Subprocessors
Otto uses trusted services to host the app, deliver messages, process payments and provide AI assistance. This page explains which services are involved and why.
Services that help run Otto
The services below receive information needed for the features you use. A listing does not mean every service receives every request. Some providers, such as payment companies and the accounts you connect, also have independent responsibilities under their own privacy terms; they do not act solely as Otto's subprocessors.
- Google (Gmail API & OAuth)
- Sign-in and the mailbox itself. Otto reads, sends and modifies mail through the Gmail API using the access you grant. (Global)
- Microsoft (Graph API & OAuth)
- Connection to Outlook and Microsoft 365 mail, calendar and tasks. Otto reads and changes the selected account through Microsoft Graph using the access you grant. (Global)
- AI model providers (OpenAI, Anthropic, Google, and others)
- Generate responses and support AI features such as search and message classification. Available models include OpenAI, Anthropic, Google, DeepSeek, Z.ai, Moonshot AI, Alibaba (Qwen), Meta and Grok; specialized tasks also use Cohere and TypeSafe AI (Jev). The selected model depends on your plan, preferences and the feature. Relevant prompts, conversation context and authorized account content may pass through our routing services to the selected provider. Provider retention and data-use terms depend on the service and applicable routing settings. (United States and other regions)
- Vercel (hosting & AI Gateway)
- Application hosting and delivery. AI requests may be routed to the model provider through the Vercel AI Gateway, which passes the request through and does not train on it. (Global)
- OpenRouter
- AI request routing. When Otto routes a request through OpenRouter, relevant prompts and context (which can include email text you asked about) pass through its API to the selected model provider. Provider retention and data-use restrictions depend on the applicable account and routing settings; this listing does not promise zero retention for every route. (United States)
- Perplexity
- Powers the assistant's web-research tool. When you ask Otto to research a topic, your research query — which can include details you provide from an email — is sent to Perplexity's API to search the web and return current information. Perplexity processes this as our data processor and, per its API terms, does not use the data to train its models. (United States)
- Convex
- Our managed database and real-time backend. Stores account information, settings, assistant chats, mailbox metadata, saved work and subscription status, and powers live updates. (United States)
- Paddle
- Merchant of record for web/PWA subscriptions. Handles checkout, card processing, tax and refunds; receives your email and payment details directly (we never see your card number). (Global)
- RevenueCat
- Cross-platform subscription management. Reconciles entitlements and in-app purchases on iOS/Android; receives your subscription identifiers, not your payment card. (United States)
- Apple & Google (push delivery)
- If you enable notifications, a device token and a content-free “new mail” signal are sent through Apple's APNs, Google's FCM or your browser's web-push service to alert your device. (Global)
- Resend
- Sends transactional email (e.g. an account-deletion confirmation) from our no-reply address to your registered email. It receives only the recipient address and message content needed to deliver the email. (United States)
- Sentry
- Error monitoring and performance diagnostics to help us find and fix failures. Receives technical error reports and limited performance information. Otto removes request bodies, cookies, headers and URL query parameters from error reports before sending them. (European Union by default; depends on project configuration)
- Apple (sign-in & App Store) and Google Play
- Apple sign-in provides the account identity you authorize. Apple and Google process native app purchases and provide subscription records used to manage your plan. These services also operate under their own privacy terms. (Global)
- PostHog
- Product analytics. Records structural usage events (which features you use, onboarding steps, errors, subscription changes) and performance timings tied to your account id, plus session replays limited to non-inbox pages (landing, sign-in, pricing, settings) with typed input masked, so we can improve the product and its conversion flow. It never records your inbox and never receives your email content, subjects, recipients, attachments, search text or assistant messages. EU-hosted. (European Union)
Chat services you choose to connect
When you connect Slack, Telegram, Discord, WhatsApp, Microsoft Teams or Google Chat, the connected service handles messages you send to Otto and replies delivered there. A reply may include email, calendar or other account information you asked Otto to use. Only integrations currently available in Otto can be connected.
These services operate under their own terms and, where relevant, your workspace's policies. Disconnecting in Otto stops future access through that connection; it does not erase messages already delivered to the chat service.
AI processing and locations
AI requests can include your prompt, relevant conversation history and information from accounts you have allowed Otto to use. The selected model and routing service determine which providers process a request. Otto uses shared cloud services with account-scoped access, rather than a dedicated model for each customer.
Locations above describe service regions, not a guarantee that all processing stays in one country. AI processing and provider retention depend on the selected service, applicable agreements and routing settings. Otto does not currently offer a choice of data-residency region or a universal zero-retention guarantee across model providers.
Retention, changes and questions
Otto's own storage and deletion of data are separate from processing by these services. See our Privacy Policy for the data we keep, retention periods and your deletion options. We update this list as our services change.
For questions about a provider or how your information is handled, contact privacy@ottomail.app.