Privacy Policy
Last updated: July 22, 2026
The short version
Otto reads your recent email and calendar to write you a short daily brief. We do not store the contents of your emails or calendar events, we do not sell your data, and we only ever request read-only access. The sections below explain exactly what we access, how it is used, and what we keep.
Who we are
Otto by Nura Labs (“Otto,” “we,” “us”) provides a personal decision-support assistant that summarizes your day. This policy covers the Otto application and its connections to third-party accounts such as Google and Microsoft.
Information we access
- Account & sign-in details. When you sign in, we receive basic identity information (such as your name and email address) from our authentication provider.
- Email (read-only). When you connect a mailbox, we read recent messages (subject, sender, a short preview, timestamp, and a link back to the message) so we can summarize what needs your attention.
- Calendar (read-only). When you connect a calendar, we read the events on your schedule (title, time, and location) to build your agenda.
- Your settings. Personalization preferences you provide, such as instructions for how your brief should be prioritized.
We request read-only permissions. Otto cannot send, modify, or delete your email or calendar.
How we use your information
- To generate your daily brief — highlighting priorities, things to avoid, upcoming risks, and today’s schedule.
- To send your recent email and calendar content to Microsoft Azure OpenAI Service for processing so it can be summarized. Azure OpenAI runs within Microsoft’s enterprise cloud — it is not the public ChatGPT service. Your content is not used to train any AI models, is not shared with OpenAI or other customers, and is used only to produce your brief.
- To maintain your connected accounts and keep your brief current.
What we store — and what we don't
We do not retain the raw content of your emails or calendar events. That content is fetched on demand, used to generate your brief, and then discarded. We do not keep a copy of your messages or events.
To operate the service, we do store:
- Connection credentials. The access tokens needed to retrieve your email and calendar on your behalf, so you don’t have to reconnect every time. These tokens are encrypted by Otto before they are stored, so a copy of our database alone cannot be used to access your accounts.
- Your generated brief. The summarized text we produce is cached so your brief loads quickly and doesn’t need to be rebuilt every time you open the app.
- Your preferences. The personalization settings you configure.
This data is stored in Microsoft Azure. Azure encrypts all stored data at rest, and your connection credentials are additionally encrypted by Otto before storage.
Google user data (Limited Use)
Otto’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We only use Google user data to provide and improve the Otto brief you request. We do not transfer or sell Google user data to third parties for advertising, and no humans read your data except as required for security, to comply with the law, or with your explicit consent.
How your information is shared
We do not sell your personal information. We share data only with:
- Service providers that help us run Otto, including Microsoft Azure (hosting and storage), Microsoft Azure OpenAI Service (brief generation), and our authentication provider (sign-in).
- Legal or safety reasons, if required by law or to protect the rights and safety of our users.
Your choices and controls
- Disconnect at any time. Removing a connected account from your settings deletes the stored credentials for that account and stops all further access.
- Delete your data. You can request deletion of your stored data — including connections, generated briefs, and preferences — by contacting us at the address below.
- Revoke access with the provider. You can also revoke Otto’s access directly from your Google or Microsoft account security settings.
Data retention
We keep your stored data (connection credentials, generated briefs, and preferences) for as long as your account is active. When you disconnect an account or request deletion, the associated data is removed. Raw email and calendar content is never retained.
Children's privacy
Otto is intended for adults and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above. Significant changes will be communicated within the app.
Contact us
Questions about this policy or your data? Email us at brijen.shah@gmail.com.
See also our Terms of Service.