Legal
Privacy Policy
Effective August 22, 2026
This Privacy Policy explains how Ocho collects, uses, and shares information from the website at ocho.day and the Ocho iOS app. It covers the public landing page, historical waitlist and referral links, app analytics, AI stack generation, purchases, and support requests.
Who We Are
Ocho is a goal-planning service available on the web and through its iOS app. In this policy, "Ocho," "we," "us," and "our" mean the operator of the Ocho website and app.
Privacy requests can be sent to [email protected].
Information We Collect
We collect the following information when you use the site or app:
- Email address, referral code, source, waitlist position, and referral count if you previously joined the waitlist or use a referral link.
- App install identifiers, session credentials, an opaque Apple account identifier after you sign in, entitlement status, and purchase-related identifiers used to operate your account and Ocho Pro access. Ocho does not receive or store your Apple password.
- Goal Stack inputs, onboarding answers, domino candidates, generated stack content, Drift signals, check-ins, and planning state that you enter, generate, or accept on the website or in the app.
- AI planning requests and responses when you ask Ocho to generate a plan or, with active Ocho Pro access, interpret saved evidence and propose a revision.
- Technical request information, such as IP address, user agent, request headers, and timestamps, for security, fraud prevention, logs, and rate limiting.
- Analytics events, such as page views, App Store CTA clicks, onboarding progress, stack generation, paywall events, purchase outcomes, restore outcomes, weekly ritual activity, and app settings activity.
- Local storage, cookies, on-device UserDefaults, and a Keychain-held device credential used for referral attribution, install identity, planning state, session recovery, and authenticated deletion.
- Support messages and related contact information when you contact us.
The website and app keep a local copy of your working Goal Stack and weekly review state. Ocho also stores the planning state you accept so it can be recovered and used across supported surfaces. Your goal interview stays on your device if Apple sign-in does not finish. Ocho shows an AI-processing notice before it sends planning content. Content is sent through Ocho's server-side endpoint to Anthropic only when you request a plan or an Ocho Pro evidence review.
How We Use Information
We use information to:
- Operate the website, web planner, iOS app, historical waitlist, and referral flow.
- Verify accounts through Apple, maintain sessions, recover accepted planning state, and limit the free initial plan to one successful generation per verified account.
- Generate, rebuild, and improve Goal Stack and domino recommendations.
- Process purchases, restores, and entitlement status for Ocho Pro.
- Send product updates, support replies, and lifecycle communications.
- Prevent repeated free-plan generation, spam, account abuse, and automated requests.
- Measure site performance and understand which messages are working.
- Debug errors, protect the service, and comply with law.
Service Providers
We use service providers to run the site. They process information for the purposes described in this policy.
- Cloudflare hosts and protects the website and API, and stores waitlist, referral, account, identity-binding, session, accepted-planning, deletion-receipt, usage-limit, and entitlement records in D1.
- PostHog receives minimized structural events for operations such as plan generation and historical waitlist signup. Browser autocapture and session replay are disabled, and Ocho asks PostHog not to add IP-derived location to new events.
- RevenueCat helps manage purchase offerings, restores, and subscription entitlement status.
- Apple verifies Sign in with Apple and processes App Store downloads, in-app purchases, subscriptions, receipts, refunds, and subscription management.
- Anthropic processes AI stack-generation requests routed through Ocho's server-side endpoint.
We do not sell waitlist or app user information. The website does not run checkout; purchases happen through Apple's in-app purchase system.
Ocho does not use planning inputs or outputs to train its own model. Under Anthropic's standard commercial API terms, Anthropic says API inputs and outputs are not used to train its generative models by default and are ordinarily deleted from its backend within 30 days, subject to its stated safety, legal, and separately agreed exceptions.
Referral Links
If you previously joined the waitlist or use a referral link, the site may create or preserve a referral code. Referral counts are used internally to understand demand and acquisition sources. Full email addresses are not shown publicly through the referral flow.
Cookies And Local Storage
Browser analytics are disabled for this launch. The site may store a valid referral code, session credential, and local planning state in your browser so attribution, sign-in, and your work can survive navigation between pages and tabs in that browser. The iOS app uses on-device storage for install identity, session credentials, and local planning state.
You can block or delete cookies and local storage through your browser settings. Blocking local storage may prevent the browser from retaining your local plan, sign-in session, or referral attribution.
Retention
Local planning state remains in the browser or on the device until you reset Ocho, clear the site's data, or delete the app. Ocho stores accepted goals, plans, weekly actions, check-ins, evidence, and revisions in its product database so signed-in users can recover and continue their work. Planning text is excluded from product analytics. Anthropic's standard commercial API retention is described above. Rate-limit records expire after no more than 24 hours. Account, identity-binding, session, initial-plan, entitlement, waitlist, referral, support, and structural analytics records are retained only while needed for the stated service, security, legal, or operational purpose and are deleted or de-identified after that purpose ends.
Ocho does not currently offer user file or photo uploads and does not use a public object-storage bucket for user content. If uploads are added later, this policy and the in-product notice will be updated before collection; user objects must remain in a private bucket and be removed through the storage API when the related content is deleted.
Your Choices
You may ask us to access, correct, or delete your information by emailing[email protected]. Product emails will include the legally required sender information and an opt-out method. You can clear local planning state without deleting the account, or delete your Ocho account and server-side data from Ocho settings. Apple subscriptions are managed separately in Apple Account settings.
Children
Ocho is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 provided information, contact us and we will delete it.
Security
We use reasonable technical and organizational safeguards, including HTTPS, server-side validation, rate limiting, platform purchase controls, and limited data exposure in the browser. No internet service can be guaranteed perfectly secure.
International Visitors
Ocho is operated for a United States-based launch. Information may be processed in the United States or other countries where our service providers operate.
State And Regional Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information. You may also have the right to object to or restrict certain processing. Send requests to[email protected].
Changes
We may update this policy as the product changes. The effective date above shows when this version took effect.