Legal
Privacy Policy
Last updated: July 15, 2026
1. Information We Collect
We collect account information such as email address, profile fields you choose to provide, saved records, usage counts, subscription status, support messages, and technical information needed to operate the app.
2. AI Processing
When you use an AI feature, the text you submit may be sent to our AI model provider so it can generate the requested reflection, analysis, or communication draft. Unsaid currently uses DeepSeek for AI processing: fast requests use deepseek-v4-flash, member and deeper analysis requests use deepseek-v4-pro, and safety checks may also use DeepSeek, currently defaulting to deepseek-v4-flash. Do not submit information you are not comfortable processing through an AI service.
3. Payments and Analytics
Payments, invoices, taxes, subscriptions, cancellations, and refunds are processed by Creem. We do not store full card numbers. We may use analytics tools such as PostHog to understand product usage and improve reliability.
4. How We Use Information
We use information to provide the service, authenticate accounts, enforce usage limits, process memberships, respond to support requests, protect against abuse, debug reliability issues, and improve product quality.
5. Your Choices
You can export your account data, delete your account, cancel subscriptions through the Creem Customer Portal, or contact us for privacy and support requests.
A paid member may delete immediately or schedule deletion for the end of the current paid period. We stop future renewal before completing either request. Immediate deletion revokes active sessions; scheduled deletion preserves paid access only until the recorded period end.
6. Retention and Deletion
After we verify an immediate deletion request, we aim to remove account identity, credentials, saved AI records, public Moments, and account-linked usage data from Unsaid's online systems within 24 hours. Sessions are revoked immediately. Deletion requests involving a third party are tracked and normally sent to that party within 30 days.
Account usage and local analytics records are normally kept for no more than 90 days. Restricted security and audit records are normally kept for no more than 12 months and are stripped of direct account identity after deletion. Minimal, pseudonymous privacy-request evidence may be kept for 24 months.
Unsaid-controlled backup snapshots are rotated within 7 calendar days. Until rotation, deleted data in an encrypted backup is unavailable for ordinary use and a restored backup must replay pending deletions before service resumes. Necessary financial records are restricted from product use and may be retained for 7 years or a longer mandatory accounting period. Irreversibly anonymous aggregates may be retained.
7. Service Providers
Creem, DeepSeek, and PostHog apply their own contractual, legal, and technical retention controls. We manage them through provider settings, agreements, and deletion or access requests where data can be linked to you. Creem may retain buyer, tax, invoice, refund, and transaction information as Merchant of Record. These provider-controlled systems and backups are not covered by Unsaid's seven-day backup rotation.
8. Contact
For privacy, account, billing, or support questions, contact support@gettyou.com.