Privacy Policy
Last updated: July 11, 2026
This Privacy Policy explains how Otto ("Otto," "we," "us," or "our"), operated in connection with heyotto.me, collects, uses, stores, shares, and protects information when you use our website, SMS/iMessage-based service, waitlist, and paired iOS companion application (together, the "Service").
1. Overview
Otto is a text-based life assistant. You interact primarily by messaging Otto. A paired iOS app enables certain device-level features, most importantly Screen Time / Family Controls–based app shielding for Focus Zone, and writing workout or activity data to Apple Health (HealthKit) for Fitness Canvas.
We collect only what we need to operate and improve the Service, honor your requests, communicate with you, and meet legal and App Store requirements. We do not sell your personal information. We do not use Apple HealthKit data or Screen Time / Family Controls data for advertising or marketing.
2. Scope of This Policy
This Policy applies to:
- Our website and marketing pages (including waitlist signup);
- SMS, RCS, or iMessage (or similar messaging) conversations with Otto;
- The Otto paired iOS application distributed via the Apple App Store;
- Related support channels (for example, email to support@heyotto.me).
It does not cover third-party websites, Apple's own privacy practices, cellular carriers, or other apps you choose to connect. Apple's handling of Health and Screen Time data on your device is governed by Apple's policies and your iOS settings.
3. Information We Collect
Depending on how you use the Service, we may collect the categories below. Not all categories apply to every user.
3.1 Information you provide
- Contact & account identifiers: phone number, and if you provide them, name, email address, or other contact details.
- Messages & content: the text (and any attachments or media you send) in messages to Otto, including instructions such as focus requests, workout logs, reminders, calendar-related requests, and preferences.
- Waitlist & consent records: phone number, SMS consent status, signup source, and timestamp when you join the waitlist or opt in to texts.
- Support communications: information you include when you email or otherwise contact us.
- Preferences & settings: focus schedules, blocked-app choices (as configured through the Service), notification preferences, and similar settings you choose.
3.2 Information from the paired iOS app
- Device & app identifiers: device model, iOS version, app version, push notification tokens, and identifiers needed to pair your phone number with the installed app and deliver focus or sync commands.
- Pairing & authentication data: codes, tokens, or session data used to link your messaging identity to the iOS app securely.
- Diagnostics & performance: crash logs, performance metrics, and coarse usage events (for example, that a focus session started or ended) to keep the app reliable. Where possible we minimize or aggregate this data.
- Permissions status: whether you have granted or denied permissions such as Screen Time / Family Controls authorization, HealthKit access, notifications, or other capabilities the feature requires (we learn authorization state so we can tell you if a feature cannot run, not to circumvent your choices).
3.3 Screen Time / Family Controls–related information
See Section 4 for details. In short: we process the minimum data needed to apply and lift app shields or focus restrictions you request, and to confirm that those restrictions are active.
3.4 Health & fitness information
See Section 5. When you use Fitness Canvas, we process workout and related activity information you provide by message and/or authorize us to write to (and, if you choose, read from) Apple Health.
3.5 Information collected automatically on the website
- Standard server logs (IP address, browser type, referring URL, timestamps) and similar technical data when you visit heyotto.me.
- Cookies or local storage only as needed for basic site function, security, or (if enabled) aggregated analytics. We do not use HealthKit or Screen Time data in website tracking.
3.6 Information we do not collect for Otto's core features
We do not require access to the full contents of your photo library, microphone, or contacts to provide Focus Zone or Fitness Canvas. We do not sell personal information. We do not use the precise contents of your HealthKit store for advertising.
4. Screen Time, Family Controls & Focus Features
Focus Zone uses Apple frameworks such as Family Controls, Managed Settings, and/or Device Activity (and related Screen Time capabilities) so that when you text Otto to lock distracting apps, the paired iOS app can apply system-level shields until your focus period ends or you ask to unlock.
4.1 What we process
- Your focus requests and parameters (for example, duration, end time, categories or apps you asked to block).
- Authorization status for Family Controls / Screen Time APIs.
- State needed to apply, monitor, and remove Managed Settings shields (for example, whether a shield is currently on, and which tokenized app or category selections you authorized the app to manage).
- Limited Device Activity or schedule signals required to start or end a focus session you requested.
4.2 What we do not do with this data
- We do not sell Screen Time, Family Controls, or Device Activity data.
- We do not use this data for third-party advertising or cross-app tracking.
- We do not use Family Controls / Screen Time APIs to surveil unrelated device activity beyond what is required to provide the focus feature you requested.
- We do not circumvent Apple's permission prompts or parental controls. You (or a parent/guardian, where applicable) must grant authorization in iOS.
4.3 On-device vs. our servers
App shielding is enforced on your device through Apple's APIs. We may send encrypted commands or session metadata from our servers to your paired app (for example, "start focus until 4pm" or "end focus") so that a text message can trigger the shield. We retain only what is needed to operate the feature, show status in Messages, troubleshoot failures, and prevent abuse.
4.4 Your control
You can revoke Family Controls / Screen Time authorization in iOS Settings, uninstall the Otto app, or text Otto to end a focus session (subject to any intentional "lock-in" rules you configure and Apple's platform limits). Revoking permission will disable Focus Zone until you re-authorize.
5. Health & Fitness Data (Apple Health / HealthKit)
Fitness Canvas lets you log workouts and related activity in plain language. With your permission, the paired iOS app may write that information to Apple Health (HealthKit) and, if you allow it, read limited Health data needed to confirm syncs, avoid duplicates, or show you summaries you request.
5.1 Types of health & fitness data
Depending on your use and permissions, this may include:
- Workout type (for example, run, walk, strength), duration, distance, start/end time, and related metrics you provide or that are derived from your message.
- Energy, heart-rate, or other samples only if you explicitly authorize those HealthKit types and the feature needs them.
- Streaks, weekly totals, or other fitness summaries generated from your logged activity.
5.2 Purpose of use
We use Health & Fitness data solely to:
- Log and sync workouts you request;
- Confirm successful writes to Apple Health;
- Provide status replies in Messages and in-app fitness features;
- Improve reliability of parsing and sync (for example, fixing failed writes), not for advertising.
5.3 Apple HealthKit commitments
Consistent with Apple's HealthKit requirements and our own practices:
- HealthKit data is not used for advertising, marketing, or sold to data brokers, advertising platforms, or information resellers.
- HealthKit data is not used to build advertising profiles or for similar commercial data-mining unrelated to providing the fitness features you requested.
- Access to HealthKit requires your explicit iOS permission. You can change or revoke access in iOS Settings → Health → Data Access & Devices (or the equivalent path on your OS version).
- Otto is not a medical device and does not provide medical diagnosis, treatment, or emergency services. Health data in Otto is for personal fitness logging and organization only.
5.4 Storage of health-related content
Message content that describes workouts may be stored on our systems as part of your conversation history so Otto can respond, maintain your log, and troubleshoot. Data written into Apple Health remains in your Health store under Apple's and your control. You may request deletion of Otto-held fitness history as described in Section 10; deleting Otto's copy does not automatically delete samples already saved in Apple Health. You can manage those in the Health app.
6. How We Use Your Information
We use information to:
- Provide, operate, and improve the Service (messaging, focus/shielding, fitness logging, reminders, and related features);
- Pair your messaging identity with the iOS app;
- Send service messages, transactional texts, and (with consent) waitlist or product updates;
- Authenticate users and prevent fraud or abuse;
- Debug, monitor uptime, and secure our systems;
- Comply with law, enforce our Terms, and respond to lawful requests;
- Analyze aggregated or de-identified trends to improve product quality (never using HealthKit data for advertising).
8. Data Retention
We retain personal information only as long as needed for the purposes described in this Policy, including to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.
- Account & pairing data: for as long as your account is active and for a reasonable period afterward for security and fraud prevention.
- Message history: while your account is active, unless you request deletion earlier or we set shorter product-specific retention.
- Focus session metadata: for the duration needed to operate sessions and for limited historical/troubleshooting retention.
- Health-related logs on our servers: while needed to provide Fitness Canvas and respond to your requests; you may ask us to delete Otto-held copies.
- Waitlist records: until you ask to be removed or we close the waitlist campaign.
- Diagnostics: typically for shorter operational windows unless needed longer for security investigations.
9. Security
We implement administrative, technical, and organizational measures designed to protect personal information, such as encryption in transit (HTTPS/TLS), access controls, and least- privilege practices for staff and vendors. No method of transmission or storage is completely secure; we cannot guarantee absolute security. Please use a passcode/biometrics on your device and keep iOS updated.
10. Your Choices & Rights
Depending on where you live, you may have rights to:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Delete personal information we hold (subject to legal exceptions);
- Export or receive a copy of certain data;
- Opt out of marketing texts (service texts may still be needed if you continue using Otto);
- Withdraw consent where processing is consent-based;
- Appeal or lodge a complaint with a regulator where applicable.
To exercise these rights, email support@heyotto.me with the subject line "Privacy Request" and enough detail for us to verify your identity (for example, the phone number associated with your account).
Device-level controls: revoke Health or Screen Time permissions in iOS Settings; disable notifications; or delete the Otto app. Deleting the app may not delete server-side account or message data. Contact us for full deletion.
11. SMS / Messaging Communications
By providing your phone number and opting in (for example, checking the consent box on our site or completing in-app pairing), you consent to receive automated and manual text messages from Otto related to the Service. Message frequency varies. Message and data rates may apply. Reply STOP to cancel marketing or waitlist texts as applicable; reply HELP for help. Consent to texts is not a condition of purchase. Carrier filtering or delivery failures are outside our control.
12. Children's Privacy
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it. Where Family Controls are used in a parent–child context, parents/guardians are responsible for managing Apple's parental permissions and for supervising a minor's use of Otto in accordance with our Terms.
13. International Users
Otto is operated from the United States and initially offered for U.S. iPhone users. If you access the Service from outside the U.S., you understand that your information may be processed in the United States and other countries that may have different data- protection rules than your country. Where required, we will take appropriate measures for cross-border transfers.
14. U.S. State Privacy Disclosures
If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have rights to know, delete, correct, and opt out of certain "sales" or "sharing" of personal information. We do not sell personal information as that term is commonly defined, and we do not share HealthKit or Screen Time data for cross-context behavioral advertising. To submit a request, email support@heyotto.me. We will not discriminate against you for exercising privacy rights.
Categories of personal information we collect align with Sections 3–5 (identifiers, customer records, internet/electronic activity, health information as described, and inferences limited to operating features you request).
15. Apple Platform Requirements
Our iOS app may request access to sensitive Apple frameworks. We use those frameworks only for the user-facing features described in this Policy and in the App Store listing, including:
- Family Controls / Managed Settings / Device Activity: to provide Focus Zone app shielding at your request;
- HealthKit: to provide Fitness Canvas logging and Apple Health sync at your request;
- Push Notifications: optional alerts related to focus sessions, sync status, or service notices.
App Store "Privacy Nutrition Labels" summarize data types linked to you or used to track you. This Policy is the controlling detailed description. If there is a conflict between a short label and this Policy, this Policy and our in-app disclosures explain our practices more fully.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may also be communicated via the Service, email, or SMS where appropriate. Continued use after changes become effective constitutes acceptance of the updated Policy, except where additional consent is required by law.
17. Contact Us
For privacy questions, data requests, or concerns, contact:
Otto
Website: https://heyotto.me
Email: support@heyotto.me
Related: Terms of Service.