The short version. We store your email address, your date of birth, your username, and your messages. We do not sell any of it, we run no advertising, and there is no analytics or tracking SDK in the app or on this site. Messages are not end-to-end encrypted: we can read them, and we do when somebody is reported.
Who is responsible for your data
Evie Software Limited is a company registered in England and Wales, number 15280612. It runs OTR and is the data controller for everything described here.
Registered address
C/O Taxassist Accountants
2 The Old George
George Street
Nailsworth
GL6 0AG
England
Email: [email protected]
We are not required to appoint a Data Protection Officer and have not appointed one. Anything on this page is answered by a person at the address above.
The promise, stated precisely
A masked thread hides the sender's identity from the person receiving it. That is a promise about other people, not about us. We know who sent every message, because an account nobody could identify is an account nobody could block, report or rate limit either.
Nothing in the app ever hands a recipient the sender's account. The alias and colour you see on a masked thread are all that leaves our servers.
What we collect, and why we are allowed to
UK data protection law asks us to have a reason — a "lawful basis" — for every use of your data, and to say which one. Ours are below. Where the basis is legitimate interests, we have weighed ours against yours and said whose and why.
Because you gave it to us
- Your email address. It is how you sign in — there is no password to forget. We use it to send six-digit codes and nothing else. No newsletters. Basis: performance of our contract with you.
- Your username and display name. Public by design: a username is the link you hand out. Basis: performance of our contract with you.
- Your date of birth. Asked once, when you first sign in, because we are not allowed to process your data on your say-so if you are under 13. It is never shown to anybody else, never used to work out anything but your age, and cannot be changed afterwards — a date you can edit is not an age check. If it says you are under 13 we lock the account until the birthday that makes it lawful. Basis: complying with a legal obligation.
- Your profile picture, if you set one. It is stored in a private bucket and served through an unguessable address, so a link you have not shared cannot be found by trying. Basis: performance of our contract with you.
- Your name and where you are, if you fill them in. Both are optional, both are typed by you rather than measured, and each one carries its own setting for who may see it — nobody, your friends, people you have unmasked to, or anyone. The location is a town and a country, never an address and never a coordinate. Basis: consent, which you give by filling the field in and withdraw by clearing it.
- Your settings — whether you accept masked messages, allow games, limit your link to friends, have it paused, or are in the pool that suggests strangers to each other. Basis: performance of our contract with you.
Because you used the app
- Messages you send and receive, with the time they were sent. Basis: performance of our contract with you.
- Who is in each conversation. For a masked thread this is the one piece we keep and never show. Basis: our contract with you, and our legitimate interest in being able to act on a report — an account nobody can identify is an account nobody can stop.
- Posts you write for the For You feed, whether you signed them or posted masked, and the colour rolled for each one. Basis: performance of our contract with you.
- Likes and shares you give a post, and the replies you send from it. A reply is a masked conversation like any other. Basis: performance of our contract with you.
- Who you said hello to, and who you passed on, if you joined the pool. Both are kept, and neither is shown to the other person — that is the only way a pass can stay indistinguishable from a hello nobody returned. Basis: performance of our contract with you.
- Blocks and reports you make. Basis: our legitimate interest in keeping the service usable, and yours in not being contacted by somebody you have blocked.
- A push token per device, so a notification can reach you. A push notification carries a conversation id and never the message itself. Basis: consent, which you give by turning notifications on and withdraw by turning them off.
- Moderation records — what a moderator decided, and every time an administrator asked who was behind a report. Basis: legal obligation, and our legitimate interest in being accountable for our own decisions.
What we deliberately do not collect
- No advertising identifiers, no third-party analytics, no tracking pixels, no crash-reporting SDK.
- No contact list. The app never asks for one.
- No browsing history, and no cookie on this website for anyone simply reading it.
- No special category data — we do not ask about your health, beliefs, politics, sex life or ethnicity, and nothing in the app is built to infer them.
No device location. The app has no location permission in either build and never asks for one. The town and country on a profile are typed into a text box and picked from a list — which is still location data about a person, and is declared as such, but it is not measured and cannot be more precise than a town.
No IP addresses are retained by the application. The sessions
table has ip_address and user_agent columns — they come with
Laravel's default migration — but production stores sessions in Redis, so that table is
never written, and the public pages are stateless so no session is created for a visitor
at all. Our hosting and network providers keep their own access logs, which contain IP
addresses, as every web host does; those are kept to operate and secure the service and
are not read for anything else.
No automated decision-making. Nothing here profiles you, and no decision with a legal or similarly significant effect is made about you by a machine. A post is checked by an automated filter before a person sees it, but a post being held back is always a person's decision, and you are told and can write to us about it.
Posts, and who reads them first
A post written for the For You feed is public: anyone with an account can read it. A masked post carries a colour and nothing else — no name, no picture, no link back to your account — and the colour is rolled per post, so two posts by the same person cannot be tied together by it.
Every post is read by a moderator before anybody else sees it. That is not a spot check: nothing reaches the feed until it has been approved, and a post that is reported goes straight back into that queue rather than staying up while somebody looks at it. A moderator reading the queue is not shown whose account wrote a masked post.
The pool that suggests strangers to each other is off until you turn it on. While it is on, other people may be shown a colour, the word "Mystery", and your town — but only if you have set your location to be visible to anyone. Nothing else about you is in a suggestion, and a conversation only opens when you have both said hello.
Who can read your messages
Messages are stored in plain text on our servers. We are telling you this rather than implying otherwise, because an app that says "private" and leaves you to assume end-to-end encryption has misled you.
In practice that means:
- The other person in the conversation. Obviously.
- A moderator, if that conversation is reported. Only the reported conversation, and a moderator is never shown whose account sent it.
- An administrator, if they ask to know who sent it. Asking is written down against their account, permanently, along with what they did next.
Nobody at OTR browses conversations. There is no screen in the product that lists them, and the only way into one is a report somebody filed.
What is kept on your phone
The app keeps a copy of your conversations on your device so that it opens instantly and still works on a train. Your sign-in token lives in the device keychain, never in that database. Signing out deletes both.
A reported conversation is never copied to your device.
Who we share it with
Nobody, commercially. We do not sell, rent or trade any of it, and we run no advertising.
We use a small number of suppliers to run the service. Each of them processes data on our written instructions and for no purpose of their own:
- Laravel Cloud (and the infrastructure it runs on) — hosting, the database and file storage.
- Cloudflare — DNS and the network in front of this website.
- Postmark — delivering sign-in codes.
- Apple and Google — delivering push notifications, which carry a conversation id and never the message.
We will hand over data if we are legally required to — a court order, or a request we are satisfied is lawful. If we are allowed to tell you it happened, we will.
Where your data goes
Our suppliers above are based in, or operate from, the United States. Where data leaves the UK it is transferred under the UK's International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, or under the UK extension to the EU–US Data Privacy Framework where the supplier is certified under it. You can ask us which applies to a particular supplier and we will tell you.
How long we keep it
- Messages and conversations — until you delete your account, or the conversation is deleted.
- Posts — until you delete them, or your account.
- Sign-in codes — ten minutes, and one use.
- An unconfirmed username reservation — a week, then it is released.
- Push tokens — until you turn notifications off, sign out, or the device stops existing as far as Apple and Google are concerned.
- Reports and moderation records — kept after the conversation is gone, so that a pattern of behaviour across accounts can still be seen. We review these periodically and remove what is no longer needed for that purpose.
- Retired usernames — indefinitely, as a list of names and nothing else, so that a link somebody saved does not later point at a stranger.
Deleting your account
In the app: You → Settings → Your account → Delete my account. You type your username to confirm, and it happens immediately — there is no cooling-off period and no way for us to undo it. If you cannot get into the app, this page explains the other way.
What deletion does:
- Your account, profile, picture, settings, friends, push tokens and sign-in codes are deleted.
- Your posts are deleted, along with their likes and shares — including posts that were already in the feed.
- Conversations you received are deleted, with their messages and games.
- Conversations you sent stay with the person who received them, with the link back to you destroyed. After that nobody can learn who wrote them — us included.
That last one is deliberate. The messages are the other person's conversation as much as yours, and an account that could erase what it had written from someone else's phone would be a way to take back harassment after the fact.
Your username is retired rather than recycled, so that a link somebody saved does not later point at a stranger.
Your rights
You have the right to:
- Be told what we hold and why — this page.
- See a copy of it.
- Correct anything wrong. Most of it you can edit in the app.
- Have it deleted, subject to the one exception above, which we have explained rather than hidden.
- Restrict what we do with it while a disagreement is sorted out.
- Object to anything we do on the basis of legitimate interests.
- Take it with you, in a machine-readable form, for the things you gave us and the things you made.
- Withdraw consent at any time, where consent is the basis. Turning notifications off, or clearing your town, does exactly that.
Deleting is in the app. For anything else, write to [email protected] from the address on your account and we will answer within one month. It costs nothing. If a request is unusually complex we may take up to two further months, and we will tell you inside the first one if so.
If you are not happy with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk, or by phone on 0303 123 1113. We would rather you came to us first, but you do not have to.
Children
OTR is for people aged 13 and over, and in some countries the minimum is higher. We ask your date of birth once, when you first sign in, and you cannot use the app until you have answered.
If the date says you are under 13, the account is locked until the day you turn 13, and we tell you so. We do not refuse the date and invite you to try another one, which would only teach you what to type — we take the answer you gave and act on it.
If you believe a child has an account, tell us at [email protected] and we will remove it.
Security
Sign-in is by one-time code, so there is no password of yours for us to lose. Codes are stored hashed. Traffic is encrypted in transit. Access tokens can be revoked, and deleting your account revokes every device at once. Profile pictures are stripped of their metadata and re-encoded before they are stored, so a photograph does not carry where it was taken.
No service is perfectly secure. If you find a flaw, please tell us at [email protected] before telling anyone else, and we will not take action against you for having looked.
If something happens to your data that is likely to put you at risk, we will tell you and the Information Commissioner, within the time the law allows.
Changes
If this page changes in a way that matters, we will say so in the app rather than quietly editing the date at the top.