Unmask
HomeTerms & safetyOpen Unmask →
Plain-English notice

Privacy

Pre-launch note: this is a practical privacy notice for the rebuilt beta, not a substitute for legal advice. It should be reviewed by an Australian privacy professional before paid public launch.

Last updated: 17 July 2026.

The short version

Unmask is designed to collect less. Live support answers are used to generate a response and are not intentionally written to an Unmask database in this beta. Pattern-journal entries remain in your browser unless you explicitly choose to send recent entries for AI reflection.

Do not enter names, addresses, school names, medical-record numbers or other details that identify you or your child.

Information stored on your device

The app uses browser local storage for:

  • Your choice to accept the AI disclosure.
  • An anonymous random session identifier used for abuse and cost controls.
  • Simple anonymous feedback such as whether a response helped.
  • Pattern-journal entries you choose to save.

You can delete all of this from Privacy & data inside the app. Clearing browser storage also removes it.

Information sent for a tailored response

When you accept the disclosure and request a tailored response, the app sends your selected structured answers and any optional note to Unmask’s server. The server then sends the minimum required context to Anthropic’s API to generate the response.

The browser cannot choose the model instructions. Unmask keeps those instructions on the server and restricts requests to approved support actions.

Pattern reflection

Pattern entries stay on your device by default. When at least two entries exist, you may choose Reflect on these patterns. Only then are up to eight recent entries sent through the same AI process. The app asks you to keep every entry brief and non-identifying.

Service providers

The beta may use:

  • Vercel for website hosting and server functions.
  • Anthropic for generated support responses.
  • Airtable for optional founder-update email signups.
  • Upstash, when configured, for anonymous request-rate controls.

These providers may process technical logs or submitted information under their own terms, security practices and retention settings. Before public launch, Unmask should document the final provider configurations, retention periods and cross-border disclosures.

Email signups

When you choose to receive founder updates, Unmask stores your email address and a signup-source label. Early access itself is open and does not require an email. The address is used for product updates and optional research invitations. It should not be sold or used for unrelated advertising. Every marketing email should include an unsubscribe method.

What Unmask should not collect

Please do not submit information about immediate abuse, detailed medical histories, medication instructions, legal disputes, precise locations or anything you would not want processed by an external AI provider. Immediate safety situations belong with emergency or qualified human services.

Security and retention

The rebuilt beta applies server-side action restrictions, request-size limits, same-origin controls, rate limits and structured output validation. No online service is risk-free. Production launch should add formal logging rules, incident response, provider agreements, access controls, backups and a documented retention schedule.

Your choices

  • Use a general offline fallback instead of sending context to AI.
  • Leave optional notes blank.
  • Use the app without a pattern journal.
  • Delete local data from the app at any time.
  • Ask to access or delete your founder-update email record.

Contact

Privacy questions and access or deletion requests can be sent to hello@unmaskyou.com.

Unmask
Open the appTerms & safetyContact