Unl

Privacy Policy

Our promise, in plain language

Before the detail, the position — because this is the part that matters:

The rest of this policy is the detail behind those sentences.

1. Who we are

Unlimitless (“Unlimitless”, “we”) operates the website at unlimitless.ai and the Unlimitless service, which stores the decisions and reasoning you choose to keep and makes them available to AI tools you connect. For anything in this policy, contact privacy@unlimitless.ai.

2. What we collect

Account data — when you sign up we receive, via our authentication provider (Clerk), your name, email address, and the identifier from the sign-in method you choose (Google or GitHub). We do not receive or store your passwords for those services.

Your content — the thoughts, decisions, reasoning, plans and related material you deliberately choose to save. Nothing is captured silently: content enters Unlimitless only when you (or a tool acting on your explicit instruction) save it.

Technical event data — when the service runs, we record operational events: which operation ran (for example, a save or a context request), whether it succeeded, how long it took, and a pseudonymous user identifier. These events never include your content. Our error-monitoring is configured to strip request bodies so that even failure reports cannot carry what you wrote.

Waitlist data — if you join the waitlist, your email address, referral code activity, and (via our waitlist provider) approximate location data.

Correspondence — if you email us, we keep the thread.

3. How we use it

4. What we never do

5. The deliberation record — a future possibility, stated now

We believe the patterns in how people reason with AI — in aggregate, stripped of identity — may one day support research or products, including potentially licensing de-identified, aggregated reasoning patterns to AI developers or researchers. If Unlimitless ever pursues any of this, three things are guaranteed in advance:

  1. Opt-in only, off by default. Nothing happens to your data without your explicit, informed, revocable consent, requested clearly at the time.
  2. De-identified and aggregate. Any such use would work with patterns across many users, not your identifiable record.
  3. Personal data is never sold, under this section or any other.

This section creates no right for us today. It exists so that our long-term thinking is on the record from day one.

6. Who processes data on our behalf

We use a small set of providers, each seeing only what its job requires:

We don’t share personal data with anyone else, except if required by law, to protect the service and its users from a genuine, specific threat, or as described below if Unlimitless ever changes hands.

If Unlimitless is ever acquired or merges with another company, your data would transfer with the service — and this policy’s commitments would transfer with it. Any successor is bound by the promises made here, including Section 5’s guarantees: nothing about your identifiable content is used for AI training or research without your explicit opt-in, and personal data is never sold. We would notify you before any such transfer takes effect, with a clear window to export and delete your account first if you choose.

7. Retention — and the append-only promise

Unlimitless is deliberately built so that what you save is kept: your record grows, nothing is overwritten, and nothing is expired or trimmed by us. We retain your content and account data for as long as you have an account.

You can leave, completely. If you ask us to delete your account (privacy@unlimitless.ai), we will delete your content and personal data within 30 days, with residual copies clearing from encrypted backups within a further 30 days. Waitlist data is deleted on request at any time. Technical event data is retained in de-identified form for service analytics.

You can also do it yourself, without asking us. In your account settings you can schedule deletion directly. Your account then holds in a dated pending state for 30 days, and during that whole window you alone can cancel it and keep everything. Signing in shows you the pending deletion and offers to cancel. Your export stays available throughout, so you can take your data with you first. At the end of the 30 days the deletion runs and your content and personal data are gone for good. This is the same 30 days described above, not an additional wait: it is the window before deletion executes, and residual copies clear from encrypted backups within the further 30 days already stated. The email route above remains available, and is the route to use if you have lost access to your account.

8. Your rights

Depending on where you live (including under UK/EU GDPR and similar laws), you have the right to:

Write to privacy@unlimitless.ai and we will respond within a month.

9. International transfers

Unlimitless is used globally and our providers operate internationally, with our analytics deliberately EU-hosted. Where personal data crosses borders, it does so under recognised safeguards (such as standard contractual clauses) implemented by us and our providers.

10. Security

Data is encrypted in transit and at rest. Access to production systems is restricted, credential-controlled, and monitored around the clock, with independent uptime and error monitoring. No internet service can promise perfection; we can promise that the service was designed so that the most sensitive thing you give us — your reasoning — has the smallest possible surface area: never sent to analytics, no advertising pipelines, no third-party enrichment.

11. Age

Unlimitless is for adults. You must be at least 18 to use it.

12. Changes

If this policy changes materially, we’ll tell you — on the site and, for account holders, by email — before the change takes effect. The effective date at the top always tells you which version you’re reading.

Contact: privacy@unlimitless.ai