Otto.

You are handing Otto your inbox. Here is how we treat that.

Your data is encrypted, never used to train anything, and deleted when you leave. That sentence is on every page of this site because it is the whole deal. Below is what sits behind it, in plain words.

Encrypted, with a key that is yours alone

Everything Otto keeps for your company, including the passwords and keys you give it for other tools, is locked with an encryption key created for your company only. Even a copy of the whole database is unreadable without it. Keys are unlocked only for the moment Otto needs them and are never written to disk in the open.

Encrypted on the way, too

Every connection, between you and Otto, Otto and Slack, Otto and Google, and Otto and any tool you plug in, is encrypted in transit. There is no unencrypted path.

Your company is walled off from every other

Each customer gets its own separate Otto: a separate running process, separate storage, and a separate encryption key. One company’s Otto cannot see, touch or be confused with another’s.

Never used to train anything

Your emails, documents and numbers are used to answer you, and for nothing else. We do not use them to improve Otto, and neither do the providers we work with. This is in our contracts with them and in our Terms with you.

Deleted when you leave

Cancel and Otto stops the same day. Within 30 days everything is permanently deleted: your memory, your stored credentials, your conversation history. You can also press the button yourself from the dashboard, at any time, and it happens immediately. The docs Otto wrote live in your own Google Drive, so those stay with you.

Only what you allow

Otto asks Google for exactly the permissions it needs and no more: read and send your mail, manage your calendar, and create or edit documents it made itself. It cannot see files in your Drive that it did not create. Each person on your team connects their own account, so Otto only reads the mail it has been given permission to read.

A record of every action

Every time Otto sends an email, changes your calendar, or reads from a tool you plugged in, that action is recorded with who asked for it and when. If you ever want to know what Otto did on your behalf, the answer exists.

Nothing sensitive in our logs

Our own technical logs, the ones our engineers look at to fix problems, have email addresses, names and other personal details removed before they are written. Engineers see that something happened, not what it said.

Verified messages, always

Every message Otto receives from Slack is checked to prove it really came from Slack. Every sign-in with Google is protected against the two common ways sign-ins get hijacked. Each company also has a limit on how fast requests can arrive, so a runaway script cannot burn through your plan.

What Otto does not do yet

We would rather tell you now. Otto does not yet offer single sign-on for large companies, does not run on your own servers, and is not certified for handling medical records. If you need any of those, Otto is not the right tool for you today.

Who to talk to

Security questions, a data processing agreement, or a report of something you found: security@otto.example. We answer within one business day. The legal detail is in our Privacy policy, Data processing agreement and list of subprocessors, the companies whose services we use to run Otto.

Add to Slack