LEGAL

Privacy Policy

Last updated: August 23, 2026

What Ottoframe processes

We process account and show membership details, studio scheduling and participant information, local recording chunks, exports, campaign briefs, brand assets, consent and rights records, review decisions, billing state, security logs, and support communications. Camera and microphone access begins only after browser or device permission.

Recording and participant notice

Each recording participant must be told that a session is being recorded and locally uploaded. Hosts are responsible for obtaining any notice or consent required where participants are located. Accountless guest links identify the invited participant and expire; they are not a substitute for recording consent.

Campaign Studio and AI providers

When a director starts Campaign Studio work, Ottoframe sends the approved brief, references, prompts, and only the assets required for that job through Vercel AI Gateway to the selected model provider. Routing and providers can change as our benchmark allowlist changes. We request no-training routing where supported, but a provider may retain inputs or outputs for service operation, safety, or abuse prevention under its own terms. Do not submit regulated, highly sensitive, or confidential data to Campaign Studio.

Service providers and transfers

Ottoframe uses service providers for authentication, database and private object storage, realtime studio transport, durable job delivery and media processing, AI model routing and generation, payments, mobile subscriptions, monitoring, and email or support operations. These providers may process data outside your state or country. Their access is limited to operating the requested service.

Rights, likenesses, and provenance

Campaign records include rights attestations, claim approvals, consent references, model and prompt snapshots, and AI-generated labels. These records help your review; they do not independently establish that a campaign is lawful or cleared for broadcast.

Retention and deletion

Show content remains until an authorized member deletes it or the account is deleted, subject to operational backups and legal obligations. Account deletion removes controlled database records and private stored media after subscription cancellation and storage cleanup succeed. Model providers, payment processors, and other subprocessors apply their own documented retention. Archived data from the retired product is isolated and scheduled for deletion after its stated migration window.

Your choices

You can manage permissions in your browser or device, export completed media, update account details, and delete your account from Account settings. Depending on where you live, you may also request access, correction, deletion, portability, or restriction by emailing privacy@ottoframe.com.

Security and children

Ottoframe uses private storage, short-lived signed URLs, role-based access, verified worker callbacks, and payment providers so card data does not pass through our application. No system is completely secure. Ottoframe is not directed to children under 13, and users must be legally able to enter a contract in their location.