Privacy Policy

Last updated: 2026-07-19

This Privacy Policy describes how Talking Unicorn ("we", "us") handles your information when you use our hosted email service ("Service"). The Talking Unicorn service is operated by Talking Unicorn Inc., a Florida corporation, which is the data controller for personal information processed under this Policy.

TL;DR

How UNI handles your mail (the important part)

We are a privacy-first email service that includes AI. That means being precise about what "AI" does with your mail, rather than pretending it never touches it.

Two separate kinds of memory. Your account memory — your messages, contacts, learned preferences, and (on some tiers) a personal model adapter trained only on your data — lives in your account and belongs to you. UNI itself is a stateless worker. When you ask for something, UNI reads the relevant content as input, produces the result, and retains nothing. The shared AI model does not learn from your mail: serving your request never changes the model's weights, so nothing from your mail can leak into another customer's results.

Processed only for the job you asked for. UNI reads message content only to perform a feature you invoked (e.g. summarising a thread, drafting a reply). While it is generating, your text sits in the processing system's temporary working memory for the few seconds the job takes; this is not written to disk, not logged, and is discarded when the job completes.

On infrastructure we operate. AI inference runs on GPU infrastructure we own or directly control. No third-party AI provider processes your email content. The companies that provide the underlying servers and GPUs (our infrastructure subprocessors) supply hardware and hosting only — they do not operate an AI over your mail. They are listed at /legal/subprocessors.

What "remembering" means. When UNI learns something useful — a contact, that you prefer short replies — it writes that back into your account's memory, never into the shared model. Delete your account and that memory is gone.

Improving the Service. By default we do not train any model on your mail. If you opt in to help improve UNI, we may retain anonymised records of AI suggestions and your corrections (accept / edit / reject) — never your correspondents' messages — and any personalisation is scoped to your own account. You can turn this off in account settings at any time.

What we collect

Account information

Mail and content

Service-operation data

Website access

We use no third-party analytics. We log basic web access (IP, URL, user agent) for security and capacity planning, retained 30 days.

How we use the data

We do not: - Sell, rent, or trade your data to anyone. - Send your mail to any third-party AI service. - Train the shared AI model on your mail content. - Show you ads or let anyone advertise to you on the Service. - Read your mail manually, except (a) when you ask us to (e.g. a support request where you share a message), or (b) when required by valid legal process.

Subprocessors

We use third parties for infrastructure (hosting and GPU compute), payments, push notifications, and TLS — never for AI processing of your mail content. The authoritative, continuously-updated list, with each vendor's role, region, and data category, is at /legal/subprocessors. We give tenant admins at least 30 days' notice before adding or changing a subprocessor.

Where your data lives

Your mail and account data are stored in the European Union (Hetzner, Finland), on encrypted disks.

AI inference runs on GPU infrastructure we operate. Depending on capacity this compute may currently be located outside the EEA (see the region column on the subprocessors page). Where that involves a transfer of EEA/UK personal data outside the EEA/UK, it is carried out under Standard Contractual Clauses. We are working toward offering in-region (EEA) inference for EEA users. If you have specific data-residency requirements, contact us before signing up.

How long we keep it

Your rights

Depending on where you live, you may have rights to access, correct, delete, object to processing, and port your data.

To exercise any right, write to privacy@talkingunicorn.email. We respond within 30 days.

Children

The Service is not directed at children under 13 (or 16 in the EU). We don't knowingly collect data from anyone under that age. If you believe a child has an account, write to us and we'll delete it.

Service Integrity

We run abuse detection to protect the platform from spam, fraud, and malicious use. In plain terms:

What we examine (patterns, not your correspondence): - Outbound velocity — counts of how many messages a tenant sends per hour/day. Counts only; we do not inspect bodies for this. - UNI prompts — what a user types into the assistant (e.g. "draft a reply to Alice") is screened by an automated classifier for jailbreak and bulk-spam attempts. We do not review UNI's responses for this. - Signup and billing patterns — e.g. one Stripe customer creating many tenants quickly is a fraud signal.

We do not read the content of your incoming or outgoing mail to train classifiers, profile you, or build ad audiences.

When a signal trips: it is logged with a severity and confidence and, by default, lands in an operator review queue — no automated action is taken unless the operator has explicitly enabled auto-action for critical, high-confidence signals (off by default). You can request every signal recorded against your account, and dispute any action, by writing to us.

Security

No system is perfectly secure. If you discover a vulnerability, write to security@talkingunicorn.email — we'll thank you and fix it.

Changes to this policy

We may update this Policy. Material changes are sent to your admin email at least 30 days before they take effect.

Contact