Privacy policy
Otto runs on your Mac. The app has no account, no analytics and no server of its own. This page lists everything the signed app sends, where it goes, what stays on your Mac, and what this website records.
When you send a message
Otto sends nothing to Anthropic until you press send. Then it sends a request to api.anthropic.com over HTTPS, with your own API key. The request carries your message, anything you attached (a file, an image, a screenshot, selected text, or a browser tab's title and address), your custom instructions, the conversation so far and today's date.
With Actions on, the request also carries your time zone and local time. While Claude answers, Otto sends back the result of each action that runs. That covers the calendar events and reminders it reads or adds, the names of your shortcuts and what a shortcut returns, what an AppleScript returns, and the track, artist and state of Music or Spotify. Anthropic's privacy policy covers all of this data.
License checks
About once a day, and when you activate, deactivate or click Check Now, the signed app contacts api.polar.sh. Every request carries your license key and Otto's organization ID at Polar. A check adds Otto's license benefit ID at Polar and this Mac's activation ID, and deactivating adds the activation ID. When you activate, the app also sends a label like "Mac 7F3A" made from random characters. Each request names the app and its version in its User-Agent header, such as Otto/1.1.0, and carries no cookies. Otto never sends your name, your email, your Mac's name or a hardware ID.
Polar's answer also includes the customer record that belongs to the key. Otto reads only what it needs to check the license (the key's status, seat limit and IDs) and never reads the customer record. Polar records the time and count of each check and the activation label, and links them to your purchase, so I can see when a license was last checked. I use this only for support.
Updates
Once a day the signed app downloads the list of releases from ottonotch.com/appcast.xml. The request carries Otto's version number and nothing that identifies you or your Mac. Updates download from hbf1i2zuh6iqdyiw.public.blob.vercel-storage.com, which is Vercel's file storage. You can turn automatic checks off in Settings, License.
Other requests
If Now Playing is on and Spotify is playing, Otto loads the album art from Spotify's image server. Only if you turn on Apple's speech service in Settings, Voice, your recorded audio goes to Apple for transcription; otherwise speech is recognized on your Mac. Web search and web fetch run on Anthropic's servers, not on your Mac.
What every server sees
Each of these servers sees your IP address, like any website you visit, and keeps logs under its own policy: Anthropic, Polar, Vercel, Spotify's image server and, if you turn it on, Apple's speech service.
What stays on your Mac
Your API key, license key, activation ID and trial start date are in your login Keychain. Conversations, the File Shelf, the actions activity log and usage totals are in your Library folder. A conversation leaves your Mac only in the requests to Anthropic described above, after you press send, and a Shelf file only when you attach it. The activity log and usage totals never leave your Mac. You choose how long history is kept in Settings, Privacy.
When you buy
Polar runs the checkout as the merchant of record. It collects your name, email, billing address and payment details under its privacy policy. Polar records you as a customer of my Polar organization, and my Polar dashboard shows me your orders: your name and email, the billing name and address, the amount and tax, and your license key with its activations and checks. I use your email only to reply to you and to handle refunds. No newsletter unless you ask for one.
This website
ottonotch.com is hosted by Vercel, which keeps standard server logs. The site counts page views with Vercel Web Analytics. Its script sets no cookies. Instead, Vercel tells visitors apart by a hash made from each incoming request, and it discards each visitor session after 24 hours.
With each page view, Vercel stores the time, the page's address, the site that linked you here, your country, region and city, your operating system and browser with their versions, whether you're on a phone, tablet or computer, and the script's version. These pages remove anything after "?" or "#" in the address before it's sent. I see only totals. The Otto app has no analytics or telemetry.
Your rights
Jalen Edusei is responsible for the purchase details I can see in Polar. I keep them while you hold a license, and longer only where tax law requires it. You can ask me for a copy, a correction or deletion at jalenedusei@gmail.com, and you can complain to your data protection authority.
Deleting your data
Quit Otto and delete the Otto folder in Application Support. In Keychain Access, delete the items whose names start with "Otto (", such as "Otto (license)" and "Otto (trial)". To delete your purchase records, email me. Polar keeps what tax law requires.