ooto.cxthe mcp harness
connectorsthe vaultpricingfrench datamarketplaceappsfaqosssign increate an account→

Privacy Policy

Version 2.0 — July 8, 2026 · effective July 7, 2026 download the PDF

Versions
  • Version 2.0 — July 8, 2026current
  • Version 1.0 — June 1, 2026

What changed

Data controller: Otomata, a SASU registered in Marseille (SIREN 106 974 637). Payments handled by Stancer (instead of Stripe); moved from a “credits balance” to “subscription”. Added privacy-respecting audience measurement (PostHog, EU), enabled only after explicit consent. The AI model is brought by the customer (not an oto sub-processor). Updated links to trust.oto.ninja and the data processing agreement (DPA).

CommitmentWhat we don't collectWhat we collectCookies & analyticsProcessorsYour rights

Our Commitment

In short: oto is built with privacy as a principle. Your secrets and connection credentials are encrypted (AES-256-GCM) and isolated per user.

We believe your data belongs to you. oto minimizes data collection and encrypts sensitive items: your secrets and credentials for third-party tools are encrypted at rest (AES-256-GCM), with the master key kept out of the database, and isolated per user.

The data controller is Otomata, a SASU registered in Marseille (SIREN 106 974 637) — see legal notice. Details of our security measures are published on trust.oto.ninja.

What We Don't Collect

In short: No ad cookies, no ad networks, no data selling. Audience measurement, if enabled, only runs after your consent.
  • Ad cookies — No advertising cookies, no ad networks, no retargeting pixel.
  • Fingerprinting — We don't use any browser fingerprinting techniques.
  • Data selling — Your data is never sold, traded, or shared for commercial purposes.
  • No tracker without consent — No audience measurement is active before your explicit agreement.

What We Collect

In short: The minimum to run your account: sign-in profile, encrypted secrets for connected tools, subscription.

Account data

DataPurposeLegal basis
Sign-in identity (Logto)Authentication, account identificationContract
EmailIdentification, support, notificationsContract
Secrets / credentials for connected toolsRunning automations (encrypted AES-256-GCM)Contract
Subscription, plan and billing historySubscription management and billingContract

Payments

DataPurposeLegal basis
Transaction data (via Stancer)Collecting subscription paymentsContract

Card details (number, security code) are processed directly by our payment provider (Stancer) and do not pass through our servers.

Cookies & Analytics

In short: Essential cookies only (session, language). Audience measurement (PostHog, hosted in the EU) is enabled only after your explicit consent — nothing is collected before.
CookiePurposeDurationType
sessionAuthentication (logged-in session)SessionEssential
langLanguage preference1 yearEssential

The essential cookies above are strictly necessary to run the service. Audience measurement: we may measure audience and improve the site using PostHog (hosted in the European Union). This is enabled only after your explicit consent via the dedicated banner; without consent, no audience tracker is set. You can withdraw your consent at any time.

Processors

In short: A few processors within the meaning of Article 28 GDPR, bound by contract. A data processing agreement (DPA) is available.
  • Scaleway — Hosting, database, storage, secrets management, and transactional email — European Union (France)
  • Stancer — Collecting subscription payments; payment institution supervised by the French ACPR — France
  • Logto — OAuth 2.0 / PKCE authentication (self-hosted at Scaleway, EU)
  • PostHog — Audience measurement, only after consent — European Union
  • Sentry — Monitoring and logging of technical errors (may contain personal data) — European Union (Germany)
  • Anthropic (Claude) — AI assistant used by the Publisher's team for operations, support, and hands-on services (may occasionally process customer data in that context) — API mode with no training on submitted content; transfers outside the EU covered by standard contractual clauses — United States
  • Optional connector services — some connectors (e.g. hosted browser, messaging) rely on third-party services, enabled only if you use them and possibly operating outside the EU (covered by standard contractual clauses); up-to-date list on trust.oto.ninja

In accordance with Article 28 GDPR, a data processing agreement (DPA) governs this processing; it is also available on trust.oto.ninja. Any transfers outside the EU are covered by standard contractual clauses.

Your Rights (GDPR)

In short: You have control over your data. Access, rectification, deletion, portability, objection — on request.
  • Access — Get a copy of your data
  • Rectification — Correct inaccurate data
  • Deletion — Have your data erased, on request
  • Portability — Get your data in a standard format
  • Objection — Object to processing
  • Complaint — To the CNIL (French data authority)

To exercise your rights: email alexis@otomata.tech. We respond within 30 days.

Legal NoticeSubscription TermsData Processing Agreement (DPA)
ooto.cx
otomata ecosystem
↗otomata.tech the studio↗agent.otomata.tech the agent
links
alexis@otomata.techgithubabout usfaqopen sourcesecuritylegal noticeprivacyterms of useterms of saledpa
oto.cx · otomata sasu · mmxxvihandmade, in marseille.v0.1 · alpha · oss