Unspool Privacy Policy

Last updated: August 16, 2026

Unspool is a CBT-informed self-practice app. It is not a medical service, does not diagnose mental health conditions, and does not replace therapy, medical care, or emergency support.

Who Operates Unspool

Unspool is operated by Flipior LLC, a Colorado limited liability company. Contact: admin@flipior.com.

Information You Enter

You may enter thought restructuring notes, worry notes, urge delay records, mood records, and optional free-text reflections. These entries may include sensitive personal information if you choose to write it.

Local Storage

The current MVP stores practice records on your device using local app storage. Anyone with access to your unlocked device may be able to view app content.

You can clear local practice records inside the app from About and Safety. This clears thought records, worry notes, urge delay records, mood records, past-record review state and private comments, and worry-time settings on that device.

Past-record review and Patterns are processed locally. Past-record review may show one existing completed thought reflection with a fuller perspective, or one mood record with a non-empty note, after that record is at least 30 days old. It does not include worry notes or urge-delay records. The app stores the current card identifier, identifiers for cards you have seen or saved, and any timestamped private comments you add; it does not create a second copy of the source record. A card stays in place until you deliberately swipe to another one. Past-record review does not schedule reminders, ask for an outcome or reaction, or send card content or private comments to the AI service.

AI Processing

Before the first AI-assisted request, Unspool identifies the data and recipients described below and asks for your explicit permission. If you allow AI data sharing and request AI help, the app collects the information directly from the text, ratings, and records you choose in the app and sends only the fields needed for that request.

Depending on the feature, the information sent may include:

The app sends this information over HTTPS to a proxy operated by Flipior LLC and hosted on Cloudflare infrastructure. The proxy then sends it to Google Gemini API (paid), which generates the requested result. The result returns through the proxy to the app. If you finish and save the exercise, relevant input and output may be stored in the local practice record on your device.

Cloudflare processes request content transiently to provide hosting, security, and network delivery. Network requests necessarily expose an IP address and technical request metadata to Cloudflare. The Unspool proxy is configured not to persist or log the content of your entries. Operational logs may include non-content metadata such as request path, response status, timing, rate-limit events, or server errors.

Under the paid Gemini API terms, Google does not use prompts or responses to improve its products. Google may retain prompts and responses for a limited period solely for abuse monitoring, safety, and required legal or regulatory disclosures. Unspool does not enable search grounding, provider-side conversation storage, or optional log sharing for this feature.

Flipior LLC confirms that Cloudflare and Google are required under their applicable service agreements and data-processing terms to provide the same or equivalent protection for personal data as stated in this policy. They may process the information only as needed to provide and secure the services described above, subject to applicable legal obligations. See the Cloudflare Data Processing Addendum and the Gemini API Additional Terms.

AI content requests do not include the RevenueCat app user identifier, App Store or Google Play purchase history, subscription entitlement status, an Unspool account identifier, or another stable billing identifier.

If you do not allow AI data sharing, withdraw your AI permission, or AI is unavailable, Unspool uses local fallback rules and does not send the exercise to Cloudflare or Google Gemini. You can withdraw permission in About & Safety → AI Data Sharing → Stop Sharing with Google Gemini. Withdrawal applies to future requests and does not undo processing that occurred while permission was active.

Data Sharing

The MVP does not include analytics, advertising SDKs, third-party tracking, account creation, or account sync. Only after explicit permission, AI requests are sent through Cloudflare to Google Gemini API (paid) for app functionality.

For an AI-enabled release, the App Store privacy disclosure describes submitted content as Other User Content and Health, used only for app functionality. It is not used for tracking, advertising, analytics, or product personalization.

Retention and Deletion

Subscriptions and Purchases

Unspool uses Apple In-App Purchase or Google Play Billing and RevenueCat to offer and restore Plus subscriptions. RevenueCat may receive an anonymous app user identifier, store product and transaction identifiers, purchase and renewal dates, subscription status, trial eligibility, and limited technical data needed to provide subscription functionality.

Thought, worry, urge, mood, and AI-request text is not sent to RevenueCat. Payment-card information is handled by Apple or Google and is not provided to Unspool. Subscription data is used for app functionality, and RevenueCat provides aggregate subscription analytics from purchase data. It is not used for advertising or cross-app tracking.

Crisis and Safety

Unspool may show crisis guidance when user text appears to include self-harm, harm to others, or immediate safety risk. In the United States, call or text 988 for crisis support. If there is immediate danger, call 911 or go to the nearest emergency department.

Children

Unspool is not designed for children under 13.

Your Privacy Choices

You can choose what to write, decline or withdraw your AI permission, clear local records from About & Safety, and contact Flipior LLC with a privacy request. Because Unspool has no account system, Flipior LLC may not be able to identify or retrieve records stored only on your device.

Depending on where you live and applicable law, you may request access to, correction of, deletion of, or a portable copy of personal data processed by Flipior LLC by emailing admin@flipior.com. If a request is denied and applicable law provides an appeal right, reply with the subject “Privacy Appeal.” Unspool does not sell personal data or use it for targeted advertising.

Contact

For privacy questions, contact admin@flipior.com. For product help, visit Unspool Support. Read the Terms of Service.