Last updated August 2026
This policy covers two separate things: the marketing/documentation website you're reading right now (openota.xyz), and OpenOTA Cloud (api.openota.xyz and the dashboard), the hosted version of the open-source OpenOTA server. If you self-host OpenOTA instead, none of the Cloud section below applies — your server, your data, your policy to write.
Analytics (Google Analytics 4 and Microsoft Clarity) run only if the site operator has configured them — both are entirely optional integrations gated behind environment variables. When enabled, they collect standard, anonymized usage data (pages visited, approximate location from IP, device/browser type) the same way most websites do. This site does not run its own first-party tracking beyond that.
The dashboard and API store exactly what's needed to run the service:
Delete a project from the dashboard and its releases, API keys, and device check-in history are removed. Delete your account and everything tied to it goes with it. Because OpenOTA is open source, you can also verify all of this directly by reading the server code, or move to self-hosting at any time — same API, your own infrastructure.
Email developmet1043@gmail.com for anything not covered here, including data deletion requests.