Last updated: 27 July 2026
This notice explains how Simone Marrocco ("we", the Controller) processes personal data when you use UnlockGPT (the "App" or the "Service"), an AI-powered productivity assistant that integrates with your email accounts, calendars, document storage, and other services to provide intelligent task automation.
Our guiding principle is simple: your data is yours. It is encrypted so that we cannot read it, you can delete it at any time, and the only thing we collect about your usage is anonymous-by-design statistics (such as token counts) that never include the content of your conversations. For a plain-language explanation of how this works, see How We Protect Your Data.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national laws.
All data is stored exclusively within the European Union:
Your chat messages and uploaded documents are encrypted using AES-256-GCM with a per-user encryption key derived from your account password (PBKDF2, 600,000 iterations, performed in your browser). The encryption key is derived client-side and never stored on our servers — we keep only a one-way bcrypt hash of your password to verify your login, which cannot be reversed into the password or the key. This means that even we cannot read your messages or documents. Changing your password re-encrypts your data with the new key; resetting a forgotten password deletes your encrypted content, because nobody can decrypt it.
Encryption with your personal key covers: your messages, the AI's responses, the results and arguments of every tool the AI uses (email contents, file contents, calendar data it retrieves), the AI's reasoning traces, and chat previews. Only minimal operational metadata remains unencrypted so the App can function: chat titles, timestamps, message counts, tool names, and token usage statistics.
OAuth tokens for your connected accounts (Google, Microsoft, Dropbox) are likewise encrypted at rest with AES-256-GCM using a separate server-side key that is stored outside the database. We never receive or store your account passwords.
We do NOT log, store, or have access to:
We DO log for service improvement and platform analytics:
Our administrators see this data only as aggregate dashboards (total requests, token volumes, response times, error rates). By design, no message content, prompt text, or AI output is ever written to these logs — so neither administrators nor anyone else can read your conversations through them.
These usage logs are stored in a dedicated collection, separate from your messages, and contain your email address and the internal account identifier alongside the technical figures. They are retained independently of your messages: deleting a chat, a message, or your account does not delete them. They are kept for 36 months, after which they are deleted automatically (see Section 8). Our legal basis for keeping them after account deletion is our legitimate interest (Art. 6(1)(f) GDPR) in proving service delivery for payment disputes and refunds. Because they contain no message content, they cannot be used to reconstruct anything you wrote.
This data is used solely to improve the Service, understand usage patterns, and ensure reliable operation. It is never sold or shared with third parties for advertising purposes, and it is never used to train AI models.
Depending on how you use the Service, we may process:
Account data: Email address, name (if provided), authentication tokens for connected services (encrypted).
User-provided content: Prompts, files, images you upload — all encrypted at rest with your personal key.
Technical/usage data: Access logs, IP address, device identifiers, user agent, timestamps, error events, performance metrics.
Billing data: (if you subscribe) Data necessary to manage your subscription. Payments are processed by Creem, acting as Merchant of Record: Creem handles the payment, collects applicable taxes, and issues the invoice. We receive only your email address and subscription status — never your card details.
We do not intentionally collect special categories of data (Art. 9 GDPR). Please avoid entering unnecessary sensitive information.
To generate AI responses, your prompts are sent to Fireworks AI, our AI infrastructure provider, which processes them in the United States (see Section 10). Fireworks AI provides strong privacy guarantees:
For more information, see:
UnlockGPT has achieved CASA Tier 2 certification (Cloud Application Security Assessment), validated by TAC Security using the ESOF AppSec ADA framework.
CASA is built upon OWASP's Application Security Verification Standard (ASVS) and provides trusted assurance assessments for applications handling sensitive data.
We process data for:
Providing the Service (contract, Art. 6(1)(b) GDPR): sending prompts to AI models, returning outputs, maintaining your account, and providing support.
Security, abuse prevention, and reliability (legitimate interest, Art. 6(1)(f)): monitor anomalies, defend the Service from misuse or attacks, prevent fraud.
Product improvement and analytics (legitimate interest, Art. 6(1)(f)): aggregated analysis of feature usage and token consumption to improve the service — never the content of your messages.
Legal compliance (legal obligation, Art. 6(1)(c)): tax and accounting duties, and responding to lawful requests.
We retain data only for as long as necessary:
Deletion is self-service. You can delete any individual chat (which immediately removes the chat, all its messages, and its task lists from our production database) or delete your entire account. Deleting your account removes, in a single cascading operation: your chats and messages, your jobs, your tasks and suggestions, your uploaded documents and their pages, your connected-account tokens, your proactive analysis records, your bug reports, your artifacts, your waitlist and invite entries, and your profile. Three records are kept: the usage logs (linked to your email) and the subscription record, both described above, and the Instant Scan run record that holds the address you connected, which enforces one free scan per address. You must cancel your subscription before you can delete your account. Residual copies may persist temporarily in the automated backups of our infrastructure providers before expiring on their standard rolling cycles; in any case, we complete deletion within 30 days, except for the kept records described above and where retention is required by law. Deleted conversations remain encrypted with your personal key in any such residual copy, so they stay unreadable even before the backup expires.
We may share data with the following categories of recipients:
AI provider (Fireworks AI): Processes your prompts to generate responses. Zero data retention by default.
Platform integrations: Google, Microsoft, Dropbox — only when you explicitly connect your accounts and initiate actions. Web-search queries made by the AI are sent to Brave Search (United States).
Infrastructure providers: MongoDB Atlas (Europe), Google Cloud (Europe) for hosting and database services.
Payment provider (Creem): Processes subscription payments as Merchant of Record, collects and remits applicable taxes, and issues invoices. Creem receives the data needed to process the payment (email address, billing country, payment details); we never see your card details.
We do not sell your personal data. We require recipients acting as processors to follow our documented instructions and to implement appropriate safeguards (Art. 28 GDPR).
All primary data storage is within the EU/EEA (MongoDB Atlas Europe, Google Cloud Europe). Fireworks AI may process data in the United States; transfers are covered by EU Standard Contractual Clauses and supplementary technical measures. Information on specific transfers is available on request.
Under GDPR, you have the right to:
To exercise your rights, contact: [email protected]
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante) at www.garanteprivacy.it.
The Service is not intended for children under 14 (per Italian law). If you believe a minor has provided personal data without valid consent, contact us to request removal.
We do not carry out solely automated decisions producing legal or similarly significant effects. AI-generated outputs are tools to assist you, not automated decisions about you.
Instant Scan lets you connect one or more Gmail or Outlook accounts on our homepage and receive a one-off summary of what needs your attention, without creating an account. It is optional and separate from the Service described above.
What we ask for. Read-only access to your mail and calendar, and your email address. We do not request permission to send, delete, or modify anything, and we do not request offline access — the authorisation we receive expires within about an hour and cannot be renewed by us.
Where the authorisation lives. The access token is held only by your own browser tab, for the duration of your visit. We never write it to our database. When the scan finishes we end the authorisation, and closing the tab discards it.
What is processed. To write your summary, the content of recent messages and calendar entries is sent to our AI provider (Fireworks AI, see section 5) and to our servers in transit. Neither we nor Fireworks retain that content after the scan, and it is not used to train any model.
What we keep. Only the email address of each account you connected — so the free scan stays one per address — together with technical facts about the run: when it happened, how long it took, how many messages were reviewed, how many suggestions were produced, and what it cost us in AI usage. We do not store your messages, their senders or subjects, or the summary itself, unless you press the button offering to send that summary to our team.
Legal basis. Your consent (Art. 6(1)(a) GDPR), given when you authorise the connection. You may withdraw it at any time by closing the tab, and you can ask us to delete your address using the contact details below.
We may update this notice to reflect legal or technical changes. Updates will be published on this page with the new effective date. Continued use after changes take effect constitutes acceptance of the updated notice.
For privacy questions or requests: [email protected]
Simone Marrocco — VAT IT02799690223 — Italy