Privacy Policy
Effective date: May 28, 2026 · Last updated: June 3, 2026
The short version
You're the user. Your child only experiences Officer Otto during the call itself. Everything else — settings, memory, transcripts — is for you, the parent.
We collect what we need to personalize the experience (your kid's name, age, a few facts you tell us) and nothing for advertising. We do not sell your data and we do not use your conversations to train AI models.
You stay in control. You can read, edit, or delete anything Otto remembers at any time, and you can delete your entire account in a single tap.
The rest of this document is the full legal version. We've kept it as plain-English as we could.
Contents
- Who we are
- Scope of this policy
- Information we collect
- How we get this information
- How we use information
- Legal basis for processing (EU/UK/EEA)
- Who we share information with
- Sub-processors
- How long we keep information
- Security
- Children's privacy
- Your rights and choices
- International data transfers
- California residents (CCPA / CPRA)
- Cookies and tracking technologies
- Changes to this policy
- Contact us
1. Who we are
This Privacy Policy is published by V7Canvas Inc., a California corporation doing business as Officer Otto ("we", "us", "our"), the operator of the Officer Otto iOS application ("the App") and the website at officerotto.netlify.app (collectively, "the Service"). When this document refers to "you", we mean the parent or legal guardian who downloads, installs, or uses the Service.
For any privacy-related question, request, or concern, contact us at v7canvas@gmail.com. We respond to verifiable requests within thirty (30) days, or sooner if required by applicable law.
2. Scope of this policy
This policy describes how we collect, use, disclose, retain, and protect personal information when you interact with the Service. It applies to:
- Use of the App on iOS, including all of its features (sign-in, profiles, chat, calls, settings, in-app purchases).
- Use of the website at officerotto.netlify.app.
- Any communication you have with us (including support emails and beta feedback).
This policy does not apply to the practices of third parties that we do not own or control, including operating system providers (Apple, Google), payment processors (Apple App Store / RevenueCat), or any third-party website you reach by following a link. We encourage you to read their privacy policies separately.
3. Information we collect
We collect only what we need to make the Service work, keep you safe, and improve it over time. We have grouped the categories of information below.
3.1 Account information
- Identifier — a unique account ID assigned by Supabase Auth and tied to your Apple ID or Google account.
- Email address — provided when you sign in with Apple or Google. If you choose Apple's "Hide My Email" option, we receive only the relay email and never see your real address.
- Display name — only if your sign-in provider shares it; you can change or remove it at any time in the App.
- Subscription status — which tier you're on, when it renews. We never receive your credit-card number; payments are processed by Apple and surfaced to us through RevenueCat as anonymized entitlement events.
3.2 Child profile information (entered by you)
- The first name or nickname you use for your child.
- The child's age (a single integer between 3 and 12).
- The pronouns you choose for the child (one of she/her, he/him, or they/them).
- What the child calls you (e.g. "Mom", "Daddy", "Papa", or a custom term).
- Optional short facts you choose to share (e.g. "has a younger brother", "loves dinosaurs"). You always control what facts to add and you can delete any of them at any time.
- An optional avatar: an emoji you pick from a 12-emoji palette, or a gendered illustration. The current version of the App does not upload photos from your device to our servers.
3.3 Activity information
- Chat content — the messages you exchange with a character in the parent-side chat. Stored under your account so future conversations can reference prior context.
- Call transcripts — text transcripts of phone-call sessions between your child and an AI character. Transcripts are saved only when you choose to keep them. You can delete any transcript at any time.
- Memories — short summaries we extract from conversations to make the AI character feel personal. You can read, edit, pin, or delete each memory.
- Call metadata — start time, end time, which scenario, which severity, which character. Used to enforce rate limits and to show you a history.
3.4 Audio data
During an active call, the App captures audio from your device's microphone and streams it to our voice infrastructure provider (ElevenLabs, see §8) so the AI character can hear and respond. Audio is processed in real time. We do not retain raw audio after the call ends. The only persisted artifact of a call is the text transcript, and only if you choose to save it.
3.5 Device and technical information
- Device model, iOS version, App version, language, region.
- Anonymous diagnostic information about crashes and errors (so we can fix them).
- Anonymous product analytics events — which screens you visit, which features you use, when calls happen — processed by our analytics provider PostHog (see §8). These events are tied to an anonymous device-level identifier, never to your name, email, child's name, transcripts, or memories.
- A self-generated random identifier used to detect duplicate session events; this is not your Advertising Identifier (we do not request it) and cannot be used to track you across other apps.
3.6 Communications
If you contact us by email (for support, feedback, deletion requests, or otherwise), we receive your email address and the contents of your message, and we keep that record so we can respond and so we have a history of how the issue was handled.
3.7 Information we do NOT collect
- We do not collect your contacts, calendar, photos library (other than a photo you explicitly choose to upload as an avatar), browsing history, or device-level identifiers used for advertising.
- We do not collect location data of any kind.
- We do not collect biometric identifiers (such as Face ID / Touch ID data — those stay on your device with Apple).
- We do not collect data directly from your child. Every piece of information about your child enters the Service through you, the parent.
4. How we get this information
We receive information from the following sources:
- From you directly — when you set up a child profile, send a chat message, save a transcript, or contact our team.
- From your sign-in provider — Apple or Google sends us your identifier and email (and, optionally, your name) when you sign in for the first time.
- From your device and the App — diagnostic data and audio during a call (audio is described in §3.4).
- From our service providers — Supabase, ElevenLabs, Anthropic, Apple App Store / RevenueCat, as listed in §8.
5. How we use information
We use information only to operate, improve, and secure the Service. Specifically:
- To run the Service — sign you in, keep your settings, remember which child is active, save your subscription state.
- To personalize the experience — so that an AI character can call your child by name and reference what they know about your family.
- To generate AI responses — we send the relevant prompt (child name, age, scenario, recent memories) to our LLM provider (Anthropic Claude) and our voice provider (ElevenLabs) so they can render the character's response. We send only what is needed for that turn of conversation.
- To enforce safety rules — we apply automated content filters to every AI response and every candidate memory entry before it is stored or returned.
- To improve the product — we look at aggregate, anonymized usage patterns to decide what to build next.
- To enforce rate limits and prevent abuse — including the hard cap of 90 seconds per call and 2 calls per child per day.
- To communicate with you — about support requests, important service announcements (changes to terms, security issues), and (only with your opt-in) marketing.
- To comply with the law — when we are legally required to retain, disclose, or block content.
We do not:
- Use your data, your child's data, or your conversations to train machine-learning models. Our LLM provider, Anthropic, has confirmed that API inputs are not used to train their foundation models.
- Sell your personal information to anyone. (See §14 for California-specific definitions.)
- Display advertising in the App or use third-party advertising trackers.
- Profile you, your child, or your family for purposes unrelated to running the Service.
6. Legal basis for processing (EU / UK / EEA users)
If you are in the European Union, the United Kingdom, or the European Economic Area, we process your personal information only when we have a lawful basis under the EU General Data Protection Regulation (GDPR) or the UK GDPR:
- Performance of a contract — to provide the Service to you in accordance with our Terms of Service.
- Legitimate interests — to keep the Service running, secure, and free from abuse; to communicate with you about it; and to improve it based on aggregate usage.
- Consent — for any optional processing where we ask you explicitly (such as opt-in to marketing emails).
- Legal obligation — when we must retain, disclose, or block information to comply with applicable law.
You may withdraw consent at any time, with effect for the future, by contacting v7canvas@gmail.com.
7. Who we share information with
We share personal information only with the categories of recipients described below, and only to the extent reasonably necessary:
- Service providers (sub-processors) — see §8 for the full list. Each is bound by a written data-processing agreement that requires them to use the data only on our documented instructions and to protect it with appropriate security measures.
- Apple and Google — only for sign-in identity verification at the moment you sign in.
- Apple App Store — for in-app purchases. We do not see your payment-card details.
- Legal and safety — to comply with a valid legal request (subpoena, court order, or equivalent), or to protect the rights, property, or safety of any person.
- Business transfers — if we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; you will be notified in advance and offered the choices then required by law.
We do not share personal information with advertisers, data brokers, social-media ad platforms, or any party who would use it for advertising or profiling.
8. Sub-processors
The following service providers ("sub-processors") process personal information on our behalf to run the Service. Each is bound by a written agreement.
| Sub-processor | Purpose | Data accessed | Location |
|---|---|---|---|
| Supabase, Inc. | Authentication, database, file storage | Account ID, email, child profiles, memories, saved transcripts | USA (AWS US-West) |
| Anthropic, PBC | Large-language model that generates AI character responses | Per-turn prompt context (child name, age, scenario, recent memories) | USA |
| ElevenLabs Inc. | Real-time voice (speech-to-text + text-to-speech) for phone calls | Real-time audio (not retained after call), per-turn LLM context | USA |
| Apple Inc. | Sign in with Apple, App Store delivery, in-app purchase processing | Identifier, optional email and name | Global |
| Google LLC | Sign in with Google | Identifier, email, optional profile name | Global |
| RevenueCat, Inc. | Subscription entitlement tracking | Anonymous subscriber ID, subscription events | USA |
| PostHog Inc. | Product analytics (anonymous event tracking, crash reporting) | Anonymous event names, device model, App version, region; no name, email, or transcript content | USA / EU |
| Netlify, Inc. | Hosts the marketing website | Standard web-server logs (IP address, page requested, user agent) | USA / EU CDN |
We may update this list from time to time. The current list is always the canonical version of this page; we will notify you in the App or by email of any material change.
9. How long we keep information
We keep personal information only for as long as we need it for the purposes described in this policy, after which we delete or anonymize it.
| Category | Retention |
|---|---|
| Account record (identifier, email) | For the life of your account. Deleted within thirty (30) days of account deletion. |
| Child profile (name, age, pronouns, parent term, family facts) | For as long as the child profile exists in your account. Deleted within thirty (30) days after you delete the profile or your account. |
| Memories | Pinned memories: until you remove them. Unpinned memories: up to ninety (90) days, then auto-expire. |
| Saved transcripts | For the duration permitted by your subscription tier (currently up to ninety (90) days on the free tier; longer for paid tiers, as described in the App). |
| Real-time audio | Not retained after the call ends. |
| Call metadata (timestamps, scenario, character, duration) | For the same duration as the transcript it is associated with. |
| Diagnostic / crash reports | Up to twelve (12) months, then deleted or anonymized. |
| Support correspondence | Up to three (3) years, then deleted unless required for legal or compliance reasons. |
| Records of consent and deletion requests | Up to the period required by applicable law (typically three (3) to seven (7) years). |
10. Security
We use commercially reasonable administrative, technical, and organizational measures to protect your information against loss, misuse, unauthorized access, disclosure, alteration, and destruction:
- All network traffic between the App and our servers is encrypted with TLS 1.2 or higher.
- All data stored by Supabase is encrypted at rest.
- Access to production systems is limited to authorized personnel using multi-factor authentication.
- We follow the principle of least privilege when granting access to data.
- We use Sign in with Apple and Sign in with Google for authentication; we never see, store, or transmit your password.
No system is perfectly secure. If you suspect that your account has been compromised, please contact us at v7canvas@gmail.com and we will lock the account and investigate. In the event of a data breach affecting your personal information, we will notify you and any applicable regulator within the timeframes required by law.
11. Children's privacy
Officer Otto is a parenting tool. It is designed to be downloaded, configured, and operated by a parent or legal guardian. The child profile and any related content are entered into the Service by the parent on behalf of the child.
We do not knowingly collect personal information directly from children under thirteen (13) years of age. The Service has no mechanism by which a child can create an account, sign in, or independently submit personal information. The child's only direct interaction with the Service is during the 90-second simulated phone call, during which their voice is processed in real time and immediately discarded — never persisted.
This Service is intended to comply with the United States Children's Online Privacy Protection Act ("COPPA"). Because all child-related personal information is provided by the parent (a "verifiable parental consent" under COPPA), no separate consent flow with the child is required.
If you believe that we have inadvertently received any personal information directly from a child, please contact v7canvas@gmail.com immediately and we will delete it within five (5) business days.
12. Your rights and choices
You have the following rights regarding personal information about you and your child. To exercise any of them, use the controls in the App where available, or contact v7canvas@gmail.com.
- Access — view what we know about you and your child in the Profile and "What Otto knows" screens. You may also request a complete copy of your personal information.
- Correction — edit your name, your child's name, age, pronouns, parent term, and family facts at any time from the App.
- Deletion — delete a memory, a transcript, a child profile, or your entire account. Account deletion is permanent and removes all associated personal information from our active systems within thirty (30) days.
- Portability — request a machine-readable export of your personal information.
- Restriction — ask us to limit the processing of your personal information in certain circumstances.
- Objection — object to processing where our legal basis is legitimate interests.
- Withdraw consent — for any processing based on your consent.
- Complain — lodge a complaint with your local data-protection authority. We would appreciate the chance to address your concerns first.
To verify the identity of the person making a request, we may ask you to confirm your account email by replying from that address, or to confirm details about your account that only the account holder would know.
13. International data transfers
The Service is operated from the United States. If you access the Service from outside the United States, your personal information will be transferred to, stored in, and processed in the United States and other countries where our sub-processors operate, which may have data-protection laws different from those in your country.
Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to the United States or another country that has not been deemed to provide adequate protection, we rely on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Agreement, as applicable) with our sub-processors as the legal mechanism for the transfer. A copy of the relevant clauses is available on request.
14. California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights regarding your personal information.
Categories of personal information collected
In the past twelve (12) months, we have collected the following categories of personal information about California residents:
- Identifiers (account ID, email).
- Customer records (name, contact details).
- Internet or other electronic network activity (App usage events, diagnostic data).
- Audio information (during real-time calls; not retained).
- Inferences drawn from the above to personalize the Service.
Sources
We collect this information from you directly and from your sign-in provider, as described in §4.
Disclosure for a business purpose
We disclose the categories above to the sub-processors listed in §8 for the business purposes described in §5. We do not "sell" personal information for monetary or other valuable consideration, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under the CCPA / CPRA.
Sensitive personal information
We do not use or disclose any "sensitive personal information" (as defined under the CCPA / CPRA) for any purpose other than to provide the Service you requested, in accordance with the limitations in Cal. Civ. Code §1798.121.
Your rights
You have the right to know what personal information we collect, to delete it, to correct it, to opt out of any sale or sharing (we do neither), to limit our use of any sensitive personal information (described above), and to be free from discrimination for exercising any of these rights. To exercise any right, contact v7canvas@gmail.com. You may also designate an authorized agent to make a request on your behalf; we will ask the agent for proof of authorization.
15. Cookies and tracking technologies
The marketing website at officerotto.netlify.app does not use cookies, retargeting pixels, third-party advertising trackers, or cross-site tracking technologies of any kind.
The App itself does not use cookies (cookies are a web-browser concept). Within the App we use Apple's standard secure storage (the Keychain) to keep your sign-in session, and the App's local storage to remember which child is active.
16. Changes to this policy
We may update this policy from time to time to reflect changes to the Service, to our practices, or to applicable law. The "Last updated" date at the top of this page tells you when the most recent change was made.
If we make a material change, we will notify you in advance through the App and / or by email to the address on your account, and where required by law we will obtain your consent to the new terms. Your continued use of the Service after the effective date of a change indicates your acceptance of the updated policy.
17. Contact us
For questions or to exercise any of your rights, please write to us:
- General privacy questions: v7canvas@gmail.com
- Security concerns: v7canvas@gmail.com
- General support: v7canvas@gmail.com
We are based in California, United States. If you are in the European Union or the United Kingdom and need to contact us under the GDPR or UK GDPR, please use the v7canvas@gmail.com address and we will respond within thirty (30) days.