Privacy Policy

Unadmin ("we", "us") provides an AI back office for small businesses. This policy explains what personal data we collect, why, and the choices you have. Unadmin is operated from the United Kingdom and we act as the data controller for account data, and as a processor for the business content you connect. Questions or requests: hello@unadmin.co.uk.

What we collect

How we use it

Google user data — Limited Use disclosure

Unadmin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain language: data we receive from Google APIs (such as Gmail, Google Business Profile, Google Calendar, Search Console, Google Analytics, or Merchant Center) is used only to provide the features you asked for — drafting replies, chasing invoices, surfacing signals — and is never sold, never used for advertising, and never used to train generalised AI or machine-learning models. Human access is limited to cases where you ask us for support, security requires it, or the law demands it.

Meta Platform Data — what we access and why

If you connect a Facebook Page, an Instagram professional account, or a Messenger inbox, we receive Platform Data from Meta and handle it under the Meta Platform Terms and Developer Policies. What we access:

We use Platform Data only to provide the features you asked for. We do not sell it, use it for advertising or ad targeting, transfer it to data brokers or ad networks, use it to build profiles of the people who message you, or use it to train general-purpose AI models. Nothing is posted or sent from your Page or account without a person in your workspace approving it first.

You can revoke our access from Facebook at any time under Settings & privacy → Settings → Apps and websites, or delete the Platform Data we hold by following Deleting your data. When you disconnect or remove the app we delete the stored access tokens immediately and stop all access.

Disconnecting and revoking access

You can disconnect any source from your workspace settings at any time. We stop syncing straight away and delete the stored connection tokens. For Google accounts you can also revoke Unadmin's access yourself at myaccount.google.com/permissions. Disconnecting does not remove data already in your workspace; you can delete that from settings or ask us to — see Deleting your data for every route, including how to remove Unadmin from Facebook and Instagram.

Lawful bases

We process account and billing data to perform our contract with you. We process connected-source data on your instruction as part of the service. Security telemetry rests on our legitimate interest in keeping the service safe. Where consent is required (for example connecting a provider account), we ask for it explicitly and you can withdraw it by disconnecting the source.

Where your data lives

Production data is hosted on Microsoft Azure infrastructure in the UK South region. Our subprocessors are Microsoft Azure (hosting), Clerk (authentication), Stripe (payments), and our AI model providers (draft generation, under agreements that prohibit training on your content).

International transfers

Some subprocessors process data outside the UK, for example our AI model providers in the United States. Where that happens we rely on UK adequacy regulations or the UK International Data Transfer Agreement or Addendum with the provider concerned.

Security

Data is encrypted in transit and at rest. Connection tokens are held in a dedicated secret vault rather than our application database, and each connection requests the narrowest scopes its workflow needs. Access to production systems is limited and logged.

Retention

We keep your data while your workspace is active. If you close your workspace, we delete or de-identify personal data within 30 days, except where a longer period is required for legal or accounting reasons. You can request an export or deletion at any time from your workspace settings or by emailing us. Full instructions are on Deleting your data.

Your rights

Under UK GDPR you can request access, correction, deletion, restriction, or a portable copy of your personal data, and you can object to processing. Email hello@unadmin.co.uk and we will respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

Cookies

We use only the cookies needed to sign you in and keep your session secure, set by our authentication provider. We do not use advertising or cross-site tracking cookies.

Changes

We will post any changes here and, for material changes during the beta, email workspace owners before they take effect.