Cookie Policy
Last updated: March 2026
1. What Are Cookies
Cookies are small text files stored on your device when you visit a website. They serve various purposes including security, authentication, and site functionality.
2. Cookies We Use
Otto uses only cookies that are strictly necessary for security and authentication. We do not use any analytics, advertising, or marketing cookies.
| Cookie | Provider | Purpose | Duration | Classification |
|---|---|---|---|---|
| _GRECAPTCHA | Google reCAPTCHA | Bot and fraud prevention | Session / 180 days | Security-essential |
| next-auth.session-token | NextAuth.js | User authentication session | Session (30 days) | Strictly necessary |
| next-auth.csrf-token | NextAuth.js | CSRF protection | Session | Strictly necessary |
| next-auth.callback-url | NextAuth.js | Auth redirect URL | Session | Strictly necessary |
3. Security-Essential Classification
Otto classifies reCAPTCHA cookies as security-essential under GDPR Recital 49 and the legitimate interests basis. reCAPTCHA is used exclusively for bot and fraud prevention on signup, signin, and contact forms. It is not used for analytics, advertising, or user tracking.
reCAPTCHA is a Google service that analyzes user interaction patterns (such as mouse movement and keystroke timing) to distinguish humans from bots. This data is processed by Google according to their Privacy Policy and Terms of Service.
4. Strictly Necessary Classification
Authentication cookies (session token, CSRF token, callback URL) are strictly necessary for the operation of the service. Without these cookies, user authentication and CSRF protection cannot function. These cookies do not require consent under GDPR or the ePrivacy Directive.
5. No Analytics or Marketing Cookies
Otto does not use any analytics, advertising, or marketing cookies. We do not use Google Analytics, Facebook Pixel, or any other tracking services. If this changes in the future, we will update this policy and implement a full consent mechanism before loading any such cookies.
6. Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, blocking strictly necessary cookies may prevent you from signing in or using authenticated features of the service.
7. Contact
For questions about our cookie practices, contact us at privacy@otto-mode.ai. For more information about how we handle personal data, see our Privacy Policy.
