unbuilt
Back to Unbuilt

Privacy Policy

Last updated: April 20, 2026

1. Operator

unbuilt.me (the “Service”) is operated by an independent developer based in Türkiye (“we,” “us,” “our”).

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you access or use the Service.

2. Scope

This Privacy Policy applies to personal data collected through or in connection with:

  • the website and product at unbuilt.me,
  • user accounts,
  • free and paid features,
  • subscriptions and add-on purchases,
  • saved reports, exports, and gated features,
  • customer support and service communications,
  • and any related interactions with the Service.

This Policy does not govern third-party sites, services, or payment flows that may have their own privacy notices.

3. Categories of Data We Collect

Depending on how you use the Service, we may collect the following categories of data.

A. Account and Identity Data

If you create or use an account, we may collect:

  • email address,
  • authentication identifiers,
  • account ID,
  • subscription status,
  • purchase status,
  • and other account-related metadata.

Authentication may be handled by third-party providers such as Clerk.

B. Input and Output Data

We may collect and process:

  • prompts,
  • business ideas,
  • product concepts,
  • stack requests,
  • feature requests,
  • text you submit,
  • generated outputs,
  • reports,
  • saved analyses,
  • exports,
  • and related content you create or receive through the Service.

C. Usage Data

We may collect:

  • feature usage,
  • pages viewed,
  • buttons clicked,
  • analyses started or completed,
  • plan status,
  • analyses remaining,
  • subscription events,
  • add-on purchases,
  • save/export activity,
  • and other interaction logs.

D. Technical and Device Data

We may collect:

  • IP address,
  • approximate region or country inferred from IP,
  • browser type,
  • device type,
  • operating system,
  • referring URL,
  • timestamps,
  • request metadata,
  • error logs,
  • and performance diagnostics.

E. Billing and Transaction Data

Payments are processed by our Merchant of Record and payment providers. We may receive limited billing-related data such as:

  • transaction IDs,
  • subscription IDs,
  • plan or product purchased,
  • billing status,
  • invoice/payment status,
  • renewal status,
  • cancellation status,
  • and amounts paid.

We do not directly store full payment card numbers.

F. Abuse Prevention and Security Data

To protect the Service, we may collect and process:

  • rate limit logs,
  • IP-based usage logs,
  • account-to-usage relationships,
  • suspicious request patterns,
  • fraud or abuse signals,
  • failed access attempts,
  • and other security-related metadata.

4. How We Use Data

We use personal data only as needed to operate, secure, maintain, improve, and support the Service.

This includes using data to:

  • provide the Service and generate AI outputs;
  • authenticate users and manage accounts;
  • operate free and paid plan logic;
  • track included monthly analyses and purchased analyses;
  • process subscriptions, renewals, cancellations, and add-on purchases;
  • provide saved reports, exports, and gated features;
  • enforce rate limits, access controls, and anti-abuse protections;
  • detect fraud, abuse, scraping, evasion of limits, or security threats;
  • monitor performance, reliability, errors, and service health;
  • improve product functionality and user experience;
  • communicate about purchases, billing, plan changes, support, or security;
  • comply with legal obligations;
  • and protect our rights, systems, users, contractors, vendors, and the Service itself.

We may also use aggregated or de-identified data for analytics, service improvement, and internal reporting.

5. AI Processing

The Service relies on third-party AI and infrastructure providers to process prompts and generate outputs.

When you submit Inputs to the Service, those Inputs may be transmitted to and processed by third-party model or infrastructure providers solely for purposes of providing the Service, improving performance, preventing abuse, debugging issues, or maintaining reliability.

You acknowledge that:

  • AI processing may involve temporary or logged transmission of your Inputs and Outputs to service providers;
  • AI-generated results may be stored by us for account history, saved reports, abuse prevention, debugging, support, and product improvement;
  • we do not promise that outputs are private in any absolute or privileged sense;
  • you should not submit highly sensitive, regulated, confidential, or legally privileged information unless you are comfortable with the associated risks and have all necessary rights and permissions to do so.

We do not sell your personal data for third-party advertising.

6. Legal Bases for Processing (GDPR / UK GDPR)

If you are in the EEA, UK, or another jurisdiction with similar rules, we rely on one or more of the following legal bases:

A. Performance of a Contract

We process data as necessary to:

  • create and manage accounts,
  • deliver analyses and outputs,
  • provide subscriptions and add-ons,
  • process saved reports and exports,
  • and otherwise provide the Service you requested.

B. Legitimate Interests

We process data where reasonably necessary for our legitimate interests, including:

  • operating and improving the Service,
  • measuring feature performance,
  • detecting abuse and fraud,
  • enforcing usage limits and Terms,
  • securing systems,
  • supporting users,
  • and protecting the Service, our rights, and other users.

C. Consent

Where required, we rely on consent for certain cookies, tracking, or optional communications.

D. Legal Obligation

We may process data where necessary to comply with applicable law, lawful requests, tax, accounting, consumer, payment, or regulatory obligations.

7. Cookies and Similar Technologies

We may use cookies, local storage, and similar technologies for:

  • authentication and session management,
  • essential product functionality,
  • remembering preferences,
  • measuring usage,
  • performance monitoring,
  • and security or abuse prevention.

Some cookies may be set by third-party providers such as authentication, analytics, hosting, or payment vendors.

You can control some cookies through your browser settings. However, disabling essential cookies may break parts of the Service.

If local law requires consent for non-essential cookies or similar technologies, we will request it where applicable.

8. When We Share Data

We do not sell your personal data for third-party advertising. We may share data only in the following limited circumstances:

A. Service Providers and Processors

We may share data with vendors who process data on our behalf to operate the Service, such as providers for:

  • authentication,
  • hosting,
  • database storage,
  • payments and subscriptions,
  • AI/model inference,
  • search enrichment,
  • email delivery,
  • logging,
  • analytics,
  • monitoring,
  • and support tools.

B. Payment and Billing Providers

Payment-related data may be shared with our Merchant of Record and payment partners to process transactions, manage subscriptions, prevent fraud, and comply with legal obligations.

C. Compliance and Legal Requests

We may disclose data if reasonably necessary to:

  • comply with law, regulation, court order, or lawful government request;
  • enforce our Terms or policies;
  • investigate fraud, security incidents, or abuse;
  • or protect the rights, property, or safety of us, our users, service providers, or others.

D. Business Transfers

If we are involved in a merger, acquisition, asset sale, restructuring, financing, or similar transaction, user data may be transferred as part of that transaction, subject to applicable law.

E. With Your Direction

We may share data when you request or direct us to do so, such as when exporting, downloading, or connecting certain services.

9. Third-Party Providers We May Use

Depending on how the Service is configured over time, we may use providers such as:

  • Clerk for authentication and account management,
  • Supabase for database and storage,
  • Paddle (or related payment entities) for billing, subscriptions, taxes, invoicing, and payment operations,
  • Anthropic and other AI/model providers for prompt processing and output generation,
  • Serper or similar enrichment/search providers,
  • hosting, logging, monitoring, analytics, email, and infrastructure vendors as needed.

These providers may process personal data on our behalf or, in some cases, as independent controllers under their own privacy terms.

We are not responsible for third-party privacy practices outside our control.

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, comply with law, enforce Terms, prevent abuse, resolve disputes, and maintain business records.

Retention periods may vary by data type:

  • Account data: typically retained while your account is active and for a reasonable period afterward for compliance, security, fraud prevention, or dispute handling.
  • Inputs, outputs, and saved reports: may be retained while needed to provide account functionality, saved history, exports, debugging, abuse prevention, and product improvement.
  • Usage logs and technical logs: retained for limited periods as reasonably necessary for monitoring, security, analytics, and abuse prevention.
  • Billing and subscription records: retained as needed for tax, accounting, consumer protection, payment dispute handling, and legal compliance.
  • Free usage / rate-limit logs: retained as needed to enforce free-tier limits and prevent abuse.

We may delete, anonymize, aggregate, or de-identify data when it is no longer needed.

We do not guarantee indefinite retention of saved reports, exports, or account history.

11. International Data Transfers

Your data may be processed in countries other than your own, including countries that may not provide the same level of legal protection as your home jurisdiction.

By using the Service, you understand that your data may be transferred internationally as necessary to operate the Service.

Where required, we take reasonable steps to use appropriate safeguards for cross-border transfers.

12. Data Security

We use reasonable technical, organizational, and administrative measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.

However:

  • no internet service is completely secure,
  • no storage system is completely immune from breach,
  • and no method of transmission is 100% secure.

You use the Service at your own risk and are responsible for maintaining the security of your devices, browsers, email accounts, and authentication credentials.

13. Children

The Service is not intended for children under 16.

We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will take reasonable steps to delete it where required.

14. Your Rights

Depending on your location and applicable law, you may have rights including the right to:

  • access your personal data,
  • request correction of inaccurate data,
  • request deletion of personal data,
  • request restriction of processing,
  • object to certain processing,
  • request portability of certain data,
  • withdraw consent where processing is based on consent,
  • and lodge a complaint with a supervisory authority.

These rights are not absolute and may be limited by law, security needs, fraud prevention needs, legal retention obligations, or overriding legitimate interests.

To exercise rights, contact us using the details below.

We may need to verify your identity before fulfilling a request.

15. Account Deletion

If you request account deletion, we may delete or anonymize personal data associated with your account, subject to:

  • legal retention requirements,
  • fraud prevention needs,
  • billing and accounting obligations,
  • dispute resolution,
  • enforcement of our Terms,
  • and legitimate internal recordkeeping.

Deletion may result in loss of saved reports, exports, account history, and other account-linked materials.

Some records may be retained where permitted or required by law.

16. Do Not Track / Similar Signals

The Service may not respond to “Do Not Track” browser signals or similar mechanisms unless required by applicable law.

17. Changes to this Privacy Policy

We may update this Privacy Policy at any time.

The updated version becomes effective when posted, unless otherwise stated.

Your continued use of the Service after an updated Privacy Policy becomes effective constitutes acknowledgment of the updated Policy.

18. Contact

If you have questions, concerns, or requests regarding this Privacy Policy, contact:

builder@unbuilt.me

Privacy PolicyTerms of ServiceCookie PolicyAcceptable UseAI TransparencyDo Not Sell My InfoDisclaimerRefund, Billing, and Cancellation Policy