WakeOpp
Privacy Policy
WakeOpp is an iOS alarm app. We try to collect as little as possible about you. This policy describes everything that's actually true.
What changed on 2026-07-29: WakeOpp added Duel Mode, where you race friends to get out of bed. That required things the app previously did not have — an account, a friends list, and a server. This policy has been rewritten to describe them. If you never sign in, none of the account sections below apply to you: the alarm works exactly as it always has, entirely on your phone.
What we collect
Alarm settings. When you create an alarm, the time, repeat days, label, sound, and your toggle preferences (haptic feedback, volume boost) are stored on your device. They never leave your device unless iCloud Backup is enabled in your iOS settings — that's an Apple-managed backup, not us.
An account — only if you use Duel Mode. Duels need a way to tell two people apart, so signing in is required to race and optional for everything else. We use Sign in with Apple. Apple sends us a user identifier and an email address, which is Apple's private relay address unless you chose to share your real one. You then pick a handle (like @loya) and a display name. We store your handle, display name, account creation date, and your device's time zone — the time zone is what makes a duel between two cities resolve to the right moment for each of you.
Your friends and duels — only if you use Duel Mode. Who you're friends with, the invite codes you create or redeem, the duels you're in and their terms (which days, what time, the stake text you typed), and the result of each round: whether you got up, how long it took from prompt to photo, your placement, and your coins. This is the scoreboard. It's what the feature is.
A push notification token — only if you allow notifications. So we can tell you a friend accepted your duel or that you won. Standard Apple Push token, tied to your account, deleted when you delete your account.
Photos you take during the challenge. When the alarm fires, WakeOpp shows you a prompt (e.g. "your toothbrush in your mouth") and asks for a photo. That photo is uploaded to a proxy server we run on Vercel, which forwards it to OpenAI's vision API to verify the photo matches the prompt. Once OpenAI returns a verdict, the photo is discarded. It is never stored on our servers, never shown to another person, and never used for anything else. Duel opponents see that you completed the challenge and how fast — never the picture.
An anonymous device identifier. When the proxy receives your photo, it sees Apple's identifierForVendor (a UUID generated by iOS that resets if you delete the app). The proxy uses it only to rate-limit the endpoint so abuse can't burn the OpenAI account. We don't link it to your account.
Subscription state. If you subscribe to WakeOpp Premium, your subscription is managed by RevenueCat (our billing service) and Apple (the App Store). RevenueCat receives a UUID and your subscription transactions. We use that to know whether to unlock premium features in the app.
What other people can see
Duel Mode is social, so some of your data is visible to specific other people. Precisely this much, and no more:
- Anyone who knows your handle can look up your handle, display name, and nothing else. That's how invites work.
- Your friends can see the same, and can invite you to duels.
- People in a duel with you can see your results in that duel — whether you got up, your time, your placement, your coins — and, while a round is running, how far along you are (awake, photo taken, finished). They cannot see your time until the round finishes.
Nobody can see your email address, your alarm times outside a shared duel, your subscription status, or any photo you take.
What we don't collect
- No password. Sign in with Apple only. We never see or store a password.
- No analytics. No Google Analytics, no Amplitude, no Mixpanel, no Firebase Analytics, no Segment, no third-party SDK that watches your taps.
- No location. Ever. Duels use your time zone, which is not your location.
- No contacts, calendar, photo library, or microphone. The camera permission is only used during the challenge. We never scan your contacts to find friends — you invite people with a code.
- No advertising IDs. We don't show ads and we don't share data with ad networks.
- No conversion or attribution tracking beyond what Apple's App Store provides natively.
- No stored photos. See above. The challenge photo is discarded after verification.
How we use what we do collect
- Alarm settings — to make your alarm work.
- Account, handle, time zone — to let friends find you and to schedule duels correctly across time zones.
- Friends, duels, results — to run the competition and keep score.
- Push token — to notify you about your duels. Nothing else.
- Photos — to verify them with OpenAI's vision API. Discarded immediately after.
- Device identifier (proxy-side only) — to rate-limit the proxy. Reset when you delete the app.
- Subscription state — to know if you're a paying user.
That's the whole list. We do not sell any of it, and there is nobody to sell it to.
Third parties we send data to
| Service | What it sees | Why | Their privacy policy |
|---|---|---|---|
| Supabase | Your account, handle, friends, duels, and results | Hosts the database and sign-in for Duel Mode | supabase.com |
| OpenAI | The photo you took + the prompt text | To verify the photo matches the prompt | openai.com |
| RevenueCat | Subscription transactions + a UUID | To manage subscription state across devices | revenuecat.com |
| Apple | Sign in with Apple, App Store + StoreKit data, push notification delivery | Sign-in, billing, App Store presence, iOS notifications | apple.com |
| Vercel | Network logs of proxy requests | Hosts the photo-verification proxy | vercel.com |
We have no other third-party SDKs in the app.
Storage and retention
- On your iPhone: alarm settings + your toggle preferences stay on your device until you delete the app or change them.
- On Supabase: your account and duel history are kept until you delete your account, at which point they're erased (see Your rights). Supabase hosts in the United States.
- On the proxy: photos are processed in memory and not written to disk. Network logs (timestamps, IP, response codes) are retained by Vercel for 30 days for ops + abuse monitoring, then auto-deleted.
- OpenAI's side: governed by OpenAI's API data policy. As of this writing, OpenAI does not train on API data.
- RevenueCat's side: governed by RevenueCat's privacy policy.
Your rights
- Delete your account and everything attached to it: Settings → Delete Account, in the app. This erases your account, handle, friendships, duel participation, results, and push token. It cannot be undone. Duels you created may remain visible to their other participants as their own history, without your handle attached.
- Delete the local stuff: uninstall the app. Alarm settings live on your device and go with it.
- Block someone: in the app, from your friends list. A blocked user can't invite you or see you in search.
- Report someone: in the app, from your friends list. It opens a pre-filled email to support@wakeopp.com, which one human actually reads. Reports are answered within 24 hours.
- Restore your subscription: Settings → ABOUT → Help & Support, or use Apple's standard "Restore Purchases" flow.
- Ask a question or request a data export: email support@wakeopp.com.
- Cancel your subscription: through your iPhone's Settings → Apple ID → Subscriptions. We can't cancel it for you (Apple controls billing).
Children
WakeOpp is rated for 17+ in the App Store and is not directed at children under 13. We don't knowingly collect data from children under 13. If you believe a child has used the app, email support@wakeopp.com and we'll address it.
Changes
If this policy changes, we'll update the version stamp at the top and post the new policy at the same URL. Material changes will be surfaced in the app's About section. Continued use of the app after a change means you accept the new policy.
Contact
Loya — independent developer, sole operator of WakeOpp.