Legal
Privacy Policy
Last updated July 14, 2026
Your calendar is deeply personal. This policy explains what DayOtter collects, why, and the control you have. In short: we collect the minimum needed to run scheduling for you, we never sell your data, and sensitive tokens are encrypted at rest.
What we collect
- Account data - your name, email, timezone, and booking handle.
- Calendar data - connections and busy/free times we sync to compute your availability. OAuth tokens are encrypted at rest (AES-256-GCM).
- Booking data - event types, bookings, attendees' names/emails, and any intake answers.
- Usage data - basic analytics about how the product is used, and (on public booking pages) anonymous view counts to power your funnel analytics.
- Payment data - handled by Stripe; we store only a customer/subscription reference, never card numbers.
How we use it
To provide scheduling - syncing calendars, computing availability, creating bookings, sending reminders and confirmations - and to operate, secure, and improve the Service. We process data to perform our contract with you and for our legitimate interest in running a reliable product.
Otter, our AI assistant
When you use Otter - DayOtter's built-in assistant - the message you send and the relevant scheduling context (your event types, availability, and upcoming bookings) are sent to our AI provider, Anthropic, to generate a response. Otter is confirm-first: it only ever drafts a change and waits for your explicit confirmation - it never books, moves, or cancels anything on its own. Our AI provider does not use your data to train its models, and we don't use Otter conversations for advertising. AI features are optional - if you never use Otter, none of your data is sent to an AI provider.
How we share it
We share data only with the processors needed to run the Service - never for advertising, and we never sell your personal data. Those processors are listed below.
Subprocessors
We rely on a small set of vendors to operate the Service:
- Calendar & conferencing - Google, Microsoft, Apple, and Zoom, for the accounts you choose to connect.
- Anthropic - powers Otter's AI responses, only when you use Otter.
- Stripe - payments and subscription billing.
- Resend - transactional email (confirmations and reminders).
- Twilio - SMS one-time codes and reminders, if you enable them.
- Cloudflare - bot protection on public booking pages.
Some of these processors are based in the United States; where required, international transfers rely on standard contractual clauses.
Security
OAuth tokens, notification secrets, and webhook signing keys are encrypted at rest. API keys are stored only as hashes. Access is scoped per user and organization. See our security page for details.
Cookies
We use a session cookie to keep you signed in, and - where enabled - a bot-protection cookie on public booking pages. We don't use advertising or cross-site tracking cookies.
Retention
We keep your data while your account is active. When you delete data or your account, we remove it within a reasonable period, except where we must retain records for legal or accounting reasons.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your data, and to object to certain processing. You can export your bookings from the app and manage connections and channels in settings, or email us to exercise any right.
Self-hosting
If you self-host DayOtter, your data lives on your own infrastructure and this policy does not apply - you are the data controller.
Contact
Privacy questions or requests? Email hello@dayotter.com.
This is a plain-language template, not legal advice.