Privacy Policy
Last updated: 2026-07-19
This Privacy Policy describes how Talking Unicorn ("we", "us") handles your information when you use our hosted email service ("Service"). The Talking Unicorn service is operated by Talking Unicorn Inc., a Florida corporation, which is the data controller for personal information processed under this Policy.
TL;DR
- We host your mail and run an AI assistant, UNI, that helps you with it — triage, summaries, drafting replies, and the other features you turn on.
- To help you, UNI reads the specific messages a task needs, at the moment you ask. It does its job and keeps nothing: your mail is never absorbed into the shared AI model, and it is not used to build a profile of you or to serve ads.
- UNI runs on infrastructure we operate. No third-party AI service ever receives your mail.
- Anything UNI "remembers" (your contacts, your preferences, phrases it learns) is stored in your account — owned by you, deleted when you delete your account.
- We don't sell your data, and we don't show ads.
- You can export everything and delete your account at any time, right from the app.
How UNI handles your mail (the important part)
We are a privacy-first email service that includes AI. That means being precise about what "AI" does with your mail, rather than pretending it never touches it.
Two separate kinds of memory. Your account memory — your messages, contacts, learned preferences, and (on some tiers) a personal model adapter trained only on your data — lives in your account and belongs to you. UNI itself is a stateless worker. When you ask for something, UNI reads the relevant content as input, produces the result, and retains nothing. The shared AI model does not learn from your mail: serving your request never changes the model's weights, so nothing from your mail can leak into another customer's results.
Processed only for the job you asked for. UNI reads message content only to perform a feature you invoked (e.g. summarising a thread, drafting a reply). While it is generating, your text sits in the processing system's temporary working memory for the few seconds the job takes; this is not written to disk, not logged, and is discarded when the job completes.
On infrastructure we operate. AI inference runs on GPU infrastructure we own or directly control. No third-party AI provider processes your email content. The companies that provide the underlying servers and GPUs (our infrastructure subprocessors) supply hardware and hosting only — they do not operate an AI over your mail. They are listed at /legal/subprocessors.
What "remembering" means. When UNI learns something useful — a contact, that you prefer short replies — it writes that back into your account's memory, never into the shared model. Delete your account and that memory is gone.
Improving the Service. By default we do not train any model on your mail. If you opt in to help improve UNI, we may retain anonymised records of AI suggestions and your corrections (accept / edit / reject) — never your correspondents' messages — and any personalisation is scoped to your own account. You can turn this off in account settings at any time.
What we collect
Account information
- Your email address (the admin contact for your tenant).
- Your domain name.
- Your name, if you provide one.
- Your payment information, processed by Stripe — we never see your card number directly.
- Your IP address at signup and on subsequent logins, for security and abuse-prevention.
Mail and content
- All email messages you send and receive, while stored in your account. Mail is stored on encrypted disks in the EU. We do not read it for advertising or profiling; UNI reads only what a task you request needs, as described above.
- Files you save to the PDF Vault.
- Contacts and preferences UNI stores in your account memory.
Service-operation data
- Authentication logs (who logged in, when, from where) for security.
- IMAP/SMTP transaction logs for troubleshooting and abuse detection (sender, recipient, size, timestamp — not message body). Retained 30 days.
- AI feature logs recording that a feature ran (which feature, latency, success) — not the message content it processed.
Website access
We use no third-party analytics. We log basic web access (IP, URL, user agent) for security and capacity planning, retained 30 days.
How we use the data
- To operate the Service: store and transmit your mail, run the features you enable, authenticate your sessions.
- To run UNI: process the specific content a requested AI task needs, on our own infrastructure, retaining nothing beyond your account memory.
- To bill you: send account information to Stripe for payment.
- To prevent abuse: spam-filter inbound, score outbound, detect compromised accounts (see Service Integrity).
- To improve the Service: aggregate (not individualised) usage metrics, and — only if you opt in — the anonymised corrections corpus above.
- To comply with the law: on a valid legal request.
We do not: - Sell, rent, or trade your data to anyone. - Send your mail to any third-party AI service. - Train the shared AI model on your mail content. - Show you ads or let anyone advertise to you on the Service. - Read your mail manually, except (a) when you ask us to (e.g. a support request where you share a message), or (b) when required by valid legal process.
Subprocessors
We use third parties for infrastructure (hosting and GPU compute), payments, push notifications, and TLS — never for AI processing of your mail content. The authoritative, continuously-updated list, with each vendor's role, region, and data category, is at /legal/subprocessors. We give tenant admins at least 30 days' notice before adding or changing a subprocessor.
Where your data lives
Your mail and account data are stored in the European Union (Hetzner, Finland), on encrypted disks.
AI inference runs on GPU infrastructure we operate. Depending on capacity this compute may currently be located outside the EEA (see the region column on the subprocessors page). Where that involves a transfer of EEA/UK personal data outside the EEA/UK, it is carried out under Standard Contractual Clauses. We are working toward offering in-region (EEA) inference for EEA users. If you have specific data-residency requirements, contact us before signing up.
How long we keep it
- Account information: while your account is active, plus 90 days after closure for legal/billing retention.
- Mail content: until you delete it, or shortly after account closure. When you request account deletion, data is permanently removed (see Your rights).
- Backups: retained per our backup schedule; deletions propagate to backups within 12 months.
- Operation logs / abuse signals: 30 days (longer only if required to defend the platform against a recurring threat).
- AI feature logs: metadata only, 90 days. Optional corrections corpus: retained anonymously until you disable AI-improvement.
Your rights
Depending on where you live, you may have rights to access, correct, delete, object to processing, and port your data.
- Export — download your data from the app (Settings → account export), or write to us.
- Delete — you can permanently delete your account and all its data from within the app (Profile → Delete account) or on the web. We send a confirmation link, then permanently delete your mail, PDF Vault, account memory, and derived data.
- Port — we support standard IMAP migration; we'll help if you ask.
To exercise any right, write to privacy@talkingunicorn.email. We respond within 30 days.
Children
The Service is not directed at children under 13 (or 16 in the EU). We don't knowingly collect data from anyone under that age. If you believe a child has an account, write to us and we'll delete it.
Service Integrity
We run abuse detection to protect the platform from spam, fraud, and malicious use. In plain terms:
What we examine (patterns, not your correspondence): - Outbound velocity — counts of how many messages a tenant sends per hour/day. Counts only; we do not inspect bodies for this. - UNI prompts — what a user types into the assistant (e.g. "draft a reply to Alice") is screened by an automated classifier for jailbreak and bulk-spam attempts. We do not review UNI's responses for this. - Signup and billing patterns — e.g. one Stripe customer creating many tenants quickly is a fraud signal.
We do not read the content of your incoming or outgoing mail to train classifiers, profile you, or build ad audiences.
When a signal trips: it is logged with a severity and confidence and, by default, lands in an operator review queue — no automated action is taken unless the operator has explicitly enabled auto-action for critical, high-confidence signals (off by default). You can request every signal recorded against your account, and dispute any action, by writing to us.
Security
- Mail at rest is on encrypted disks; mail in transit is on TLS (STARTTLS for SMTP, TLS for IMAP, HTTPS for the web UI).
- Passwords are hashed with bcrypt.
- We do not use SMS or "secret questions" for password recovery.
No system is perfectly secure. If you discover a vulnerability, write to security@talkingunicorn.email — we'll thank you and fix it.
Changes to this policy
We may update this Policy. Material changes are sent to your admin email at least 30 days before they take effect.
Contact
- Privacy questions / data requests: privacy@talkingunicorn.email
- Security disclosures: security@talkingunicorn.email