Privacy Policy
Last updated: 28 July 2026
MyOTGO is built privacy-first. Your home is yours: wherever it is technically possible, your devices run and your data stay on your own network. We do not sell your personal data, we do not use it for third-party advertising, and core smart-home control of devices you own does not require a paid subscription. This Privacy Policy explains what personal data we collect, why, the legal bases we rely on, who we share it with, how long we keep it, and your rights. It applies to the MyOTGO apps, the MyOTGO Hub, connected devices, our websites and related services (the “Service”).
Who we are (data controller)
MyOTGO (“we”, “us”) provides the Service and, for UK-GDPR and EU-GDPR purposes, is the data controller for the personal data described here. Contact us about privacy at keyhanazarjoo@gmail.com.
Information we collect
- Account & contact data: name, email, phone (if added) and authentication details.
- Device & home data: devices you add, their state, scenes, automations and energy readings (kept on your network in local mode).
- Messages & content you create: chat messages, call metadata, voice notes/audio, photos and files, and AI-assistant prompts.
- Precise location: only if you enable location-based features; you can turn it off.
- Contacts you choose to import (e.g. Google Contacts); we do not read your device address book.
- Connected-service data from Gmail, Google Calendar, Google Drive, GitHub, Slack or Notion — only the least-privilege scope you authorise.
- Purchases (plans/wallet/add-ons); card details are handled by our payment processor, not stored by us.
- Usage & diagnostics (interaction, crash and performance data). Analytics are OFF by default and opt-in.
- Identifiers: a user ID and device identifiers to sync your account and deliver notifications.
How we use your data & legal bases
We process personal data to provide and operate the Service and run your devices (performance of our contract), secure your account and prevent abuse (legitimate interests and legal obligation), send the notifications you enabled (contract/consent), improve the Service through opt-in analytics and crash reports (consent), and meet legal, tax and safety obligations. We do not sell your personal data or use it for advertising or profiling.
Connected services & Google user data
MyOTGO’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Data obtained from Google (such as Gmail, Calendar, Drive or Contacts) is used only to provide or improve the specific user-facing feature you requested, is not transferred to others except as needed to provide that feature or as required by law, is not used for advertising, and is not read by humans unless you consent, it is needed for security, or the law requires it. You can disconnect any connected service at any time, which revokes our access.
Voice & AI features
Voice and AI assistants are optional and can be turned off. Where possible, speech recognition and AI run on-device or on your own Hub (local-first), so your audio and prompts do not leave your home. When you choose a cloud option, only the content needed to answer your request is sent to the relevant provider.
Sharing & third-party processors
We do not sell your personal data. We share it only with processors acting on our behalf under contract:
- Google / Firebase — push notifications and opt-in analytics.
- Sentry — crash and error diagnostics (only if diagnostics are enabled).
- Microsoft Azure — cloud hosting, configuration and file storage.
- MongoDB Atlas — database hosting.
- Our payment processor — secure payments (it handles card data; we do not store card numbers).
- Apple and Google — app distribution and, where used, in-app purchases.
We also disclose data where required by law or to protect users’ rights and safety.
International data transfers
Where data is transferred outside the UK or EEA, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, with additional measures where needed.
Data retention
We keep personal data only as long as needed to provide the Service or to comply with law (e.g. purchase records). When you delete your account we erase or anonymise your data, except limited records we must retain by law. See our Account Data Deletion page for Google-linked accounts.
Your rights (UK-GDPR / EU-GDPR)
You may access, correct, erase, restrict, object to processing, port (export) your data, and withdraw consent at any time — most directly in Settings ▸ Account or by emailing keyhanazarjoo@gmail.com. UK users may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk; EEA users to their local authority.
California privacy rights (CCPA/CPRA)
California residents may know, access, delete and correct their personal information, and not be discriminated against for exercising these rights. We do not sell or “share” (as defined by the CPRA) your personal information. To make a request, email keyhanazarjoo@gmail.com.
Children’s privacy
The Service is not directed to children and is intended for users aged 16 and over (or the minimum age required in your country). We do not knowingly collect data from children.
Security
We use technical and organizational measures — encryption in transit, encryption of secrets at rest, and mutual-TLS device identity — to protect your data. No system is completely secure, so please use a strong, unique password and safeguard your credentials.
Changes & contact
We will update this policy as the Service evolves and show the revised date above. For privacy questions or to request data deletion (including Google-linked accounts), email keyhanazarjoo@gmail.com.