Legal
Otto App & Device Privacy Policy
Effective September 5, 2026
How information is handled by your Otto, the companion apps and the services they use.
1. What this policy covers
The Tokenry, Inc. (“The Tokenry,” “we,” “us”) makes Otto hardware, Otto OS, and the Otto apps for phone, desktop and web. This policy covers those products, Otto accounts, AI-credit billing and connected services, including the application shown on Google’s consent screen as Otto AI.
Our marketing website, hardware orders, advertising and website/order analytics are covered by the separate Website & Commerce Privacy Policy. Website advertising tags are not embedded in the Otto app. Visiting our website from the app is subject to that website policy.
2. Account and operational information
- Account and security: name, email, profile image when provided, account and sign-in identifiers, authentication records, session IP and browser information, preferences, permissions and deletion requests.
- Device and service operation: device identifiers and serial numbers, names, software versions, connection and health status, update records, and technical reliability and security logs.
- Billing and usage: AI-credit balance, transaction history, payment references, model/provider, token usage, costs, timing and request outcomes, with account, device and task attribution where needed for billing, limits and operations.
- Support and privacy requests: contact details, messages, attachments you provide, the scope of your request and records of how we handle it.
We use this information to provide and secure accounts and devices, process payments, carry out AI and integration tasks, deliver updates and notifications, troubleshoot problems, provide support and meet accounting and legal obligations. Our servers and service providers also receive ordinary connection information such as IP addresses, request times and browser or device information.
3. Local content and encrypted chat
Your Otto stores its working files, browser sessions, direct-service credentials, conversations and agent memory locally. The app can also cache conversation data locally. We do not operate a general cloud backup of those device files or conversations. Your agent can send information to model providers, connected services or recipients as part of the tasks it performs, as explained below.
Chat content between the Otto app and your Otto is end-to-end encrypted. Our relay forwards that encrypted content without decrypting it, while handling the account, device and connection information needed to route it. This protection applies to the app-to-device connection; it does not mean model providers, integration services or support tools cannot receive content sent to them for a task.
If you enroll a recovery phrase, our backend stores an encrypted backup of your app’s encryption identity and the information needed to restore it. Your recovery phrase is not sent to us. This identity backup is separate from your conversation history and device files.
4. AI requests and your own provider keys
When you use our AI gateway, our backend and the selected model provider process the request and response to provide the service. Requests can contain prompts, conversation context, attachments, tool results and connected-service information your agent uses. That content can include personal information. The gateway is configured not to retain prompt or response bodies in its inference logs; it keeps billing and operational metadata, including usage, cost, model, timing and outcome.
Depending on the model and route, AI services can include Anthropic, OpenAI, Google, Together AI and OpenRouter. The available services can change, and custom providers receive requests when you configure them. Model providers and routing services process the content needed for the request, including when a request is retried or routed to another available provider.
When you use your own provider key, it is stored encrypted on your Otto and used for direct requests to that provider under your account. Providers receive request content and handle it according to their terms and applicable account settings. Provider retention and data-use practices depend on the service and settings. The restricted analytics in Section 6 do not change what a model provider must receive to answer a request.
5. Connected accounts and remote access
Direct, hosted and custom connections
Connections are optional. Direct integrations, such as the device’s Google and GitHub connections, store credentials on your Otto and call those services directly. Hosted integrations use Composio: it stores connection credentials, and our backend and Composio process connected-account identifiers, action names, arguments and results to carry out requested actions. Failure diagnostics can also contain information from an action. Custom API and MCP connections send the credentials and request data needed by the service you configure.
Actions follow your approval settings, standing permissions and automation permissions. Retrieved information and action results can remain in local conversation history and agent memory and can be included in later model requests. Disconnecting or revoking a connection removes or revokes access as the disconnection completes; an offline Otto may need to reconnect to process the request. It does not automatically erase existing local history or records already held by the external service.
Google user data
If you connect Google, you grant the requested access on Google’s consent screen. The Otto AI Google integration page explains Gmail, Calendar and Drive access. The direct Google connection keeps encrypted tokens on your Otto and calls Google from the device. Information used for your requested tasks can appear in local history and memory and be sent to the model provider used for those tasks. Disconnect in the app to remove the connection credentials when your Otto processes the request, or revoke access from your Google Account permissions.
Otto AI’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train AI models.
Optional remote access through Tailscale
You can enable Tailscale for remote access through your own private network. You sign in to Tailscale directly, and your devices exchange the coordination information needed for that connection, including device names, public keys and IP addresses. Traffic in the private tunnel is encrypted between your devices. The Otto app itself does not contain a VPN or network extension; using the separate Tailscale app on your phone can establish a VPN connection there. See Tailscale’s privacy policy.
6. App and runtime analytics
We use PostHog for app usage and Otto runtime measurements to understand feature use and improve reliability and performance. This analytics is enabled by default for an account. You can turn it off using the usage analytics switch under Account → Security → Privacy in the Otto app. The preference applies across that account’s apps and owned Ottos, including background runs and calls made with your own model-provider key. Existing opt-out choices are preserved.
- App events: that a message was sent, a fixed error category, an onboarding step, a spending-limit or security-setting change, or an integration connection action. Properties are restricted to approved categories and yes/no values. They do not include the message, an exact spending amount, or a custom integration name.
- Runtime measurements: AI-call and agent-attempt duration and success, failure or cancellation; available input, output, cache and total token counts; latency to the first stream event; and AI request size in bytes. Request size can include encoded attachments in the request body, but the body and attachments are not sent to PostHog. These measurements are made on your Otto, including for background tasks.
App and runtime analytics exclude prompts, responses, conversation or attachment contents, filenames, tool arguments and results, credentials, error text, URLs, personal names, email addresses, account identifiers, device serial numbers, operational device identifiers, and agent or session identifiers. The separate analytics identifiers below are included.
Your Otto’s Analytics ID
Your Otto generates a random Analytics ID and stores it encrypted on the device. Enrolled apps obtain it through their encrypted connection to that Otto. App events associated with the selected Otto and its runtime events use this ID. It does not contain your name, but it allows activity from that Otto and its enrolled apps to be linked over time in PostHog. This makes the analytics pseudonymous, rather than unlinked anonymous events.
The Analytics ID survives restarts, app sign-out or reinstall, and analytics opt-out. Opting back in resumes use of the same ID. Erasing the Otto’s owner data removes the stored ID; subsequent owner setup can create a new one. This does not erase analytics already received by PostHog.
Our backend checks ownership and your account preference before permitting runtime analytics. These permission checks do not include the Analytics ID or event contents. We do not automatically store a readable mapping between the Analytics ID and your account or operational device identifier in our backend. Analytics may be delivered directly from your app or Otto, or through our backend; device routing identifiers used by our backend are removed before delivery to PostHog.
PostHog receives analytics identifiers, approved event properties, timestamps, individual event identifiers, the project token and delivery metadata such as SDK version. Direct requests expose the app’s or Otto’s source IP and ordinary connection metadata to PostHog; runtime requests delivered by our worker expose our server’s connection information. Geographic enrichment is disabled, but that does not hide network IPs or make traffic impossible to correlate. The Analytics ID is separate from your account identity, but we cannot promise that analytics can never be associated with you.
Choosing to share an Analytics ID with support
A connected, enrolled app lets you reveal and copy the ID under Device settings → Advanced → Analytics ID. Copying it places it on your clipboard; it does not send it to support. If you choose to share it, support can use it to locate that Otto’s analytics and associate them with your request. Hiding the displayed ID does not delete it, clear your clipboard or remove earlier analytics. The ID can be revealed while analytics is turned off.
Capture limits and opt-out
Automatic screen and interaction capture, session replay, exception collection, feature-flag reporting and person profiles are disabled. Disabling profiles does not prevent events with the same Analytics ID from being linked. We do not use app or runtime analytics for cross-company advertising tracking, advertising identifiers, or data-broker sharing. See PostHog’s privacy policy.
Turning analytics off stops capture on that app and discards its pending events. Other apps refresh the account preference on startup, focus and reconnect and approximately every minute while active. Runtime delivery requires current ownership and consent checks. Requests already sent cannot be recalled, and opt-out does not delete previously received analytics. The switch does not disable billing, authentication, security, necessary service diagnostics, or the separate website and order analytics described in the Website & Commerce Privacy Policy.
7. Payments and AI credits
We use Stripe to process AI-credit and other Otto account payments. Your full card number and security code are supplied directly to Stripe and are not stored on our servers. We receive Stripe-issued identifiers, payment status and amounts, and limited payment-method details such as card brand, last four digits and expiry date. We also maintain AI-credit balances, transaction history and the usage records needed to bill requests and apply spending limits. These billing records are separate from optional analytics.
Stripe processes contact, billing and payment information supplied for these transactions. Its handling is described in the Stripe Privacy Policy. Hardware purchases and shipping are covered by our Website & Commerce Privacy Policy.
8. Notifications, support and diagnostics
Notifications and service communications
We use Expo, Apple and Google to deliver notifications such as chat and background-task updates, pairing requests and billing or usage alerts. Delivery includes push tokens and routing information such as device, agent or session identifiers and links into the app. Chat preview content is encrypted before delivery. Other operational notifications can contain readable text, including spending or limit amounts. You can manage notification permission in your device settings.
We may also send account, payment and service communications through email delivery providers. Those providers process the recipient address and message contents needed to deliver the communication. Marketing subscriptions and unsubscribe choices are described in the separate website policy.
Support and operational diagnostics
Device health and reliability reporting helps us operate and troubleshoot Otto. Support staff can use account, billing, device health and technical diagnostic records to investigate problems. Authorized support tools can request device service logs; credential patterns are filtered, but diagnostic material can still contain personal information or content.
Support communications and material you submit may be processed by our staff, support systems such as Chatwoot, and an AI service used to help answer support requests. This is separate from your private app-to-Otto chat and the restricted analytics in Section 6.
9. Storage and security
The Otto account backend runs on Amazon Web Services in the United States, primarily us-west-2. Hosting, databases, queues, operational logs and backups process the account, device, billing and service information described here. Our providers may process information in the United States and other countries where they operate.
Our account systems store authentication information, including password hashes, session credentials, sign-in provider tokens and passkey public keys. Public connections to our services use HTTPS/TLS; this differs from the end-to-end encryption described for specific features above. Access controls restrict administrative access, but no storage or transmission method can provide an absolute guarantee of security.
10. Service providers and recipients
These providers and recipients process information for the purposes below. Which recipients receive information depends on the features and connections you use. Their own terms and privacy notices also describe how they handle information.
- Amazon Web Services
Purpose: Otto backend hosting and operations
Data shared: Account, authentication, device, billing, technical and support information; encrypted identity backups; data processed by hosted AI gateway and integration services.
- PostHog
Purpose: App usage and runtime performance analytics
Data shared: Restricted categorical events, timing/token/request-size measurements, event identifiers, a persistent per-Otto Analytics ID, timestamps and connection metadata, as described in Section 6.
- Stripe
Purpose: Payments and AI-credit billing
Data shared: Payment information you supply to Stripe, contact and billing details, transaction references and amounts, and limited payment-method information.
- Apple and Google
Purpose: Optional sign-in and platform services
Data shared: Sign-in account/profile information and authentication exchanges; platform distribution and push-delivery information.
- Expo, Apple and Google
Purpose: Push notifications and app distribution or updates
Data shared: Delivery tokens, routing identifiers, encrypted chat previews, readable operational notifications and ordinary app-update request metadata.
- AI providers and routing services
Purpose: AI responses and AI-assisted features, including support
Data shared: Request content and context, which can contain personal information; provider credentials and usage information needed for the request.
- Composio and connected services
Purpose: Authorized integration actions
Data shared: Connection identifiers and credentials where hosted, action arguments, results and operational diagnostics. Direct and custom connections are described in Section 5.
- Chatwoot and support service providers
Purpose: Customer support
Data shared: Support messages and submitted material, contact/account references and diagnostic information used to respond.
- Email delivery services, including Resend
Purpose: Account, payment and service communications
Data shared: Recipient addresses and message contents, including account or payment information and confirmation links needed for the communication.
- Tailscale
Purpose: Optional private-network access
Data shared: Device/network coordination metadata, including names, public keys and IP addresses.
11. Retention and deletion
We retain account and service information for the time needed to operate your account, provide the features you use, handle support or disputes, and meet legal and accounting obligations. The relevant periods depend on the record and its purpose. The deletion process and specific backup and log periods are described below.
Deleting an Otto account
You can request account deletion in the Otto app. The account is restricted during a 30-day recovery period, during which you can cancel the request. After that period, our deletion process removes the active account and associated data and instructs your Ottos to erase their owner data. Processing can take longer when a deletion step needs to be retried. An offline Otto must reconnect before it can receive and carry out a remote wipe.
We retain records needed for payments, accounting, legal obligations and documenting deletion or privacy requests, including a record of the deletion with account identifiers, email and handling history. Stripe payment records and separate website order records are not automatically erased by deleting an Otto account. Use Section 12 to request access to or deletion of those records; website orders are covered by the Website & Commerce Privacy Policy.
Backups, logs and analytics
Removal from active systems does not immediately remove copies from backups or operational logs. Our production account database has a 30-day automated backup window; production service logs are generally configured for 90-day retention. Other providers and data categories can have different retention periods. Analytics opt-out prevents future collection as described in Section 6; it does not erase earlier PostHog events or reset a persistent Analytics ID. If you voluntarily provide that ID, we can use it to locate associated analytics when handling a request. We may not be able to locate analytics using your account details alone.
12. Your rights and choices
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Data portability
- Withdraw consent where processing relies on consent
- Complain to the data protection authority where you live or work
The fastest way to exercise them is our data request form. Tell us what you want handled; we email that address a confirmation link, and a person replies. You can also contact us at the address below. Either way, we will respond within 30 days. We may need to verify your identity before handling a request. Some records must be retained for legal or security reasons; we will explain applicable limitations when responding.
You can turn off app and runtime analytics using the account setting in Section 6, manage notification permission in device settings, revoke connected-account permissions, or request account deletion in the app. These controls have the scope and limits described above.
13. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by posting a notice on our website. The “Effective” date at the top of this page indicates when the policy was last revised.
14. Contact
If you have questions about this policy or wish to exercise your data rights, contact us at:
The Tokenry, Inc.
1115 West Bay Drive Northwest, Ste 302
Olympia, WA 98502
support@myotto.ai