Privacy Policy
Effective date: 8 August 2026
Applies to: unlimitless.ai and the Unlimitless connector (api.unlimitless.ai)
Our promise, in plain language
Before the detail, the position — because this is the part that matters:
- What you save is yours. Your thoughts, decisions and reasoning belong to you. We store them so your AI tools can use them on your instruction. That is the entire business.
- We never sell your personal data. Not to advertisers, not to data brokers, not to anyone. There are no ads on Unlimitless and never will be data-funded ones.
- We never delete what you save. Your reasoning is kept — never overwritten, never expired by us. The only person who can remove your data is you.
- Your content never touches analytics. Our analytics see events — “a save happened,” “a request failed” — never what you wrote. What you save is never sent to analytics or error-tracking services, by architecture, not just policy.
- We don’t read your content to police it. Unlimitless only receives what you choose to save and only serves it back to tools you connect. We don’t scan, moderate, or mine what you think.
- If we ever want to learn from de-identified reasoning patterns in aggregate, we will ask you first. It would be strictly opt-in, off by default, and explained at the time. You’re hearing about the possibility now because we’d rather you hear it from us than find it in fine print later.
The rest of this policy is the detail behind those sentences.
1. Who we are
Unlimitless (“Unlimitless”, “we”) operates the website at unlimitless.ai and the Unlimitless service, which stores the decisions and reasoning you choose to keep and makes them available to AI tools you connect. For anything in this policy, contact privacy@unlimitless.ai.
2. What we collect
Before you sign up, we measure almost nothing. Our analytics are session-scoped: no cookies, nothing stored on your device, nothing that follows you between visits. A visit is an anonymous session that ends when you close the tab — we don’t know who you are, and we don’t try to find out. We honour Do Not Track, we record no sessions, and our analytics are hosted in the EU. When you do sign up, our sign-in provider sets the cookies needed to keep you signed in — functional only, never tracking. That’s the whole of it.
Account data — when you sign up we receive, via our authentication provider (Clerk), your name, email address, and the identifier from the sign-in method you choose (email with a verification code, GitHub, or Google). We do not receive or store your passwords for those services.
Your content — the thoughts, decisions, reasoning, plans and related material you deliberately choose to save. Nothing is captured silently: content enters Unlimitless only when you (or a tool acting on your explicit instruction) save it.
Connections you make — when you connect one of your own services, such as analytics, error-tracking, a search console, a document drive, a public feed, or another MCP server, you give Unlimitless a credential for that service. We store it encrypted, use it only to make the calls you direct, and it never leaves our connector. Remove a connection and its credential is deleted. Anything those calls return is material from your own sources, fetched because you asked for it and held only to serve against the positions you have saved; it is cached briefly, each refresh overwriting the last, and is treated as source content, not a new record of you.
API keys — you can create a personal key in the portal so your own tools can reach the service on your behalf. A key stands in for you: anything you give it to receives what the API serves for you, exactly as a tool you connect would. You can revoke a key at any time in the portal.
Feedback — if you send feedback from within the product, we receive the feedback type, your message, and your account email, so we can read it and reply.
Technical event data — when the service runs, we record operational events: which operation ran (for example, a save or a context request), whether it succeeded, how long it took, and a pseudonymous user identifier. These events never include your content. Our error-monitoring is configured to strip request bodies so that even failure reports cannot carry what you wrote.
Waitlist data — Emails given to our pre-launch waitlist are used once, to tell you we’ve launched, then deleted.
Correspondence — if you email us, we keep the thread.
3. How we use it
- To run the service: storing your content, serving it back to you and to the AI tools you connect, at your instruction.
- Making the connections you direct: when you connect one of your own services or use a personal API key, we use the stored credential only to make the calls you ask for, and return the result to you and the tools you connect.
- AI-assisted housekeeping: some saved items may be processed by Anthropic’s Claude API for upkeep — for example, proposing a summary for your confirmation — under commercial terms that prohibit the provider from training models on the data.
- Security and abuse prevention: authentication, access control, rate protection, and investigating specific abuse reports or attacks.
- Aggregate product analytics: event-level usage (never content) to understand whether the product works — activation, retention, failures.
- Communicating with you: service messages, waitlist updates, and replies to your emails.
4. What we never do
- We never sell or rent personal data.
- We never run advertising or share data with ad networks.
- We never train AI models on your content.
- We never send your content to analytics or error-tracking services.
- We never use a service credential you connect, or a personal API key, for anything but the calls you direct — and a stored credential never leaves our connector.
- We never scan or mine your content for moderation, profiling, or any purpose beyond operating the service.
- We access individual content only when strictly necessary to operate or debug the service, to investigate a specific reported abuse or attack, or when legally compelled — and in every case, as narrowly as the situation allows.
5. The deliberation record — a future possibility, stated now
We believe the patterns in how people reason with AI — in aggregate, stripped of identity — may one day support research or products, including potentially licensing de-identified, aggregated reasoning patterns to AI developers or researchers. If Unlimitless ever pursues any of this, three things are guaranteed in advance:
- Opt-in only, off by default. Nothing happens to your data without your explicit, informed, revocable consent, requested clearly at the time.
- De-identified and aggregate. Any such use would work with patterns across many users, not your identifiable record.
- Personal data is never sold, under this section or any other.
This section creates no right for us today. It exists so that our long-term thinking is on the record from day one.
6. Who processes data on our behalf
We use a small set of providers, each seeing only what its job requires:
- Clerk handles authentication — your name, email and sign-in identifiers (you’ll see Clerk on our sign-in page).
- Anthropic performs the AI-assisted housekeeping described above, on limited saved items, under terms that prohibit training on the data.
- PostHog (EU-hosted) receives product analytics — technical events and pseudonymous identifiers, never your content.
- Slack receives the feedback you choose to send us — its type, your message and your account email — as a notification to our team, and never your saved content.
- Beyond these, we use established providers for encrypted database hosting, application hosting, error monitoring (configured so failure reports cannot contain your content), our waitlist, and uptime monitoring (which handles no personal data at all). A complete, current list of providers is available any time on request at privacy@unlimitless.ai.
The services you connect are your own. When you connect an external service, or point a personal API key at a tool, that service or tool is yours — governed by its own terms, not ours. We pass your instruction to it with the credential you stored and return the result; those are your providers, chosen by you, and we don’t add them to ours or send them your saved content.
We don’t share personal data with anyone else, except if required by law, to protect the service and its users from a genuine, specific threat, or as described below if Unlimitless ever changes hands.
If Unlimitless is ever acquired or merges with another company, your data would transfer with the service — and this policy’s commitments would transfer with it. Any successor is bound by the promises made here, including Section 5’s guarantees: nothing about your identifiable content is used for AI training or research without your explicit opt-in, and personal data is never sold. We would notify you before any such transfer takes effect, with a clear window to export and delete your account first if you choose.
7. Retention — and the append-only promise
Unlimitless is deliberately built so that what you save is kept: your record grows, nothing is overwritten, and nothing is expired or trimmed by us. We retain your content and account data for as long as you have an account.
You can leave, completely. If you ask us to delete your account (privacy@unlimitless.ai), we will delete your content and personal data within 30 days, with residual copies clearing from encrypted backups within a further 30 days. Waitlist data is deleted on request at any time. Technical event data is retained in de-identified form for service analytics.
You can also do it yourself, without asking us. In your account settings you can schedule deletion directly. Your account then holds in a dated pending state for 30 days, and during that whole window you alone can cancel it and keep everything. Signing in shows you the pending deletion and offers to cancel. Your export stays available throughout, so you can take your data with you first. At the end of the 30 days the deletion runs and your content and personal data are gone for good. This is the same 30 days described above, not an additional wait: it is the window before deletion executes, and residual copies clear from encrypted backups within the further 30 days already stated. The email route above remains available, and is the route to use if you have lost access to your account.
8. Your rights
Depending on where you live (including under UK/EU GDPR and similar laws), you have the right to:
- Access and export what we hold about you — ask and we will provide your content in a portable format;
- Correct account data; for saved content, correction works the way the product works — you save the updated decision and your record reflects it, with the history remaining yours;
- Delete your account and data (Section 7);
- Object to or restrict processing, and withdraw consent where processing rests on it;
- Complain to your data-protection authority.
Write to privacy@unlimitless.ai and we will respond within a month.
9. International transfers
Unlimitless is used globally and our providers operate internationally, with our analytics deliberately EU-hosted. Where personal data crosses borders, it does so under recognised safeguards (such as standard contractual clauses) implemented by us and our providers.
10. Security
Data is encrypted in transit and at rest. Access to production systems is restricted, credential-controlled, and monitored around the clock, with independent uptime and error monitoring. No internet service can promise perfection; we can promise that the service was designed so that the most sensitive thing you give us — your reasoning — has the smallest possible surface area: never sent to analytics, no advertising pipelines, no third-party enrichment.
11. Age
Unlimitless is for adults. You must be at least 18 to use it.
12. Changes
If this policy changes materially, we’ll tell you — on the site and, for account holders, by email — before the change takes effect. The effective date at the top always tells you which version you’re reading.
Contact: privacy@unlimitless.ai