The whole policy, in a paragraph
We collect the minimum needed to give you a working account: your name and email, your captures, and basic usage data to spot bugs. We never sell data, never train models on your captures, and never share anything with advertisers. You can export or delete all of it from inside the app, without asking us.
What we collect
Your account email and the name you go by. The captures you create — audio, transcripts, typed text, and anything you share into the app. The items produced from them: tasks, notes, checklists, habits, countdowns and projects. The facts the app learns about you so it can sort future thoughts sensibly. Crash reports and aggregate usage counts, such as captures per day, with no capture content attached.
How you sign in
Three ways: an email address and a password, your Google account, or your Apple account. Google and Apple confirm who you are and pass us two things, your name and your email address. Google also sends a link to your profile picture, which is kept with the sign-in record and never shown anywhere in the app. Neither one hands over your contacts, your calendar, your files, or the ability to post anything as you. If you use Apple’s Hide My Email, the only address we ever see is the relay one Apple generates for us; your real address stays with Apple, and we cannot see through it. Apple sends your name once, on your first sign-in and never again, so if you skip it then we simply do not have one — you can set it yourself in Settings at any time.
What we don’t collect
Contacts, location, browsing history, advertising identifiers, or microphone access outside an explicit recording you started. We do not run analytics that follow you around other sites, and we do not sell personal information or share it with advertisers.
How the AI works
Speech-to-text, the sorting that turns a capture into suggested items, and Ask all run on OpenAI models, reached through OpenAI’s API. OpenAI does not train its models on data submitted through the API. OpenAI may retain API content for a limited period — up to 30 days at the time of writing — solely to detect abuse, after which it is deleted. The models see the text of the capture being processed plus the facts the app has already learned about you, and nothing else from your account. Nothing you write is used as training data by us.
Who else touches your data
We use a small number of service providers, each for one job, each under a data-processing agreement:
- Supabase — the database, authentication, and file storage that hold your account. Hosted on Amazon Web Services in the United States (us-east-1).
- OpenAI — transcription, sorting, and Ask, as described above.
- Vercel — hosting for this site and the app.
- Google Firebase — push notification delivery, crash reporting (Crashlytics) and aggregate usage counts (Analytics) in the iOS and Android apps.
- Apple and Google — sign-in, and in-app purchases when you subscribe on a phone. They tell us that a subscription is active; they do not give us your payment details, and we never see your card.
- RevenueCat — reconciles subscription status across the app stores when you subscribe. It receives a subscription identifier and whether the subscription is active; it never receives your captures.
Storage, retention and deletion
The tasks, notes, checklists, habits and countdowns you make stay on our servers until you delete them. The raw captures they came from — a transcript, typed text, an uploaded recording and any attachments — are kept for 30 days once they have been processed and you have decided what to keep from them, then deleted automatically. A capture that failed to process, or is still waiting on your decision, is kept until it is resolved. Deleting a capture never deletes what you made from it. Deleting your account removes everything immediately and irreversibly — see how to delete your account. Our database provider keeps encrypted backups for disaster recovery; a deletion applies to live systems at once and ages out of those backups within 30 days.Two things survive a deletion, both deliberately. Records of payments are kept because tax and accounting law requires it, with your identity stripped out and replaced by a meaningless reference. Security logs of administrative actions keep the action and the internal record id, with the email address redacted. Neither contains anything you wrote.
Isolation
Every row belonging to you is scoped to your account by the database itself through row-level security, not only by application code. Uploaded files are stored under a path keyed to your user id and enforced the same way. Traffic is encrypted in transit, and storage is encrypted at rest.
Connected AI apps
You can connect an outside AI client — Claude, ChatGPT, or any other client that speaks the Model Context Protocol — to Unload Thoughts. This is off until you turn it on, and connecting takes an explicit authorization step where you sign in and approve it.
Once connected, that client can read and write your data: it can see your captures, tasks, notes, checklists, reminders, what the app has learned about you, and your review queue, and it can create, change, and archive those things on your behalf. It reaches them through the same row-level security as everything else, so it only ever sees your account and never anyone else’s.
What you send to a connected client, and whatever it does with what it reads, is governed by that provider’s privacy policy rather than this one. We do not control it and we do not receive a copy of your conversation there.
You can disconnect any app at any time in the web app under Settings → Integrations. Disconnecting ends that client’s sessions and invalidates its refresh tokens immediately; an access token it already holds can remain usable for up to an hour before it expires. Deleting your account revokes every connection as part of the same operation.
Once connected, that client can read and write your data: it can see your captures, tasks, notes, checklists, reminders, what the app has learned about you, and your review queue, and it can create, change, and archive those things on your behalf. It reaches them through the same row-level security as everything else, so it only ever sees your account and never anyone else’s.
What you send to a connected client, and whatever it does with what it reads, is governed by that provider’s privacy policy rather than this one. We do not control it and we do not receive a copy of your conversation there.
You can disconnect any app at any time in the web app under Settings → Integrations. Disconnecting ends that client’s sessions and invalidates its refresh tokens immediately; an access token it already holds can remain usable for up to an hour before it expires. Deleting your account revokes every connection as part of the same operation.
Your rights (GDPR / CCPA)
Export. In the web app, Settings → Data → Export everything downloads your whole account as a single JSON file: every capture, task, note, checklist, habit, countdown and learned fact, plus time-limited download links for your audio and attachments. The iPhone and Android apps link out to the same place.Deletion. Settings → Danger zone → Delete account. It is immediate and final, with no recovery window and no support ticket required. The deletion page also explains how to do it if you no longer have the app installed.Correction and objection. You can edit or remove anything in the app at any time. For anything the app does not let you change, or to object to a particular use of your data, email us and we will action it.We do not sell personal information, we do not share it with advertisers, and we do not use it for automated decisions with legal effects.
Children
Unload Thoughts is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.
Changes to this policy
If we change how we handle your data in a way that matters, we will update the effective date on this page and tell you in the app before the change takes effect.
Contact
Unload Thoughts is operated by Sit Wiz LLC, which is the data controller for everything described on this page. Email privacy@unloadthoughts.com with any privacy question, or to exercise any right above. We answer every email within five working days. For anything else, the support page is the place to start.