Privacy Policy
This policy explains what personal information Otava (operated by Creativco Inc., “we”, “us”) collects when you use otava.ai, why, who we share it with, and the choices you have. We are based in Canada and follow the Personal Information Protection and Electronic Documents Act (PIPEDA); where the GDPR or UK GDPR applies to you, the rights in section 7 apply as written there.
1. What we collect
- Account information — your name, email address, password (stored only as a salted hash), and whether you opted into product emails.
- Your sites and content — everything you put into the editor: text, images, files, and the code and configuration of repositories you connect.
- Instructions to the assistant — the messages you send in the editor, files you attach to them, and the assistant’s replies and the edits it made. These are kept as your site’s history so you can see and undo what changed.
- Connections — tokens that let Otava act on your GitHub account or installation, scoped to what you authorised. We store them encrypted at rest and use them only to read and write the repositories you connected.
- Billing — your plan, credit balance and invoices. Card details go directly to Stripe; we never see or store your card number.
- Technical data — IP address, browser type, the pages and API endpoints you use, timestamps and errors, in server logs kept for operating and securing the service.
- Visitors to sites you publish — we record page views for the analytics shown to you. We do not build profiles of your visitors or use their data for our own purposes.
2. Why we use it
- To provide the service: run your editor and previews, carry out the edits you ask for, publish and host your sites, and bill your plan.
- To keep the service secure: detect abuse, rate-limit, investigate incidents.
- To communicate: transactional email (sign-in links, password resets, invoices, notices about your account or these policies), and product email only if you opted in. You can opt out of product email at any time.
- To improve the service, using aggregate usage that does not identify you.
- To meet legal obligations, such as keeping tax and accounting records.
3. The AI assistant
When you ask the assistant to change your site, your instruction, any files you attach, and the relevant parts of your site or repository are sent to our AI model provider (Anthropic) to produce the edit. That provider processes the data to return a response and, under our agreement with them, does not use it to train their models. We do not use your content to train models either.
4. Who we share it with
We share personal information only with the providers we need to run the service, each under a contract that limits what they may do with it:
- Stripe — payments, subscriptions and invoices.
- GitHub — the repositories you connect.
- Anthropic — the AI model behind the assistant (section 3).
- Vercel and Google Cloud — hosting for the portal, previews and published sites.
- Supabase — the database that holds your account and site data.
- Resend — sending email.
We also disclose information where the law requires it, to protect our rights or safety, or as part of a merger or acquisition (in which case this policy continues to apply to your data). We do not sell personal information.
5. Where it is stored
Our providers store and process data in the United States and, for some hosting, in other regions. Where the law requires safeguards for that transfer, we rely on the providers’ standard contractual terms and data-processing agreements.
6. How long we keep it
- Account and site data: for as long as your account exists.
- After you delete your account: removed within 30 days, except invoices and records we must keep for tax and accounting (up to 7 years), and copies in backups, which expire on the backup schedule.
- Server logs: 90 days.
- GitHub tokens: deleted immediately when you disconnect the account or delete yours.
7. Your rights
You can, at any time:
- see and correct your account information in Settings;
- export your sites — your content is yours and your connected repositories are already in your Git provider;
- delete your account from Settings, which triggers the deletion in section 6;
- ask us for a copy of the personal information we hold about you, ask us to correct or delete it, object to or restrict how we use it, or withdraw consent where consent is the basis, by writing to the address below. We answer within 30 days.
- complain to the Office of the Privacy Commissioner of Canada, or to your local data-protection authority if you are in the EU or UK.
8. Security
We protect your data with encryption in transit and at rest, isolated environments for each customer’s previews, scoped credentials, and access limited to the people who need it. No service is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.
9. Cookies
We use a small number of strictly necessary cookies: to keep you signed in, to remember which workspace you are viewing, and to protect forms against forgery. We do not use advertising or cross-site tracking cookies, and we do not need a cookie banner for the cookies we set.
10. Children
Otava is for adults and businesses. We do not knowingly collect information from anyone under 18; if you believe we have, contact us and we will delete it.
11. Changes
We will post changes here and, for material changes, email the address on your account before they take effect. The effective date at the top is the version in force. See also our Terms of Service.
12. Contact
Privacy questions and requests go to the address at the bottom of this page.
Questions about this document: support@otava.ai