Privacy Policy
Botty OS ("Ugly Botty"), an Orathon product · Last updated August 13, 2026
Botty OS is a personal executive assistant. To do its job it handles data you choose to connect. This policy explains exactly what we collect, why, and what we never do with it.
What we collect
- Account basics: your name and email when you sign in with Google, and your WhatsApp phone number if you link it.
- Your map: the context cards, projects, decisions, voice rules, playbooks, and chat messages you and your assistant create inside the product.
- Google user data (only if you connect Google Workspace and only per the permissions you toggle on): Gmail messages for triage, reply drafting, and voice training; Calendar events; Google Tasks; and Drive/Docs/Sheets content for answering your questions.
- Billing: handled by Stripe. We never see or store card numbers.
- Waitlist: your email address if you join the beta list.
How we use it
- To run your assistant: reading the data you connected, drafting replies for your approval, sending WhatsApp messages to you, and remembering what you tell it.
- Message content is processed by Anthropic's Claude models to generate responses, and voice notes by speech-to-text providers (OpenAI) and text-to-speech (ElevenLabs). These providers process data to provide the service, not to advertise to you.
- We do not sell your data. We do not use your data for advertising. We do not train our own models on your data.
Google user data — Limited Use
Botty OS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide the assistant features you asked for; it is never sold, never used for advertising, and never used to train generalized AI models. Gmail message bodies fetched for answering a question are read live and are not persisted to our database; we store only the minimum needed for the features you use (for example, the reply drafts you are reviewing and the sent emails you explicitly kept during voice training).
How we protect your data
- Encryption in transit: all traffic between your browser, our servers, and Google's APIs uses TLS (HTTPS). We never transmit Google user data over unencrypted connections.
- Encryption at rest: our database is encrypted at rest by our hosting provider (Neon).
- OAuth token protection: the Google OAuth tokens that grant access to your account are additionally encrypted at the application layer with versioned keys before they are stored, and are never sent to your browser or any third party.
- Least-privilege access: we request only the narrowest Google OAuth scopes needed for the features you enable, and inside the product each capability (reading mail, sending drafts, editing calendar, and so on) has its own permission toggle you control.
- Access controls: Google user data is isolated per account; organization data is readable only by authorized active members. Sensitive actions taken on your behalf (like sending an email) are recorded in an audit log.
- Operational security: credentials and signing keys live in managed environment configuration, never in source code, and production access is limited to the people who operate the service.
- Incident response: if we ever discover a breach affecting your data, we will notify you promptly at the email on your account and revoke affected credentials.
Storage and retention
- Data lives in a Postgres database hosted on Neon (US region) behind Vercel.
- Clearing a conversation archives it inside your account. Private data is isolated by account; organization data is available only to authorized active members.
- Disconnecting Google revokes our access; you can also revoke at myaccount.google.com/permissions.
- Expired login and verification records are removed automatically. WhatsApp deduplication receipts are kept for 30 days and provider-action audit records for 12 months by default.
- You can download your data or request account deletion in the product. We review shared-organization ownership and confirm deletion within 30 days.
Sharing
We share data only with the processors that make the product work: Vercel (hosting), Neon (database), Anthropic (model responses), OpenAI (speech-to-text), ElevenLabs (text-to-speech), Meta (WhatsApp delivery), Twilio (SMS and call delivery), and Stripe (billing). Each receives only what its function requires.
Text messaging (SMS)
Some businesses using Botty OS send text messages through us — for example, a one-time follow-up text after you call them and the call goes unanswered, or replies when you text a business's number first.
- No sharing of mobile numbers: mobile phone numbers and text-messaging originator opt-in data and consent are never shared with, sold to, or transferred to third parties or affiliates for marketing or promotional purposes.
- Message frequency: varies with your interaction — typically a single follow-up message per call or reply, never recurring subscriptions.
- Message and data rates may apply, according to your mobile carrier plan.
- Opting out: reply STOP to any message to stop receiving texts from that number immediately. Reply HELP for help.
Contact
Orathon · Miami, FL · fmo@orathon.com