Plain-language summary
- Ottr is built for one private shared world between exactly two adults.
- Ottr does not sell personal data, run behavioral advertising, or use private content to train advertising or general-purpose AI models.
- Ottr's approved architecture requires supported private content to be end-to-end encrypted. Production activation and final independent verification must finish before real users are admitted.
- Google provides sign-in and content-free push delivery. A separate operator-controlled Google Drive connection stores encrypted production backups only.
- You can sign out, revoke or forget a device, disconnect from a partner, or permanently delete your account. These actions have different consequences.
Operator and scope
Ottr is operated by Syed Irfan (“Ottr,” “we,” “us,” or “our”). This policy applies to the Ottr Android app, Ottr’s API, and the public pages at ottr.chat. Questions, privacy requests, and verified deletion requests can be sent to ottr.chat@gmail.com.
For laws that use those terms, Ottr is the data fiduciary, controller, or business responsible for deciding how Ottr account data is processed. Service providers process limited data on Ottr’s behalf under their applicable terms.
Data Ottr processes
Account and profile data
Google Sign-In and Firebase Authentication provide the identifiers and verified token claims needed to authenticate you. Ottr stores your Firebase user identifier, an internal random Ottr identifier, chosen display name, permanent username, account status, and relevant consent or policy-version records. Ottr never receives your Google password.
Pair and shared-world data
Ottr stores pairing and world membership, disconnect and recovery state, delivery state, module state, purchase and entitlement records, and Ottr Coin records. Under the approved production design, private user-generated content, including chat text, Shared Notes text, private labels and choices, moods, and delayed answers, will be end-to-end encrypted on qualified worlds. The service will store recipient and ordering metadata plus opaque ciphertext, not the private content keys.
Device and security data
Ottr stores installation and device identifiers, device label and platform, app build, push token, public cryptographic identity material, trust and verification state, revocation status, key-generation metadata, and security events needed to approve, recover, or revoke devices. Private device keys remain encrypted on trusted endpoints and are not uploaded as server-readable keys.
Operational data
Privacy-filtered access logs, health metrics, abuse controls, and crash diagnostics may process timestamps, network address, request or command identifiers, app/build/device characteristics, route names, status codes, and technical error details. They must not contain private message or note text, authorization credentials, recovery secrets, or private cryptographic keys.
Payments
If purchases are enabled, Google Play processes payment details. Ottr receives only the purchase tokens, product identifiers, transaction state, and entitlement records required to verify and provide the purchase. Ottr does not receive full payment-card details.
Purposes and legal bases
Ottr processes data only to authenticate accounts; create and secure the selected pair; deliver, synchronize, and recover the shared world; enforce authorization and device trust; operate purchases and Coins; send generic notifications; prevent abuse and fraud; diagnose failures; maintain backups; comply with law; and protect users and the service.
Depending on the law that applies, processing is based on providing the service you request, your consent, compliance with legal obligations, and legitimate interests such as service security, fraud prevention, reliability, and defending legal claims. Where consent is the basis, you may withdraw it, but withdrawal does not make earlier lawful processing unlawful and may prevent features that require the data from operating.
Google services and Google Drive
Google Sign-In, Firebase Authentication, and messaging
Ottr uses Google Sign-In through Firebase Authentication. Google and Firebase may process Google account identifiers, email address, user agent, network address, Firebase installation identifiers, and related security information under Google’s terms. Firebase Cloud Messaging receives device and installation identifiers plus content-free notification requests. Ottr notifications use generic wording and do not include private message text.
Encrypted production backups
Ottr’s operator may authorize a separate administrative Google Drive connection solely for encrypted production backups. The backup tool requests the narrow drive.file scope so it can create and manage only backup files it created or that were explicitly provided to it; it does not request access to unrelated Drive files. Backup archives are encrypted before leaving the production server. The Drive account owner may revoke access through their Google Account.
Information received from Google Workspace APIs is used and transferred in accordance with the Google Workspace API User Data and Developer Policy, including its Limited Use requirements. Ottr does not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train general-purpose AI models.
Encryption and security
Ottr uses TLS in transit, an encrypted local synchronized database, Android secure platform storage for device secrets, server-side access controls, private PostgreSQL networking, restricted production secrets, encrypted off-host backups, and the approved Olm/HPKE design for supported private content.
End-to-end encryption protects content, not every piece of metadata. It cannot erase content or keys already received by a formerly trusted device, and it cannot recover old content after every trusted endpoint key is lost. A first device-key observation is trust-on-first-use unless the pair independently compares fingerprints. Device revocation protects future access; it cannot remotely destroy copies already received.
No system is perfectly secure. Ottr monitors and limits access proportionately, fails closed when identity or key state is unsafe, and will provide legally required incident notices if a breach creates a notification duty.
International transfers
Ottr, Google, Hostinger, Google Drive, and Google Play may process data in countries other than your own. Those countries may have different privacy laws. Where required, Ottr relies on recognized transfer mechanisms, contractual protections, or another lawful basis and limits transfers to what the service requires.
Retention
Account, profile, device, and active-world records are kept while needed to provide and secure Ottr. A disconnected world is inaccessible during its 30-day mutual-recovery period. Security, transaction, purchase, abuse-prevention, and legal records may be retained longer where necessary for integrity, fraud prevention, dispute resolution, or legal obligations.
Production database backups use a rolling schedule of 14 daily, 8 weekly, and 12 monthly encrypted snapshots. Deleted data may remain in inaccessible encrypted backups until those snapshots expire. A restore must reapply deletion safeguards before restored data can return to active use.
After account deletion, Ottr retains a minimal disabled identity tombstone so a cached authentication token cannot silently recreate the deleted account. Opaque shared ciphertext and de-identified integrity records may remain when deletion would destroy the other participant’s legitimate copy or undermine required security, financial, or legal records. They are not used to reactivate the deleted account.
Your privacy rights
Depending on where you live, you may have rights to receive notice, access personal data, correct inaccurate data, obtain a copy, erase data, withdraw consent, restrict or object to processing, nominate another person where law allows, and complain to a regulator. You may also appeal a refusal where applicable.
Send a request to ottr.chat@gmail.com. Describe the request and the Google account used for Ottr. We may ask for proportionate verification before acting, but never for your password, sign-in code, private message, or recovery key. We will respond within the period required by applicable law. Some requests may be limited where another person’s rights, security, fraud prevention, or legal duties require it.
Account deletion
You can request permanent deletion in Settings → Profile → Delete account permanently, or through the external deletion page. Once accepted, the request disables the Ottr account, ends the shared world, removes the public profile and username, clears notification tokens, revokes devices and crypto identities, and queues deletion of the Firebase Authentication user. The requesting phone erases its owner-bound keys after server acceptance.
Deletion cannot remove messages or keys already delivered to the other participant’s devices. It is separate from signing out, forgetting one local device, revoking another device, or disconnecting a world. Review the deletion page before confirming because permanent deletion is not a recovery mechanism and may make encrypted history unrecoverable.
Cookies and tracking
The public ottr.chat pages are static and do not set advertising cookies, run analytics scripts, fingerprint visitors, or load third-party trackers. Basic server access logs are retained only for security and reliability and are filtered to remove credentials and query values. The Android app does not use private content for advertising or cross-app tracking.
Children and policy changes
Ottr is intended only for adults and is not directed to children. Do not use Ottr if you are under 18. If we learn that a child’s personal data was processed, contact us and we will take appropriate deletion and restriction steps.
We may update this policy when the service, law, or processors change. Material changes will receive a new effective date and, where required, in-app notice or renewed consent. Archived versions will be retained where reasonably practical.
Contact
Email privacy questions, rights requests, complaints, and deletion requests to ottr.chat@gmail.com. Please do not include passwords, authentication codes, private messages, private keys, or recovery secrets.