otto
Effective Date: March 31, 2026 · Last Updated: March 31, 2026
Otto is designed with privacy as a foundational principle. We collect only what is necessary to provide the Service, we never sell your personal data, and you can delete everything at any time.
Otto ("Service") is operated by Kevin Ho ("Operator," "we," "us," "our") at ottolab.com. This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you use the Otto web application, mobile application, and related services.
For privacy inquiries, contact: privacy@ottolab.com
| Data Type | Examples | Purpose |
|---|---|---|
| Account information | Email address, first name, display name | Authentication and personalization |
| Demographic data | Age, biological sex, height, weight | Required for biological age computation and metabolic scoring |
| Laboratory reports | PDF or CSV files containing blood work results | Biomarker extraction and analysis |
| Health stack | Supplements, medications, habits, devices you report taking | Stack tracking, community features, and personalized insights |
| Community content | Journey posts, captions, reactions, profile bio | Social features you opt into |
| Chat messages | Questions and conversations with the AI assistant | Providing AI-powered health insights |
| Data Type | Examples | Purpose |
|---|---|---|
| Device information | Device type, operating system, browser type | Service optimization and debugging |
| Usage data | Pages visited, features used, timestamps | Service improvement |
| Authentication tokens | JWT session tokens stored as httpOnly cookies | Secure session management |
If you choose to connect Apple Health through the Otto iOS app, we collect:
This data is only collected with your explicit permission through the iOS HealthKit permission prompt. You can revoke this permission at any time in your iPhone Settings. We do not access any other Apple Health data categories beyond those listed above.
We use your information solely for the following purposes:
To generate AI-powered insights, we transmit portions of your health data (biomarker values, health stack, and conversation context) to:
These providers process your data according to their respective API data usage policies. We use their API services (not consumer products), which generally do not use your data for model training. However, we encourage you to review their policies directly.
| Provider | Purpose | Data Processed |
|---|---|---|
| Vercel | Web hosting | HTTP requests, static assets |
| Railway | API hosting, database, cache | All application data |
| Resend | Transactional email | Email addresses |
| Google Cloud | File storage (future) | Uploaded documents |
We may disclose your information if required by law, subpoena, court order, or government regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
Your data is stored on servers in the United States operated by Railway (PostgreSQL database) and Vercel (web application). Backups are encrypted at rest.
No method of electronic storage or transmission is 100% secure. While we use commercially reasonable security measures, we cannot guarantee absolute security of your data. You use the Service at your own risk.
| Data Type | Retention Period |
|---|---|
| Account data | Until you delete your account |
| Biomarker data | Until you delete your account |
| Uploaded PDF/CSV files | Processed and discarded — raw files are not permanently stored |
| Chat conversations | Until you delete your account |
| Apple Health data | Until you delete your account or revoke access |
| Community posts | Until you delete the post or your account |
| Audit logs | 90 days, then automatically purged |
You have the following rights regarding your data:
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact privacy@ottolab.com.
If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectification, erasure, restriction of processing, data portability, and the right to object. Our legal basis for processing is your explicit consent (provided when you upload data) and legitimate interest (for service operation). To exercise your rights or lodge a complaint, contact privacy@ottolab.com.
The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will promptly delete that information.
We use the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
otto_token | Authentication session (httpOnly, secure) | 24 hours |
preview_token | Beta access gate (httpOnly) | 30 days |
We do not use advertising cookies, analytics cookies, or third-party tracking cookies.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy with a new effective date. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
For any privacy-related questions, concerns, or data requests:
Email: privacy@ottolab.com
Otto Lab
Operated by Kevin Ho
California, United States
© 2026 Otto Lab. All rights reserved.