Ottipod

Privacy Notice

Effective 14 September 2026 · One notice for everyone, wherever you live. Written to meet the EU and UK GDPR, India's Digital Personal Data Protection Act, 2023 (DPDP) and US state privacy laws including California's CCPA. Plain words on purpose.

In one breath: Ottipod listens when you tell it to, turns what it hears into cards, and keeps those cards until you delete them. Audio is transcribed and not stored. Nothing is sold, shared for advertising, or used to train AI models. You can download everything or erase everything, yourself, any time, from anywhere.

Who is responsible

Ottipod, Bengaluru, Karnataka, India is responsible for your personal data — the controller under the GDPR, the Data Fiduciary under the DPDP Act, and the business under the CCPA. Questions, requests and complaints go to our privacy contact at hello@ottipod.ai, who is also the Grievance Officer required by Indian law.

What we collect, and why

WhatWhy (purpose)
Your Google account email (from Google sign-in)To create and secure your account and to reach you about it.
Your words — transcripts of what you say and what is said around you, from your phone, a wearable, a browser link or a OttipodTo make your cards, notes and reminders. This is the whole point of the service and only happens when you switch listening on.
Audio sent by a deviceTranscribed on the spot and then discarded. We do not keep recordings — audio is not kept.
Your cards, notes, comments and sharesSo you have them. Shared cards are visible to whoever you share them with.
Your settings — what you do (profession), where you usually are, your apps, your devicesTo sort and write things up the way your work needs.
Text you share into Ottipod from another app (a message, an email, a page)To make the card you asked for. Only what you share, only when you share it.
Your calendar — only if you paste its private addressTo know where you are and what is next while it listens, and to show the day ahead in the morning digest. Read every 15 minutes, never written to. The address is kept encrypted and you can remove it any time.
Usage counts — how many AI calls, how many words (never the content)To show you what your usage costs and to keep the service running.
Technical data — IP address, browser type, request logsSecurity, rate limits, fixing faults. Kept 30 days.

On what basis

If you bring in information about your patients, clients or students, you are the controller of that information and we act on your instructions as your processor. Ask us for a data processing agreement if your organisation needs one.

Where your data lives, and where it travels

Your data is stored on servers in Singapore (Fly.io). AI transcription and sorting is done by Google, which may process it in data centres outside your country. When data leaves the EU or the UK, it travels under the Standard Contractual Clauses (and the UK Addendum) in Google's and Fly.io's data processing terms. When it leaves India, it goes only to countries the Government has not restricted; none of the above is restricted as of the effective date. If you need your data kept in a particular region, ask us.

Who else touches your data (processors)

We do not sell your personal data, do not share it for cross-context behavioural advertising, and have not done so in the past 12 months. There is nothing to opt out of.

How long we keep things

Your rights, and how to use them

The same rights for everyone, wherever you live. Most of them are buttons.

RightHow
Access — a copy of everything we holdAbout you → Your data → Download everything. One file, instantly.
Portability — take it elsewhereThe same file. It is plain JSON, readable by any tool.
CorrectionEdit or dismiss any card in the app; change settings under About you. For your email, write to us.
Erasure / withdraw consentAbout you → Your data → Delete my account. Immediate. Shared pages and comments go with it; a claimed Pod is released.
Restrict or objectStop listening on any device (every ear can be muted), or write to us and we will pause processing while we look.
No automated decisions about youCards are suggestions you accept or dismiss. Nothing with a legal or similar effect is decided about you by a machine.
No discrimination for using your rightsUsing any right never changes what you get or what it costs.
Nominate someone to exercise these rights if you are unable toWrite to us with their name and contact.
ComplainWrite to us first: we acknowledge within 7 days and answer within 30 days. If you are not satisfied, you may complain to your supervisory authority — your national data protection authority in the EU, the Information Commissioner's Office in the UK, the Data Protection Board of India, or your state Attorney General or the California Privacy Protection Agency in the US.

Anyone can make a request for you (an authorised agent, or a nominee) — we may ask them to show they are allowed to. We will not ask you to create anything new to make a request; an email is enough.

Other people's voices

Ottipod hears the room, so it may hear other people. You decide when it listens, and you are responsible for telling people around you and for any consent the law where you are requires. In many places — parts of the United States, much of Europe — recording a conversation needs everyone's consent. Every ear shows when it is on — the orb, the tile under it, the light on a Pod — and every one can be muted. In a clinic, a court or an office, put up a notice.

Health, legal and other professional information

If you are a doctor, lawyer, nurse or other professional, your words may include information about patients or clients. Ottipod treats it with the same safeguards as everything else, and never stores audio — but you remain the professional responsible for that information and for your obligations to those people. Ottipod's notes and answers are reference material for you, not medical, legal or financial advice.

Children

Ottipod is for people aged 18 and over, everywhere. We do not knowingly collect a child's data, and do not track or profile children. If you believe a child has an account, write to us and we will erase it.

Keeping it safe

Everything travels over HTTPS. Keys and tokens are encrypted at rest. Access is limited to what is needed to run the service. If a breach affects your personal data, we will tell you, and the authority where you live, in the time the law there requires — within 72 hours to the authority under the GDPR, and to the Data Protection Board of India under the DPDP Act.

Cookies and storage on your device

Three cookies, all strictly necessary: your sign-in session, and two that live for ten minutes while Google signs you in. The app keeps a few settings on your device (which tab you were on, whether you have seen a tip). No advertising or analytics cookies, no tracking, so there is no banner to click.

Changes

If this notice changes in a way that matters, you will be asked to agree again inside the app before we continue. The effective date at the top always tells you the current version.

Ottipod · Terms · Contact