ototi. Back to Ototi

Effective 18 July 2026

Privacy Policy

This policy explains what Ototi processes, why we process it, how long we keep it, and the choices available to you when you use the Ototi website or mobile app.

Who we are Scope What we process How we use it Who receives it Retention Your choices Security International transfers Children Changes Contact

Who we are

Ototi is an independent editorial reading and listening service. In this policy, “Ototi”, “we”, “us” and “our” refer to the service and its operator. For data-protection purposes, the operator of Ototi is the controller of personal data processed for the service.

Privacy questions and rights requests can be sent to hello@endlessriver.xyz.

What this policy covers

This policy covers the Ototi website, the Ototi app for iPhone and Android, and the systems used to provide support, verify purchases, deliver content, send enabled notifications, protect the service, diagnose failures, and measure whether the product works.

The public Ototi website is static. It has no account, newsletter, waitlist, or email-collection form. We do not use advertising trackers or non-essential cookies on it. Our hosting provider still receives ordinary web-request information, such as an IP address, request time, requested page, browser or device information, and security signals, to deliver and protect the site.

What we process

App activity and data on your device

Ototi is designed to start without an account. Progress, reading and listening position, completion history, saved ideas, weekly-goal activity, downloads, and settings are stored on your device. Your device platform may include app data in a device backup according to its own settings and policy.

Service identity and access

To provide app access without asking for personal profile details, Ototi may create a random, pseudonymous installation or service identifier. We may process that identifier together with authentication tokens, app and platform version, Store territory, entitlement state, and technical request information. This helps us deliver the correct content, preserve access, and prevent abuse.

If optional account linking or cross-device sync is introduced, we will explain what is uploaded and linked before you choose to use it. We will also provide a way to request account and associated-data deletion in the app and outside the app.

Minimal product measurement

The app may send first-party product events associated with a random installation identifier. Allowed event fields are limited to information such as an ototi content ID and version, reading or listening mode, topic domain, duration band, source surface, entitlement state, and experiment ID.

These first-party product events do not include profile details, advertising identifiers, the text of an ototi, saved-idea text, exact quotations, or full URLs. Because content IDs can reveal a reading or listening pattern, we treat them as pseudonymous learning history. Optional analytics can be turned off without losing access to Ototi.

Install attribution

Ototi uses AppsFlyer's mobile measurement SDK to understand which marketing channel or campaign an install came from. For this purpose AppsFlyer may process your device's advertising identifier (the Android Advertising ID or Apple IDFA) together with basic device and install signals. We use this only to attribute your install to Ototi's own marketing and to measure campaign performance. We do not use it for cross-app tracking, we do not build advertising profiles, and we do not share it with advertising networks to target you. Where your platform requires a tracking permission, attribution that relies on the advertising identifier runs only after you allow it, and you can reset or limit the identifier in your device settings at any time.

Purchases and entitlements

Apple or Google processes payments. Ototi does not receive your full payment-card details. We may receive transaction references, product and subscription status, Store territory, expiry, refund, revocation, and entitlement information needed to provide or restore Premium access. Transaction references are protected or transformed where practicable, and billing data is kept separate from product analytics by default.

Diagnostics, notifications, and messages

Technical logs may include app version, device and operating-system class, error traces, and limited state needed to reproduce a failure. Diagnostics are configured to avoid content text, signed links, purchase receipts, authentication tokens, and unnecessary personal data.

Local notification preferences remain on your device. If you enable a feature that requires remote notifications, we may process a device delivery token and notification status. If you email us or send a content report, we process the message, the address you use, any title or category you identify, and any technical reference or other information you choose to include.

How and why we use data

  • Provide the service: open content, keep your place, play audio, deliver downloads, verify and restore purchases, and preserve entitlements.
  • Operate safely: authenticate requests, prevent abuse, diagnose failures, secure delivery, and investigate content or rights reports.
  • Improve the core experience: understand whether onboarding, reading, listening, offline use, and calm retention features work as intended.
  • Respond to you: answer support, privacy, accessibility, and content-report messages that you send.
  • Meet legal obligations: keep records required for purchases, tax, complaints, security, and rights requests.

Depending on the context, our legal bases are performance of a contract, our legitimate interests in operating and improving Ototi, consent where required, and compliance with legal obligations. We do not sell personal data, use it for behavioural advertising, or conduct cross-app tracking.

Who receives data

We disclose only what is needed to the following recipients:

  • Apple and Google for app distribution, purchases, refunds, subscription management, and enabled notification delivery;
  • AppsFlyer for install attribution and mobile measurement, as described above;
  • infrastructure providers, including Vercel for website and API hosting, Supabase for app authentication and data services, and Cloudflare for private media delivery;
  • diagnostic or notification providers if those features are enabled in the released app;
  • professional advisers, regulators, courts, or law enforcement when required by law or necessary to protect legal rights; and
  • a successor responsible for Ototi if the service is transferred, subject to appropriate confidentiality and notice.

We do not provide protected source text, saved-idea text, or private support messages to advertising brokers. Providers process data under their own terms and, where they act for Ototi, under appropriate contractual restrictions.

How long we keep data

  • Raw first-party product events and content-access logs are kept for no more than 30 days, then deleted or converted into aggregate information that is not intended to identify you.
  • Local progress, history, saved ideas, settings, and downloads remain on your device until you remove them, reset the app, or uninstall it, subject to device backup behaviour.
  • Pseudonymous service and progress records are kept while needed to provide the service or until they are deleted under an available control or valid request.
  • Purchase, entitlement, refund, and fraud-prevention records are kept while needed to provide or restore access, resolve disputes, and meet Store, accounting, tax, and legal obligations.
  • Support, safety, and rights-request records are kept only as long as needed to resolve the matter and meet legal obligations.

Your choices and rights

You can turn off optional analytics and delete local history and statistics without creating an account. You can control notifications through Ototi and your device settings. Store subscriptions are managed and cancelled in the App Store or Google Play account used for the purchase.

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to withdraw consent. You may also complain to your local data protection authority. These rights may be subject to legal exceptions.

Send a request to hello@endlessriver.xyz. Please describe the device, installation, purchase, or message involved without sending passwords, full receipts, or unnecessary sensitive information. We may need to verify a request before acting on it.

Security

We use access controls, private content storage, short-lived or scoped delivery credentials, encrypted network transport, separation between billing and product analytics, and managed secret storage. The mobile app does not contain database-administration credentials. No system can be guaranteed completely secure, and we update safeguards as the service changes.

International transfers

Our providers may process data outside your country. Where the law requires a transfer safeguard, we rely on a recognised mechanism such as an adequacy decision or regulation, approved standard contractual clauses, a UK transfer addendum, or another lawful safeguard.

Children

Ototi’s catalog and editorial voice are intended for adults, and the service is not directed to children. We do not knowingly collect personal data from a child. If you believe a child has provided personal data, contact us so we can review and delete it where appropriate.

Changes to this policy

We may update this policy as Ototi, its providers, or applicable law changes. The effective date at the top identifies the current version. We will provide additional notice in the app or another appropriate place before a change takes effect when required by law.

Contact

For privacy questions, rights requests, or concerns about this policy, email hello@endlessriver.xyz.

ototi.
Home Terms of Use Contact