Simple OTP

Privacy Policy

Last updated August 16, 2026

Simple OTP is local-first. It does not run an application server, sell personal data, or use advertising or analytics trackers.

Google user data accessed

For each Google account you choose to connect, Simple OTP requests only the gmail.readonly scope by default. It reads Gmail message identifiers, history information, sender and subject metadata, timestamps, and message bodies only to identify verification messages and extract one-time passcodes. Denying the separate Auto Archive permission does not affect these read-only features.

Optional Auto Archive

Auto Archive is off by default. If you explicitly enable it for an account, Simple OTP separately asks Google for the gmail.modify scope. After a message successfully produces an OTP, the app removes only that message’s INBOX label; the message remains available in Gmail All Mail. It does not send email, delete messages, change message content, or change any other label. Non-OTP messages, failed or ambiguous extractions, other accounts, and codes captured from paste, clipboard, or AutoFill are never changed. You can deny or later disable Auto Archive while continuing to use all read-only features.

How Google user data is used

Google user data is used only to provide the user-facing code inbox, freshness countdown, copy action, and user-initiated field-fill features. Simple OTP does not create aggregated or anonymized datasets from Google user data and does not use Google user data for advertising, profiling, credit decisions, or any unrelated purpose.

Sharing and transfer

Simple OTP does not sell or transfer raw, derived, aggregated, or anonymized Google user data to the developer, advertisers, data brokers, analytics providers, or AI services. Gmail data travels directly between Google and the app on your Mac. An extracted code is disclosed to another app or website only when you explicitly choose to copy or fill that code into the destination.

Data protection

Connections to Google use HTTPS in transit. OAuth refresh tokens are protected by the device-only macOS login Keychain and are never written to the local database. Extracted OTP records and connected-account metadata are kept in a local SQLite database within the current macOS user account. Decoded email bodies are processed in memory and discarded immediately after code extraction. Simple OTP has no application server or analytics pipeline to receive this data.

Retention and deletion

Decoded email bodies are not retained. Extracted OTP records remain locally for the history period you select. You can remove them at any time with Clear OTP History. Disabling Auto Archive stops future label changes without affecting read-only access. Disconnecting a Google account revokes its Google authorization when possible and deletes its local Keychain token, granted-scope record, account metadata, and code records. You can also revoke access from your Google Account.

Google API Services User Data Policy

Simple OTP’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

AI and machine learning

Simple OTP does not use Google Workspace user data to train, develop, or improve generalized or personalized AI or machine-learning models, and it does not transfer that data to third-party AI services.

Accessibility and clipboard

Accessibility access is used only to recognize the focused verification-code field, place the suggestion panel, and fill a code after you choose it. Clipboard text is read after you use Paste and Parse, or when optional clipboard auto-catch detects a new pasteboard change. Only an extracted code is kept in memory, for at most five minutes.

What Simple OTP does not access

Simple OTP does not read or scrape SMS, iMessage, or personal WhatsApp inboxes. It does not transmit email content or OAuth tokens to the developer, and it does not collect usage analytics, advertising identifiers, or tracking data.

Contact

Privacy questions can be sent to brahim@scalingadventures.com.