Privacy Policy
Otto is a free AI car assistant. You show it a dashboard light, a leak, some damage, or a repair estimate, and it gives you a straight answer grounded in your own car's details. To do that it has to handle some personal data. This page says exactly what, why, who else sees it, how long we keep it, and how to get it deleted. It is written to be read, not skimmed. If anything here is unclear, email [[SUPPORT_EMAIL]].
1. Who we are
Otto is operated by [[LEGAL_NAME]], [[ADDRESS]] ("Otto", "we", "us"). We are the data controller for the information described here.
2. What we collect
Everything below is something you type, photograph, or choose in the app. Otto has no hidden collection: no advertising identifiers, no third-party analytics or crash-reporting SDKs, and no access to your phone's GPS.
Account
- Email address, and a name if you sign in with Apple or Google and share one, or if you add one in Settings. Sign-in is handled by Supabase Auth using a one-time email code, Sign in with Apple, or Google.
- A random user ID that ties your data together, and the timestamps when you accepted the AI consent screen and (if you did) the optional photo-improvement setting.
- Your sign-in session token is stored on your phone in the iOS Keychain so you stay signed in.
Home location
- If you enter a home ZIP code in Settings, the app looks it up and stores the ZIP, city, state, and the ZIP code's approximate latitude/longitude (the centre of the ZIP area, not your address). This is used only to find repair shops near you. Otto never uses the phone's location services.
Your cars
- VIN (typed, or read from a photo of the door-jamb sticker), year, make, model, trim, engine, drivetrain, body style, an optional nickname, licence plate if you enter one, and mileage with the date you updated it.
- Optional baseline photos of the car.
Photos and documents
- Photos you take or pick from your library: dashboard lights, leaks, damage, parts, the VIN sticker, and photos taken during a DIY step. The app resizes them (longest side 1600 px) and uploads them to a private storage bucket under your user ID. Nothing in that bucket is publicly reachable; the app and our server read it with short-lived signed links.
- Repair estimates, invoices, and receipts you scan, plus the structured text Otto extracts from them (shop name, line items, totals).
- Otto only accesses the camera or photo library when you tap to take or choose a photo, and iOS asks your permission first.
Conversations and assessments
- Chat messages you send to Otto and the replies it gives, including which car the chat was about.
- Problem reports: the symptoms you describe, when they started, how it happened, the photos you attached, and the assessment Otto produced (likely causes, triage level, what to check first, typical cost range).
- DIY jobs: the procedure Otto wrote for you, which step you are on and when you finished each one, photos you took on a step, and, if you chose to proceed against Otto's recommendation, the risk acknowledgement you accepted (its wording version and the time).
Service history
- Service records you log: the kind of work, notes, date, mileage, and cost, and records Otto creates when you finish a DIY job.
Beta interest list (website)
- If you ask for a beta invite on this website, we store the email address you enter and, if you add them, your name, car, and ZIP code, together with the time you signed up. We use them only to send invites and to prioritise which cars and regions to support first. Email [[SUPPORT_EMAIL]] to be removed; we delete the row within 30 days.
Operational records
- Usage counts for AI requests (which feature, which model, how many tokens), used for rate limiting and cost control. These do not contain the content of your requests.
- An audit log of significant actions tied to your account (for example "consent accepted", "risk waiver accepted", "assessment created"). It is append-only so it cannot be quietly edited.
- Our hosting provider keeps short-lived server logs (IP address, timestamps, request size, error messages) for debugging. We do not build profiles from them.
- When the app launches it checks Expo's update service for a newer version of the app's JavaScript. That request includes the app version and platform, not your account.
3. How we use it
- To sign you in and keep your garage, chats, assessments, DIY jobs, and service history in sync.
- To answer your questions and assess problems: your message, the relevant photos, and your car's details are sent to the AI model (see section 4) so the answer fits your actual car.
- To decode a VIN and check for open recalls.
- To find repair shops near your home ZIP and show their rating, phone, and address.
- To explain and sanity-check a repair estimate you scanned.
- To write a step-by-step procedure for a DIY job, find reference photos for each step, and locate a part in a photo you took.
- To build a maintenance schedule for your car's year, make, model, and engine. These schedules contain no personal data and are shared across everyone with the same car.
- To enforce rate limits, keep the service working, and investigate abuse or errors.
- To reply when you contact support.
We do not use your data for advertising, we do not sell or rent it, and we do not share it with data brokers. We do not use it for any kind of automated decision that has legal or similarly significant effects on you.
4. Who else sees it
Otto is built on a small number of service providers. Each receives only what it needs for the job in the table, under an agreement that limits what it may do with the data.
| Provider | What it receives | Why |
|---|---|---|
| Supabase (hosting: sign-in, database, file storage, server functions) | All of the data in section 2 | It is where Otto's backend runs. Stored in Supabase's US East (Ohio) region on AWS. |
| Anthropic (the Claude AI models) | Your chat messages, problem descriptions, the photos you attach (via a link that expires in 5 minutes), scanned estimates, DIY step photos, and your car's year, make, model, engine, mileage and VIN-decoded details. For maintenance schedules and reference-photo checks, only the car's year/make/model/engine and the step text. | To produce the answer, assessment, estimate review, procedure, part locator result, or schedule. Under Anthropic's commercial API terms your data is not used to train Anthropic's models. Anthropic may retain API inputs briefly for abuse monitoring under its own policy. |
| Google Places | Your home ZIP's approximate latitude/longitude, a search radius, and the kind of shop you are looking for (for example "ac" or "brakes") | To list nearby repair shops with ratings. If Google Places is unavailable, Otto uses OpenStreetMap (Overpass API) with the same coordinates and no ratings. |
| Brave Search (image search) | A short search phrase built from the DIY step and your car's year, make, and model, for example "2014 camry glove box damper arm". Never your photos, your name, or your account. | To find reference photos for a DIY step. Candidates are then checked by the AI model before you see them. Results are cached for 30 days and shared with anyone who searches the same phrase. |
| NHTSA (US Department of Transportation) | Your car's VIN (to decode it) and its year, make, and model (to look up recalls) | Free public government APIs for VIN decoding and open recalls. |
| Zippopotam.us | The ZIP code you type in Settings, sent directly from the app | To turn a ZIP into city, state, and approximate coordinates. |
| Apple and Google (sign-in) | Your choice to sign in with them; they send us your email and, if you allow it, your name | Sign in with Apple and Google sign-in. Their privacy policies apply to what they collect on their side. |
| Expo (EAS Update) | App version, platform, and an update-channel name | To deliver over-the-air updates to the app's JavaScript. |
Links that leave the app. Otto can open a shop's address in Apple Maps, dial its phone number, and open a parts search on Amazon, AutoZone, or O'Reilly for a part Otto named. Those open outside Otto, carry only the address or the part search terms, and are governed by those companies' privacy policies. If we join a retail affiliate programme, Amazon links may carry a referral tag that tells Amazon the click came from Otto; it does not identify you to us or to them.
We may also disclose data if the law requires it, to protect the safety of a person, or as part of a merger or acquisition (in which case this policy continues to apply to the data, and we will tell you).
Google user data
If you choose "Continue with Google", Otto uses Google Sign-In to receive your Google account's email address, name, and profile picture (the basic "email" and "profile" scopes). Otto's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Access. Only the email, name, and profile picture that Google shares at sign-in. Otto never asks for access to your Gmail, Drive, Calendar, contacts, or any other Google data.
- Use. To create and identify your Otto account, to show your name in Settings, and to contact you about your account. Nothing else.
- Storage. The email and name are stored with your account in our database (Supabase, US East). The profile picture URL is not stored.
- Sharing. Google user data is never sold, never used for advertising, never transferred to the AI model or any other third party, and never used to train models.
- Deletion. Delete your account (section 7) and the Google-provided data is deleted with it. You can also revoke Otto's access at myaccount.google.com/permissions.
5. Optional: improving Otto with your photos
Settings has a switch called "Help improve Otto with my photos". It is off by default and nothing changes unless you turn it on.
- If you turn it on, we may add photos you upload, together with the related description and Otto's assessment, to internal sets we use to measure and improve how accurately Otto reads dashboard lights, leaks, wear, and estimates, and to tune the instructions we give the AI model.
- These sets are used by us only. They are not given to the AI provider for model training and are not shared with anyone else.
- You can turn it off at any time. We stop adding new material immediately and remove your existing photos from those sets within 30 days.
- Deleting your account removes them too.
6. How long we keep it
- While your account exists, we keep your garage, photos, chats, assessments, DIY jobs, and service history so they are there when you come back. You can delete individual cars (which removes that car's issues, photos, chats, jobs, and records) from the app at any time.
- When you delete your account, everything tied to your user ID, including every file in your private storage folder, is deleted within 30 days. Copies in our hosting provider's backups roll off on their normal rotation within that same window.
- Audit log entries are kept, but when your account is deleted they are unlinked from you (the user reference is cleared) and contain no photos or message text.
- Shared caches (maintenance schedules per car model, cached reference-photo search results) contain no personal data and are kept.
- Server logs at our hosting provider are kept for a short rolling period, typically days, and then discarded.
- Support emails are kept as long as needed to resolve the request and for our records.
7. Your choices and rights
- See and fix your data. Your name, email, ZIP, cars, mileage, records, chats, and jobs are all visible and editable in the app.
- Download your data. Settings → "Download my data" builds a JSON export of your whole account (profile, cars, chats, assessments, DIY jobs, service records, audit log) with links to your photos that work for 7 days, and opens it so you can save or share it. If you can't use the app, email [[SUPPORT_EMAIL]] from the address on your account and we will send the same export within 30 days.
- Delete your account. Settings → "Delete account" removes your sign-in, every row tied to it, and every photo in your private folder immediately, and revokes Otto's Sign in with Apple grant if you used one. Audit-log entries are kept with the user reference cleared. If you can't use the app, email [[SUPPORT_EMAIL]] from the address on your account and we will do it for you within 30 days.
- Withdraw consent. Otto cannot work without sending your content to the AI model, so withdrawing that consent means deleting your account. The photo-improvement switch can be turned off at any time without affecting anything else.
- Camera and photos. Permissions can be changed any time in iOS Settings → Otto.
- Complaints. If you are in the EU/EEA, UK, or another region with a data-protection authority, you have the right to lodge a complaint with it. We would rather hear from you first.
We honour these requests for everyone, wherever you live, including rights under the California Consumer Privacy Act (access, deletion, correction, and knowing what is collected and shared; we do not sell or share personal information for cross-context advertising) and the EU/UK GDPR (access, rectification, erasure, restriction, portability, objection). We will not treat you differently for exercising them.
8. Security
- All traffic between the app, our backend, and our providers uses TLS.
- Every database table is protected by row-level security: your records can only be read with your own session.
- Photos live in a private bucket and are reached only through signed links that expire after 5 minutes.
- The AI provider's API key never ships in the app; it lives only on the server.
- No system is perfectly secure. If we learn of a breach that affects your data we will tell you without undue delay, as the law requires.
9. Children
Otto is not for children. You must be at least 13 to create an account, and the DIY repair features are for adults (18+). We do not knowingly collect personal information from anyone under 13. If you believe a child has given us data, email [[SUPPORT_EMAIL]] and we will delete it.
10. Where data is stored
Otto is built for drivers in the United States and its data is stored and processed there (Supabase, US East region) and by the providers in section 4, which may process data in the US or elsewhere. If you use Otto from outside the US, you understand your data is transferred to and processed in the US, where privacy laws may differ from those where you live. Where the GDPR applies, we rely on standard contractual clauses with our providers for those transfers.
11. Changes
If we change this policy in a way that matters, for example a new provider or a new kind of data, we will update the date at the top and tell you in the app before the change takes effect. Minor wording fixes may happen without notice. Earlier versions are available on request.
12. Contact
[[LEGAL_NAME]]
[[ADDRESS]]
Email: [[SUPPORT_EMAIL]]