Privacy Policy

Privacy Policy

Last updated 29 July 2026

This explains what we collect, who else touches it, how long we keep it, and how to get it back or deleted. We wrote it to be read, not to be impenetrable.

The three things that matter most. We do not sell your data. We do not use it to train AI models, and neither do our AI providers under their commercial terms. You can ask for an export or a deletion at any time and we will do it.

1. Who controls your data

[LEGAL ENTITY NAME], at [BUSINESS ADDRESS], is the data controller for information about you as our customer. Privacy questions and requests go to [PRIVACY EMAIL].

For the content inside your account — your customers' emails, their names and order details — you are the controller and we are your processor. We handle that material on your instructions, to run your agents, and for nothing else.

2. What we collect

Information you give us directly

Information we process from connected accounts

Once you connect a service, the agents read what they need to do their work. Depending on what you connect, that can include:

We request the narrowest access that makes each feature work — for email, the ability to read messages and to send the replies you approve.

Information generated by the service

Technical information

Our hosting provider records standard server logs, including IP address, request time, and pages requested, for security and debugging. Our site uses no advertising trackers and no third-party analytics. We load fonts from Google Fonts, which means Google receives the IP address of visitors to our pages.

3. Why we process it

PurposeLegal basis (UK/EU GDPR)
Running your agents and producing your briefingsPerformance of our contract with you
Setting up your account and providing supportPerformance of our contract with you
Taking payment and keeping accounting recordsContract, and legal obligation
Replying to an early-access enquiry you submittedLegitimate interests, or your consent
Keeping the service secure and debugging faultsLegitimate interests

We do not use your data for advertising, we do not build profiles for marketing, and we do not make automated decisions with legal effects about anyone.

4. Who else processes it

We use a small number of subprocessors. Each one receives only what its job requires.

ProviderWhat it doesWhat it receives
AnthropicThe AI models that draft your contentThe prompt sent for each task: your knowledge base plus the relevant input, such as an email being answered
HiggsfieldGenerates images for social postsThe image description for the post
StripePayments and subscriptionsYour billing details and card data, collected directly by Stripe
[HOSTING PROVIDER, e.g. Render]Runs the servers and stores the databaseAll stored account data
GoogleGmail access when you connect it, and web fonts on our siteMailbox access under the permissions you grant; visitor IP addresses for fonts
MetaPublishing approved posts when you connect itThe post content you approved

Our AI providers process your prompts to return a response and, under their commercial API terms, do not use them to train their models. Some subprocessors are based in the United States, so data may be transferred there; where required we rely on Standard Contractual Clauses or an equivalent transfer mechanism.

Beyond these, we disclose data only if you ask us to, if we are legally compelled to, or to protect against fraud or an imminent threat to someone's safety. If our business is ever sold, we will tell you before your data moves.

5. How long we keep it

DataRetention
Account, knowledge base, and connection settingsWhile your account is open, then deleted within [NUMBER, e.g. 30] days of closure
Drafts, approvals, and activity logs[NUMBER, e.g. 12] months, then deleted
Briefings and reportsWhile your account is open
Early-access signups that do not become customers[NUMBER, e.g. 24] months, then deleted
Invoices and payment recordsAs long as tax law requires, typically [NUMBER, e.g. 7] years
Server logs[NUMBER, e.g. 30] days

We do not keep copies of your email. Messages are read to produce a draft and are not stored on our servers beyond the draft and the log entry recording that the agent acted.

6. How we protect it

No system is perfectly secure. If a breach affects your data we will tell you and, where the law requires it, the relevant regulator — without undue delay and within [NUMBER, e.g. 72] hours of becoming aware where GDPR applies.

7. Your rights

Wherever you are, you can ask us to: give you a copy of your data, correct it, delete it, export it in a portable format, restrict how we use it, or object to processing based on legitimate interests. If you are in the UK or EU you have these rights under GDPR; if you are in California you have comparable rights under the CCPA, including the right not to be discriminated against for exercising them. We do not sell personal information, so there is nothing to opt out of on that front.

Email [PRIVACY EMAIL] and we will respond within 30 days. We may need to verify who you are first.

If your data reached us because a business you deal with uses Otto, that business controls it — ask them, and we will support their response. If you are unhappy with how we have handled a request, you can complain to your data protection authority (in the UK, the ICO).

8. Children

The service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children. If you think we have, tell us and we will delete it.

9. Cookies

We use no advertising or analytics cookies. Your browser's local storage holds your email address on the setup pages so you do not have to retype it, and a logged-in session uses a strictly necessary cookie. Nothing here tracks you across other websites.

10. Changes

We will update this policy as the service develops, and the date at the top will change. For material changes we will email you at least [NUMBER, e.g. 30] days beforehand.

11. Contact

Privacy questions, requests, and complaints go to [PRIVACY EMAIL], or write to [LEGAL ENTITY NAME] at [BUSINESS ADDRESS].