Privacy Policy
Version 1.2 · July 22, 2026
The short version: your activity is stored under a random code and kept
separate from your name and email. No ads, no third-party ad tracking, and we
don't sell your data. You can export or delete everything, anytime.
What we collect
- Guest mode (default): your data stays on your device unless backup is on.
- If you sign in (Apple), we store a stable account id and an optional
email, encrypted, used only to sync your data. Hide My Email is fully supported.
- Activity (tasks, categories, times, routines) is stored under a random
code (your "anonId") and kept separate from your name and email. The identity
mapping is encrypted, access-controlled, and not joined into the data we use
to improve Unfurl.
- The text you type about what you're avoiding is used only to generate your
tiny step and is not stored on our servers beyond the request.
What we don't do
- No ads and no ad SDKs.
- No third-party ad tracking, no cross-app tracking, no IDFA.
- We don't sell your data, and we don't share it for advertising or
unrelated purposes.
How we use data
To run the app and make it better (for example, learning which tiny
steps actually help). You can opt out of improvement use in the app's Account screen.
Your rights
- Export your data anytime (Account screen → Export my data).
- Delete your data or your whole account anytime in the app, or on the web at
unfurllife.com/delete-account.
- We respond to privacy requests as required by the laws that apply to you,
including the GDPR and CCPA/CPRA.
Retention & where data lives
Activity on your device keeps only the last 30 days. Account data
stays until you delete it. Our servers are located in the United States.
Children
Unfurl is not directed to children under 13.
Security
Data is encrypted in transit (TLS) and at rest. Sign-in tokens are
kept in your device's Keychain. Access to identity data is limited.
Contact
Questions or requests: privacy@unfurllife.com