Legal

Privacy Policy

Effective August 16, 2026

Contents

  1. Overview
  2. Information We Collect
  3. Payment Processing (Stripe)
  4. Analytics, Ad Pixels & UTM Tracking
  5. Email Communications
  6. Data Storage
  7. Your Otto and the Otto App
  8. Third-Party Services
  9. Data Retention & Deletion
  10. Your Rights
  11. Changes to This Policy
  12. Contact

1. Overview

The Tokenry, Inc. (“The Tokenry,” “we,” “us”) operates myotto.ai and makes the Otto hardware, Otto OS, and the Otto apps for phone and desktop — the application shown on Google’s consent screen as Otto AI. This Privacy Policy covers all of them: what we collect when you order a device, what your Otto and the Otto app handle once it is set up, and what happens to any third-party account you connect to it.

2. Information We Collect

Information you provide

  • Email address — collected when you reserve an Otto or subscribe to updates.
  • Payment information — your card details are collected by Stripe during checkout. We never see, store, or process raw card numbers on our servers.
  • Shipping address — name and mailing address, collected during the preorder flow so we can ship your Otto when production is complete. Stored in our database; not shared with Stripe or other third parties until fulfillment.

Information generated automatically

  • Order metadata — order ID, reservation status, amount, Stripe customer ID, and payment method ID.
  • Analytics data — page views and conversion events collected via the Meta, TikTok, and Lapis pixels (see Section 4).

3. Payment Processing (Stripe)

We use Stripe to handle all payment processing. When you reserve an Otto, a $20 fully refundable deposit is charged immediately through Stripe. Key details:

  • Your card information is transmitted directly to Stripe and is never sent to or stored on our servers.
  • We store only Stripe-issued identifiers (customer ID, payment intent ID, payment method ID) to reference your account.
  • A $20 deposit is charged at the time of reservation. Before shipment, we will email you to confirm your address and final total, then charge the remaining balance plus flat $15 shipping per unit, worldwide, through Stripe after the 7-day adjustment window. International orders may have additional carrier or import costs due on delivery.
  • Stripe’s handling of your data is governed by the Stripe Privacy Policy.

4. Analytics, Ad Pixels & UTM Tracking

Meta Pixel (Facebook & Instagram)

We load the Meta Pixel to measure the effectiveness of ads we run on Facebook and Instagram and to understand how visitors interact with our website. The pixel reports the following events to Meta Platforms, Inc.:

  • Page view events
  • Checkout initiation events
  • Purchase/lead conversion events (upon successful reservation)

This data is shared with Meta Platforms, Inc. and is subject to the Meta Privacy Policy. You can opt out of interest-based advertising through your Facebook Ad Settings or through the Digital Advertising Alliance opt-out.

TikTok Pixel

We load the TikTok Pixel to measure the effectiveness of ads we run on TikTok. The pixel reports the same categories of events to TikTok Inc.:

  • Page view events
  • Checkout initiation events
  • Purchase/conversion events (upon successful reservation)

This data is shared with TikTok Inc. and is subject to the TikTok Privacy Policy. You can opt out of interest-based advertising through your TikTok Ad Settings or through the Digital Advertising Alliance opt-out.

Lapis Pixel (ChatGPT Ads)

We load the Lapis Pixel to measure the effectiveness of ads we run on ChatGPT. The script file loads on every page, so your browser requests it from Lapis on any visit. It only begins tracking once you arrive from one of those ads — the landing URL carries a ChatGPT campaign parameter — after which it reports:

  • Page view events
  • Purchase/conversion events (upon successful reservation)
  • The campaign, ad group, and ad from the landing URL
  • A first-party cookie (lapis_sid) that expires after 30 days

That cookie keeps the session open for 30 days, so page views and conversions on later direct visits are attributed to the same ad. Before it is set, and once it expires, the script sends no tracking event.

This data is shared with Lapis, which reports it to OpenAI OpCo, LLC for ad measurement. It is subject to the Lapis Privacy Policy and the OpenAI Privacy Policy. You can prevent Lapis tracking by blocking the Lapis script or its requests in your browser.

UTM Parameters

Ads we run on Facebook, Instagram, TikTok, and other platforms may include UTM tracking parameters (such as utm_source, utm_medium, utm_campaign) appended to the destination URL. When you click an ad link, these parameters arrive in your browser and are read by the ad platform pixels described above to attribute your visit to a specific campaign. UTMs are URL metadata only — no additional personal data is collected through UTM parameters beyond what the pixels already report.

5. Email Communications

When you provide your email address — whether through the reservation flow or our subscribe form — we share it with two email providers. Our marketing list is managed by Loops, which handles product announcements and waitlist updates. Transactional order email (order confirmations, order-access links) is delivered by Resend. Together they process your email to send:

  • Order confirmations, preorder status updates, and shipping notifications
  • Product announcements and updates

Every marketing email includes an unsubscribe link. Transactional emails (order confirmations, charge notifications) will still be sent as needed.

6. Data Storage

Order data (email, shipping address, Stripe reference IDs, order status, timestamps) is stored in a PostgreSQL database hosted by Neon in the US-East-1 region. The connection is encrypted via TLS. We do not store passwords, raw card numbers, or sensitive authentication credentials in our database.

7. Your Otto and the Otto App

This section describes how data is handled once your device is delivered and set up, and what the Otto app collects.

Data on your Otto

Your files, credentials, browser sessions, and agent working data reside locally on the device. We do not copy, sync, or back that data up to our servers. Outbound traffic is whatever your agents do themselves — API calls, web browsing, emails sent — plus the AI model requests and account services described below.

Account and device data

When you set up the Otto app, we collect and store:

  • Account details — your name, email, and the account identifier returned by Sign in with Apple, Google Sign-In, or email and password. Used to authenticate you and link you to the Otto you own.
  • Device details — device identifier and serial number, the name you give the device, OS version, last-seen time, and connection and health state. Used to show you your device’s status, deliver software updates, and provide support.
  • Push notification token — used only to deliver notifications the product needs: tool-approval prompts you must answer, and new-device pairing alerts.
  • Billing and usage records — your prepaid AI-credit balance, transaction history, Stripe customer and payment-method identifiers, and the token count and cost of each AI request. Used to meter and bill AI usage and show you your balance.

The Otto app contains no analytics, attribution, or advertising SDK. We do not collect advertising identifiers, do not track you across other apps or websites, and do not sell your data. The advertising pixels described in Section 4 run on our website only, never in the app.

Conversations with your Otto

Chat between the app and your Otto is end-to-end encrypted. Messages pass through our relay so the app can reach your device from anywhere, but the relay forwards ciphertext it cannot read. We cannot see the content of your conversations, and we do not store them.

AI model requests

When your agent calls an AI model, the request is routed through our AI gateway to the model provider you select — currently Anthropic, OpenAI, Google, DeepSeek, or Together AI. The provider receives the content of that request and returns the response. We record only the token count and cost, so we can bill you. No account, contact, or payment information is sent to model providers.

We will also offer a subscription plan that lets you use your own AI provider account and API key instead of buying credits from us. On that plan your requests are billed by your provider directly under your own account. We store your API key encrypted and use it only to make the requests your agent initiates.

Connected accounts (Google)

You can connect your own Google Account so your agent can work your Gmail, Google Calendar, and Google Drive on your behalf. Connecting is optional, nothing is connected by default, and you grant access on Google’s own consent screen. We request the Gmail, Calendar, and Drive scopes so the agent can read, create, and organize the items you ask it to; what each one covers, and why a narrower scope is not sufficient, is set out on the Otto AI Google integration page.

The access tokens are stored encrypted on your Otto, not on our servers, and your Otto calls Google directly. Actions that change something — sending a message, moving an event, sharing a file — pause and ask you to approve them first. Content fetched from Google is used to answer the request in front of you and is not retained afterwards. Disconnect the account in the Otto app to delete the stored tokens, or revoke access from your Google Account permissions page.

Otto AI’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train AI models.

Remote access (Tailscale)

Remote access is optional and off by default. If you turn it on, your Otto joins a private network you create with your own Tailscale account, so you can reach your device’s dashboard while away from home. You sign in to Tailscale directly; we never see or store your Tailscale credentials, and we send no data about you to Tailscale.

Using remote access means installing the official Tailscale app on your phone, which creates a VPN connection on your device. That VPN is operated by Tailscale under your own account, not by us, and it exists for one reason: your Otto sits behind your home router, and a private network is the only way your phone can reach it from outside. It is split-tunnel — it carries traffic to your own devices on your own private network and nothing else. Your ordinary internet traffic does not enter it. We do not advertise exit nodes or subnet routes from your Otto, so your general browsing is never routed through it, and traffic inside the tunnel is encrypted end to end between your phone and your Otto.

We collect nothing over that connection. The Otto app itself contains no VPN or network-extension capability and cannot inspect, log, or redirect your phone’s traffic. Tailscale, as the coordination service for your private network, sees device names, public keys, and the IP addresses used to establish connections — but not the contents of the tunnel. That is governed by Tailscale’s own privacy policy.

8. Third-Party Services

We share information with the following third-party services, each for a specific purpose:

ServicePurposeData shared
StripePayment processingEmail, payment card details, shipping address (at fulfillment)
Meta PlatformsAdvertising analytics (Facebook & Instagram)Page views, conversion events
TikTokAdvertising analyticsPage views, conversion events
LapisAdvertising analytics (ChatGPT), reported onward to OpenAIPage views, conversion events, ad campaign identifiers
LoopsEmail marketingEmail address
ResendTransactional email deliveryEmail address
NeonDatabase hostingOrder metadata, shipping address (no raw card data)
Amazon Web ServicesHosting for the Otto app backend (US, us-west-2)Account, device, and billing data (Section 7)
AppleSign in with Apple; push notification deliveryAccount identifier Apple issues, push token
GoogleGoogle Sign-In (optional); Android push delivery; Gmail, Calendar & Drive, if you connect that accountName, email, Google account ID — only if you sign in with Google. If you connect the account to your Otto, requests go from your device to Google directly and pass through no server of ours
ExpoRelays our push notifications to Apple and GoogleThe push token Expo itself issues. Notification contents are encrypted before they leave us; any visible text is generic (“A new device wants access”)
AI model providers — Anthropic, OpenAI, Google, DeepSeek, Together AIGenerating your agent’s responsesThe content of the AI requests your agent makes. No account, contact, or payment data
TailscaleOptional remote access, only if you enable itNone from us — you sign in to your own Tailscale account directly

9. Data Retention & Deletion

We retain your order data for as long as necessary to fulfill your order and comply with legal obligations (e.g., tax records). After that period:

  • Cancelled reservations — data is deleted within 90 days of cancellation.
  • Completed orders — data is retained for up to 7 years for accounting and legal compliance, then deleted.
  • Email subscribers — you can unsubscribe at any time. Upon request, we will delete your email from our marketing lists within 30 days.

10. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Data portability

The fastest way to exercise them is our data request form — you tell us what you want handled, we email that address a confirmation link, and a person replies. You can also contact us at the address below. Either way, we will respond within 30 days.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on our website. The “Effective” date at the top of this page indicates when the policy was last revised.

12. Contact

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

The Tokenry, Inc.
1115 West Bay Drive Northwest, Ste 302
Olympia, WA 98502
support@myotto.ai

© 2026 | The Tokenry, Inc.