← Omora

Privacy Policy

Effective 14 July 2026

Omora is a personal home-inventory app. We store what you give us, process it to make the app work, and never sell your data — the app itself contains no ads and no tracking code. Your inventory is automatically backed up to our EU-hosted backend on every account, including the free tier; syncing it live across multiple devices is a Plus feature. This policy explains exactly what we collect, why, who else touches it, and what you can do about it.

1. Who We Are

Omora is operated by Philip Seacrest ("we", "us"). Our contact details are at the bottom of this page. Our backend infrastructure (database, authentication, and file storage) is hosted in the EU.

2. What We Collect

DataPurposeLinked to You
Email addressAccount creation, sign-in, verificationYes
NameAccount profile, claim documentsYes
Product recordsInventory tracking, warranty & coverage remindersYes
Receipts, photos, documentsProof storage, AI extractionYes
Forwarded receipt emailsReceipt extraction (only if you use your forwarding address)Yes
Country & currencyCoverage rules, formattingYes
IP addressCountry detection at onboarding, sign-in bot protection, rate limitingNot stored with your profile
Purchase & coverage detailsCoverage calculation, claims exportYes
Product usage analyticsFeature usage & improvement (no personal content)Yes (no PII)
Crash & performance dataStability and performance monitoringPseudonymised ID only

We do not ask for your phone number, postal address, or date of birth. We collect only the data above.

3. What We Don't Collect

4. How Data Is Processed

On your device

Omora prefers on-device processing wherever possible. When you scan a receipt with the camera or pick a photo, text recognition (OCR) runs locally using Apple's Vision framework. Omora then sends a reduced-size copy of the receipt image, together with the locally extracted text, through our backend to our AI provider to structure it — the image is the ground truth for the scan. Forwarded emails and plain-text inputs are processed as text only; no image is sent to the AI provider for those. Warranty and coverage reminders are scheduled as local notifications on your device. Extraction caches, pending uploads, and your reminder schedule stay on your device. Face ID / Touch ID unlock happens entirely on your device — we never receive your biometric data.

Your product records, photos, and documents are automatically backed up to our EU-hosted backend on every account, including the free tier, so you don't lose them if you lose your device. Syncing them live across multiple devices is a Plus feature. Your account email and sign-in details always live on our backend, because they are how you log in.

Backend services

Your account, product records, documents, photos, and profile are stored in our EU-hosted backend. This backup is automatic on every account, including the free tier; syncing them live across multiple devices is a Plus feature. Row-level security ensures you can only access your own data.

Forwarded receipt emails

Omora can give you an optional personal @omora.app forwarding address so you can forward order-confirmation emails straight into your inbox of receipts. If you use it, those emails — including the message body and any attachments — are received by our email provider, passed to our backend, and stored there. Unlike camera scans, these are read and parsed on our servers (including extracting text from PDF attachments and sending the relevant text to our AI provider, described below), not on your device. You never have to use the forwarding address; if you don't, none of this happens.

AI processing

After text is extracted — on your device for camera scans, or on our servers for forwarded emails — Omora may send the relevant text to a third-party AI provider (routed through our backend) to: structure receipt data into product records, suggest matching product names, and draft a damage description for a claim. For camera, photo, and PDF imports Omora also sends the receipt image itself, reduced in size, so the AI provider can read the receipt visually — the locally extracted text serves as a hint alongside it. Only the text or image needed for that specific feature is sent, and email addresses, links, and long tokens are stripped from text before sending where possible. The AI is limited to these specific Omora tasks; it is not a general-purpose chatbot, and Omora has no chat or "assistant" you can ask free-form questions.

For the "find a product manual" feature, and for replacement-price, retailer-support, and product-insight lookups, we send only product metadata — such as the name, brand, model, and retailer — to a web-search provider and an AI provider, then fetch the manufacturer's page or PDF from our servers to verify links. No receipt content, receipt images, or personal identifiers are included in these lookups.

AI provider API keys are managed server-side and are never stored in the app. Receipt parsing runs on OpenAI in the United States, which processes the receipt text and, for image-based imports, the reduced-size receipt image. Our product-lookup, product-suggestion, and product-insight provider, DeepSeek, receives only product metadata — never receipt content or personal identifiers. We strip identifiers from text before sending where possible (see "International Transfers").

Reporting a mistake

If a receipt is skipped or rejected and you tell us it was a mistake, you can optionally let an Omora engineer review that receipt's already-stored content for up to 90 days to help us fix it — nothing new is collected, and it only happens if you opt in each time you report one.

Product usage analytics

We record lightweight analytics about which features you use (for example "item added" or "paywall shown"). These events are sent to our own backend and to PostHog, an EU-hosted product analytics platform we use to understand how the app is used and improve it. PostHog operates under a data-processing agreement, is hosted in the EU (Frankfurt), and does not use your data for advertising or sell it. These events are tied to your account so we can honour your opt-out and include them in your data export and deletion, but they contain no personal content: no receipt text, no search queries, no names, and no document contents. You can turn analytics off any time in Settings → Privacy controls.

Password security

Passwords are validated locally for strength and checked against a public database of known breached passwords using k-anonymity. Only a short, partial hash (the first 5 characters) is sent, never the password itself.

Crash reporting

We use a third-party diagnostics provider for crash and performance monitoring. It receives a pseudonymised user identifier (a hash of your account ID), crash data, and app performance metrics. It does not receive your email, name, product data, or documents, and diagnostic logs are scrubbed of personal data before they are sent. Default PII collection is disabled. You can turn crash reporting off in Settings → Privacy controls.

5. Legal Basis (GDPR)

6. Data Sharing

We do not sell your data. Nothing from your account, inventory, receipts, or documents is ever shared with advertisers — the one thing we do send to an ad platform is described under “Advertising on our website” below. Your data is only processed by a small number of sub-processors, each acting on our behalf under a data-processing agreement:

Each acts only on our instructions under a data-processing agreement and may not use your data for their own purposes. If you have questions about a specific provider, contact us at hello@omora.app.

Advertising on our website. We sometimes advertise Omora on other platforms — currently Reddit. If you arrive at omora.app from one of those ads and then continue to the App Store, our server tells the platform that its own ad click reached the store. The only thing sent is the click identifier that platform put in the link it showed you — no cookie, no advertising ID, no email address, no IP address, and nothing from your Omora account or inventory. We do not store it, and we set no advertising cookies on this site. If you did not arrive from one of our ads, nothing is sent at all.

Transferring an item to someone else. If you choose to use Item Transfer, Omora bundles that one item — its photos, documents, and any price or coverage details you decide to include — and uploads it behind a private, single-use link that expires. Only a person you give the link to can import it. Nothing is shared with anyone unless you start a transfer.

Sharing a household. If you turn on Household Sharing (Settings → Household), the product records, documents, photos, and receipts in your shared household become visible to every member you invite, and to you for everything they add — exactly as if you kept one shared filing cabinet. Your personal account data is never shared this way: your email, sign-in method, push notification tokens, personal receipt-inbox forwarding address, and app usage analytics stay visible only to you, in every case. Because each of you decides what to add to the shared household, GDPR Article 26 (joint controllers) governs your relationship with each other for that shared data — we remain the processor for both of you under the same data-processing agreements listed above, and we do not decide what either of you shares. Any arrangement you and your household member want between yourselves about who is responsible for what is between you.

7. Data Retention

We keep your data for as long as your account is active. When you delete your account (Settings → open your account → Delete account, after verifying by email), we immediately remove from our backend:

A small amount of de-identified data may be retained because it is no longer linked to you: aggregated product-name corrections that improve recognition for everyone, de-identified rate-limiting counters, and operational logs of AI requests (timing, model, and status — never receipt content) with your identifier removed. Crash logs that contain your pseudonymised ID are retained by our diagnostics provider for up to 90 days per their retention policy.

Leaving a shared household. If you leave a shared household, or are removed from one, the product records, documents, and receipts you added while a member stay with the household — they were joint records of things you shared together, not solely yours to take back out. You keep everything you had before you joined. If you are the paying member and your subscription lapses, your household member keeps full access for 30 days while it gets sorted out; if it is still lapsed after that, they are removed from the shared household the same way and keep what they had before joining. Deleting your account always erases every piece of your own personal data — profile, email, sign-in methods, forwarding address, app usage analytics — even if you were a household member when you deleted it; only the joint household records you contributed remain, as described above.

8. Your Rights

Under the GDPR, you have the right to:

You may also lodge a complaint with your local data protection authority.

9. Children's Privacy

Omora is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it.

10. Security

We protect your data with:

11. International Transfers

Our primary infrastructure is EU-hosted (Frankfurt). Some sub-processors process limited data outside the EU/EEA under appropriate safeguards — standard contractual clauses (SCCs), the EU–US Data Privacy Framework where the provider is certified, or, where only non-identifying data is transferred, data minimisation:

12. Changes to This Policy

We may update this policy to reflect changes in the app or legal requirements. Material changes will be communicated through the app. The effective date at the top will always reflect the latest version.

13. Contact

Omora

Philip Seacrest

Email: hello@omora.app

Web: omora.app