Privacy Policy
Effective September 6, 2026Last updated September 6, 2026
Unsent is operated by HMU, Inc.. This policy explains how we collect, use and share information when you use the Unsent iPhone app and unsent.photos. Contact us at support@unsent.photos with questions or privacy requests.
Information we collect
- Your account: your phone number, profile name, username, optional avatar, account identifiers, settings and authentication records. We use your phone number to verify access to your account.
- Contacts: with permission, the app hashes contacts’ phone numbers on your phone and sends those hashes to find registered users. Raw address-book phone numbers and contact names are not sent by this lookup. Hashes are compared with registered phone-number hashes; they are not anonymous. We do not retain the submitted lookup list.
- Photos: with photo-library permission, the app analyzes accessible photos for faces and uploads eligible photos as a thumbnail, a display image and an original. We store photo identifiers, dimensions, dates when provided, hashes used for deduplication, face locations and sharing records. Original files can contain embedded metadata, including location, if it is present in the original.
- Face data: the app detects faces and creates numerical face embeddings on your device. When you enroll with a selfie, the selfie image stays on your device; its embedding is sent to our database. Embeddings and face locations from analyzed library photos are also sent for matching and grouping. This data can be sensitive biometric information.
- Activity and support: friend requests, sharing and download actions, reports, support messages, device push tokens and technical logs needed to operate and secure the service. Requests to our website and API expose network information such as your IP address to our hosting providers.
Why we use face data
We use face embeddings to match photos with enrolled, accepted friends and to group faces appearing in your photos. A face may be represented in an uploaded photo and its associated embedding even when that person does not have an Unsent account. Unmatched faces may be grouped for the photo owner; they are not automatically discarded after analysis. We do not use face data for advertising, sell it, or use it to train general-purpose AI models.
Enrolling your own face is optional. You can remove your enrollment in Settings to stop future matching to that enrollment. Removing your enrollment does not delete every photo in which you appear or embeddings associated with another person’s uploaded photos. For help with those records, contact us. Matching can make mistakes; review suggested recipients and report incorrect matches.
Photo sharing and your controls
Sharing is between accepted friends. You can review pending deliveries, send them manually, or use automatic sharing according to your settings. A display image can become available before the original finishes uploading. Downloads use the original once it is available. Friends who receive or save a photo may keep their own copy, including metadata in that file.
You can change automatic-sharing settings, remove friends, block people, hide or report photos, delete your uploaded photos, remove your face enrollment, or delete your account. Photo, camera, contacts and notification permissions can be changed in iOS Settings. Limited photo access restricts the library items the app can inspect. Background processing and uploads depend on iOS, network availability and device conditions.
Service providers and other disclosures
- Cloudflare: website and API hosting, request handling, database connectivity, scheduled work and job queues.
- Supabase: PostgreSQL storage for accounts, embeddings, photo metadata, relationships, sharing and support records.
- Amazon Web Services: private S3 storage for photo thumbnails, display images, originals and avatars.
- Twilio: phone-number verification and SMS verification delivery.
- Apple: app distribution, device permissions and push notifications. Notifications may show a friend’s display name and the number of shared photos.
- Telegram: internal operations alerts containing report/support record identifiers and service-status summaries. We do not send photo files, face embeddings or the contents of support messages through these alerts.
Providers process information needed to supply their services. Our storage and providers may process information in the United States and other countries, including where hosting requests are handled. We may also disclose information when required by applicable law, to investigate abuse or protect safety, or as part of a business transfer subject to applicable privacy obligations. We do not sell personal information or share it for cross-context behavioral advertising.
Retention and deletion
We retain account, photo and face records while needed to provide the features you use. Deleting your account removes its active account records and schedules associated stored-file cleanup. Deleting uploaded photos likewise schedules file deletion. File removal is asynchronous and may take longer if a provider or background job is unavailable. Previously issued temporary download links may continue to work until they expire or the object is removed.
Removing face enrollment deletes that enrollment from the active database. Support, abuse-prevention, security, legal and backup records may be retained where necessary for their purpose or required by law. Backup copies are subject to the providers’ retention and recovery processes. We do not promise immediate physical erasure or a fixed backup-deletion period. Deleting data from Unsent cannot remove copies already saved by other people.
Security
Connections use HTTPS. Photo storage is private and encrypted at rest; authorized requests receive time-limited storage URLs. Backend access controls restrict account and photo access. Face matching requires processing embeddings in our backend, so Unsent is not end-to-end encrypted. No service can guarantee absolute security.
Your rights and requests
Depending on where you live, you may have rights to access, correct, delete or obtain a copy of your information, object to or restrict processing, or withdraw consent. Contact support@unsent.photos. We may need to verify your identity before completing a request. Withdrawing permission affects future processing and does not undo sharing already completed. You may also have the right to complain to your local privacy regulator.
Where a legal basis is required, we process information to provide the service you request, with consent for optional permissions and face enrollment where required, and for legitimate interests in security and support or to meet legal obligations. Applicable local law may give you additional rights.
Children
Unsent is not intended for children under 13 or anyone below the minimum age required to use the service in their jurisdiction. If you believe a child has provided information without required authorization, contact us so we can investigate and take appropriate action.
Website and policy changes
The landing page may load image assets from external image hosts; those hosts receive the network information needed to deliver the image. We may update this policy as the service changes and will update the date above. We will provide additional notice or seek consent when required.
See our Terms of Service and Support page.