Privacy Policy
Last updated September 27, 2026
The short version: Otto stores your to-dos, notes and everything you write on your own Mac, and nowhere else. There is no account and no cloud copy. Your calendar is read directly from Apple's or Google's servers under your own account.
Otto does have one small server of its own, for one thing only: anonymous usage counts, and only if you say yes — for example how many people finish the setup, or how often the notch is opened with the keyboard. It never receives your to-dos, notes, calendar, or anything you type. You choose at the end of setup, and can change it anytime in Settings.
Who this is
Otto is developed by Marcello Zanetta as an individual developer, not a company. Contact: marcello.zanetta1@gmail.com. Source code: github.com/AlphaTedi/Otto.
Data Otto stores
| Data | Where it lives | Ever transmitted? |
|---|---|---|
| To-dos, categories, notes, checklists | A JSON file in your Mac's Application Support folder | No |
| Settings and preferences | macOS user defaults, on your Mac | No |
| Calendar events | Read live from macOS Calendar (EventKit) or the Google Calendar API — not copied or cached beyond what is needed to render the current view | Only the request to fetch your own events, sent directly to Apple's or Google's servers under your account |
| Contact photos for meeting attendees | Read live from your Mac's Contacts app when a meeting has attendees | No — this lookup is entirely local and nothing is sent anywhere |
| Voice recordings (optional feature, off by default) | Transcribed on-device using Apple's Speech framework | No — audio never leaves the Mac and nothing is sent to Apple or any server for this feature |
Anonymous usage data (opt-in)
Otto asks once, during setup ("Connect your day"), with a switch you can turn off before you finish. If you installed an update without going through setup, nothing is shared unless you switch it on yourself. You can change it at any time in Settings › General › Privacy — turning it off also deletes anything still waiting to be sent.
| What is sent (only with your yes) | What is never sent |
|---|---|
| Which features are used and how (for example "a to-do was created", "the notch was opened from the keyboard", "the setup reached the shortcut step"), with coarse values such as yes/no or a time rounded and bucketed | The text of any to-do, note, step, list or section name |
| Otto and macOS version, language, the layout you chose, whether a calendar is connected | Calendar events, meeting titles, attendees, email addresses |
| A random ID created on your Mac, not linked to your hardware, Apple ID or any account (Settings shows it and can reset it) | Your IP address is not stored; your name and files are never sent |
The data goes to a small service run by Otto's developer on Cloudflare, stored in the European Union. Raw events are deleted after 90 days; only daily totals are kept longer. "Show what is sent" in Settings opens the exact file waiting to be sent. To have your data deleted, email the ID shown in Settings to the address above.
Feedback
"Send feedback" (in the panel's gear menu) sends what you write — the category, your message, any files you attach, your email if you want a reply, and, if you leave it on, the diagnostic lines shown in the form — to Otto's service, which forwards it straight to the developer's inbox as an email (through Resend, an email delivery service) and keeps no copy. It is only sent when you press Send. If you share usage data, Otto also counts that a feedback was sent and its category — never its words.
Google Account access
If you choose to connect a Google account, Otto requests exactly two permissions, and asks for nothing beyond what each is used for:
- See your calendar events (read-only) — used to show today's meetings in the notch and warn you before they start. Otto never creates, edits, or deletes a calendar event, and never requests write access.
- Your name and email address — used only to show which account is connected in Settings (for example, "Connected as you@gmail.com"). Not used for anything else.
This exchange happens directly between your Mac and Google's own servers, using Google's standard OAuth sign-in in your browser. Otto never sees or stores your Google password. The access token is kept in the macOS Keychain and is never transmitted to any server operated by Otto or its developer.
You can revoke this access at any time from your Google Account's third-party access settings, or by disconnecting the calendar from within Otto's Settings.
What Otto does not do
- No tracking, and no analytics unless you opt in to the anonymous usage counts above.
- No advertising, and no data is ever sold or shared with advertisers.
- No user accounts — there is nothing to sign up for and nothing tied to a central identity.
- No server — Otto's or anyone's — receives your to-dos, notes, or calendar data.
Automatic updates
Otto checks GitHub for new versions using Sparkle, an open-source updater. This check contacts GitHub's servers directly (not a server operated by Otto) to read a public update feed, and downloads the update package if you choose to install it. No personal data is sent as part of this check.
Data deletion
Uninstalling Otto removes the app; to also remove its stored to-dos and settings, delete
~/Library/Application Support/NotchSnap. Disconnecting a Google account (in
Settings, or via your Google Account permissions page) immediately revokes Otto's access —
Otto retains no copy of your calendar data once disconnected, since it was never stored, only
read live.
Children's privacy
Otto is not directed at children and does not knowingly collect data from anyone under 13.
Changes to this policy
If this policy changes, the "Last updated" date above will change accordingly. Material changes affecting how Google Account data is used will be reflected here before they take effect.