unlose · policy

Privacy notice

Effective September 3, 2026

What the service receives

Unlose receives your provider account ID and handle or email, encrypted capsules, routing metadata such as agent and session ID, byte and file counts, timestamps, active-session records, and share-link metadata. It uses IP addresses to enforce abuse limits; hosting providers may also process ordinary connection and request logs. For capacity planning and billing it also keeps small operational counters: daily stored-byte totals per account, a one-way daily digest of each signed-in machine's token (kept 90 days), service-wide share-open counts, and — for paid accounts — the opaque Stripe customer and subscription identifiers. Daily totals are kept about a year. Card details go to Stripe and never reach this service.

What stays encrypted

Prompts, responses, file paths, and session files are encrypted before hosted sync. The server cannot decrypt them unless you choose recovery-key hosting. If you enable dashboard titles, the server can read titles but not session contents. A complete share link gives its holder the key to that shared copy.

Cookies

The site uses an HttpOnly sign-in nonce and, after login, an HttpOnly session cookie. It has no advertising scripts or browser analytics scripts.

Retention and deletion

Current encrypted backups remain until you delete them. Deleted or replaced ciphertext may be retained temporarily for recovery. Login and share records expire or can be revoked. To permanently delete the active hosted account and its stored data, run unlose account delete --confirm DELETE on a logged-in machine that has the recovery key. The service keeps a one-way deletion marker so a database recovery cannot bring that account back. Encrypted database backup copies expire within seven days. If the account had a paid plan, deletion also cancels the subscription and, for deletions from September 3, 2026 on, deletes the Stripe customer record the plan was billed to; Stripe keeps the invoice and payment records that tax and payment rules require. The local plaintext, owner-only vault stays on that machine. Signing out does not delete the account or its data. Signing in again after deletion creates a new, empty hosted account.