Skip to main content
OCTOVO

Otto splits its data into seven paths, depending on what they are. Four stay entirely on the device or run directly between your device and your own provider, without Otto standing in between. Only one actually carries content to a language model — and even that one only a snippet, never a whole mailbox.

Contents Docs overview

Memory · The data paths

Seven chains, seven destinations

Every kind of data takes its own, fixed path. The “Data paths” window makes this checkable: every chain shows its stations, who stands there, and what explicitly never happens on it.

The seven chains

  1. 01

    The local chain

    “Everything I know about you stays on this device. This chain has no endpoint outside it.” A single encrypted file (SQLCipher), its key held in the operating system’s keychain — not in the file, not in the backup. Searching and recalling run with a model that lives on the device: no request goes out to the network, no quota is used.

    No copy at Otto, no backup in someone else’s cloud, no remote access. Credentials live exclusively in the keychain — never in the database, never in the log.

  2. 02

    The thinking chain

    “For me to understand or write something, a snippet goes out — never your whole inbox, never your whole memory at once.” Otto assembles only what a single question needs. The Otto server (TCB GmbH, Germany/Hetzner) checks licence and quota and passes the request through without storing the content — only timestamp, account, model, character count, duration and status code are logged. The language model itself runs at Microsoft (Azure AI Foundry, EU resource Sweden Central), under a data processing agreement, with “store: false”.

    No intermediate storage, no log with content, no error message with content. Only if you switch on diagnostic mode yourself is anything recorded — for at most seven days, visibly, and deletable immediately.

  3. 03

    The account chain

    “Who you are and what you have booked — this chain carries nothing more.” Carries sign-in, plan and billing data, nothing from your mailbox, calendar or memory.

    No content from mailbox, calendar, files or memory — that is what the other chains are for.

  4. 04

    The mail chain

    “Between your mailbox and this device stands nobody — not even us.” Otto builds the connection itself, via IMAP/SMTP or your provider’s own interface, directly from the device.

    No email passes through a server belonging to Otto — the path runs directly from the device to the provider.

  5. 05

    The calendar chain

    “Between your calendar and this device stands nobody, not even us.” The exact same principle as the mail chain, via CalDAV or Microsoft Graph.

    No calendar appointment passes through a server belonging to Otto.

  6. 06

    The screen chain

    “Off by default. If you switch it on, text is created on this device — and the moment you ask something about it, a snippet goes to the language model.” That is why this is its own chain and not a subsection of the local one: screen text stays purely local only for as long as nobody asks about it.

    Nothing runs by default — recording first has to be switched on, visibly, in settings.

  7. 07

    The location chain

    “Off by default. Switched on, your iPhone measures roughly where it is once — the point itself stays between your phone and this device, only a place name goes further.” Deliberately kept separate from the local chain here too, because a place name can travel along the thinking chain, but the exact point never does.

    The exact measured point never leaves the phone-device pair — only a place name can travel further, and only when switched on.

Next: Quota, devices & account Back to memory & context