Privacy

What we know about you

OTR hides who sent a message from the person reading it. It does not hide anything from us, and this page is about the difference.

Last updated 22 September 2026

The short version. We store your email address, your date of birth, your username, and your messages. We do not sell any of it, we run no advertising, and there is no analytics or tracking SDK in the app or on this site. Messages are not end-to-end encrypted: we can read them, and we do when somebody is reported.

Who is responsible for your data

Evie Software Limited is a company registered in England and Wales, number 15280612. It runs OTR and is the data controller for everything described here.

Registered address
C/O Taxassist Accountants
2 The Old George
George Street
Nailsworth
GL6 0AG
England

Email: [email protected]

We are not required to appoint a Data Protection Officer and have not appointed one. Anything on this page is answered by a person at the address above.

The promise, stated precisely

A masked thread hides the sender's identity from the person receiving it. That is a promise about other people, not about us. We know who sent every message, because an account nobody could identify is an account nobody could block, report or rate limit either.

Nothing in the app ever hands a recipient the sender's account. The alias and colour you see on a masked thread are all that leaves our servers.

What we collect, and why we are allowed to

UK data protection law asks us to have a reason — a "lawful basis" — for every use of your data, and to say which one. Ours are below. Where the basis is legitimate interests, we have weighed ours against yours and said whose and why.

Because you gave it to us

Because you used the app

What we deliberately do not collect

No device location. The app has no location permission in either build and never asks for one. The town and country on a profile are typed into a text box and picked from a list — which is still location data about a person, and is declared as such, but it is not measured and cannot be more precise than a town.

No IP addresses are retained by the application. The sessions table has ip_address and user_agent columns — they come with Laravel's default migration — but production stores sessions in Redis, so that table is never written, and the public pages are stateless so no session is created for a visitor at all. Our hosting and network providers keep their own access logs, which contain IP addresses, as every web host does; those are kept to operate and secure the service and are not read for anything else.

No automated decision-making. Nothing here profiles you, and no decision with a legal or similarly significant effect is made about you by a machine. A post is checked by an automated filter before a person sees it, but a post being held back is always a person's decision, and you are told and can write to us about it.

Posts, and who reads them first

A post written for the For You feed is public: anyone with an account can read it. A masked post carries a colour and nothing else — no name, no picture, no link back to your account — and the colour is rolled per post, so two posts by the same person cannot be tied together by it.

Every post is read by a moderator before anybody else sees it. That is not a spot check: nothing reaches the feed until it has been approved, and a post that is reported goes straight back into that queue rather than staying up while somebody looks at it. A moderator reading the queue is not shown whose account wrote a masked post.

The pool that suggests strangers to each other is off until you turn it on. While it is on, other people may be shown a colour, the word "Mystery", and your town — but only if you have set your location to be visible to anyone. Nothing else about you is in a suggestion, and a conversation only opens when you have both said hello.

Who can read your messages

Messages are stored in plain text on our servers. We are telling you this rather than implying otherwise, because an app that says "private" and leaves you to assume end-to-end encryption has misled you.

In practice that means:

Nobody at OTR browses conversations. There is no screen in the product that lists them, and the only way into one is a report somebody filed.

What is kept on your phone

The app keeps a copy of your conversations on your device so that it opens instantly and still works on a train. Your sign-in token lives in the device keychain, never in that database. Signing out deletes both.

A reported conversation is never copied to your device.

Who we share it with

Nobody, commercially. We do not sell, rent or trade any of it, and we run no advertising.

We use a small number of suppliers to run the service. Each of them processes data on our written instructions and for no purpose of their own:

We will hand over data if we are legally required to — a court order, or a request we are satisfied is lawful. If we are allowed to tell you it happened, we will.

Where your data goes

Our suppliers above are based in, or operate from, the United States. Where data leaves the UK it is transferred under the UK's International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or under the UK extension to the EU–US Data Privacy Framework where the supplier is certified under it. You can ask us which applies to a particular supplier and we will tell you.

How long we keep it

Deleting your account

In the app: You → Settings → Your account → Delete my account. You type your username to confirm, and it happens immediately — there is no cooling-off period and no way for us to undo it. If you cannot get into the app, this page explains the other way.

What deletion does:

That last one is deliberate. The messages are the other person's conversation as much as yours, and an account that could erase what it had written from someone else's phone would be a way to take back harassment after the fact.

Your username is retired rather than recycled, so that a link somebody saved does not later point at a stranger.

Your rights

You have the right to:

Deleting is in the app. For anything else, write to [email protected] from the address on your account and we will answer within one month. It costs nothing. If a request is unusually complex we may take up to two further months, and we will tell you inside the first one if so.

If you are not happy with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk, or by phone on 0303 123 1113. We would rather you came to us first, but you do not have to.

Children

OTR is for people aged 13 and over, and in some countries the minimum is higher. We ask your date of birth once, when you first sign in, and you cannot use the app until you have answered.

If the date says you are under 13, the account is locked until the day you turn 13, and we tell you so. We do not refuse the date and invite you to try another one, which would only teach you what to type — we take the answer you gave and act on it.

If you believe a child has an account, tell us at [email protected] and we will remove it.

Security

Sign-in is by one-time code, so there is no password of yours for us to lose. Codes are stored hashed. Traffic is encrypted in transit. Access tokens can be revoked, and deleting your account revokes every device at once. Profile pictures are stripped of their metadata and re-encoded before they are stored, so a photograph does not carry where it was taken.

No service is perfectly secure. If you find a flaw, please tell us at [email protected] before telling anyone else, and we will not take action against you for having looked.

If something happens to your data that is likely to put you at risk, we will tell you and the Information Commissioner, within the time the law allows.

Changes

If this page changes in a way that matters, we will say so in the app rather than quietly editing the date at the top.

Contact

[email protected]