Privacy Policy

Effective Date: March 31, 2026 · Last Updated: March 31, 2026

Otto is designed with privacy as a foundational principle. We collect only what is necessary to provide the Service, we never sell your personal data, and you can delete everything at any time.

1. Who We Are

Otto ("Service") is operated by Kevin Ho ("Operator," "we," "us," "our") at ottolab.com. This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you use the Otto web application, mobile application, and related services.

For privacy inquiries, contact: privacy@ottolab.com

2. Information We Collect

2.1 Information You Provide

Data TypeExamplesPurpose
Account informationEmail address, first name, display nameAuthentication and personalization
Demographic dataAge, biological sex, height, weightRequired for biological age computation and metabolic scoring
Laboratory reportsPDF or CSV files containing blood work resultsBiomarker extraction and analysis
Health stackSupplements, medications, habits, devices you report takingStack tracking, community features, and personalized insights
Community contentJourney posts, captions, reactions, profile bioSocial features you opt into
Chat messagesQuestions and conversations with the AI assistantProviding AI-powered health insights

2.2 Information Collected Automatically

Data TypeExamplesPurpose
Device informationDevice type, operating system, browser typeService optimization and debugging
Usage dataPages visited, features used, timestampsService improvement
Authentication tokensJWT session tokens stored as httpOnly cookiesSecure session management

2.3 Apple Health Data (Mobile App Only)

If you choose to connect Apple Health through the Otto iOS app, we collect:

This data is only collected with your explicit permission through the iOS HealthKit permission prompt. You can revoke this permission at any time in your iPhone Settings. We do not access any other Apple Health data categories beyond those listed above.

2.4 Information We Do NOT Collect

3. How We Use Your Information

We use your information solely for the following purposes:

4. How We Share Your Information

4.1 Third-Party AI Model Providers

To generate AI-powered insights, we transmit portions of your health data (biomarker values, health stack, and conversation context) to:

These providers process your data according to their respective API data usage policies. We use their API services (not consumer products), which generally do not use your data for model training. However, we encourage you to review their policies directly.

4.2 Infrastructure Providers

ProviderPurposeData Processed
VercelWeb hostingHTTP requests, static assets
RailwayAPI hosting, database, cacheAll application data
ResendTransactional emailEmail addresses
Google CloudFile storage (future)Uploaded documents

4.3 We Never

4.4 Legal Requirements

We may disclose your information if required by law, subpoena, court order, or government regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

5. Data Storage and Security

5.1 Where Your Data is Stored

Your data is stored on servers in the United States operated by Railway (PostgreSQL database) and Vercel (web application). Backups are encrypted at rest.

5.2 Security Measures

5.3 What We Cannot Guarantee

No method of electronic storage or transmission is 100% secure. While we use commercially reasonable security measures, we cannot guarantee absolute security of your data. You use the Service at your own risk.

6. Data Retention

Data TypeRetention Period
Account dataUntil you delete your account
Biomarker dataUntil you delete your account
Uploaded PDF/CSV filesProcessed and discarded — raw files are not permanently stored
Chat conversationsUntil you delete your account
Apple Health dataUntil you delete your account or revoke access
Community postsUntil you delete the post or your account
Audit logs90 days, then automatically purged

7. Your Rights

You have the following rights regarding your data:

California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact privacy@ottolab.com.

EU/EEA Residents (GDPR)

If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectification, erasure, restriction of processing, data portability, and the right to object. Our legal basis for processing is your explicit consent (provided when you upload data) and legitimate interest (for service operation). To exercise your rights or lodge a complaint, contact privacy@ottolab.com.

8. Children's Privacy

The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will promptly delete that information.

9. Cookies

We use the following cookies:

CookiePurposeDuration
otto_tokenAuthentication session (httpOnly, secure)24 hours
preview_tokenBeta access gate (httpOnly)30 days

We do not use advertising cookies, analytics cookies, or third-party tracking cookies.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy with a new effective date. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

11. Contact Us

For any privacy-related questions, concerns, or data requests:

Email: privacy@ottolab.com

Otto Lab
Operated by Kevin Ho
California, United States

© 2026 Otto Lab. All rights reserved.