You are handing Otto your inbox. Here is how we treat that.
Your data is encrypted, never used to train anything, and deleted when you leave. That sentence is on every page of this site because it is the whole deal. Below is what sits behind it, in plain words.
Encrypted, with a key that is yours alone
Everything Otto keeps for your company, including the passwords and keys you give it for other tools, is locked with an encryption key created for your company only. Even a copy of the whole database is unreadable without it. Keys are unlocked only for the moment Otto needs them and are never written to disk in the open.
Encrypted on the way, too
Every connection, between you and Otto, Otto and Slack, Otto and Google, and Otto and any tool you plug in, is encrypted in transit. There is no unencrypted path.
Your company is walled off from every other
Each customer gets its own separate Otto: a separate running process, separate storage, and a separate encryption key. One company’s Otto cannot see, touch or be confused with another’s.
Never used to train anything
Your emails, documents and numbers are used to answer you, and for nothing else. We do not use them to improve Otto, and neither do the providers we work with. This is in our contracts with them and in our Terms with you.
Deleted when you leave
Cancel and Otto stops the same day. Within 30 days everything is permanently deleted: your memory, your stored credentials, your conversation history. You can also press the button yourself from the dashboard, at any time, and it happens immediately. The docs Otto wrote live in your own Google Drive, so those stay with you.
Only what you allow
Otto asks Google for exactly the permissions it needs and no more: read and send your mail, manage your calendar, and create or edit documents it made itself. It cannot see files in your Drive that it did not create. Each person on your team connects their own account, so Otto only reads the mail it has been given permission to read.
A record of every action
Every time Otto sends an email, changes your calendar, or reads from a tool you plugged in, that action is recorded with who asked for it and when. If you ever want to know what Otto did on your behalf, the answer exists.
Nothing sensitive in our logs
Our own technical logs, the ones our engineers look at to fix problems, have email addresses, names and other personal details removed before they are written. Engineers see that something happened, not what it said.
Verified messages, always
Every message Otto receives from Slack is checked to prove it really came from Slack. Every sign-in with Google is protected against the two common ways sign-ins get hijacked. Each company also has a limit on how fast requests can arrive, so a runaway script cannot burn through your plan.
What Otto does not do yet
We would rather tell you now. Otto does not yet offer single sign-on for large companies, does not run on your own servers, and is not certified for handling medical records. If you need any of those, Otto is not the right tool for you today.
Who to talk to
Security questions, a data processing agreement, or a report of something you found: security@otto.example. We answer within one business day. The legal detail is in our Privacy policy, Data processing agreement and list of subprocessors, the companies whose services we use to run Otto.