OttoLegal

Cookie and tracking notice

Draft — must be reviewed by a qualified lawyer in the EU before publishing.

Words in [SQUARE BRACKETS] are placeholders to fill in. Notes marked Review, Decision, Verify or Engineering are for the reviewing lawyer and for Max; remove every one of them before publishing.

Version: Draft 0.2 · 30 September 2026 · In force from [EFFECTIVE DATE]

This notice covers Otto's website at [DOMAIN] (the landing page, setup and these legal pages) and the Otto app at app.[DOMAIN]. It lists everything our pages store in your browser and every other website your browser contacts because of our pages. How we use the data is in our Privacy Policy.

The short version

Cookies

CookieSet byWhenPurposeLasts
otto_consentOtto (first party)When you answer the question on the landing pageRemembers your answer (v1.granted or v1.denied), so we do not ask again and our server knows whether it may send anything to Meta. Strictly necessary for your choice.180 days
otto_fbcOtto (first party)Only after you press Accept, and only if you reached our page from a Meta ad link (the link carries a fbclid click ID)Holds that click ID so Meta can tell which of our ads brought the visit. Deleted when you reject or withdraw consent.90 days
__cf_bmCloudflareOnly if Cloudflare's bot protection needs to tell people from automated traffic Verify: whether bot protection is on for our zoneSecurity30 minutes
cf_clearanceCloudflareOnly after you pass a Cloudflare security checkSecurityVerify: the challenge passage time set in Cloudflare
__Host-otto_sidOtto (first party, app.[DOMAIN] only)When you sign in to the Otto app with GoogleKeeps you signed in: a random code whose one-way hash our server keeps. Strictly necessary. Deleted when you sign out.30 days after your last visit
__Host-otto_loginOtto (first party, app.[DOMAIN] only)While you are on Google's sign-in pageTies Google's answer to the browser that asked for it (protection against forged sign-ins). Strictly necessary.10 minutes, deleted when you come back
CF_AuthorizationCloudflare AccessOnly for Otto's team, when signing in to the owner console (admin.[DOMAIN])Keeps our team signed inVerify: the session length set in Cloudflare Access

The Cloudflare cookies are set by Cloudflare, which protects and delivers our site; all three are strictly necessary.

What our pages keep in your browser tab

Session storage belongs to the browser tab and is deleted when you close it. Nothing in it is sent to us until you finish setup. It is used only for the service you asked for.

Your language. Our pages are in English. If you choose Nederlands or Deutsch (at the bottom of the page, in the menu or in the setup bar), the page remembers that choice in your browser's local storage (otto.lang), so your next visit opens in that language. It is never sent to us, it stays until you choose English again or clear this site's data, and nothing is stored unless you make that choice. It is used only for the service you asked for.

Visit statistics without cookies

Our pages send short messages to our own server (/otto-track): the page, the referring site's domain, campaign tags in the link, the type of device, and what you do on the page (scroll depth, sections seen, main buttons clicked, questions opened, films played, a scan started). Nothing is stored on your device for these statistics. Our server replaces your IP address with a code that changes every day and never writes the IP address down. With Do Not Track or Global Privacy Control switched on, the page sends one anonymous page view and nothing else. Your answer to the ad-measurement question is counted in these statistics too (how many visitors accept and reject), without anything that identifies you. The details are in the Privacy Policy.

We advertise Otto on Facebook and Instagram. To learn which of our ads bring people who are really interested, and to let Meta show our ads to similar businesses, we can tell Meta about these moments:

Moment on our pageName Meta uses
You start a website scanViewContent
Otto shows you the scan resultLead
You press a button that starts checkout, sign-up or a trial ("Get started", "Start free trial")InitiateCheckout
Only once sign-up opens on our site: you complete sign-up, or your trial starts (our server confirms it; your browser cannot report it)CompleteRegistration, StartTrial

This happens only if you pressed Accept. It is done by our server through Meta's Conversions API; no Meta code runs in your browser and your browser makes no request to Meta because of our page. With each moment our server sends: its name and time, a random event number, the page address, your IP address and browser type (Meta needs them to match the moment to an ad; we still do not store your IP address), the Meta click ID from the otto_fbc cookie if there is one, and one-way hashes of our daily visitor code and of your country code. We never send the website address you scanned, anything you typed, the referring site or campaign tags.

Your answer is ignored in one direction only: if your browser sends Do Not Track or Global Privacy Control, nothing is sent to Meta even if you pressed Accept. More about Meta's role, and how long Meta keeps the data, is in the Privacy Policy.

Engineering: forwarding switches on only when the server holds the Meta dataset settings (meta-capi.json in the secrets folder). Until then nothing is sent to Meta, even after Accept. Keep this section published either way: the question on the page must describe what would happen.

Other websites your browser contacts

PageHostWhat and whyWhat that host sees
Landing page and setupThe website you scanYour browser loads that website's logo directly from it, to show it in the preview. No referrer is sent.Your IP address and browser type
Sign-in (app.[DOMAIN])accounts.google.comOnly when you choose Continue with Google: your browser goes to Google's sign-in page and comes back. No Google code runs on our pages.What any visit to Google's sign-in sees, under Google's privacy policy
All other pagesNoneFonts, animation code and the privacy question are served from our own server—
Legal pages (this page)NoneEverything comes from our own server—

Links to other websites, such as Meta or Google, are not loaded until you click them. Those websites have their own cookie and privacy notices.

The Billing page in the app (where you pay) loads the payment form of our payment service provider, Stripe, from js.stripe.com. Stripe may set its own cookies in that form to prevent fraud; they are strictly necessary for the payment and are covered by Stripe's cookie policy. No other page of Otto loads anything from Stripe. Review: list Stripe's cookies (for example __stripe_mid, __stripe_sid) by name if the cookie table needs them.

Your choices

Questions: [PRIVACY EMAIL].

Back to top