This policy describes how the OTM consumer product handles your information. It is written to match what the product actually does. OTM is an adult-only behavioral-support tool. It is not a medical, clinical, diagnostic, or emergency service.
Information we collect
You use the product through an anonymous account. We do not collect your name, email, phone, or government ID to use the core product. We record whether you affirmed you are 18 or older and an adult age band — never your date of birth. We collect the behavioral and support information you enter: urge reports, daily check-ins, lapse reflections, the protections you choose, and the outcomes of in-app interventions. We do not collect the content of any pornography or browsing activity. We derive risk scores, your plan, and which interventions help you. Technical data is minimal and first-party (for example, coarse rate-limiting by IP for abuse prevention). We do not use third-party advertising or analytics trackers.
Sensitive data
Some of this information may reveal aspects of your sexual behavior and wellbeing. We treat it as sensitive and process it only on the basis of your explicit consent and to provide the support you asked for. You can withdraw consent at any time.
How we use it
To provide the behavioral-support engine, to surface safety resources, and — only with your consent — to improve the product and to support de-identified research. We do not sell personal data and we do not use it for third-party advertising.
Consent layers
Product analytics (required for the engine to function), research (optional), and a care / clinical-data layer (optional). Each is a separate choice you can review and change.
Your rights
Depending on where you live, you may access, correct, delete, export, or restrict your data and withdraw consent. Because accounts are anonymous, these are served through in-app controls. Deleting your account removes your behavioral data through an automatic cascade.
Children
OTM is only for adults 18 and over. We block under-18 use and do not knowingly collect data from minors.
Security & changes
We use per-user data isolation, encryption in transit and at rest, no third-party trackers, audit logging, and staff multi-factor authentication. No method is perfectly secure. We version this policy; material changes prompt you to agree again before continued use.