Last Updated: July 8, 2026 (Effective July 8, 2026)
Unbound Technologies, Inc. ("Company," "we," "us," or "our") is committed to protecting the privacy and security of our users' personal data. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information in connection with the Unbound Loop application and services.
This Policy applies to all registered users, website visitors, and individuals who access or use our Service.
1. Data Processing Roles and Statutory Frameworks
- Company as Data Controller: Unbound Technologies, Inc. operates as the Data Controller (pursuant to Article 4(7) of the General Data Protection Regulation ("GDPR")) for all user account details, subscription information, project sharing metadata associated with registered-user sharing features within the Service, and safety reports. We determine the purposes and means of processing personal data.
- Engaged Data Processors: We utilize third-party vendors to perform operational and hosting functions. These entities process personal data on our behalf as Data Processors (Article 4(8) GDPR) and are bound by written Data Processing Agreements (DPAs):
- Google Firebase (Database, Auth, Cloud Storage): Acts as a Data Processor storing account credentials (emails, Google Auth tokens), project metadata, and uploaded/exported files on our documented instructions. Google Firebase maintains ISO 27001, ISO 27017, ISO 27018, and SOC 2 certifications. Transborder data transfers are governed by EU Standard Contractual Clauses (SCCs) embedded in the processing terms.
- Google Analytics 4 (GA4): Acts as a Data Processor measuring client-side user behavior. GA4 cookies are blocked by default and are only enabled upon explicit, opt-in consent. Payloads are routed through a server-side proxy owned and operated by Unbound to redact and obfuscate IP addresses prior to transmission to Google's servers. Telemetry data is subject to a strict two (2) month retention limitation. Residual telemetry data transmitted to Google's servers is governed by EU Standard Contractual Clauses pursuant to Google's Data Processing Addendum.
- Stripe Billing: Operates under a dual classification. Stripe acts as a Data Processor when executing subscription transactions and maintaining payment logs on behalf of Unbound. Stripe operates as an independent Data Controller for secondary processing activities, including global fraud detection, risk scoring, and compliance with anti-money laundering (AML) and Know Your Customer (KYC) regulations.
2. Data Collection Architecture
Personal data collection is structured into three distinct operational layers:
- Ephemeral Session Data (Client-Side):
- During real-time viewport sessions (the 40 Hz modeling stream), text prompts and real-time generation frames are processed locally in User's browser cache. This data is not stored or transmitted to Company servers.
- An encrypted rolling buffer of the last five (5) seconds of active viewport generation is maintained strictly within the device's local session memory, which is not transmitted to Company servers and is not persistently stored to disk by the Service. This data is overwritten continuously and is never transmitted to Company servers except when voluntarily submitted as part of a Safety Report.
- Stored Project and Download Data:
- When User initiates a "Download" or "Share to Registered Users" action, Company stores the final 3D/image assets and compiles a compliance log retained in accordance with the Data Retention Policy set out in Section 6. This log contains: (a) Account ID and subscription tier; (b) Content metadata (prompts and viewport settings); (c) Unique Content UUID embedded in the file metadata; and (d) A precise timestamp of the export event.
- Safety Report Data:
- Upon submission of a "Safety / Bug" report, Company collects the User's written text description, associated metadata, and (if selected) the compiled 5-second viewport video snapshot extracted from local RAM.
3. Purposes and Legal Bases for Processing
Company processes personal data under the following legal bases:
- Performance of Contract: To maintain user accounts, process subscriptions via Stripe, generate and export 3D models, and execute Service features.
- Legitimate Interests: To secure the Service, prevent fraud, debug application performance, and audit prompt injection attempts.
- Compliance with Legal Obligations: To comply with statutory data preservation mandates, reporting requirements regarding illegal content, and relevant digital safety regulations (including the EU Digital Services Act and EU AI Act).
- Consent: To activate analytical tracking cookies via Google Analytics 4.
- Safety and Compliance Reporting: To investigate safety reports, prevent harm, and fulfil obligations under applicable digital safety laws (including the EU Digital Services Act), based on Company's legitimate interests in maintaining a safe and lawful service and in compliance with legal obligations (Art. 6(1)(f) and Art. 6(1)(c) GDPR).
- Model Training and System Optimization Disclosure:
- Free Tier Data Processing: For Users utilizing our Free Tier or non-paid accounts, we process Inputs and Outputs (User Content) to train, validate, test, refine, and improve our machine learning models, neural weights, and 3D generation algorithms. This processing is based on our legitimate interest in continuously advancing and maintaining our core technologies (Art. 6(1)(f) GDPR). Free Tier Users may object to this processing at any time pursuant to Article 21 GDPR by contacting legal@unbound.io, and Company will cease such processing absent compelling legitimate grounds.
- Paid Tier Strict Exclusion: For Users maintaining any active paid subscription tier (regardless of level), we strictly exclude your Inputs, Outputs, and generation history from all model training, validation, testing, and model improvement activities. Paid User data is strictly private and processed solely as necessary to execute the Service on your behalf.
4. Children's Privacy Protection
- COPPA & GDPR Compliance: The Service is strictly not directed to children under thirteen (13) years of age (or under the applicable national minimum age for consent to data processing, ranging from thirteen (13) to sixteen (16) years of age depending on local Member State law, for individuals residing in the European Economic Area or United Kingdom).
- No Knowing Collection: We do not knowingly collect, solicit, or process personal information from children under these age limits. If we discover that a child has established an account or submitted personal data to us in violation of these age restrictions, we will immediately and permanently delete such records and terminate the account. If you believe we have inadvertently collected personal data from a child, please notify us immediately at legal@unbound.io.
5. ePrivacy and Tracking Disclosures
- Do Not Track (DNT) Handling: Do Not Track is a legacy privacy preference that can be configured in certain web browsers. While no uniform legal standard for DNT signals currently exists, Company honors the spirit of user privacy preferences through its opt-in consent mechanism for all analytics tracking.
- External Links Disclaimer: Our website and Service contain links to external third-party sites, such as our payment processor, Stripe. Once you click an external link, your interactions and personal data submission are governed by that third party's privacy policy, not ours. We encourage you to carefully review their policies.
6. Data Retention Policy
- Download and Compliance Logs: Retained for a period of one (1) year.
- Safety Reports and Snapshots: Retained for a period of three (3) years, unless required longer by pending legal investigations or court orders.
- Active Project Files: Stored in Firebase for the duration of the active account. Where an account has been inactive for a continuous period of three (3) years, Company will notify the User and, absent a response within thirty (30) days, may delete associated project files or convert them to anonymized aggregate format.
- Account Deletion: Upon User request or account deletion, all associated files and project records are permanently purged from active servers within thirty (30) days, unless retention is legally required.
- Encrypted Backup Archives: Data purged from active systems may persist in encrypted backup archives for up to ninety (90) additional days, after which it is permanently overwritten.
7. Data Subject Rights and Regional Representatives
Under applicable laws (including GDPR and CCPA), Users possess the following rights, which may be exercised by contacting legal@unbound.io. Company will respond to verifiable data subject requests within thirty (30) days (or forty-five (45) days for California residents under CCPA), extendable by up to sixty (60) additional days where reasonably necessary with prior written notice:
- Right of Access and Portability: Request a copy of all personal data and transaction logs associated with your account.
- Right to Rectification: Request correction of inaccurate personal data.
- Right to Erasure: Request permanent deletion of personal data.
- Right to Opt-Out: Opt-out of the sale or sharing of personal data (Unbound does not sell or share personal data to third-party advertising networks).
- Right to Know (CCPA): California residents may request disclosure of the specific personal information collected about them, the categories of sources from which it was collected, the business or commercial purposes for collection, and the categories of third parties with whom it is shared.
Designated Regional Representatives (GDPR Article 27 / DSA compliance)
Inquiries from European Union or United Kingdom regulatory authorities and data subjects may be directed to our appointed representatives:
- European Union Representative:
GDPR Local Ltd. (Ireland Office)
Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland
Email: contact@gdprlocal.com | Tel: +353 01 554 9700
- United Kingdom Representative:
GDPR Local Ltd. (UK Office)
1st Floor Front Suite, 27-29 North Street, Brighton, England
Email: contact@gdprlocal.com | Tel: +44 1772 217800
8. Contact Us and Inquiries
If you have any questions, comments, or concerns about this Privacy Policy, our data practices, or to exercise your global privacy rights, please contact us at:
- Privacy & Legal Inquiries: legal@unbound.io
- General Non-Legal Support: hello@unbound.io
- Mailing Address: Unbound Technologies, Inc., 1755 Broadway, Apt #53, Oakland, CA 94612
9. AI-Generated Content Transparency (EU AI Act)
The Service incorporates AI-assisted generative tools for 3D model creation. In compliance with applicable provisions of Regulation (EU) 2024/1689 (the EU AI Act), Company discloses that outputs produced using AI-assisted generation features are AI-generated or AI-assisted. This disclosure is provided to Users at the point of account registration and through in-application notices during active use of AI-assisted features. Company's AI-assisted generation system is designed as a creative assist tool requiring substantive manual creative input from the User; it does not operate as a fully autonomous content-generation system. Company will update this disclosure as EU AI Act obligations are phased into full effect.