Legal
Privacy Policy
Last updated 2 August 2026
What we store
Your account details, the agents you create, and the data those agents produce: email messages sent and received, memories, projects, tasks and browser session logs. That's the product — we can't provide an inbox without storing mail.
What we don't do
We do not train models on your data, and we do not sell it or share it with advertisers. Your mail, memories and tasks are yours.
Sub-processors
Supabase hosts the database and authentication. Mailgun handles email delivery and inbound routing. Both process data on our behalf under their own terms.
Security
Every table is protected by row-level security scoped to your account. API keys are stored as SHA-256 hashes and cannot be recovered — only revoked and reissued. Inbound webhooks are signature-verified and reject payloads older than five minutes.
Retention and deletion
Deleting an agent removes its inbox history, memories and keys. Deleting your account removes everything associated with it. Backups age out on a rolling 30-day window.
Contact
Questions about this policy, or a data request: privacy@ottoidentity.com.