Last Updated: July 16, 2026
This Privacy Policy explains how KIMTU LLC ("we," "us," or "our") collects, uses, and protects your information when you use Unpack ("the App").
We take your privacy seriously, especially given the personal nature of journaling. This policy is designed to be clear about what we collect, why we collect it, and the choices you have.
| Data Type | Purpose | Retention |
|---|---|---|
| Email address | Account creation, authentication, account communications | Until account deletion |
| Profile information | Personalizing your experience, such as name, age range, gender, journaling experience, and personal goals collected during onboarding | Until account deletion |
| Subscription and purchase information | Providing Premium access, syncing subscription status, restoring purchases, determining offer eligibility, and supporting billing-related issues | Until account deletion, except where limited records must be retained for legal, tax, accounting, fraud-prevention, or platform-compliance purposes |
| Journal entry photos | Scanned via your device camera and sent to AI for handwritten text extraction. For current app versions, we do not intentionally store the original photo with your saved entry after extraction completes | Not retained by us after extraction completes for current app versions. Legacy uploaded photos from earlier versions are being removed as part of our cleanup process |
| Journal entry text | Core app functionality, AI analysis, conversations, and reflections | Until you delete the entry or your account |
| Voice recordings | Recorded via your device microphone and sent to OpenAI for transcription. Audio is not stored by us after transcription is complete | Transcribed text is retained until you delete the entry or your account |
| AI-generated content | Insights, reflections, tangent conversations, and actionable tasks generated from your entries | Until you delete the associated entry or your account |
| Memories | AI-extracted patterns, themes, relationships, and insights from your journal entries, used to personalize future conversations when memory is enabled | Until account deletion or until you delete them |
| Shared content | When you choose to share a tangent, its name and conversation messages become accessible via a public link | Shared links expire after 24 hours or sooner if you turn sharing off |
| Data Type | Purpose | Retention |
|---|---|---|
| App usage and subscription events | We log selected in-app events, paywall and checkout events, feature usage records, and account, device, or session identifiers needed to understand how the App is used, provide plan entitlements, enforce free and paid plan rules, and protect the service from abuse | Until account deletion, except for limited aggregated or de-identified analytics and short-lived security or fraud-prevention logs |
| Crash reports and diagnostic events | We use these to detect app crashes, hangs, launch failures, and similar technical issues. These records can include limited device, session, and runtime metadata needed to investigate failures | Up to 90 days |
We use PostHog as a product analytics service provider to understand feature usage, onboarding funnels, retention, subscriptions, and aggregate cohort behavior. We do not send raw journal text, tangent messages, prompt text, overview text, extracted text, or photo contents to PostHog. We also do not share analytics data with advertisers or data brokers. You can choose not to share product analytics data in the Privacy & Data section of Settings.
We also use Sentry for crash reporting and technical diagnostics. Sentry helps us detect crashes, app hangs, launch failures, and similar reliability issues. We configure it to avoid sending journal content, extracted text, prompts, tangent conversations, or photo contents.
We use your information to:
We do NOT:
We use trusted third-party services to operate the App:
| Service | Purpose | Data Shared |
|---|---|---|
| OpenAI | AI processing for handwriting text extraction, journal synthesis, note-to-self task discovery, memory extraction, and audio transcription | Journal entry text, photos, and voice recordings, processed under API terms that prohibit model training from our customer data |
| Anthropic | AI processing for reflective chat conversations and some reflection generation | Journal entry text, memories, and conversation messages, processed under API terms that prohibit model training from our customer data |
| Supabase | Cloud infrastructure for database, authentication, and legacy storage cleanup | Encrypted account data, journal entries, memories, share-link data, and any remaining legacy uploaded photos pending cleanup |
| PostHog | Product analytics for feature usage, funnels, retention, and aggregate cohort analysis | App usage events and selected onboarding profile fields, but not raw journal content or photo contents |
| Sentry | Crash reporting and technical diagnostics | Crash traces, app lifecycle diagnostics, and limited device/runtime metadata needed to investigate failures, but not raw journal content or photo contents |
| Apple | App distribution, authentication with Sign in with Apple, and in-app purchases | Authentication tokens and App Store purchase or entitlement information needed to provide subscriptions |
| Authentication with Sign in with Google | Authentication tokens and basic account identity information |
All third-party providers are subject to their respective service terms and contractual restrictions.
Unpack is an AI-powered journaling service. When you scan a journal entry, dictate an entry, generate reflections, surface note-to-self tasks, use memory, or chat with a tangent, the content you choose to provide may be processed by us and by trusted AI providers, including OpenAI and Anthropic, to deliver those features. This processing can include handwritten page images, extracted journal text, voice recordings for transcription, AI-generated reflections, memories, and conversation messages.
We use this content to provide, personalize, secure, and improve the App's functionality, not to sell advertising or build a data-broker profile. For current app versions, journal page images and voice recordings are treated as temporary processing inputs: we do not intentionally retain original handwritten images after OCR completes or audio recordings after transcription completes. We retain the resulting journal text, reflections, memories, and conversations until you delete the associated content or your account.
You can turn off Unpack AI processing in Settings. Turning it off may limit or disable AI-powered features, including handwritten text extraction, dictation transcription, reflections, note-to-self tasks, memory personalization, and tangent conversations, because those features require AI processing to work.
Our AI providers:
If we ever want to use your journal content for model training or any materially different purpose, we will ask for your opt-in permission first.
We protect your data with:
No system is 100% secure. If we discover a breach affecting your data, we will notify users as required by applicable law.
| Data Type | Retention |
|---|---|
| Account and profile information | Until account deletion |
| Subscription and purchase information | Until account deletion, except where limited records must be retained for legal, tax, accounting, fraud-prevention, or platform-compliance purposes |
| Journal entries | Retained until you delete them or close your account |
| Journal entry photos | For current app versions, not retained by us after handwriting extraction completes. Legacy uploaded photos from earlier versions are being removed as part of our cleanup process |
| AI-generated insights and conversations | Retained until you delete the associated entry or close your account |
| Memories | Retained until you delete them from Settings or close your account. Disabling memory stops new extraction but does not delete existing memories |
| App usage and subscription events | Until account deletion, except for limited aggregated or de-identified analytics and short-lived security or fraud-prevention logs |
| Crash reports and diagnostic events | Up to 90 days |
When you delete your account from the Account section of Settings, your app account, profile, journal entries, memories, conversations, share links, and any remaining legacy uploaded photos are scheduled for permanent deletion and are generally removed within 30 days. Limited analytics, subscription-support, crash, fraud-prevention, and security records may remain for a short period under our providers' retention settings or where required by law. If you cannot access the App and need help with deletion, contact us at hi@unpackjournal.com.
Depending on your location, you may have the right to:
To exercise these rights, use the in-app controls where available or contact us at hi@unpackjournal.com.
California residents may have additional rights, including:
If you are in the EU or UK, our legal bases for processing are:
You may lodge a complaint with your local data protection authority.
If you would like an export of your account data, email hi@unpackjournal.com with the subject line Unpack data export request from the email address associated with your account, or include that account email in your message. We may need to verify your request before fulfilling it.
Unpack is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly.
Your data may be processed in the United States and other countries where our service providers operate. By using the App, you understand that your information may be transferred to and processed in countries that may have different data protection rules than your home jurisdiction. Where required, we rely on available transfer mechanisms provided by our service providers.
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by email, in the App, on our website, or by another appropriate method.
For privacy questions or to exercise your rights:
Email: hi@unpackjournal.com