ototi. Back to Ototi

Effective 18 July 2026 · Updated 15 September 2026

Privacy Policy

This policy explains what Ototi processes, why we process it, how long we keep it, and the choices available to you when you use the Ototi website or mobile app.

Who we are Scope What we process How we use it Who receives it Retention Your choices Security International transfers Children Changes Contact

Who we are

Ototi is an independent editorial reading and listening service. In this policy, “Ototi”, “we”, “us” and “our” refer to the service and its operator. For data-protection purposes, the operator of Ototi is the controller of personal data processed for the service.

Privacy questions and rights requests can be sent to hello@endlessriver.xyz.

What this policy covers

This policy covers the Ototi website, the Ototi app for iPhone and Android, and the systems used to provide support, verify purchases, deliver content, send enabled notifications, protect the service, diagnose failures, and measure whether the product works.

The public Ototi website is static and does not use advertising trackers or non-essential cookies. The optional onboarding at ototi.app/start lets you create or access an Ototi account with an email one-time code and, if you choose, start a subscription through Stripe. Choices you make before the account step are kept only in your browser and are not sent with the purchase. Our hosting provider still receives ordinary web-request information, such as an IP address, request time, requested page, browser or device information, and security signals, to deliver and protect the site.

What we process

App activity and data on your device

Ototi is designed to start without an account. Progress, reading and listening position, completion history, saved ideas, weekly-goal activity, downloads, and settings are stored on your device. Your device platform may include app data in a device backup according to its own settings and policy.

Service identity and access

To provide app access without asking for personal profile details, Ototi may create a random, pseudonymous installation or service identifier. We may process that identifier together with authentication tokens, app and platform version, Store territory, entitlement state, and technical request information. This helps us deliver the correct content, preserve access, and prevent abuse.

If you choose to create or link an account, we process the email address and authentication records needed to confirm and protect it. The same account identifier links supported web, Apple, and Google subscription access; it is not used as an advertising identifier. You can request account and associated-data deletion in the app or through the contact route in this policy.

Minimal product measurement

The app may send first-party product events associated with a random installation identifier. Allowed event fields are limited to information such as an ototi content ID and version, reading or listening mode, topic domain, duration band, source surface, entitlement state, and experiment ID.

These first-party product events do not include profile details, advertising identifiers, the text of an ototi, saved-idea text, exact quotations, or full URLs. Because content IDs can reveal a reading or listening pattern, we treat them as pseudonymous learning history. Optional analytics can be turned off without losing access to Ototi. These product events are kept separate from the advertising data described next, which is the only place an advertising identifier is used.

Advertising and attribution

Ototi advertises for new readers, primarily through Apple Ads and TikTok, and may also use Google Ads, Meta, Yandex, and other advertising platforms disclosed here. Singular is our mobile measurement partner.

With tracking permission allowed on iOS, and with the Android advertising ID on Android, these partners may match the device advertising identifier, install, trial, subscription and refund events, app and device basics, and coarse country derived from an IP address to the advert that brought you. We use this to measure and optimise Ototi's own advertising and subscription return on advertising spend.

If you decline tracking on iOS, identifier-based cross-app matching does not run. Apple Ads may still provide privacy-preserving attribution through AdServices, and Apple may provide aggregate campaign results through SKAdNetwork and AdAttributionKit. Ototi does not share an ototi item's identity or text, saved-idea text, or reading and listening history with advertising platforms. Singular receives only a bounded funnel: onboarding completion, a content-start signal without the content identity, meaningful session completion, paywall view, checkout start, and Store-validated non-revenue signals that a subscription became active or a trial started. The last two signals contain no product, price, currency, receipt, or transaction identifier. Revenue events are sent only by RevenueCat.

Singular assigns a device-level attribution identifier (SDID), and Ototi supplies Singular with the same random installation identifier used by first-party measurement. The SDID is also provided to RevenueCat so Store-validated trials, subscriptions, renewals, cancellations, billing issues, expiries, and refunds can be attributed to the install and Ototi campaign that led to them. This attribution linkage does not include your name or email address. During the limited migration period, older app versions may continue using AppsFlyer for the same attribution purpose until they are upgraded.

Purchases and entitlements

Apple or Google processes in-app payments. For an optional website purchase, Stripe processes payment and RevenueCat coordinates checkout and subscription entitlement. Ototi does not receive your full payment-card details. We may receive transaction references, product and subscription status, billing territory, expiry, refund, revocation, and entitlement information needed to provide or restore Premium access. Transaction references are protected or transformed where practicable, and billing data is kept separate from product analytics by default.

Diagnostics, notifications, and messages

Technical logs may include app version, device and operating-system class, error traces, and limited state needed to reproduce a failure. Diagnostics are configured to avoid content text, signed links, purchase receipts, authentication tokens, and unnecessary personal data.

Local notification preferences remain on your device. If you enable a feature that requires remote notifications, we may process a device delivery token, notification preferences, delivery status, and whether a notification was opened. If you create or link an account, opt in to marketing, or otherwise ask to hear from us, we may also process your email address, communication preferences, and delivery, open, and link-interaction signals. If you email us or send a content report, we process the message, the address you use, any title or category you identify, and any technical reference or other information you choose to include.

How and why we use data

  • Provide the service: open content, keep your place, play audio, deliver downloads, verify and restore purchases, and preserve entitlements.
  • Operate safely: authenticate requests, prevent abuse, diagnose failures, secure delivery, and investigate content or rights reports.
  • Improve the core experience: understand whether onboarding, reading, listening, offline use, and calm retention features work as intended.
  • Advertising measurement: match installs, trials, subscriptions, renewals, cancellations, billing issues, expiries, refunds, and bounded funnel events to the advert that brought you, then measure and optimise the campaigns we run. Where consent is required, identifier-based matching runs only after you allow it.
  • Marketing communications: where you opt in, ask to hear from us, or applicable law otherwise permits it, send product news, editorial recommendations, offers, surveys, and re-engagement messages by email or push notification, and measure delivery and engagement so we can improve those communications.
  • Respond to you: answer support, privacy, accessibility, and content-report messages that you send.
  • Meet legal obligations: keep records required for purchases, tax, complaints, security, and rights requests.

Depending on the context, our legal bases are performance of a contract, our legitimate interests in operating and improving Ototi, consent where required, and compliance with legal obligations. Advertising measurement that uses the advertising identifier runs on your consent wherever consent is required, including the App Tracking Transparency permission on iOS. Aggregate, non-identifying campaign measurement rests on our legitimate interest in advertising Ototi efficiently.

Marketing by email or push notification is not a condition of using Ototi. We rely on consent where required and otherwise use marketing only where applicable law permits it. You can withdraw consent or opt out at any time; service, security, purchase, and sign-in messages may still be sent when needed to provide or protect your account or subscription.

We do not sell personal data. We do share limited attribution data — the advertising identifier, install and subscription events, and coarse signals derived from your IP address — with our ad-measurement partner and with the advertising platforms named in this policy, so that we can measure and optimise our own advertising. Some privacy laws treat that as “sharing” for cross-context behavioural advertising. You can stop it from your device settings, as described under your choices.

Who receives data

We disclose only what is needed to the following recipients:

  • Apple and Google for app distribution, in-app purchases, refunds, subscription management, and enabled notification delivery;
  • Stripe for website checkout, payment processing, tax and fraud controls, receipts, refunds, and subscription management;
  • RevenueCat for presenting website checkout, synchronising Apple, Google, and Stripe subscription status, providing Premium entitlements, and forwarding Store-validated revenue and subscription-lifecycle events to Singular;
  • Singular, our mobile-measurement partner, for install, bounded funnel, trial, subscription-lifecycle, refund, revenue, and campaign attribution;
  • AppsFlyer, temporarily, for the same attribution purpose in older app versions during migration;
  • Apple, for the adverts we run in the App Store through Apple Ads and the results measured against them;
  • Google, for the adverts we run through Google Ads and the results measured against them;
  • Meta, for the adverts we run on Facebook and Instagram and the results measured against them;
  • TikTok, for the adverts we run on TikTok and the results measured against them;
  • Yandex, for the adverts we run through Yandex and the results measured against them;
  • infrastructure providers, including Vercel for website and API hosting, Supabase for app authentication and data services, and Cloudflare for private media delivery;
  • email, push-notification, and diagnostic providers acting for Ototi if those features are enabled, limited to the contact, delivery, engagement, and technical data needed for the service;
  • professional advisers, regulators, courts, or law enforcement when required by law or necessary to protect legal rights; and
  • a successor responsible for Ototi if the service is transferred, subject to appropriate confidentiality and notice.

We do not provide protected source text, saved-idea text, or private support messages to advertising brokers. Providers process data under their own terms and, where they act for Ototi, under appropriate contractual restrictions.

How long we keep data

  • Raw first-party product events and content-access logs are kept for no more than 30 days, then deleted or converted into aggregate information that is not intended to identify you.
  • Local progress, history, saved ideas, settings, and downloads remain on your device until you remove them, reset the app, or uninstall it, subject to device backup behaviour.
  • Pseudonymous service and progress records are kept while needed to provide the service or until they are deleted under an available control or valid request.
  • Purchase, entitlement, refund, and fraud-prevention records are kept while needed to provide or restore access, resolve disputes, and meet Store, accounting, tax, and legal obligations.
  • Support, safety, and rights-request records are kept only as long as needed to resolve the matter and meet legal obligations.
  • Marketing contact details, preferences, and delivery or engagement records are kept while you remain opted in or while applicable law permits the communication, then deleted or minimised; a limited suppression record may be retained so an opt-out is honoured.
  • Attribution data is also retained by Singular, transitional AppsFlyer processing for older app versions, and by the advertising platforms under their own policies, which you can read here: Singular, AppsFlyer, Apple, Google, Meta, TikTok, and Yandex. On our own side we keep campaign results in aggregate.

Your choices and rights

You can turn off optional analytics and delete local history and statistics without creating an account. You can control notifications through Ototi and your device settings. Store subscriptions are managed and cancelled in the App Store or Google Play account used for the purchase.

You can turn marketing push notifications off in Ototi or your device settings. Marketing emails will include an unsubscribe route, and you can also opt out by contacting us. Opting out of marketing does not stop transactional messages needed for sign-in, security, purchases, subscriptions, or a support request you made.

You can change your mind about advertising at any time, and nothing in Ototi stops working if you do. On iPhone, open Settings > Privacy & Security > Tracking and switch Ototi off or back on. On Android, open Settings > Google > Ads, where you can reset the advertising ID or delete it entirely. Turning tracking off on iOS, or deleting the advertising ID on Android, stops identifier-based attribution at the source.

The platforms have their own advertising controls too: Google’s ad settings, Meta ad preferences, and Yandex advert settings. Apple’s personalised-advert switch is in Settings > Privacy & Security > Apple Advertising, and TikTok’s advert settings are inside the TikTok app. Information about Singular's privacy controls is available in Singular's privacy policy; AppsFlyer's migration-period opt-out is at appsflyer.com.

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to withdraw consent. You may also complain to your local data protection authority. These rights may be subject to legal exceptions.

If you live in California, Colorado, Connecticut, Texas, Virginia, or another US state with a privacy law, that law may treat the attribution data described in this policy as “sharing” for targeted or cross-context behavioural advertising, and in some states as a “sale”. You can opt out at any time by turning tracking off on iOS or deleting the advertising ID on Android. You can also email us to opt out or to exercise any other state privacy right, including an appeal, and we will not treat you differently for asking.

Send a request to hello@endlessriver.xyz. Please describe the device, installation, purchase, or message involved without sending passwords, full receipts, or unnecessary sensitive information. We may need to verify a request before acting on it.

Security

We use access controls, private content storage, short-lived or scoped delivery credentials, encrypted network transport, separation between billing and product analytics, and managed secret storage. The mobile app does not contain database-administration credentials. No system can be guaranteed completely secure, and we update safeguards as the service changes.

International transfers

Our providers may process data outside your country. Where the law requires a transfer safeguard, we rely on a recognised mechanism such as an adequacy decision or regulation, approved standard contractual clauses, a UK transfer addendum, or another lawful safeguard.

Children

Ototi’s catalog and editorial voice are intended for adults, and the service is not directed to children. We do not knowingly collect personal data from a child. If you believe a child has provided personal data, contact us so we can review and delete it where appropriate.

Changes to this policy

We may update this policy as Ototi, its providers, or applicable law changes. The effective date at the top identifies the current version. We will provide additional notice in the app or another appropriate place before a change takes effect when required by law.

Contact

For privacy questions, rights requests, or concerns about this policy, email hello@endlessriver.xyz.

ototi.
Home Terms of Use Contact