Privacy Policy
Last updated 1 August 2026 · Invite-gated beta
Unadmin ("we", "us") provides an AI back office for small businesses. This policy explains what personal data we collect, why, and the choices you have. Unadmin is operated from the United Kingdom and we act as the data controller for account data, and as a processor for the business content you connect. Questions or requests: hello@unadmin.co.uk.
What we collect
- Account data. Name, email address, and authentication identifiers, managed through our sign-in provider (Clerk).
- Business profile data. The business details, tone, services, FAQs, and policies you enter to configure your assistants.
- Connected source data. When you connect a source (for example a Gmail or Outlook mailbox, accounting platform, or Google Business Profile), we access the messages and records needed to prepare drafts and surface signals for you. We access the minimum required for each workflow.
- Billing data. Plan, credit usage, and payment status. Card details are handled by Stripe and never touch our servers.
- Service telemetry. Operational logs and usage metrics. We do not write your customer content into our logs.
How we use it
- To run the product: watching connected sources, preparing drafts, and queueing them for your approval. Nothing is sent without your say-so.
- To operate billing, support, and security.
- To improve the product using aggregate, de-identified usage patterns. We do not use your customer content to train general-purpose AI models.
Google user data — Limited Use disclosure
Unadmin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain language: data we receive from Google APIs (such as Gmail, Google Business Profile, Google Calendar, Search Console, Google Analytics, or Merchant Center) is used only to provide the features you asked for — drafting replies, chasing invoices, surfacing signals — and is never sold, never used for advertising, and never used to train generalised AI or machine-learning models. Human access is limited to cases where you ask us for support, security requires it, or the law demands it.
Meta Platform Data — what we access and why
If you connect a Facebook Page, an Instagram professional account, or a Messenger inbox, we receive Platform Data from Meta and handle it under the Meta Platform Terms and Developer Policies. What we access:
- Page and account details. The list of Pages and Instagram accounts you manage and their profile information, so you can choose which ones Unadmin works with.
- Messages and comments. Conversations in your Page inbox, Instagram direct messages, and comments on your posts, so we can prepare replies for your approval.
- Posts and content. Existing and scheduled content, so drafts fit what you already publish and we can post the ones you approve.
- Engagement and insights. Aggregate reach and interaction figures used to surface signals in your workspace.
We use Platform Data only to provide the features you asked for. We do not sell it, use it for advertising or ad targeting, transfer it to data brokers or ad networks, use it to build profiles of the people who message you, or use it to train general-purpose AI models. Nothing is posted or sent from your Page or account without a person in your workspace approving it first.
You can revoke our access from Facebook at any time under Settings & privacy → Settings → Apps and websites, or delete the Platform Data we hold by following Deleting your data. When you disconnect or remove the app we delete the stored access tokens immediately and stop all access.
Disconnecting and revoking access
You can disconnect any source from your workspace settings at any time. We stop syncing straight away and delete the stored connection tokens. For Google accounts you can also revoke Unadmin's access yourself at myaccount.google.com/permissions. Disconnecting does not remove data already in your workspace; you can delete that from settings or ask us to — see Deleting your data for every route, including how to remove Unadmin from Facebook and Instagram.
Lawful bases
We process account and billing data to perform our contract with you. We process connected-source data on your instruction as part of the service. Security telemetry rests on our legitimate interest in keeping the service safe. Where consent is required (for example connecting a provider account), we ask for it explicitly and you can withdraw it by disconnecting the source.
Where your data lives
Production data is hosted on Microsoft Azure infrastructure in the UK South region. Our subprocessors are Microsoft Azure (hosting), Clerk (authentication), Stripe (payments), and our AI model providers (draft generation, under agreements that prohibit training on your content).
International transfers
Some subprocessors process data outside the UK, for example our AI model providers in the United States. Where that happens we rely on UK adequacy regulations or the UK International Data Transfer Agreement or Addendum with the provider concerned.
Security
Data is encrypted in transit and at rest. Connection tokens are held in a dedicated secret vault rather than our application database, and each connection requests the narrowest scopes its workflow needs. Access to production systems is limited and logged.
Retention
We keep your data while your workspace is active. If you close your workspace, we delete or de-identify personal data within 30 days, except where a longer period is required for legal or accounting reasons. You can request an export or deletion at any time from your workspace settings or by emailing us. Full instructions are on Deleting your data.
Your rights
Under UK GDPR you can request access, correction, deletion, restriction, or a portable copy of your personal data, and you can object to processing. Email hello@unadmin.co.uk and we will respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
Cookies
We use only the cookies needed to sign you in and keep your session secure, set by our authentication provider. We do not use advertising or cross-site tracking cookies.
Changes
We will post any changes here and, for material changes during the beta, email workspace owners before they take effect.