Legal

Privacy Policy

Last updated: September 15, 2026

This policy explains what Unvld collects, what we do with it, which other companies touch it, and what you can ask us to do with it.

Our Terms and Conditions cover the agreement between you and Unvld. This policy covers your data.

The short version

This summary is for convenience only and is not part of the policy.

  • We collect what you put into Unvld: your account, your deals, invoices and payments, the brand emails you forward to us, and the files you upload.
  • Some of that content is sent to the AI providers we use, so Cayhil can read contracts, pull deal terms out of email, and answer your questions. Section 8 describes what is sent and when.
  • We do not sell your data, we do not run advertising, and we do not train AI models on your content.
  • To get a copy of your data or have your account deleted, email hello@unvld.co.

1. What this policy covers

This policy applies to unvld.co, the Unvld application, the Cayhil assistant inside it, the /reflect conversation flow, and the private email address we issue you at inbox.unvld.co.

Unvld is a business-operations platform for creators who run their own brand partnerships. Because it is a business tool, most of what it holds is business information — deals, invoices, contracts, contacts. Some of that is personal information about you, and some of it is personal information about other people you work with. Section 7 covers information about other people.

2. Account and sign-in

Signing up with email and password

When you create an account this way, we store:

  • your name;
  • your email address;
  • a cryptographic hash of your password — never the password itself; and
  • whether you have confirmed your email address.

Email verification is required before you can use Unvld, so we send you a verification link when you sign up and a reset link if you ask for one.

Signing in with Google

If you sign in with Google, we receive and store your Google account identifier, your name, email address, and profile image, along with the tokens Google issues so we can complete the sign-in. We request only Google’s basic sign-in permissions — your identity, email address, and basic profile. We do not request access to Gmail, Drive, Calendar, Photos, or YouTube during sign-in.

Session records

Each time you sign in, we record the session along with the IP address and browser user-agent of the device used. We keep this so you can stay signed in and so we can see when an account is being accessed in a way that looks wrong. Sessions expire after a period of inactivity, and refresh as you keep using the product.

3. Your profile and business settings

Setting up your account and using Settings creates a profile. We store what you enter there:

  • a short bio, your content categories, your experience level, your goals, and how deals usually reach you;
  • your social platform handles and profile links, entered by you;
  • your business name, business address, invoice number prefix, and the default payment instructions you want printed on invoices;
  • your timezone, so dates and deadlines are correct;
  • whether you work with a manager, agent, or lawyer, and the commission or retainer terms you record for them — we store the role and the terms, not their name; and
  • product preferences: how much guidance you want, how much freedom Cayhil has to act, and your saved view and column settings.
Worth knowing

Payment instructions is a free-text field that prints on the invoices you send. Whatever you enter is stored as you typed it and appears on the PDF. Unvld never moves money and has no payment processor, so include only what a brand needs in order to pay you — and never your online banking login, card numbers, or anything that would let someone take money rather than send it.

4. The records you create in Unvld

The bulk of what Unvld holds is what you or Cayhil enter about your business:

  • Deals — brand, stage, fee and currency, deliverable line items, usage rights, exclusivity, payment milestones, dates, and your notes.
  • Deliverables — status, due and live dates, draft rounds, brand feedback, approvals, and links to posted content.
  • Invoices — amount, currency, invoice and PO numbers, net terms, due, sent, and paid dates, the bill-to company and contact details you enter, payment instructions, and the generated PDF.
  • Payments — the amounts and dates you record as received, the payment method category, and any note you add. Unvld records that you were paid; it does not process the payment and is never connected to a bank account.
  • Contracts — the documents you upload, their status, and the analysis Cayhil produces from them.
  • Relationships — the brands, agencies, contacts, lists, conversations, and notes you keep.

All of this is private to your account. Other Unvld users cannot see your records. The one deliberate exception is the shared brand contact directory, described in Section 7.

5. Email you forward to Unvld

Unvld issues you a private address at inbox.unvld.co. When you forward a brand email there, we store the message in full so you can read it, and so Cayhil can pull deal terms out of it.

For each forwarded message we store:

  • the sender’s name and address, the reply-to name and address, and the name and address of everyone on CC;
  • the subject line;
  • the message body;
  • the technical headers that travel with the message, including the routing and authentication information email systems attach to it; and
  • every attachment — we keep the file itself, and for documents we also keep the text inside them so the message can be read and searched.
Keep this address private

Anyone who knows your inbox.unvld.co address can send mail into your Inbox, and we do not filter by sender. Nothing that arrives touches your deals, contacts, or invoices — it waits in the Inbox until you approve it. It is read on arrival, though: a message that reaches your Unvld inbox is sent to our AI provider so it can be sorted and its deal terms pulled out, whether you forwarded it or someone else sent it. So treat the address like a private forwarding address rather than something to publish. If it ever gets out, email hello@unvld.co and we will issue you a new one.

We may filter, ignore, or stop processing mail that appears to be spam, is oversized, or otherwise places an unreasonable load on the service.

Forwarding a message also means forwarding whatever is inside it — the sender’s words, anyone copied on the thread, and any attachment. Section 7 covers what that means for the other people on the thread.

6. Files you upload

Contracts, briefs, drafts, screenshots, and invoice PDFs are stored privately, filed under your account, and are accessible only to you through your signed-in session.

You can also attach a file as an external link instead of uploading it. In that case we store only the link and the label you gave it — the file itself stays wherever you keep it, under that service’s rules, not ours.

Brand and agency logos are stored separately and are publicly readable. Those are company logos, not your content or your documents.

7. Information about other people

Unvld is a CRM, so it necessarily holds information about people who are not you and who never signed up for it — the brand managers, agency contacts, and colleagues you deal with. This is where that information comes from.

Contacts you enter

When you add a contact, we store the name, email address, phone number, job title, LinkedIn URL, and any notes you write about them. Invoices additionally store the bill-to company name, contact name, email, and address you enter.

Contacts created from forwarded email

When you apply a forwarded email to a deal, Unvld can create contact records from the sender and from the people copied on the thread, using the names and addresses in the message headers.

The shared brand contact directory

Unvld maintains a directory of brand-side contacts that is shared across the platform rather than scoped to one account. Entries reach it only when a user deliberately submits one through the contribute flow; nothing you keep in your own contacts is added to the directory automatically. Submitted entries hold a name, email, job title, LinkedIn URL, and the brand they are associated with, are reviewed before they become visible, and record which account contributed them. We log which user reveals a directory contact’s email address, so we can enforce the directory rules in our Terms and investigate misuse.

How we treat it

  • Contacts in your account are yours. Other Unvld users cannot see them.
  • We do not sell contact information, rent it, or use it to market to those people.
  • We do not email anyone on your behalf. Unvld generates pitch drafts for you to send yourself; it never sends them.
  • You are responsible for having a legitimate business reason to hold information about the people you enter, and for what you write in the notes field about them.

If you are one of those people and you want to know what Unvld holds about you, or want it removed, email hello@unvld.co and we will look into it. Where the information sits inside a specific creator’s private records, we may need to involve them.

8. Cayhil and AI processing

Cayhil is the AI assistant inside Unvld. It reads brand emails and contracts, extracts deal terms, answers questions about your business, drafts pitches, and — when you ask it to — creates and changes records for you. Everything it does runs on large language models operated by a third party, which means some of your content leaves our servers.

Who processes it

The AI providers we use are named on our sub-processor list. The provider handling a given feature may change; the list reflects the current set.

Our agreements with these providers prohibit them from using the content we send to train their models, or for any purpose other than returning a result to us.

What gets sent, and when

  • Forwarded email. When a message arrives at your Unvld inbox, the subject, the sender, reply-to and CC names and addresses, the message body, and the text of every attachment are sent so the message can be classified and its deal terms pulled out. If the message relates to an existing deal, that deal’s current terms are sent with it for comparison.
  • Contract review. When you run a contract review, the contract document itself is sent, along with the deal terms Unvld holds, so the review can flag where the paper and the deal disagree. On a second or later round, the previous round’s findings and the new version of the contract go with it.
  • Talking to Cayhil. What you type is sent, along with the earlier messages in that conversation, your profile (categories, tone preference, timezone, social handles), your active deal roster, and the records relevant to what you asked — deal terms, deliverables, invoices with their bill-to contact, and payment history. Forwarded email bodies are not sent to Cayhil in chat.
  • Pitch drafting. The brand and contact you are pitching, your bio, categories, tone preference and past work, and your name for the sign-off.
  • The /reflect flow. Your multiple-choice answers are sent to produce the short written summary you see at the end. This happens before you have an account.

What we keep afterwards

We retain the following in your account:

  • your Cayhil conversations — every message you send and every reply, kept so the conversation has memory and so you can return to it;
  • a record of each exchange with Cayhil — what was sent, what came back, and a snapshot of the business information assembled for it;
  • a log of every change Cayhil makes on your behalf, including the before-and-after of the affected records, so that actions can be reviewed and undone;
  • the structured terms extracted from each email and the findings from each contract review; and
  • the pitch drafts generated for you.

What we do not do

  • We do not train models on your content, and we do not build models from it.
  • We do not share your business records with other Unvld users, and we do not use them to train AI models. Section 11 describes the aggregated, de-identified benchmarks we build.

We never send your password or your sign-in credentials — but some of the content listed above does identify you: your name goes on an email pitch sign-off, and your social handles are part of the profile Cayhil is given. Each provider’s own retention and handling are governed by its terms, which we link from the sub-processor list.

No AI opt-out today

There is no global switch that turns AI off, because reading email and contracts is what Unvld does. The control you have is over what reaches Unvld in the first place: nothing is sent to a model unless it arrives at your Unvld inbox, you upload it, or you ask Cayhil about it. Unvld never scans anything on its own, and it never reaches into an inbox, a drive, or a folder you have not handed it.

9. Usage data and error reports

Product analytics

We use a product analytics service that records page views, page exits, interactions with the interface, and product events such as an invoice being created or marked paid. Once you are signed in, these events are associated with your account.

Error monitoring

We use an error monitoring service to catch crashes. When something breaks, we receive the error, where in the product it happened, and technical details about the browser or server. We do not use session replay.

Server logs

Our servers keep a log of the requests made to them — what was asked for, whether it succeeded, and how long it took. Our hosting providers keep their own connection logs, which include IP addresses, in the ordinary course of running a website.

10. The waitlist and /reflect

Before you have an account, there are two ways to give us information.

The waitlist form collects your email address, one platform, and your handle on it.

The /reflect conversation asks a series of multiple-choice questions about how your brand-deal business runs. We store your email address, the answers you chose, and the short summary the model writes from them. Your answers and that summary are also emailed to the founding team, which is the point of the exercise — it is how we decide who to talk to.

If you submitted a /reflect response and want it deleted, email hello@unvld.co.

11. How we use your information

We use what we collect to:

  • run the product — show you your deals, deliverables, calendar, invoices, and payments, and keep them accurate;
  • create and maintain your account, sign you in, and keep the account secure;
  • read your forwarded email and contracts and turn them into structured deal terms;
  • answer your questions through Cayhil and carry out the changes you ask it to make;
  • generate invoices, pitch drafts, and contract reviews for you;
  • send you the emails the service depends on — verification and password reset;
  • diagnose errors, monitor performance, and understand how the product is used so we can improve it; and
  • prevent abuse and comply with the law when we are legally required to.

Aggregate benchmarks

As the platform grows we build anonymous fee ranges — for example, what a 3-video TikTok package with 6 months of paid usage typically pays. These are built from deal figures across many accounts, with the brand, the creator, and the individual deal stripped out before anything is aggregated. No one can see your fee, your brand, or your deal from a benchmark. This is the aggregated, de-identified data our Terms describe.

12. What we never do

  • We do not sell or rent your personal information.
  • We do not run advertising, and we do not share your data with ad networks or data brokers.
  • We do not train AI models on your content, and the AI providers we use are not permitted to train on what we send them.
  • We do not send email to your brand contacts, or to anyone else, on your behalf.
  • We do not read your Gmail, Drive, or Calendar. Unvld sees email only when you forward it to your Unvld inbox.
  • We do not move money, and we are never connected to your bank.

13. Companies that process data for us

Unvld is built on services run by other companies — hosting and storage, AI, email delivery, background processing, product analytics, and error monitoring. Each of them processes some of your data on our behalf and under our instructions in order to make the product work, and none of them may use it for their own purposes. We do not share your data with anyone else.

Our sub-processor list names every company we use and says what each one handles.

Legal requests

We may disclose information if we are required to by law, court order, or valid legal process, or to protect the safety and rights of our users. Where we receive a legal request for your information, we will notify you before disclosure unless we are prohibited by law from doing so, or where notice would create a risk of harm.

If Unvld is ever acquired or merged, your information may transfer as part of that transaction. We will notify you of the change and of any change to this policy that results from it.

14. Cookies and browser storage

Unvld sets a small number of cookies, all functional. There is no advertising cookie, no cross-site tracking pixel, and no third-party marketing tag anywhere in the product.

  • Session cookies. Keep you signed in. They are set for unvld.co only, and scripts running on the page cannot read them.
  • Analytics cookies. Our analytics service sets cookies in your browser to recognise a returning visitor across page loads.

Unvld also stores interface preferences and unsent form drafts in your browser’s local storage. This information does not reach our servers, and it is not cleared automatically when you sign out.

15. How long we keep things

We keep your information for as long as your account is open, and afterwards as described below. You can ask us to remove specific records, or your entire account, at any time.

Deleting things inside Unvld

Inside the product, deleting a deal, contact, or conversation hides it from your views but keeps the underlying record, so that history, audit trails, and financial records stay intact. Finalized invoices, payments, and contracts cannot be deleted while your account is open.

Deleting your account

Closing your account removes all of it, including finalized invoices and payments. The rule above applies while your account is open; it does not survive account deletion. The one exception is anything you contributed to the shared brand contact directory — as our Terms explain, a contribution cannot be recalled from the creators who have already seen it.

Copies may persist in encrypted backups for a period after that before those backups roll over, and we may retain what we are legally required to retain.

16. How we protect your data

We protect your information with administrative, technical, and physical safeguards appropriate to what it holds. Traffic between your browser and Unvld is encrypted, your records and the files you upload are encrypted at rest, and your passwords are stored only as cryptographic hashes — we do not store, and cannot read, your password.

Your records are private to your account. One user cannot reach another user’s deals, invoices, contacts, or documents. Files you upload are stored privately and are not accessible to other users.

No method of transmission or storage is completely secure. If we determine that a security incident has affected your personal information in a way that requires notice, we will notify you by email at the address on your account without undue delay, and tell you what we know at the time. We may delay notice where law enforcement asks us to, or where earlier notice would make the problem worse.

17. Your choices and rights

Seeing and correcting your information

Almost everything Unvld holds about you is visible and editable inside the product. Your profile and business settings are in Settings; your deals, contacts, invoices, and files are on their own pages; your forwarded email is in the Inbox; your Cayhil conversations are in the assistant panel.

Getting a copy of your data

Email hello@unvld.co and we will put together a copy of your data and send it to you.

Deleting your account

Email hello@unvld.co from the address on your account. We will delete your account and the data in it within 30 days of verifying your request, subject to the retention exceptions in Section 15, and confirm when it is done.

Disconnecting Google sign-in

If you signed in with Google, you can revoke Unvld’s access at myaccount.google.com/connections. Doing so will stop you signing in with Google; if you have not set a password, use the password-reset flow first so you do not lose access to your account.

Email

The only emails Unvld sends you are the ones the service requires — verification and password reset. We do not run marketing campaigns, so there is no marketing list to unsubscribe from. If that changes, those emails will carry an unsubscribe link.

Product analytics

Email hello@unvld.co and we will exclude your account from product analytics.

Local privacy laws

Depending on where you live, you may have rights over your personal information — to access it, correct it, delete it, obtain a portable copy, or object to certain processing. Email hello@unvld.co and tell us what you would like, and we will handle your request as the law that applies to you requires. We aim to respond within 30 days; where the law allows an extension for a complex or high-volume request we may take it, and we will tell you if we do. We may need to verify your identity before acting on a request, and we may decline where the law permits — for example where we need the information for a legal obligation, an ongoing dispute, or another person’s rights. We do not sell personal information or share it for cross-context behavioural advertising, and we will not treat you differently for exercising any of these rights.

18. Where your data is processed

Unvld is operated from the United States, and your records are stored there. If you use Unvld from outside the US, your information is transferred to and processed in the US, where privacy law may differ from the law where you live.

The companies listed in Section 13 process data on our behalf, and not all of them operate only in the United States. Your information may be stored and processed wherever a provider operates, under terms that require them to protect it and to use it only to provide the service to us. By using Unvld, you consent to these transfers.

19. Age requirement

You must be at least 18 years old to have an Unvld account. Unvld is a business tool involving contracts, invoices, and financial records, and we do not knowingly collect personal information from anyone under 18.

If you are a parent or guardian and believe a minor has created an account, email hello@unvld.co and we will remove the account and its data.

20. Changes to this policy

We will update this policy as the product and our practices change. When we do, we will update the date at the top of this page.

If a change materially affects how we handle your information, we will tell you by email or in the product, and where we reasonably can, before it takes effect.

21. Contact

For anything in this policy — a question, a request for your data, a deletion request, or a concern about information Unvld holds about you — email hello@unvld.co.

Unvld is operated from the United States.