App + website privacy

Last updated: April 28, 2026

Privacy policy for Otter.

A plain-English policy for the Android app and this website: what stays local, what the site tracks, what uses Google services, and what becomes optional when hosted features are enabled.

This Privacy Policy explains how the Otter Android app and the Otter website handle information.

Otter is built as a local-first notes app. Core app note-taking can be used without creating an account, while this website uses Firebase Web Analytics to understand page views, navigation, CTA clicks, and documentation engagement.

Last updatedApril 28, 2026

Current assumptions: this website uses Firebase Web Analytics; Android app analytics consent is off by default; FCM is used for push; local notes remain usable without an account.

Core notesNo account required
WebsitePage + CTA analytics
App analyticsConsent controlled

Plain-English summary

The important parts first.

This summary does not replace the full policy below. It makes the data model clear before the legal detail starts.

Local notes stay local first

Core writing, search, tags, links, and export are designed to work from the on-device database without an account.

Website analytics is active

This website reports page views, source attribution, CTA clicks, navigation clicks, and documentation engagement to Firebase Web Analytics.

App analytics starts disabled

Android app Firebase Analytics is off by default and follows Otter’s app analytics consent setting when app usage metrics are enabled.

Push is feature-specific

Firebase Cloud Messaging supports notifications and token registration, not a requirement for basic local note-taking.

Service map

Connected service map.

Otter’s local editor does not need an account, but some app features rely on providers. This map keeps the purpose, data, and control surface visible.

Firebase Web Analytics

Purpose
Website measurement for page views, navigation, CTA clicks, documentation engagement, and source attribution.
Data
Page path, page URL, title, referrer, UTM fields, derived traffic source and medium, click target type, target URL, element label, element ID, component, and position.
Control
This website does not currently include a separate analytics opt-out switch; browser privacy controls, cookie controls, tracker blockers, or JavaScript controls can limit collection.

Android app Firebase Analytics

Purpose
Product health and usage understanding after analytics consent is enabled.
Data
Screen names, app-flow counts, result positions, purchase-flow metadata, notification status, and technical identifiers. Raw note text and raw search queries are intentionally excluded.
Control
Collection starts disabled by default; ad storage, ad user data, and ad personalization consent are denied.

Firebase Cloud Messaging

Purpose
Push notification delivery for app, sync, reminder, and account-related messages.
Data
FCM registration token, Firebase installation ID, app version, message metadata, notification titles, notification bodies, and data payloads when a push is delivered.
Control
Notification display is controlled by Android notification permission and app behavior.

Google Play Billing

Purpose
Subscriptions, paid features, entitlement checks, purchases, and restore flows.
Data
Product IDs, purchase state, restore status, entitlement tier, active status, renewal timing, and billing-flow outcome metadata.
Control
Payment method and Play account billing relationship are handled by Google Play.

Optional Otter services

Purpose
Account, sync, attachments, backups, and hosted entitlement features when enabled.
Data
Account identifiers, device IDs, access tokens, sync metadata, encrypted sync payloads, attachment metadata, and backup metadata depending on the feature used.
Control
Hosted features are optional layers on top of local note-taking.

Section 01

Scope and surfaces

This policy applies to two surfaces: the Otter Android app, and the informational website at otter.snyders.xyz.

The Android app privacy sections describe local notes, app analytics, Firebase Cloud Messaging, Google Play Billing, and optional account, sync, attachment, entitlement, or backup services that are offered for the app. The website analytics section describes Firebase Web Analytics used on this website.

If we materially change how the app handles personal information or add new third-party service providers that affect privacy, we will update this policy before or when those changes go live.

Section 02

Website analytics

The Otter website uses Firebase Web Analytics, which is connected to Google Analytics, to measure how people find and use the site. The site records page views, navigation clicks, CTA clicks, guide and syntax-documentation links, markdown-authored links, guide menu opens, and 404 recovery clicks.

Website analytics events include page title, page path, page URL, page referrer, derived traffic source and medium, UTM campaign fields when present, clicked target URL, clicked target type, element label, stable element ID, component name, and page position. This source information is kept with click events so, for example, a Google Play install CTA can still be attributed to a Google, campaign, referral, direct, or internal visit.

The website is informational. It does not provide a web note editor, website account, payment form, or website-hosted note storage. Website analytics do not include note content because note content is not entered into the website.

Google Analytics and Firebase may also process technical information such as browser, device, approximate geography, language, screen information, IP-derived location, cookies or similar identifiers, and other measurement data according to Google’s analytics services.

  • Page views for Home, Product, Guide, Syntax reference, Privacy, and 404 pages.
  • CTA clicks such as Google Play install links, product exploration, guide links, and privacy-policy links.
  • Documentation navigation such as guide shortcuts, section links, syntax links, and markdown-rendered links.
  • Traffic source fields such as UTM parameters, Google click identifiers, referrer host, and direct/referral/search/social classification.
  • No website note editor, no website account login, and no note content submitted through the website.

Section 03

Information stored on your device

Otter is designed so you can create, edit, search, and export local notes without signing in. Notes, tags, links, search data, preferences, and other note metadata are intended to be stored locally on your device.

Canonical note content is meant to remain in Markdown and plain text rather than a cloud-only format. Android cloud backup and device-to-device transfer for app data are currently disabled by default in the app configuration, so app data is not included in those platform backup flows at this time.

  • Local note-taking does not require signing in.
  • The on-device database is intended to remain the source of truth for local use.
  • Platform auto-backup for app data is currently disabled by default.

Section 04

Internet permission and network connections

The Otter Android app requests Internet access because Firebase Analytics, Firebase Cloud Messaging, Google Play Billing, and optional Otter service-backed features use network connections. The app is also configured to avoid unencrypted HTTP traffic by default.

Internet access is not intended to make normal local writing dependent on an account or a constant connection. For local-only use, Otter is intended to remain usable offline, although analytics after consent is enabled, notification registration, and billing checks may contact third-party services when the app is used.

  • Firebase Analytics app usage events after analytics consent is enabled.
  • Firebase Cloud Messaging token registration and push notification delivery.
  • Google Play Billing catalog, purchase, restore, and entitlement checks.
  • Account setup and device registration for optional Otter services.
  • Optional sync upload, sync download, and revision retrieval.
  • Entitlement refresh for paid tiers.
  • Attachment upload and download support.
  • Backup metadata retrieval.

Section 05

Android app Firebase Analytics

Otter starts with Firebase Analytics collection disabled by default. If analytics consent is enabled in the app, Otter uses Firebase Analytics to understand how the app is used, improve product decisions, and monitor whether important app flows are working. Firebase Analytics may collect technical and usage information such as app instance identifiers, device and operating system information, app version, approximate geography, sessions, app opens, app updates, first launches, and in-app purchase-related events.

Otter also sends custom Firebase Analytics events for app screens and actions. These events are designed to avoid raw note content: we do not intentionally send note titles, note bodies, tag names, folder names, or raw search queries to Firebase Analytics. Instead, analytics events use values such as screen names, feature entry points, counts, depths, result positions, product IDs, purchase outcomes, notification status, and whether a push token exists.

Otter configures Analytics ad storage, ad user data, and ad personalization consent as denied. The Android app also disables Google Analytics Advertising ID collection. Otter does not show ads and does not use your notes to build advertising profiles.

  • Analytics collection is disabled by default and controlled by the app analytics consent setting.
  • Screen views such as Notes, Editor, Tags, Search, Settings, Markdown guide, and Paywall.
  • Note flow metadata such as create attempts, note count, free limit, folder depth, note opened source, archive source, and delete source.
  • Search metadata such as query length, result count, and result position, but not the search text itself.
  • Folder and tag metadata such as depth and note count, but not literal folder or tag names.
  • Notification metadata such as received/opened source and whether notification or data payloads were present.
  • Billing and paywall metadata such as product ID, purchase result, failure reason, and entitlement tier.

Section 06

Firebase Cloud Messaging and notifications

Otter uses Firebase Cloud Messaging to support push notifications for app, sync, reminder, and account-related messages. Firebase Cloud Messaging and Firebase Installations may collect technical information needed to deliver messages, including a Firebase installation ID, app version, Firebase user agent, and FCM registration token.

The app requests notification permission on supported Android versions. Notification permission controls whether Otter can display notifications on your device; FCM token registration and token refresh can still be part of the push-notification lifecycle. When the app receives or opens a notification, Otter logs limited analytics metadata such as the notification source and whether a notification or data payload was present.

Otter does not intentionally send note bodies through analytics events. However, notification titles and bodies are displayed on your device from the push payload, so notification content should be treated as information processed by the notification service used to deliver it.

  • FCM registration token and token refresh status.
  • Firebase installation ID and app version used by Firebase services.
  • Notification title, body, source, message ID, and data payload when a push message is delivered.
  • Notification permission prompt state stored locally on the device.

Section 07

Google Play Billing and paid features

Otter uses Google Play Billing for subscriptions and paid features. Google Play processes the purchase flow, payment method, and Play account relationship under Google Play terms and policies.

Otter receives and stores the information needed to decide whether Pro features are active, such as product IDs, purchase state, entitlement tier, active status, and related timing. Otter also logs billing events to Firebase Analytics, such as paywall views, upgrade taps, restore attempts, purchase success, purchase failure, and the product ID involved.

  • Product ID and price information shown by Google Play Billing.
  • Purchase, restore, success, failure, and cancellation status.
  • Local entitlement state such as free or Pro.
  • Firebase Analytics user property for entitlement tier.

Section 08

Optional Otter account, sync, attachment, entitlement, and backup services

If account, sync, attachment, entitlement, or backup features are made available and you enable them, Otter may process the information needed to create your account, authenticate your device, sync your notes, manage attachments, and provide paid features. These hosted features are optional layers and are not required for basic local note-taking.

Depending on the feature you use, this can include both personal information and technical identifiers, and it can include note content or attachment-related data that must be transmitted to provide the service you selected. Sync payloads are designed to be encrypted before upload, but related metadata such as account ID, note ID, revision ID, device ID, timestamps, tombstone status, and conflict records may still be processed by Otter services.

  • Email address.
  • Account ID, device ID, and device label.
  • Access tokens used to authenticate service requests.
  • Sync envelopes, revision IDs, base revision IDs, conflict records, tombstone status, and related timestamps.
  • Encrypted sync payloads containing note data if sync is used.
  • Entitlement tier, active status, and renewal timing.
  • Attachment object paths, note IDs, attachment IDs, and generated attachment URLs.
  • Backup metadata such as note counts and last-updated timestamps.

Section 09

Information you choose to share or import into Otter

If you use the Android share sheet or import files into Otter, the app processes the content you choose to send to it so it can create or update notes on your device.

Otter only receives the text, Markdown, files, or attachments that you intentionally share or import. Otter is not intended to collect content from other apps unless you start that transfer.

  • Shared text can include plain text and Markdown content.
  • Imported files can include the note content or attachments you select.
  • The share flow is user-initiated rather than automatic background collection.

Section 10

What Otter does not do

Otter does not require an account for basic local note-taking. Otter also does not use your notes for advertising and does not put ads in the editor.

We do not sell note content, and we do not intentionally send note bodies, note titles, raw search queries, literal tag names, or literal folder names to Android app Firebase Analytics or website Firebase Web Analytics.

  • No ads in the editor.
  • No advertising SDKs or session-replay tools in the app at this time.
  • No Firebase Crashlytics, Firebase Remote Config, Firebase Auth, Firebase App Check, AdMob, or Firebase Storage SDK in the app at this time.
  • No account required for basic local note-taking.
  • No sale of note content for advertising purposes.

Section 11

Sharing and service providers

We do not share your information with advertisers or data brokers.

Otter uses service providers to operate the website and app features. These include Google Firebase for website analytics, Android app analytics, and cloud messaging; Google Play for billing; and infrastructure providers such as hosting, database, storage, and networking vendors for optional Otter services. We may also disclose information if required by law or if reasonably necessary to protect the app, the website, the service, or users from abuse, fraud, or security threats.

Section 12

Retention and control

For local-only use, your notes stay on your device until you edit them, export them, delete them, uninstall the app, or remove the app data from your device.

Android app analytics records are created only after analytics consent is enabled in the app. Website analytics records are created when the website loads and when tracked site interactions occur. Analytics, notification, billing, and optional hosted-service records are retained according to the operational, security, legal, and provider requirements tied to those services. There is currently no in-site control to delete Google Analytics event history for a specific browser session.

Section 13

Security

We use reasonable technical measures to protect information associated with Otter services. Otter is built around local-first storage, which reduces the amount of information that must leave your device for basic note-taking, and the app is configured to avoid cleartext network traffic by default.

Sync payloads are designed to be encrypted before upload, while sync metadata remains necessary for routing, conflict detection, and revision history. No method of storage or transmission is completely secure, so we cannot guarantee absolute security. If you enable optional hosted features, some data may need to move beyond your device in order to provide those features.

Section 14

Your choices and contact

If you want the smallest app data footprint, keep Android app analytics consent turned off, use Otter locally without enabling optional account, sync, attachment, or backup features, and decline notification permission if you do not want Otter to show push notifications. You can also export your notes in portable formats instead of relying on hosted storage.

For website analytics, you can use browser privacy controls, private browsing modes, tracker blockers, cookie controls, or JavaScript controls. The website does not currently provide a separate analytics opt-out switch.

If you have privacy questions about Otter, contact robin@snyders.xyz.