features you use, onboarding steps, errors, subscription changes) and performance timings tied to your account id, plus session replays limited to non-inbox pages (landing, sign-in, pricing, settings) with typed input masked, so we can improve the product and its conversion flow. It never records your inbox and never receives your email content, subjects, recipients, attachments, search text or assistant messages. EU-hosted. (European Union)
We never sell your personal data, and we do not share it for cross-context behavioural advertising.
9. Data retention
- Authorization tokens are kept until you disconnect Google or delete your account.
- Chats, settings, templates, rules and the mailbox metadata index are kept until you delete them or your account.
- Full message bodies and attachments are never retained — they are fetched live from Gmail when you open a message. Email excerpts inside a saved assistant conversation follow that conversation’s lifetime.
- Per-feature usage counters used for rate-limiting are bounded: daily counters are pruned after 45 days.
- When you delete your account it is first deactivated and then permanently erased after a 30-day grace period, during which you may restore it.
10. Cookies & local storage
Otto uses only strictly necessarycookies — the session cookie that keeps you signed in and the security cookies that protect the sign-in flow. We set no advertising or analytics cookies, which is why you don’t see a cookie banner. Your browser’s local storage is used for on-device preferences (such as your theme and which in-app notices you’ve dismissed) and, in demo mode, for demo conversations that never leave your browser. You can clear these at any time through your browser settings; clearing the session cookie simply signs you out.
11. Your rights
Subject to applicable law — including the GDPR/UK GDPR, India’s Digital Personal Data Protection Act 2023, and, for California residents, the CCPA/CPRA — you have the right to access, correct, export (portability), restrict, object to, and delete your personal data, to withdraw consent, and to grievance redressal. We do not “sell” or “share” personal data as those terms are defined under California law, and we will not discriminate against you for exercising any right.
You can exercise these directly in the app:
- Access & portability — export all your stored data as a file from Settings → Privacy & data.
- Erasure — delete your account (and disconnect Google) from Settings → Privacy & data.
- Withdraw consent — disconnect Google at any time.
You can also email privacy@ottomail.app and we will respond within the timeframe the law requires. You may also lodge a complaint with your local data-protection authority.
12. Security
Data is transmitted over HTTPS and stored on managed infrastructure that encrypts data at rest, with access controls. OAuth tokens are held server-side only and are never exposed to the browser. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your data — and, above all, we limit what we hold in the first place.
13. International transfers
Our subprocessors may process data in countries other than yours, including the United States. Where required, such transfers rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
14. Children
Otto is not directed to children and is not intended for anyone under 18. We do not knowingly collect data from them.
15. Changes to this policy
We may update this policy from time to time. We will update the effective date above and, for material changes, take reasonable steps to notify you.
16. Email open & click tracking (opt-in)
Otto offers an optional, Pro-only feature that lets you see when an email you send is opened and which of its links the recipient clicks. It is strictly opt-in: off by default on every message, chosen per send, and recorded only for messages you turn it on for.
Read receipts. When you enable a read receipt, Ottoadds an invisible 1×1 image (a “tracking pixel”) to that message. When the recipient’s email client loads the image, we record that the message was opened and when. We record an open for the message as a whole — we cannot tell which recipient opened it — and many email clients block remote images, so an open may never register (notably for other Otto users, whose image proxy blocks such pixels).
Link clicks. When you enable link tracking, we rewrite the links in that message to pass through a signed redirect on our servers, which records the click and immediately forwards the recipient to the original, unchanged destination. Clicks are counted per link, not per recipient.
Recipients & your responsibility.Recipients are not notified that a message is tracked. The data we collect is your own send metadata and aggregate open/click counts; we do not build a profile of your recipients, sell this data, or use it for advertising. Depending on your jurisdiction and your relationship with the recipient, tracking another person’s opens or clicks may carry obligations (for example under the GDPR/ePrivacy rules) — you are responsible for using the feature lawfully. You can turn it off for any message, and account deletion erases all tracking records.
17. Contact
Questions or requests: privacy@ottomail.app.