Oops

Privacy Policy

Last updated: September 29, 2026

In short. Oops never connects to your mailbox: you choose which order emails you forward to your Oops address. Those emails, and the PDFs you import, are analysed on our servers with the help of an artificial intelligence service (OpenAI) to extract the order. Your orders are then saved on your iPhone. No advertising, no sale of data, no advertising tracking.

1. Who is responsible for your data

The Oops app is published by Léa Attias ("Oops", "we"). For any question about your data: [email protected].

2. The data we process

Your account

To use Oops, you sign in with your email address (one-time code) or with Sign in with Apple. We keep: your sign-in email address (or the relay address provided by Apple if you hide your email), a technical account identifier, the sign-in methods linked to your account, and your personal import address (randomly generated). Emails containing your sign-in code are sent by our email provider.

Emails you forward

When you forward an order email to your Oops address, we receive and analyse it to extract the order information: merchant, order number and date, items, amounts, delivery address, carrier and tracking number. This analysis uses OpenAI (GPT-4o model). The raw email and its attachments are not kept on our server: only the structured result is kept until your iPhone retrieves it, then it is erased. An import that is never retrieved is deleted after 30 days at most (7 days if it failed). A technical record without content (status, dates, a non-reversible fingerprint of the message identifier to avoid duplicates) is kept for 30 days at most.

Documents you import (PDF)

When you import an order confirmation or an invoice in the app, the document is sent to our server and then to OpenAI to extract the order. It is not kept on our server; the result is sent back to you and you review it before saving.

OpenAI states that it does not use data sent through its API to train its models and may retain it for up to 30 days to detect abuse, under its own terms.

Your orders

The orders you save (including items, amounts, addresses and refunds), your statistics and your profile photo are stored locally on your iPhone, in the app. They are not stored on our server.

Parcel tracking

To show the delivery status of your shipped orders, tracking numbers (and the carrier when known) are sent to our server and to our tracking provider, 17TRACK. We keep these numbers and their latest status, linked to your account, while they are tracked: they are deleted 30 days after delivery, and at the latest 180 days after they were added. No other order information is sent for tracking.

Your Oops Premium subscription

Payment is handled by Apple; we never receive your payment details. We use RevenueCat to manage subscriptions: RevenueCat receives your technical account identifier (never your email) and the purchase information provided by Apple. Our server keeps your subscription status (product, expiry date, renewal) to enable Premium features.

Technical data

Our servers record limited technical logs (errors, durations) without the content of your orders, and usage measurements of the AI service (tokens, duration, estimated cost) without content. Oops does not include any third-party advertising or analytics tool.

3. Why we use it

We do not sell your data and do not use it for advertising.

4. Our providers

ProviderRole
SupabaseDatabase and authentication (hosted in Zurich, Switzerland)
Expo (EAS Hosting)Hosting of our server
ResendSending sign-in codes and receiving forwarded emails
OpenAIExtracting order information (United States)
17TRACKParcel tracking from tracking numbers
RevenueCatSubscription management
AppleSign in with Apple, subscription payments

Some providers process data outside Switzerland and the European Union, in particular in the United States. These transfers rely on the contractual safeguards offered by these providers.

5. How long

6. Deleting your account

You can delete your account at any time in the app: Account (Compte) → Delete my account (Supprimer mon compte). This removes your sign-in methods, disables your import address, erases your pending imports, your tracking numbers and your subscription status, deletes your RevenueCat profile and, if you use Sign in with Apple, revokes Oops's access with Apple. A disabled technical identifier, with no personal data, is kept only so that an import address is never reassigned. Orders saved on your iPhone stay there until you delete them or the app. Deleting your account does not stop an Apple subscription: remember to cancel it in your Apple account settings.

7. Your rights

You can ask to access, correct, delete or port your data, or object to certain processing, by writing to [email protected]. You can also contact the competent data protection authority.

8. Security

Communications with our servers are encrypted (HTTPS). Database access is restricted to our server; the app never accesses it directly.

9. Changes

We may update this policy. The date of the last update is shown at the top of this page.