Privacy policy
Last updated August 5, 2026
The short version
We collect the minimum needed to run the service and bill for it: your email address, your API usage, and enough about queries to operate and improve the index. We do not sell data, do not serve advertising, and do not run tracking pixels on this website.
What we collect
Account data
Your email address, an organisation name derived from it, and your plan and billing status. Sign-in is by magic link, so we never hold a password. Payment details are handled by our payment processor and never reach our servers.
API keys
Stored as cryptographic hashes with the last four characters kept for display. We cannot recover a key, which is why a lost key is resolved by rotation rather than retrieval.
Usage data
Request counts, timestamps, endpoints called and response statuses — needed to enforce quotas, bill accurately and show you usage in the console.
Query data
Queries are processed to return results, and are retained in aggregate and in fingerprinted form to operate the service: to detect coverage gaps that direct crawling, to diagnose failures, and to improve retrieval. Query text is scoped to your tenant. Administrative views expose aggregates and fingerprints, never another tenant's query text.
Treat the queries you send as disclosed to us. If a query would itself be sensitive, that is a reason to consider what you put in it.
This website
Standard server logs — IP address, user agent, page requested — retained briefly for security and diagnostics. No advertising, no tracking pixels, and no cross-site profiling.
What we do not do
- Sell or rent personal data or query data to anyone.
- Serve advertising, or build advertising profiles.
- Share query text between tenants, or expose it in administrative views.
- Retain original crawled page content by default — the index holds extracted passages.
Retention
Account data is kept while your account is open and for a limited period afterwards to meet legal and accounting obligations. Usage records are retained for billing history. Query data is retained in the form described above for as long as it is useful for operating the index.
Sub-processors
We use a payment processor for billing, an email provider for transactional email such as sign-in links, and infrastructure providers for hosting and object storage. Each receives only the data necessary for its function.
Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to certain processing. Email us and we will action it. You can close your account from the console at any time.
Crawled content
unlob indexes publicly accessible web content. If a page containing personal data about you has been indexed, email us and we will tombstone the source — which also records it in the removal ledger, so why_not reports it as removed rather than never seen. Publishers can also exclude UnlobBot through robots.txt; see thecrawler page.
Security
Keys are hashed, tenant scoping is structural rather than advisory, and infrastructure errors are never returned in API responses because they can carry credentials-adjacent detail. No system is perfectly secure, and we will notify affected users promptly if that ever proves relevant.
Changes
We may update this policy. Material changes will be notified by email to account holders, and the date at the top of this page will change.
Contact
Privacy questions and data requests: hello@unlob.com.
This page describes our practices in plain language. It is not legal advice, and for a regulated deployment you should have your own counsel review it.