Privacy Policy

Draft · last updated 2026-09-02

The short version: we do not store the content of your prompts or the model's answers. We store what is needed to run an account and bill it correctly — who you are, how many tokens you spent, and what you paid.

1. Who is responsible

[LEGAL ENTITY NAME], [REGISTERED ADDRESS], is the controller of the data described here. Privacy questions and rights requests go to privacy@unbleep.ai.

2. What we do not store

Prompt and completion content is never written to our database. Your request is held in memory only for as long as it takes to forward it to the model provider and stream the answer back to you. Nothing in our schema has a column for message content, and our application logs do not record request bodies.

We also never see your card number: card details go straight to Stripe from their hosted checkout page and never touch our servers.

3. What we do store

4. Why we process it

5. Who else processes your data

We use a small number of providers to run the service. They act on our instructions, except where noted.

We do not sell your personal data, and we do not use your prompts or outputs to train models.

6. Cookies

7. How long we keep it

8. Your rights

Depending on where you live — including under the GDPR in Europe, the LGPD in Brazil, and comparable US state laws — you may ask us to:

Write to privacy@unbleep.ai and we will respond within the period the applicable law allows. You also have the right to complain to your local data protection authority.

9. Security

Traffic is encrypted with TLS. Passwords are hashed with scrypt; API keys and session tokens are stored only as hashes, so a copy of our database would not yield a usable key. Administrative access is restricted, the application runs under a sandboxed service account, and backups are held on the same restricted infrastructure. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.

10. International transfers

Your data is processed on servers in [REGION] and by the providers listed above, which may be located outside your country. Where the law requires it, transfers rely on standard contractual clauses or another approved mechanism.

11. Children

The service is not for anyone under 18 and we do not knowingly collect their data. If you believe a minor has an account, tell us and we will remove it.

12. Changes

We will post any update here and change the date at the top. Material changes will be announced by email or in the console before they take effect.

Draft for review

The factual claims here were checked against the running system — the database schema really has no column for message content. The marked fields still need your entity details, and counsel should review the document before launch.