> ## Documentation Index
> Fetch the complete documentation index at: https://docs.useotto.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How Otto AI collects, uses, and protects your data.

**Effective Date:** September 7, 2026

**Updated September 20, 2026:** This revision describes optional PostHog analytics, saved choices, withdrawal controls and anonymous daily traffic counts on useotto.xyz.

**Updated September 22, 2026:** This revision describes collection, retention and deletion of Muse research sessions, budgets and payment operations.

Welcome to Otto AI ("Otto," "we," "us," or "our"). This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding that data. It applies to all Otto AI services, including the DApp at [useotto.xyz](https://useotto.xyz), the Otto AI Agent Swarm accessible via ACP (Agent Commerce Protocol) and x402, and our public documentation at [docs.useotto.xyz](https://docs.useotto.xyz).

We believe crypto users deserve transparency. This policy is specific to our actual data practices — not generic legal boilerplate.

***

### 1. Information We Collect

#### 1.1 Wallet Data (Required)

A blockchain wallet address identifies connected-wallet interactions. Coinbase account flows also use the authenticated end-user identity and account address. Public discovery can be used without connecting a wallet. When you use an account, its identifiers are used to:

* Authenticate your session
* Execute DeFi transactions you request
* Track your points and leaderboard standing
* Link your chat history and transaction records

We do not ask you to disclose the private key or seed phrase of your connected wallet. Signing authority differs by account: Otto can execute supported actions under a permission you grant, and it operates keys for some earlier trading Safes and service accounts. See [Accounts & permissions](/account-and-settings/accounts-and-permissions). A standing permission can allow actions without a new signature for each transaction.

#### 1.2 Chat & Conversation Data

Where a service accepts a conversation or prompt, we store the content needed for that service, including messages and AI responses. Earlier chat records may remain in storage after retirement of the standalone chat interface. This data is linked to your wallet address and stored in our database. We also record metadata about each AI request, including the model used, token counts, cost estimates, and response times.

#### 1.3 Transaction Data

When you execute DeFi transactions through Otto (swaps, bridges, lending, perpetual futures), we store a record including the transaction hash, tokens involved, amounts, chains, and order details (e.g., Hyperliquid order parameters). On-chain transaction data is publicly visible on the respective blockchain by nature.

#### 1.4 Optional Personal Information

You may optionally provide:

* **Display name** (max 30 characters) — shown on the leaderboard
* **Email and authenticated account identifiers** — when you choose Coinbase account sign-in. Earlier Dynamic sign-in methods can also process email, phone number or social-login identifiers when selected
* **Telegram username** — only if you include it when submitting feedback

These identifiers depend on the feature and sign-in method you choose. Public discovery does not require them; Coinbase account features require their email sign-in, while connected-wallet features use a wallet connection.

#### 1.5 Automatically Collected Data

* **Network and request metadata** — IP addresses and request information are processed by hosting, security, authentication and analytics providers. Otto also uses temporary IP-based rate-limit counters. The application counters do not establish the retention of provider logs.
* **Rate limit and session counters** — stored temporarily in Redis with automatic expiration (60 seconds to 24 hours depending on the counter type).

**Anonymous traffic counts** — for production document navigation requests, we increment daily totals indicating whether the request carries Do Not Track (DNT), Global Privacy Control (GPC), both signals or neither. Recognized automated requests are counted separately. These counters retain no IP address, browser or visitor identifier, wallet address, page path, referrer or user-agent string. We use the totals to understand measurement coverage, not to identify visitors or override their privacy choices. They count requests rather than people, expire after 35 days, and are separate from hosting and security logs. Requests without either signal are not treated as consent.

#### 1.6 Product Analytics

On useotto.xyz, **PostHog product analytics is optional and off by default**. PostHog is initialized only after an acceptance has been saved in your browser. Before acceptance, it does not capture optional analytics events, send optional analytics requests or create analytics identifiers. **Accept optional analytics** and **Reject optional analytics** are presented with equal prominence. Wallet and sign-in functions remain available with either choice.

If you accept, PostHog receives page visits, explicitly instrumented product interactions and limited page-performance measurements (loading, layout stability and interaction timing), using browser analytics identifiers. In the connected-wallet flow, we can link this activity to the lowercased wallet address. A wallet address is pseudonymous, not anonymous. Disconnecting resets the identified analytics session; it does not withdraw your analytics choice.

Use **Manage analytics**, available on the website, to change your choice at any time. Choose **Reject optional analytics** to withdraw acceptance. Withdrawal blocks future captures and queued analytics requests and removes this project's PostHog identifiers from browser storage where the browser permits access. It does not clear wallet or authentication data, recall requests already sent or delete records already received by PostHog. See Section 7 for deletion requests.

The browser's **Do Not Track** or **Global Privacy Control** signal keeps optional analytics off, even with a saved acceptance. If the choice cannot be read or saved, optional analytics stays off. Automatic page-exit capture, SDK performance capture, interaction autocapture and session replay are disabled. Our explicit performance events include only the metric name, numeric value and sanitized page path; they are collected after acceptance and stop on withdrawal. The event filter removes URL query strings and fragments and redacts wallet-shaped identifiers in URL paths; this does not remove a wallet address intentionally used for analytics identification after acceptance.

We do not use these events for advertising or sell them. We do not ask for a residential address or government-issued ID in the app's wallet-connection flow; a third-party funding or account provider may have its own requirements.

#### 1.7 Muse Research Sessions

When you approve a research budget on the wallet page, we record the session so the budget can be enforced and audited. Each session stores your authenticated Coinbase end-user identifier, your wallet address, the per-call spending limit, the total spending limit, the amount reserved so far, the tools the budget covers, the session state (pending, active or revoked) and the session expiry.

Each session also keeps a payment-operation journal — one entry per research payment authorized under that budget — recording the operation identifier, a nonce, the amount, the resource paid for and the operation state. The entry also holds the payment signature until it is removed on the schedule in Section 5. The nonce and the expiry are what prevent a payment authorization being replayed, so they are retained as described there.

Research budgets are optional. If you do not approve one, no session or payment-operation record is created. The permission file the browser hands you when a budget is approved is delivered once and is never stored by us; it lives only on your own machine.

***

### 2. How We Use Your Information

We use the data we collect to:

* **Provide the Service** — process your chat messages, execute requested DeFi transactions, display portfolio data, and maintain your session
* **Maintain the points program** — track daily check-ins, streaks, and leaderboard rankings
* **Process airdrop claims** — verify eligibility and record claim signatures
* **Improve service quality** — analyze service response times, token usage and costs, plus page visits and product interactions when you accept optional analytics. Optional product events can be linked to a connected wallet as described above
* **Prevent abuse** — rate limiting and bot prevention via reCAPTCHA on feedback forms
* **Fulfill ACP jobs** — when agents receive work via the Agent Commerce Protocol, we store job completion records including the client wallet, deliverable content, and price

We do **not** sell your data. We do **not** use your data for advertising. We do **not** share your data with data brokers.

***

### 3. Third-Party Services

Otto AI integrates with the following third-party services. Each receives only the data necessary to perform its function:

| Service                         | Data Shared                                                                                                                                                | Purpose                                                                                                                                   |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| **Coinbase Developer Platform** | Email, authenticated end-user identifiers, account addresses, signing and transaction requests                                                             | Email sign-in, embedded account and permission or transfer flows                                                                          |
| **PostHog**                     | After acceptance: page visits, instrumented product and performance events, browser analytics identifiers and the connected wallet address when identified | Optional product analytics; automatic page-exit capture, SDK performance capture, interaction autocapture and session replay are disabled |
| **Dynamic Labs** (dynamic.xyz)  | Wallet address; email, phone, or Google ID only if you use those sign-in methods                                                                           | Authentication and wallet connection                                                                                                      |
| **Google Gemini API**           | Chat message content (processed per Google's data handling terms; not used to train Google's models under our API agreement)                               | AI conversation processing                                                                                                                |
| **Google reCAPTCHA v3**         | IP address, interaction signals, page URL                                                                                                                  | Bot prevention on feedback forms                                                                                                          |
| **Zerion API**                  | Wallet address                                                                                                                                             | Portfolio data retrieval                                                                                                                  |
| **Li.Fi SDK**                   | Wallet address, token and amount details                                                                                                                   | Swap and bridge route finding                                                                                                             |
| **Portals.fi**                  | Wallet address, token and amount details, slippage settings                                                                                                | DeFi protocol interactions (Aave, Morpho)                                                                                                 |
| **Hyperliquid**                 | Wallet address, order parameters                                                                                                                           | Perpetual futures trading                                                                                                                 |
| **CoinGecko**                   | Token symbols only (no wallet data)                                                                                                                        | Token price data                                                                                                                          |
| **Telegram Bot API**            | Wallet identifier and feedback or operational event details where the relevant flow sends an internal notification                                         | Support and account-activity operations; separate user-requested bot services process the details needed for delivery                     |

Each third-party service operates under its own privacy policy. We encourage you to review their policies if you have concerns about how they handle data.

***

### 4. Cookies & Local Storage

**We use minimal client-side storage:**

* **Preferences and saved views** — theme, Stocks watchlists and feature-specific session or display preferences can be stored in your browser.
* **Authentication and account state** — wallet and account SDKs use browser storage and session mechanisms to maintain sign-in and account interactions.
* **Analytics choice** — your acceptance or rejection is saved locally so it can apply on later visits. This preference is separate from analytics identifiers and does not require accepting analytics.
* **Optional analytics state** — after acceptance, PostHog can persist analytics identifiers and session state in browser storage. Rejecting or withdrawing removes this project's PostHog identifiers, including legacy PostHog cookies where accessible, without clearing wallet or authentication storage. The app does not use this storage for advertising.

Use **Manage analytics** to change or withdraw your choice without clearing all site data. Clearing site data removes local preferences, including your analytics choice, and can sign you out; it does not delete server records or on-chain transactions. Without a saved acceptance, optional analytics remains off. Do Not Track and Global Privacy Control also keep optional analytics off.

**Server-side temporary storage (Redis):**

* Rate limit counters keyed by wallet address or IP address, automatically expiring after 60–300 seconds
* Check-in replay prevention keys, automatically expiring after 24 hours
* Anonymous daily DNT/GPC request totals, automatically expiring after 35 days

***

### 5. Data Retention

The following periods state our retention policy for application records:

| Data Type                                                                | Retention Period                                                                |
| ------------------------------------------------------------------------ | ------------------------------------------------------------------------------- |
| Chat messages and AI responses                                           | 1 year                                                                          |
| DeFi transaction records                                                 | 1 year                                                                          |
| AI request analytics (model, tokens, cost)                               | 1 year                                                                          |
| Points, streaks, and leaderboard data                                    | 1 year                                                                          |
| Feedback submissions                                                     | 1 year                                                                          |
| Airdrop claim records                                                    | 1 year                                                                          |
| ACP job records                                                          | 1 year                                                                          |
| Muse research sessions and budgets (end-user id, wallet address, limits) | 1 year after expiry or revocation                                               |
| Muse research payment operations (nonce, amount, resource, state)        | 1 year; the payment signature is removed 7 days after its authorization expires |
| Browser preferences and watchlists                                       | Until cleared in the browser or replaced by the feature                         |
| Rate limit counters (temporary cache)                                    | 60–300 seconds                                                                  |
| Check-in session keys (temporary cache)                                  | 24 hours                                                                        |
| Anonymous daily privacy-signal request totals                            | 35 days                                                                         |

You can request earlier deletion through support as described in Section 7. Self-service data management is not yet available. This policy does not represent that every data type has an automated deletion process.

The application-record periods above do not establish the retention periods configured in PostHog or other provider accounts. Contact us for information about those records or to request deletion; the same request rights below apply.

On-chain transaction data (transaction hashes, token transfers) is permanently recorded on public blockchains and cannot be deleted by anyone, including us.

***

### 6. Data Security

We take reasonable measures to protect your data:

* Database access is restricted to authorized services via environment-scoped credentials
* All connections to our services use HTTPS/TLS encryption in transit
* API endpoints are rate-limited to prevent abuse
* Wallet and account authentication uses the relevant Dynamic or Coinbase provider infrastructure
* Connected-wallet recovery material is not requested by Otto; service-operated signing credentials are restricted to their execution infrastructure, as distinguished in the account guide

No system is perfectly secure. Given the beta nature of the Service, we encourage you to use Otto AI with amounts you can afford to lose, as stated in our [Terms & Conditions](/legal/terms-and-conditions).

***

### 7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

* **Right to Access** — You can request a copy of the data we hold about your wallet address. Contact us at [support@useotto.xyz](mailto:support@useotto.xyz).
* **Right to Erasure** — You can request deletion of your data. We will delete data stored in our database (chat messages, transaction records, analytics, points data), including Muse research sessions, their budgets and their payment operations. Please note:
  * On-chain transactions are immutable and cannot be deleted by any party.
  * Wallet addresses that appear in publicly recorded blockchain transactions will remain visible on-chain.
  * We are actively working on building self-service data deletion tools. Until those are available, deletion requests are handled manually via email.
* **Right to Portability** — You can request an export of your data in a machine-readable format.
* **Right to Rectification** — You can request correction of inaccurate data (e.g., display name).
* **Right to Object** — You can object to specific uses of your data. This includes product analytics linked to your wallet, as well as AI request analytics.

**GDPR Note:** Wallet addresses may constitute personal data under GDPR when they can be linked to an identifiable individual. We treat wallet addresses with the same care as other personal identifiers. If you are located in the European Economic Area, you have the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, contact us at [support@useotto.xyz](mailto:support@useotto.xyz).

***

### 8. Children's Privacy

Otto AI is not directed at individuals under the age of 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, please contact us and we will take steps to delete it.

***

### 9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will:

* Update the "Effective Date" at the top of this page
* Post a notice on the DApp interface
* Announce changes via our official channels ([Telegram](https://t.me/useOttoAI), [Twitter/X](https://x.com/useOttoAI))

Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

***

### 10. Contact Us

If you have questions about this Privacy Policy or want to exercise your data rights:

* **Email:** [support@useotto.xyz](mailto:support@useotto.xyz)
* **Telegram:** [t.me/useOttoAI](https://t.me/useOttoAI)
* **Twitter/X:** [@useOttoAI](https://x.com/useOttoAI)
