---
title: "Privacy — Ramosa"
description: "Sorting mail means reading it. What Ramosa reads, where it goes, what our servers keep, how Google user data is handled, and the full Privacy Policy."
url: https://ramosa.app/privacy
---

Privacy

# Why Ramosa *reads your email.*

Sorting mail means reading it. We would rather tell you exactly what happens than promise something we can’t keep.

[the Privacy Policy](https://ramosa.app/privacy#policy)·[delete or export](https://ramosa.app/privacy#controls)·[how we secure it](https://ramosa.app/security)

In short

### Your mail lives on your computer.

Messages and attachments are stored locally. Your mailbox passwords stay in your system’s keychain.

### AI sees only what it needs.

Once you switch AI on, Ramosa sends what each task needs through our servers to the AI model: to sort a message, its sender, subject, links and the opening of its text; to translate, the text you translate; to draft a reply, the thread. Our servers do not store it or write it to logs, and you can switch AI off in Settings.

### No retention, no training.

We send AI requests only to approved model endpoints that are restricted from keeping what we send and from training on it.

### Our servers hold almost nothing.

Your account email, subscription and devices. No mail content, no mailbox passwords.

The path of a letter

## Where your text goes, *and where it stops.*

### Your computer

The whole message arrives and stays here, with its attachments.

### Our servers

What the task needs passes through on its way — part of a message, the text to translate, or a thread. Not stored, not written to logs.

### The AI model

It reads what it was sent and answers. Approved endpoints are restricted from keeping it or training on it.

In your hands

## Leave whenever you like, *and take everything.*

### Clear this computer

In the app, one action removes the local mail library, attachments, logs and the saved mailbox passwords from this computer.

### Delete your account

Write to [Contact@Ottera.ltd](mailto:Contact@Ottera.ltd) from your account’s address. We delete your account and its cloud records at once — no waiting period, and no way back — so export first if you want a copy. A few limited usage and security records are kept only as long as [section 9 of the policy](https://ramosa.app/privacy#s9) describes. Your mail on your computer and at your provider is untouched.

### Export your data

Ask at the same address and you receive everything our servers hold about your account as one machine-readable JSON file: your account, plan, devices and usage counts. There is no mail in it, because we never had any.

The full text

## The Privacy Policy, *in full.*

The legal text behind this page: what we collect, why, for how long, and your rights where you live. Questions about privacy go to [Contact@Ottera.ltd](mailto:Contact@Ottera.ltd).

Effective date: 3 October 2026

This Privacy Policy explains how the global edition of Ramosa accesses, uses, stores, discloses, and deletes personal information when you use our desktop application, https://ramosa.app, and related account, support, payment, and AI functions. It covers information about users and information about other people contained in messages that users are authorized to process.

Your email database is stored on your device. AI processing is not entirely local: relevant message content is transmitted through our cloud relay to AI service providers when an AI function processes it. We do not use email content, prompts, or outputs to train general-purpose AI models, sell them, or use them for advertising. This Policy explains the boundaries of these commitments, including the separate handling of account records and technical metadata.

## Who is responsible for your information

Shanghai Ottera Internet Technology Co., Ltd., a company established in the People's Republic of China, operates Ramosa. Our registered address is Room 581, Building 2, No. 350 Xianxia Road, Changning District, Shanghai, People's Republic of China. Contact our privacy contact at Contact@Ottera.ltd.

We act as a controller where we decide the purposes and means of processing, including for Ramosa accounts, service security, billing administration, and our support correspondence. If an organization uses Ramosa to process information under its own instructions, its responsibilities and our role for that processing depend on the actual arrangement and any applicable data processing agreement. The organization's own privacy notices may also apply. This Policy does not by itself establish a processor agreement or change anyone's statutory role.

Your email provider independently operates your mailbox. Paddle independently handles its merchant-of-record, payment, fraud-prevention, tax, and transaction obligations under its own [Privacy Notice](https://www.paddle.com/legal/privacy). We explain our disclosures to those recipients below.

## Information we access and collect

### Account and profile information

We process your Ramosa login email address, account identifier, account region, account creation information, and verification and session records. We process a nickname or avatar if you choose to provide one. Email verification codes are used to authenticate you; they are not your mailbox password. We also maintain installation and device identifiers, platform information, session timestamps, and authentication token hashes needed to run the account service. Optional profile fields are not required for basic account administration.

If you choose to sign in to Ramosa with a Google or Microsoft account, that provider confirms your identity to us with a signed identity token. From it we use your account identifier with that provider, your email address and whether the provider vouches for it, and, where present, your organization's domain or tenant identifier. We keep a record that the token has been used so that it cannot be replayed. This sign-in requests only the basic identity permissions `openid`, `email`, and `profile`. It does not give Ramosa access to your mailbox, and we never receive your Google or Microsoft password. Connecting a mailbox is a separate step with its own authorization.

### Connected email information

The application accesses the accounts you connect, including email addresses, sender and recipient details, subjects, message bodies, message and folder identifiers, timestamps, read status, attachments, and other metadata needed to display, synchronize, search, or send your email. Recipients and correspondents are obtained from your messages and entries; connecting an email account does not by itself authorize a separate import of your Google Contacts or Google Drive.

The desktop application stores a working email database, downloaded or cached attachments, drafts, local organization states, preferences, and certain AI results on your device. Some results are kept only for the current application session. Mailbox authorization credentials, including OAuth tokens or an application-specific password where supported, are stored using the operating system credential facility. Our Ramosa cloud account database does not store your mailbox password or mailbox OAuth refresh token.

### Content used for AI functions

The information sent for AI processing depends on the function. Classification and summaries can use the sender's address, subject, and relevant body text. Drafting can use the recipient details, signature, tone, language, subject, and instructions you supply. Replies and follow-ups can also use selected earlier-message context. Translation uses the text to be translated. Daily overviews and reply suggestions use the relevant message information needed to produce that result.

These inputs may contain information about you or other people, including sensitive information already present in your correspondence. Links in an HTML message are listed separately in shortened form, while links written in a plain-text message travel with that text. Shortening links or limiting the length of an excerpt does not make the remaining text anonymous. We do not send attachment files to an AI provider simply because they are attached to an email. If you insert text from an attachment into an AI instruction, that inserted text becomes part of the AI input.

### Subscription and transaction information

For paid plans, we process the account and customer references, plan, subscription state, transaction identifiers, currency, amount, dates, renewal and cancellation status, and refund or dispute records needed to provide access and handle the transaction. Paddle collects payment details directly. We do not receive or store your full payment-card number or card security code. Paddle may provide billing or tax information necessary to reconcile an order or support a request.

### Technical and usage information

Our online systems and infrastructure providers process network information such as an IP address, request time, request type, connection and security information, and service error or status codes. Our application database uses hashed or opaque identifiers for relevant rate-limiting records. Hashing an identifier does not necessarily make it anonymous.

We record content-free AI usage information, such as the kind of function requested, token or allowance consumption, result status, request identifiers, and timing, to enforce allowances, prevent duplicate charging, control costs, and investigate service faults. This is distinct from storing an email body or an AI prompt or response.

The desktop application does not automatically upload crash reports or diagnostic bundles. Local event logs may exist on your device. A feedback email you choose to send includes what you write and basic application version, edition, and interface-language information; it does not automatically attach your mailbox or diagnostic logs.

### Support and website information

We receive your email address, correspondence, attachments you deliberately send, and information needed to resolve a support, privacy, security, or refund request. Do not send mailbox credentials, card security codes, or unrelated private messages. If you choose to join a beta or request updates through a website form, we process the address and choices submitted for that stated purpose. We do not treat a service or privacy request as consent to marketing.

## Where information comes from

We obtain information from you, from your device as it communicates with the Service, from email providers you authorize, from Paddle about a purchase, and from messages and recipients involved in your correspondence. If someone sends you an email, their details can be processed when your authorized Ramosa connection handles that message. We do not buy contact lists, enrich email contents with data-broker profiles, or acquire your unrelated browsing history.

If you are a correspondent rather than a Ramosa account holder, you may contact us with a privacy concern. We may need limited information to locate a cloud record and must protect the account holder's confidentiality. We cannot remotely search or erase a local-only mailbox copy that we do not hold. Where appropriate, we will explain whether the relevant request should also be addressed to the recipient or their organization.

## Purposes and legal bases

We use information for the following purposes. Where the GDPR, UK GDPR, or another law requires a legal basis, the basis depends on the information and the particular processing:

- Providing the service you request: account creation and authentication, email access, requested email actions, AI functions you enable, and plan administration. For a contracting individual, the basis is performance of the contract where the processing is objectively necessary. For authorized organizational users and correspondents, we assess the legitimate interests in providing authorized communication tools, subject to their rights and applicable restrictions.
- Protecting and operating the service: detecting unauthorized access, applying rate limits, ensuring reliable delivery, preventing duplicate charges, and investigating faults using minimized technical records. The basis is our legitimate interests in a secure, functioning service, or a legal obligation where one applies.
- Support and complaints: answering requests and resolving account, privacy, or billing issues. The basis is performance of a contract, legitimate interests in resolving the request, or a legal obligation, as applicable.
- Records required by law: complying with tax, accounting, regulatory, and valid legal-process obligations. We rely on the relevant legal obligation to the extent it applies; we assess other requests separately rather than treating every foreign request as automatically binding.
- Consent-based processing: third-party AI transfers where consent is required, optional marketing, and any non-essential website tracking. We seek the relevant consent before processing and provide a way to withdraw it. We do not treat acceptance of the Terms as a substitute for that consent.

We assess necessity and the impact on individuals before relying on legitimate interests. You may object as described in Section 11. Where special-category information is involved, an ordinary contract or legitimate-interest basis is not by itself enough: an additional applicable condition is required. We do not use sensitive email content to build independent profiles about health, beliefs, sexuality, or other protected characteristics.

The Service organizes and assists with email. We do not use email classification or AI output to make decisions about eligibility for credit, employment, insurance, or other decisions producing legal or similarly significant effects on you. We do not use the content of your correspondence to advertise to you or others.

## How email and AI processing work

### Local email functions

The desktop application connects directly from your device to your email provider to retrieve and display email and to perform the actions you authorize. Gmail and Microsoft mailboxes are reached through the provider's own mail interface (the Gmail API and Microsoft Graph); other providers are reached through IMAP and SMTP. Our servers are not part of that connection and do not hold a credential that could open your mailbox. Searching and ordinary local organization use the local database. Local archiving does not delete or move the provider's original message. Sending transfers the message and attachments to your email provider and the intended recipients. If you enable read-status synchronization, opening a message can mark it as read at your provider; AI classification alone does not do so.

Your local database is not synchronized into a cloud mailbox maintained by Ottera. Clearing local data or losing the device can remove local drafts and other information that the provider does not hold. Your operating system, backup software, or storage-sync choices may create additional copies under your control.

### AI transmission and providers

For an enabled AI function, the necessary input travels from your device through the Ramosa cloud relay to OpenRouter, which routes it to an inference provider permitted by our routing settings. The output returns through that path to your application. Our global service uses approved endpoints subject to zero-content-retention and no-training restrictions. Our relay processes AI inputs and outputs transiently and does not persist them in our application database or application logs.

Zero-content-retention means the inference endpoint must not keep prompt and response content after completing the request. It does not mean the content never leaves your device, that account and usage metadata are never stored, or that your local output disappears. We configure provider selection and retention restrictions for this purpose, and our routing settings are set to exclude endpoints that fail those restrictions. The inference operator is not necessarily the organization that originally developed the model.

We do not use your emails, AI inputs, outputs, or information derived from them to train, fine-tune, evaluate, or improve general-purpose or shared AI models, and we do not permit our AI processors to do so. Service reliability can be assessed using content-free operational measurements. We do not run human quality review of private email content for model improvement.

AI functions are off until you turn them on. Before transmitting connected-mailbox content to third-party AI services, we provide an in-product explanation of the data, recipients, and purposes and obtain the affirmative permission required for that processing. Once authorized, automatic classification and summaries may run in the background without a separate click for every message; drafting and translation follow the relevant user actions. A provider OAuth grant and acceptance of a privacy notice do not, on their own, replace the required AI-transfer disclosure and consent.

You may withdraw that permission at any time by turning off AI processing in the application's Settings. While it is off, the application on that device does not send message content to AI services; new mail still arrives and is shown unsorted. The choice is stored on each device, so turn it off on every device where you use Ramosa. You may also contact us for help, remove the affected mailbox connection, or revoke provider access. Withdrawal does not reverse processing already lawfully completed. It may make AI functions unavailable, without taking away your privacy or refund rights.

### New-message notifications

For Gmail and Microsoft mailboxes, the application asks the provider to signal when new mail arrives so that your device can fetch it sooner. This is set up when you connect such a mailbox, under the same authorization, and regular checking continues whether or not a signal arrives. Other providers are checked on a schedule only.

- Microsoft: Microsoft Graph sends a change notification to our relay. It identifies a subscription and carries a secret that we store only as a hash.
- Gmail: Gmail publishes a notification to a Google Cloud Pub/Sub topic that we operate, and Pub/Sub forwards it to our relay. The notification contains the mailbox address and a mailbox history marker. It does not contain subjects, bodies, senders, recipients, or attachments. Our relay verifies Google's signature, uses the address in memory only to compute a keyed digest for routing, and then discards the notification. To register for these notifications your device presents a Google-signed identity token for that mailbox, as described in Section 6; without it our relay does not route notifications to your device.

The cloud routing records contain subscription identifiers, installation references, verification hashes, expiry information, and, for Gmail, that keyed digest. They do not contain the mailbox address in readable form. Our relay does not persist or log the notification body, and the wake-up signal sent to your device contains only a subscription identifier and the kind of signal. Your device then retrieves the email directly from the provider. A routing record is removed when you remove the mailbox from that device or when it expires.

### Permissions for other providers

For Outlook.com and Microsoft 365 mailboxes, Ramosa requests the Microsoft Graph permissions `Mail.ReadWrite`, `Mail.Send`, and `offline_access`. We use them to read and display mail, to send messages at your direction (a large message is first staged as a draft in your mailbox and then sent), to mark a message as read when that setting is on, and to receive new-message notifications. We do not use them to delete or move messages, manage folders, or create mailbox rules. Signing in to your Ramosa account with Microsoft is a separate request for basic identity permissions only. Google permissions are described in Section 6. For providers reached through IMAP and SMTP, the application signs in with the application-specific password or authorization code you generate with that provider.

### Images and external links

When you deliberately open an external link or load remote content from an email, the external service may receive your IP address, browser information, or a tracking identifier contained in that link or content. Its privacy practices apply. Blocking or sanitizing content reduces some risks but does not make every link or attachment safe or anonymous.

## Google user data and Limited Use

Ramosa's use and transfer to any other app of information received from Google APIs will adhere to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We also comply with the applicable [Google Workspace user data and developer policy](https://developers.google.com/workspace/workspace-api-user-data-developer-policy).

### What Ramosa requests from Google

When you connect a Gmail or Google Workspace mailbox, Ramosa requests one Gmail permission, `https://www.googleapis.com/auth/gmail.modify`, together with the basic identity permissions `openid` and `email`, and calls the Gmail API directly from your device. Ramosa does not use IMAP, SMTP, or app passwords for Google accounts. We use these permissions to:

- read messages, attachments, labels, and thread identifiers so the application can display, search, and organize your mail on your device and provide the AI functions you have turned on;
- send the messages you choose to send;
- remove the unread label from a message you open, if you have enabled read-status synchronization;
- register for the new-message notifications described in Section 5; and
- prove to our relay, when your device registers for the Gmail new-message notifications described in Section 5, that it currently holds your authorization for that mailbox. We use `openid` and `email` only for this purpose.

We do not use them to delete or trash messages in your Google mailbox, to change filters, forwarding, or account settings, or to obtain Drive, Calendar, or Contacts data. These permissions do not allow permanent deletion of mail.

If you sign in to your Ramosa account with Google, that is a separate request for `openid`, `email`, and `profile` only. It identifies your Ramosa account and grants no mailbox access.

### Where Google user data is kept

Gmail messages and attachments are stored in the application's database on your device. Your Google access and refresh tokens are stored in your operating system's credential store and are exchanged directly between your device and Google; our servers never receive them. When your device registers or renews Gmail new-message notifications, it sends our relay a Google-signed identity token that Google has just issued for that mailbox. The relay checks Google's signature and that the token's email address matches the routing digest, keeps a one-way hash of the token for less than 15 minutes so that it cannot be reused, and discards the token itself without storing or logging it. Our servers do not store Gmail message content. They hold only the keyed routing digest described in Section 5, the short-lived one-way hash just described, and, if you sign in with Google, the Google account identifier and email address used as your Ramosa login. Message excerpts pass through our relay to AI providers only for the AI functions you have turned on, and are not retained there. You can delete the Google data held on a device with the “Clear local data” control, and the cloud records by closing your Ramosa account.

### Limited Use

The following restrictions apply to Google-derived information, including information derived from messages, and take precedence over a more general permission elsewhere in our documents:

- We use it only for the disclosed, prominent email and productivity functions that you authorize. AI inference serves those functions for you.
- A service-provider transfer must be necessary for an authorized user-facing function and supported by the required user consent. Other transfers are limited to permitted security needs, applicable legal requirements, or a business transfer after obtaining the user's prior explicit consent.
- People do not read Google-derived message content except with your documented permission for specific information, where necessary for a permitted security investigation or legal requirement, or within Google's narrowly permitted rules for aggregated and anonymized internal operations. We do not use the last exception to maintain a corpus of private messages.
- We do not sell the information, disclose it to data brokers or advertising networks, use it for targeted advertising, use it to determine creditworthiness or lending eligibility, or use it for surveillance.
- We do not use it to build, train, or improve general-purpose or shared AI models. This restriction also binds providers processing it for us.

Employees, contractors, processors, and successors must follow the applicable restrictions. Consent to an unrelated future purpose is not inferred from your continued use. You can revoke Ramosa's access through your [Google Account connections](https://myaccount.google.com/connections). Revocation and deletion are separate, as explained below.

## Recipients of information

We disclose only information necessary for the relevant purpose and subject to applicable confidentiality, security, and data-use terms:

- Cloudflare provides global cloud infrastructure, account-database services, request delivery and protection, notification routing, and login-email delivery. It processes the network and account information needed for these services and transient AI traffic carried through our relay.
- OpenRouter and permitted inference providers process the AI input and output described in Section 5 and the technical metadata required to deliver and account for inference. They do not receive mailbox OAuth tokens or application-specific passwords from us as part of an AI request. Their permitted purposes exclude advertising and general-purpose model training on that content.
- Email providers and recipients you choose, including Google and Microsoft where connected, process mailbox access, authorization, outgoing messages, and provider notifications. Email recipients receive what you send to them. Google or Microsoft also acts as an identity provider if you use it to sign in to Ramosa.
- Google Cloud carries Gmail new-message notifications through a Pub/Sub topic that we operate, as described in Section 5. Those notifications contain a mailbox address and a history marker, not message content.
- Paddle processes your purchases as merchant of record. We exchange account references and necessary order, subscription, refund, and fraud-related information. Paddle's own statutory retention and privacy obligations apply to its independent records.
- Support and business service providers, including the hosted business-email service that receives Contact@Ottera.ltd correspondence, process what you choose to send and necessary support records. Our business support email is handled through Feishu, a hosted service operated in mainland China, so correspondence you send to Contact@Ottera.ltd is stored there. Professional advisers may receive the limited records necessary for legal, accounting, or other legitimate advice, subject to confidentiality and the stricter Google rules.
- Authorities and other legally entitled recipients may receive information where disclosure is legally required or necessary and proportionate to protect rights, safety, or service security. We assess the request, minimize the disclosure, and notify affected people where legally permitted and appropriate. This is not unrestricted permission to share a mailbox.
- A potential successor may receive necessary non-content business records in a lawful corporate transaction subject to suitable protections. Google user data will not transfer as part of such a transaction without the prior explicit consent required by Google's policy.

We do not sell personal information or share it for cross-context behavioral advertising. We do not provide an email-content feed to advertisers or data brokers. You can ask Contact@Ottera.ltd for information about the processors relevant to your request. Material recipient or purpose changes are subject to the notice and consent rules in Section 14.

## International processing

Ottera is based in Shanghai, China. The global edition uses Cloudflare infrastructure outside mainland China and AI services delivered through OpenRouter and permitted inference providers. Our account database is currently hosted by Cloudflare in the Asia-Pacific region. Gmail new-message notifications pass through Google Cloud. Provider infrastructure may operate in the United States and other countries. Account administration and support information may be accessed by authorized Ottera personnel in China, and support correspondence is processed through our business-email arrangements. The location of a supplier's headquarters does not establish the location of every processing operation. We do not promise that all global-edition data stays in a single country or exclusively in the United States.

Our global and mainland-China service environments are separate. That separation does not eliminate the international processing described above, including authorized administration and the content you voluntarily send to support.

Where applicable law restricts a transfer, we must have an appropriate transfer basis and safeguards before making it. Depending on the transfer, this may include an applicable adequacy decision, the European Commission's standard contractual clauses and necessary supplementary measures, or the corresponding UK or Swiss arrangements. We assess relevant transfer risks and processor commitments. Contact us to request details or an appropriately redacted copy of the safeguards applicable to your information. General acceptance of this Policy is not relied upon as a substitute for required transfer safeguards.

## Retention and deletion

We retain personal information only for a defined purpose and for no longer than necessary for that purpose, subject to applicable legal requirements. Where a fixed period depends on the record or applicable law, we use the following criteria:

- Local email, drafts, attachments, and AI results: retained on your device while needed for the local functions and until removed through the available controls or deletion of the application's data. Some transient results end with the session. A local copy may remain after a message is deleted at the email provider; Ramosa is not a mirror that guarantees remote deletion immediately erases all local copies. Provider-specific caching restrictions also apply. Local event logs are kept for 14 days. The “Clear local data” control removes the application's local database, cached attachments, logs, and stored credentials from that device, subject to completion of the operation. Copies you separately exported or backed up remain under your control.
- New-message notification records: kept while the subscription is active. They are removed when you remove the mailbox from that device, replaced when the subscription is renewed, and cleared after expiry.
- Mailbox credentials: kept in your device's credential store while the connection requires them. Removing a mailbox connection or successfully clearing local data removes the associated stored credentials. Revocation at the provider invalidates further access but does not itself remove every local file.
- AI prompt and response content in our relay: transient for the request, not retained in our cloud application database or logs. Approved inference endpoints are restricted to zero-content-retention processing. Outputs saved locally remain subject to the first item above.
- Account, profile, and authentication records: maintained while the account is active and needed for authentication or administration. After a verified closure request, we delete the account and its cloud records at once; there is no waiting or recovery period, and a closed account cannot be restored. Records subject to an applicable statutory exception, such as a transaction record Paddle must keep, are retained only as that exception requires.
- Usage, entitlement, and security records: retained to administer the applicable plan or allowance, prevent duplicate charging and misuse, investigate a specific incident, and resolve billing questions. We review continuing need and delete or de-identify records when those purposes end. A continuing disputed charge or security incident may justify retaining the relevant limited records, not the entire mailbox.
- Support and privacy requests: retained for handling the request, documenting the outcome and our compliance, and the relevant complaint or legal-claim period. We minimize or remove unnecessary message content and attachments.
- Transaction and statutory records: retained for the applicable tax, accounting, anti-fraud, dispute, or legal-claim period. Paddle retains its independent transaction records under its own notice. Account closure does not require unlawful deletion of a receipt or an outstanding legal record.
- Backups: an operational deletion may not immediately remove an existing protected backup. Residual copies are restricted from normal use and expire under the relevant backup cycle. If a backup is restored, valid deletion requests must be applied again. A legal hold is limited to records and periods that the legal need requires.

We will explain an applicable retention exception when responding to a deletion request unless the law prevents disclosure. Deleting records from our systems does not erase separate copies held only on your device or in a third party's independent system.

## Security

We use measures appropriate to the information and risks, including encrypted network connections, operating-system credential storage, authentication controls, restricted operational access, minimized cloud payloads, content-excluding application logs, and tests of relevant data flows. Service providers are subject to appropriate processing restrictions. We review access and respond to incidents.

These measures cannot prevent every security incident. The operating-system credential store protects mailbox credentials; it does not encrypt the local email database. Protect your operating-system account and device, use available disk encryption, and take care with backups and shared computers. We will make legally required incident notifications.

## Your choices and privacy rights

You may contact Contact@Ottera.ltd to request access, correction, a copy or export, deletion, restriction, objection, withdrawal of consent, or help with account closure. State what you need and the email address associated with the relevant account, if any. You do not need to create a new account or purchase a plan to exercise a privacy right. We verify identity proportionately and do not routinely ask for government identification when an account or email-based verification will suffice.

Depending on the applicable law, you may have a right to:

- know what personal information we process, its source, purposes, recipients, and retention criteria, and obtain a copy;
- correct inaccurate information and request erasure, subject to lawful exceptions;
- obtain certain information you provided in a commonly used, machine-readable format and ask for its transfer where technically feasible;
- restrict processing or object to processing based on legitimate interests, and object to direct marketing at any time;
- withdraw consent without affecting processing lawfully completed before withdrawal; and
- complain to a competent supervisory authority or use an available judicial remedy.

Where the GDPR or UK GDPR applies, we generally respond within one month and explain within that period any lawful extension of up to two further months. Where applicable US state law requires a response within 45 days, we follow that deadline and any permitted extension and notice requirements. Shorter mandatory deadlines take priority. We explain a refusal and available review or complaint route. Requests are ordinarily free; a fee or refusal is used only where the applicable law permits it and we explain the basis.

Different controls have different effects. Removing a mailbox stops its ongoing connection. Revoking OAuth access stops provider authorization. Clearing local data removes data on that device. Closing the Ramosa account addresses our cloud account records and linked renewal. A cloud account export does not include a copy of every local email or export from the provider. Contact us for an export of the account information we hold and instructions for your local information. Your email provider's export tools may be the appropriate way to obtain the provider's full mailbox.

You may send a privacy request by email even if a self-service control is unavailable. We will coordinate required instructions to processors and explain steps that must be taken separately on a device or with a provider. Account deletion does not recall sent messages from recipients or delete the provider's original mailbox.

## California and other US state disclosures

To the extent applicable state privacy law covers our processing, the categories described in Sections 2 and 3 include identifiers and account records; commercial and subscription information; internet or network activity; correspondence and other content you provide; and inferences limited to the email-assistance results requested. Credentials and private email content may be sensitive personal information. An avatar or attachment can also include image or other media information. We do not independently collect precise location, biometric identifiers, or unrelated browsing activity as product features.

The sources, purposes, recipient categories, and retention criteria for each type are described in Sections 2 through 9. Those disclosures apply to our current service and, to the extent operated during that period, the preceding 12 months. Information is disclosed for the service and business purposes described above. We have not sold personal information or shared it for cross-context behavioral advertising during that period and do not knowingly sell or share information about anyone under 16.

We use sensitive information only to provide requested services and for permitted security, legal, and operational purposes; we do not use it to infer unrelated personal characteristics. We do not engage in targeted advertising or the legally significant profiling described in Section 4. Consequently, there is no such sale, sharing, targeted advertising, or unrelated sensitive-data use to opt out of under our current practices. We do not override a recognized opt-out preference signal such as Global Privacy Control if a covered activity would otherwise occur.

Eligible residents may request access, deletion, correction, portability, and other rights provided by their state's law. We do not discriminate for exercising those rights. An authorized agent may act for you with appropriate proof of authority, and we may verify your identity directly when law permits. If we deny a request and your state's law gives a right to appeal, reply to Contact@Ottera.ltd with “Privacy appeal”; we will explain our decision and any further complaint route within the applicable period. California residents may contact the California Privacy Protection Agency or the California Attorney General. These rights are subject to the scope and exceptions of the applicable law.

## Cookies and children

Our website and account functions may use storage or cookies necessary for authentication, security, consent choices, and requested preferences. We do not use email content for advertising cookies or tracking. Any future non-essential analytics or marketing technology will require an updated, specific disclosure and consent where required before it is enabled. Paddle and an external site you visit operate their own technologies under their notices.

Ramosa is intended for people aged 18 or older. We do not knowingly invite children to create accounts or intentionally collect information from them as users. If you believe a child has created an account or submitted information without appropriate authority, contact us so we can investigate and take appropriate action. This age rule does not mean an authorized adult's correspondence can never contain information about a child; such content receives the same purpose and access restrictions, with any additional protection required by law.

## Changes and contact

We will update this Policy when our processing materially changes and identify the effective date. We will give appropriate advance notice of material changes through email, the application, or our website. We will obtain fresh consent before a new Google-data purpose, materially different AI disclosure, or other change requiring consent takes effect. An update does not retroactively authorize a use that was not permitted when information was collected.

For privacy, rights, account-export, deletion, or security questions, contact Contact@Ottera.ltd. Postal requests may be sent to Shanghai Ottera Internet Technology Co., Ltd., Room 581, Building 2, No. 350 Xianxia Road, Changning District, Shanghai, People's Republic of China.
