Otto — Privacy Policy
Otto (my.ottocare.app) is a private, invitation-only voice assistant for one family, operated by Rennick & Rennick LLC (Ohio, USA). This page explains, in plain English, what information Otto handles and why. Contact: mikerennick@gmail.com.
1. What we collect
- Sign-in information — your name and email address, handled by Amazon Cognito (optionally via Google sign-in).
- Profile information entered by the family concierge — contacts, addresses, routines, and health and dietary notes used to personalize the assistant.
- Conversations with Otto — your voice is converted to text, and transcripts are retained so the assistant can provide the service and keep context.
- Reminders, notes, and notifications — reminders, things you ask Otto to remember, and push-notification subscriptions.
- Forwarded email — if the family sets up email forwarding, a copy of mail sent to the account holder is forwarded from their own Gmail to a private Otto address so the assistant can help with their email. See “Email forwarding” below.
- Approximate device location — only when the parent asks for directions, a ride, or the weather, only with their phone's permission, and only for that request. It is used to answer that one question and is not stored.
- Basic technical logs — used to keep the service running and debug problems.
2. How we use it
Solely to provide the assistant's features to the family. We do not use your information for advertising, we do not sell or share personal information for marketing, and there are no third-party ads or trackers.
3. AI processing
Conversations with Otto are processed by Anthropic's Claude API to generate the assistant's responses.
4. Connected accounts
These apply only when the account holder (or the concierge, with their consent) connects them:
- Google (Calendar, Gmail) — used to read the user's own calendar and mail, limited to the scopes granted at connection time.
- Kroger — used to search products and add items to the user's own cart. Otto cannot see Kroger order history or payment details, and it cannot place orders.
OAuth tokens for connected accounts are stored server-side only, are never sent to the browser, and are deleted when the account is disconnected.
5. Email forwarding
With the family’s consent, the account holder’s own Gmail can forward a copy of incoming mail to a private Otto address so the assistant can read it aloud, summarize it, and help with replies. When this is set up:
- Storage & encryption — forwarded mail is stored encrypted at rest in Otto’s infrastructure (Amazon Web Services, US regions).
- Retention — forwarded mail is kept for 90 days and then automatically deleted. Mail the family marks as important is kept longer, until it is unmarked.
- Use — forwarded mail is used only to provide the assistant’s features to the account holder and their family. It is never sold, never shared for marketing, and never used for advertising.
- Replies — replies the account holder asks Otto to send go out through the account holder’s own Google account, so recipients see their real address.
- Control — the account holder’s own Gmail inbox keeps every message (forwarding is a copy), and the family can turn forwarding off at any time in Gmail or disable the Otto address in the concierge console.
6. Service providers
We use a small number of processors, each receiving only what it needs to do its job: Amazon Web Services (hosting and storage, US regions), Anthropic (AI responses), Google and Kroger (when connected), and the device's push-notification service.
7. Retention & deletion
Data is kept while the account is active. Account holders — or the family concierge on their behalf — can request access to, correction of, or deletion of their data at any time by emailing mikerennick@gmail.com.
8. Security
All traffic uses HTTPS. Credentials and API keys are held in a secrets manager, and access to systems and data is limited to the operator.
9. Children
Otto is not directed to children under 13.
10. Changes
If this policy changes, the updated version will be posted on this page with a new effective date.