Privacy

Privacy Policy

How we collect, use, and protect the information needed to run Otto and publish human-reviewed SEO content for your business.

Last updated June 20, 2026

Information we collect

We collect the information you provide when you create an account, request a free visibility report, purchase a plan, connect your website, book a kickoff call, or contact support. This can include your name, email address, business name, website URL, service area, business description, topics, customer questions, billing status, and support messages.

If you connect a CMS or website platform, we collect the scoped credentials you provide so we can publish approved content on your behalf. Secret credential fields are encrypted before storage and are not displayed back in the app after they are saved.

How we use information

We use your information to create and manage your account, run visibility reports, process subscription payments, prepare SEO content, review drafts, publish approved blogs and FAQs, provide support, improve the product, and protect the service from abuse.

We may use your business brief, website URL, topics, service area, and public website content to generate content plans, blogs, FAQs, metadata, structured content, and AI-search visibility recommendations.

Payments and billing

Payments are processed by Stripe. We do not store full payment card numbers on our servers. Stripe may collect payment details, billing address, tax information, and related transaction data according to Stripe's own policies.

We store Stripe customer and subscription identifiers so we can manage billing state, customer portal access, and subscription status inside the app.

Service providers

We use trusted service providers to operate the product, including Firebase for authentication and database services, Vercel for hosting, Stripe for payments, Calendly for scheduling, and analytics tools to understand website performance.

These providers may process limited information on our behalf. We only share what is needed to provide, secure, and improve the service.

Credential security

Customer CMS credentials should be scoped to the minimum permissions needed to publish content. You can revoke these credentials from your CMS or platform settings at any time.

We use server-side access controls and app-layer encryption for stored secret credential fields. No system can be guaranteed perfectly secure, but we design the workflow to reduce unnecessary exposure of sensitive publishing credentials.

Data retention

We keep account, billing, content, lead, and support records as long as needed to provide the service, comply with legal or financial obligations, resolve disputes, and maintain accurate operational history.

If you want us to delete your account or certain business information, contact support. Some records may need to be retained for billing, fraud prevention, legal, or tax reasons.

Your choices

You can update your account, billing, website connection, and business information through the dashboard where available, or by contacting support.

You can unsubscribe from non-transactional emails, cancel your subscription through the billing portal, and revoke CMS credentials through your website platform at any time.

Changes to this policy

We may update this Privacy Policy as the product changes. When we make material changes, we will update the date on this page and, when appropriate, provide additional notice.

Questions about this policy? Email hello@webairai.com. You can also review our Terms, Privacy Policy, and Refund Policy.