Skip to main content
Effective Date: September 7, 2026 Update: This revision corrects the disclosures for Coinbase account sign-in, PostHog product analytics, browser storage and account-specific execution authority. It does not announce a new analytics integration. Welcome to Otto AI (“Otto,” “we,” “us,” or “our”). This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding that data. It applies to all Otto AI services, including the DApp at useotto.xyz, the Otto AI Agent Swarm accessible via ACP (Agent Commerce Protocol) and x402, and our public documentation at docs.useotto.xyz. We believe crypto users deserve transparency. This policy is specific to our actual data practices — not generic legal boilerplate.

1. Information We Collect

1.1 Wallet Data (Required)

A blockchain wallet address identifies connected-wallet interactions. Coinbase account flows also use the authenticated end-user identity and account address. Public discovery can be used without connecting a wallet. When you use an account, its identifiers are used to:
  • Authenticate your session
  • Execute DeFi transactions you request
  • Track your points and leaderboard standing
  • Link your chat history and transaction records
We do not ask you to disclose the private key or seed phrase of your connected wallet. Signing authority differs by account: Otto can execute supported actions under a permission you grant, and it operates keys for some earlier trading Safes and service accounts. See Accounts & permissions. A standing permission can allow actions without a new signature for each transaction.

1.2 Chat & Conversation Data

Where a service accepts a conversation or prompt, we store the content needed for that service, including messages and AI responses. Earlier chat records may remain in storage after retirement of the standalone chat interface. This data is linked to your wallet address and stored in our database. We also record metadata about each AI request, including the model used, token counts, cost estimates, and response times.

1.3 Transaction Data

When you execute DeFi transactions through Otto (swaps, bridges, lending, perpetual futures), we store a record including the transaction hash, tokens involved, amounts, chains, and order details (e.g., Hyperliquid order parameters). On-chain transaction data is publicly visible on the respective blockchain by nature.

1.4 Optional Personal Information

You may optionally provide:
  • Display name (max 30 characters) — shown on the leaderboard
  • Email and authenticated account identifiers — when you choose Coinbase account sign-in. Earlier Dynamic sign-in methods can also process email, phone number or social-login identifiers when selected
  • Telegram username — only if you include it when submitting feedback
These identifiers depend on the feature and sign-in method you choose. Public discovery does not require them; Coinbase account features require their email sign-in, while connected-wallet features use a wallet connection.

1.5 Automatically Collected Data

  • Network and request metadata — IP addresses and request information are processed by hosting, security, authentication and analytics providers. Otto also uses temporary IP-based rate-limit counters. The application counters do not establish the retention of provider logs.
  • Rate limit and session counters — stored temporarily in Redis with automatic expiration (60 seconds to 24 hours depending on the counter type).

1.6 Product Analytics

We use PostHog for page visits, page exits, performance measurements and explicitly instrumented product interactions. Before wallet identification, events use an analytics identifier. On connection through the wallet flow, we identify the analytics profile with the lowercased wallet address and can associate activity with it. A wallet address is pseudonymous, not anonymous. Disconnecting resets the identified session. The app configures PostHog with automatic interaction capture and session recording disabled, and respects the browser’s Do Not Track setting. Its event filter removes URL query strings and fragments and redacts wallet-shaped identifiers in URL paths. These measures do not mean that no analytics is collected. We do not use these events for advertising or sell them. We do not ask for a residential address or government-issued ID in the app’s wallet-connection flow; a third-party funding or account provider may have its own requirements.

2. How We Use Your Information

We use the data we collect to:
  • Provide the Service — process your chat messages, execute requested DeFi transactions, display portfolio data, and maintain your session
  • Maintain the points program — track daily check-ins, streaks, and leaderboard rankings
  • Process airdrop claims — verify eligibility and record claim signatures
  • Improve service quality — analyze response times, token usage, costs, page performance and product interactions. Product events can be linked to a connected wallet as described above
  • Prevent abuse — rate limiting and bot prevention via reCAPTCHA on feedback forms
  • Fulfill ACP jobs — when agents receive work via the Agent Commerce Protocol, we store job completion records including the client wallet, deliverable content, and price
We do not sell your data. We do not use your data for advertising. We do not share your data with data brokers.

3. Third-Party Services

Otto AI integrates with the following third-party services. Each receives only the data necessary to perform its function: Each third-party service operates under its own privacy policy. We encourage you to review their policies if you have concerns about how they handle data.

4. Cookies & Local Storage

We use minimal client-side storage:
  • Preferences and saved views — theme, Stocks watchlists and feature-specific session or display preferences can be stored in your browser.
  • Authentication and account state — wallet and account SDKs use browser storage and session mechanisms to maintain sign-in and account interactions.
  • Analytics state — PostHog can persist analytics identifiers and session state in browser storage or cookies. This storage is separate from a theme preference. The app does not use it for advertising.
Clearing site data removes local preferences and can sign you out; it does not delete server records or on-chain transactions. Browser privacy controls, including Do Not Track for the configured analytics client, can affect collection. Server-side temporary storage (Redis):
  • Rate limit counters keyed by wallet address or IP address, automatically expiring after 60–300 seconds
  • Check-in replay prevention keys, automatically expiring after 24 hours

5. Data Retention

The following periods state our retention policy for application records: You can request earlier deletion through support as described in Section 7. Self-service data management is not yet available. This policy does not represent that every data type has an automated deletion process. The application-record periods above do not establish the retention periods configured in PostHog or other provider accounts. Contact us for information about those records or to request deletion; the same request rights below apply. On-chain transaction data (transaction hashes, token transfers) is permanently recorded on public blockchains and cannot be deleted by anyone, including us.

6. Data Security

We take reasonable measures to protect your data:
  • Database access is restricted to authorized services via environment-scoped credentials
  • All connections to our services use HTTPS/TLS encryption in transit
  • API endpoints are rate-limited to prevent abuse
  • Wallet and account authentication uses the relevant Dynamic or Coinbase provider infrastructure
  • Connected-wallet recovery material is not requested by Otto; service-operated signing credentials are restricted to their execution infrastructure, as distinguished in the account guide
No system is perfectly secure. Given the beta nature of the Service, we encourage you to use Otto AI with amounts you can afford to lose, as stated in our Terms & Conditions.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:
  • Right to Access — You can request a copy of the data we hold about your wallet address. Contact us at support@useotto.xyz.
  • Right to Erasure — You can request deletion of your data. We will delete data stored in our database (chat messages, transaction records, analytics, points data). Please note:
    • On-chain transactions are immutable and cannot be deleted by any party.
    • Wallet addresses that appear in publicly recorded blockchain transactions will remain visible on-chain.
    • We are actively working on building self-service data deletion tools. Until those are available, deletion requests are handled manually via email.
  • Right to Portability — You can request an export of your data in a machine-readable format.
  • Right to Rectification — You can request correction of inaccurate data (e.g., display name).
  • Right to Object — You can object to specific uses of your data. This includes product analytics linked to your wallet, as well as AI request analytics.
GDPR Note: Wallet addresses may constitute personal data under GDPR when they can be linked to an identifiable individual. We treat wallet addresses with the same care as other personal identifiers. If you are located in the European Economic Area, you have the right to lodge a complaint with your local data protection authority. To exercise any of these rights, contact us at support@useotto.xyz.

8. Children’s Privacy

Otto AI is not directed at individuals under the age of 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, please contact us and we will take steps to delete it.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will:
  • Update the “Effective Date” at the top of this page
  • Post a notice on the DApp interface
  • Announce changes via our official channels (Telegram, Twitter/X)
Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or want to exercise your data rights: