Privacy Policy
Last updated: 15 July 2026
Unsave turns posts you save from Instagram, TikTok, and YouTube into structured, searchable notes. This policy explains what we collect, how we use it, and the choices you have. Unsave ("Unsave", "we", "us") is operated by Eshaan Singh. Questions can be sent to [email protected].
1. What we collect
| Account | Your email address, account identifier, sign-in provider (Apple, Google, or email), and any name or profile image that provider shares with us. |
|---|---|
| Your library | The source links you choose to save; generated notes; stored cover images; creators and source metadata; collections and tags; search queries; and your Ask questions and conversation history. |
| Connections | If you connect Notion, we store the Notion authorization and settings needed to mirror notes to your workspace. Obsidian exports happen locally on your device: we store your chosen vault name and preference on that device, not an Obsidian access token. |
| Payments | Lemon Squeezy processes web purchases. Apple processes App Store purchases, with RevenueCat used to manage purchase status and entitlements. We receive order, customer, and receipt details needed to provide access, but not your full payment-card number. |
| Usage and diagnostics | Website page views and clicks, coarse in-app events, app or server version, source platform, error details, and network information such as IP address that is ordinarily included in requests to us and our providers. |
2. How we use information
- To authenticate you and sync the correct private library across your signed-in devices.
- To fetch public source posts, generate notes, store them, and provide search and Ask.
- To mirror notes to Notion or export to Obsidian when you choose those actions.
- To process purchases, restore access, provide support, prevent abuse, diagnose faults, and improve reliability.
- To comply with legal, accounting, and security obligations.
3. AI processing
Unsave uses Google's Gemini API. During extraction, we may temporarily send the source media and available captions or metadata to Gemini so it can produce a structured note. When you use Ask, we send the question, relevant conversation context, and relevant notes from your library. If you choose a web-grounded Ask mode, Google Search may also be used to ground the answer.
Temporary downloaded media is deleted after processing. We keep the generated note and cover image in your library until you delete them or your account. AI output can be wrong or incomplete, so verify important information against the original source.
4. Service providers
We use the providers below to run Unsave. They process information for the stated purpose under their own terms and privacy practices. We do not sell personal information or use advertising networks.
| Supabase | Account authentication, database, and file storage. |
|---|---|
| Railway | Hosting the Unsave backend. |
| Google Gemini and Search | Generating notes and answers, including optional web grounding. |
| ScrapeCreators | Fetching public post media and metadata. |
| DataImpulse | Proxy infrastructure used when fetching some public YouTube and TikTok sources. |
| PostHog | Website interaction analytics and coarse server-side product events. |
| Sentry | Backend error monitoring and diagnostics. |
| Cloudflare | Hosting and delivering the public website. |
| Resend | Transactional and account-related email. |
| Apple and Google | Sign-in when you choose the corresponding provider. |
| Lemon Squeezy, Apple, RevenueCat | Payment processing, purchase verification, and entitlement management. |
| Notion | Mirroring notes when you connect a Notion workspace. |
Obsidian works differently: Unsave opens Obsidian's local URL action to create a Markdown copy in your chosen vault. We do not connect to an Obsidian account or receive an Obsidian token.
5. Analytics and diagnostics
On this website, PostHog records anonymous page views and interaction patterns such as which links or buttons are clicked. Session replay is disabled, analytics are kept in browser memory rather than persistent analytics storage, and we do not start website analytics when your browser sends Global Privacy Control or Do Not Track.
Our backend sends a limited set of product events to PostHog using an account identifier and coarse properties such as source platform, note type, duration, and whether an Ask request succeeded. We do not intentionally include the text of your note or Ask question in those analytics events.
Sentry monitors backend errors with default personal-data collection disabled. An error report may still contain technical context needed to diagnose a fault, such as the public source URL and, for some extraction failures, a short excerpt of generated output. We do not intentionally attach request bodies to Sentry reports.
6. International processing
Our providers may process information in the United States and other countries where they operate. Where applicable, those providers use legal safeguards for international transfers.
7. Retention and deletion
We generally keep your account and library while your account is active. You can delete individual notes inside Unsave. To delete your account, open Profile → Delete account, or contact [email protected] if you cannot access the app. Account deletion removes your account, notes, collections, conversation history, and saved Notion connection from our active systems. Limited payment, tax, fraud-prevention, security, or backup records may remain where required or reasonably necessary.
8. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your information, and to object to or restrict some processing. We do not sell or share personal information for cross-context behavioural advertising. To make a request, email [email protected]. We may need to verify that the request belongs to you.
9. Security
We use HTTPS, provider access controls, private server-side credentials, and database row-level access policies designed to keep each signed-in user's library separate. Public client configuration required for the app and website is not treated as a secret. No online service is perfectly secure, but we use reasonable technical and organisational safeguards and review the product for security issues.
10. Children
Unsave is not directed to children under 13, or a higher minimum age where local law requires it. We do not knowingly collect a child's personal information in violation of applicable law. Contact us if you believe this has happened.
11. Changes
We may update this policy as Unsave changes. We will update the date above and provide additional notice when required for a material change.