PRIVACY POLICY

Undo is designed to know less.

Effective date: July 20, 2026.

Who operates Undo

Undo is operated by OpsCopilot, 57604 Rosecrest St, New Haven, Michigan 48048, United States. Questions and privacy requests may be sent to myopscopilot@outlook.com.

Information the extension stores locally

Order date, retailer, optional order number, product name, product page URL, price, return deadline, refund details, and savings confirmations. This data is stored in Chrome extension storage on the user's device.

When data leaves the browser

Cloud sync is off by default. If a user enables it and provides a personal API key, the purchase records listed above are sent over HTTPS to the Undo service. Automatic price checks are also off by default and require explicit retailer-site access. They request product pages without sending Undo account identifiers to retailers.

Information Undo does not request

Undo does not request browsing history, inbox access, payment-account access, cookies, contacts, location, camera, or microphone access. Undo does not sell personal or shopping data.

Account and service data

The supporting service stores an email address, hashed sign-in and session tokens, hashed API keys, subscription status, and any purchase records the user chooses to sync. Payment details are handled by Stripe and are not stored by Undo. Transactional sign-in email is delivered by Resend. Cloud data is stored with infrastructure providers including Vercel and Neon.

Limited Use disclosure

Undo's use of information received from browser and Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Undo uses data only to provide or improve its single purchase-protection purpose; does not use it for personalized advertising or credit decisions; does not sell it; and does not allow human access except with specific user consent for support, for security, when required by law, or in aggregate and anonymized form for internal operations.

Retention and deletion

Local records remain until the user removes them or uninstalls the extension. Synced records remain until the user deletes the account from the dashboard or requests deletion through the contact below. Account deletion removes sessions, API keys, synced purchases, and subscription linkage from Undo's database; payment processors may retain records under their own legal obligations.

Security

Sign-in and API credentials are stored as one-way hashes. Data is transmitted over HTTPS in production. No method of storage is perfectly secure.

Contact

OpsCopilot
57604 Rosecrest St
New Haven, MI 48048
United States
myopscopilot@outlook.com