Privacy Policy
Unload turns voice and text notes into tasks. To do that, the service processes your recordings, transcripts and task text. This page explains what actually happens to them.
Version 1.0. Effective 23 August 2026.
- We do not read the content of your notes. It is processed automatically, with no human involved, and for one purpose: turning a note into a task and filing it into fields and contexts.
- Speech is recognised on our own infrastructure. Audio recordings are not sent to any third-party speech recognition service.
- A language model receives text only — never audio. By default it is not called at all.
- Your audio recording stays available to you for 180 days.
- The iOS app sends anonymous usage statistics by default — no note content, no link to your account. A settings toggle turns it off; see Section 5.
- We do not sell your data, show ads, track you across other apps and websites, or train language models on your recordings.
1. Who processes your data
The data controller is the Unload service. You can reach the controller on any matter of this policy at privacy@unloads.me and privacy@unloads.ru — both go to the same person responsible for data protection. We respond within the period required by applicable law.
The service is built so that it essentially does not need your personal data: beyond a sign-in address, all we ask of you is the voice or text of the note itself. What ends up inside a note is up to you.
This policy covers the Unload iOS app, the web app (app.unloads.me, app.unloads.ru), the Unload Telegram bot, and the unloads.me and unloads.ru websites.
2. What data we process
Account data. Your email address if you sign in by email. Your Telegram ID and username if you sign in through Telegram. Account settings and records of your active sign-in sessions.
Content you create. Voice recordings and their transcripts. Task and subtask text, dates, statuses, contexts, names of people you assign or mention in tasks, your manual transcript corrections, and any feedback messages you send us.
Your transcript corrections form a personal dictionary — pairs of “what the recogniser heard → what you wrote”. It helps recognition spell your names, titles and terms correctly, belongs to your account, is used only for your own transcripts, and is deleted together with your account. Those pairs never enter shared recognition models.
Technical data. A hashed device identifier, service records, and logs with technical request details that we need in order to find failures. Separate from those, the iOS app produces anonymous product statistics: they are not linked to your account and are described in Section 5.
If you put information about other people into your tasks, you are responsible for having the right to do so.
3. Why we process it
The content of your notes is processed automatically and without our involvement: software recognises the speech, pulls the title, dates and deadline, the “important” and “waiting” flags and the assignee out of the text, and files the task into your contexts. Content processing has no other purpose: we do not read your notes, build profiles from them, use them for advertising, or train models on them.
A human can see the content of a specific task in one case only — when investigating a failure or your complaint about recognition quality.
We do not collect advertising identifiers and use no advertising networks — neither in the iOS app, which contains no third-party SDK at all, nor in the web app. Visits to our websites are not linked to your account in the service.
Legal bases for processing: performance of our agreement with you — that is, providing the service itself; your consent where consent is required; our legitimate interest in keeping the service working and secure; and compliance with legal obligations.
4. Crash reports
When the web app breaks in your browser — it fails to load, shows a blank screen, or trips over an error — the app sends us a short report about the failure itself. Otherwise we would simply never learn about it: these errors leave no trace on the server.
A report contains the error type and message, the call stack, the page path without any URL parameters, the build version, the locale and the browser string. If you were signed in at that moment, it also contains your account identifier, so that we can tell who it is failing for and answer you specifically.
A report contains no task text, no transcripts and no audio. URL parameters are dropped deliberately: they may carry a share link to a task.
Reports are kept for no longer than 30 days after such an error last appeared, are used only to fix failures, and are never used for advertising, profiling or model training.
5. Anonymous product statistics
The iOS app sends us anonymous usage statistics by default. They serve exactly one purpose: letting us see which capture paths people actually use and where processing is slow or breaking. The “Anonymous statistics” toggle in the app settings turns them off; switching it off takes effect immediately and offline, and the journal already collected is erased on the device.
As long as you have not touched that toggle, the basis for processing is our legitimate interest in anonymous product metrics. Your decision — to switch the statistics on or off — is written to the consent journal as consent or its withdrawal (Section 10).
The statistics contain: a random install identifier, an event name from a predefined list (for example, “recording started” or “task deleted”), how the task was created, a latency bucket (“under 5 seconds”, “under 30 seconds” and so on), an error code, the app version and build, the iOS version, and the country code from the device language settings.
The statistics do not contain: note content, titles, transcripts, context or people names, task identifiers, your user identifier or your device identifier. These requests carry no sign-in token — we cannot link the events to your account, because no such link exists in the data. The install identifier lives in the app settings and does not survive a reinstall: after one it is a new install with no connection to the previous one.
The web app and the Telegram bot collect no product statistics. The app contains no third-party analytics or advertising SDK of any kind.
Events are kept for no longer than 400 days and are then deleted automatically. They are used only to improve the product — never for advertising, profiling or model training.
6. How your voice is processed
When you record a voice note, the audio file is uploaded to our server and recognised by GigaAM, which runs on our own server infrastructure. Audio recordings are not sent to any third-party speech recognition service.
On iPhone the app additionally produces a draft transcript using Apple’s system speech recognition, so that you see text immediately without waiting for the server. This step runs on the device itself: the app explicitly requires on-device recognition and declines it when the device cannot perform it locally. The final transcript arrives from our server and replaces the draft.
The microphone turns on only when you start a recording — from the app, the Action button, or the widget. The app does not listen in the background.
7. Language models
By default, turning a transcript into a title, date, assignee and other fields is done by deterministic rules on our server, without a language model.
A language model is called when you explicitly run the corresponding command — for example, when you ask to structure a task, match contexts, or polish the text — and also in the model-breakdown mode, if it is switched on in the service; when it is, the capability description right in the app says so. In both cases the request goes through OpenRouter, which routes it to the selected language model at its provider.
What is sent is text. Audio is not sent: the channel to the model accepts text messages only. Such a request may involve a transfer of data outside the country you are in. If that is not acceptable to you, do not use the commands that call a language model — nothing else in the service depends on them.
We do not control how OpenRouter and model providers handle those requests on their side. Their terms are published at openrouter.ai.
8. Retention and deletion
You can play back and download the original recording for 180 days from the moment it was created. After that period the recording stops being served: the app and any links to it return a refusal.
This is an availability period, not a deletion deadline. The reliable way to remove a recording is to delete the task or the account.
Deleting a task. The audio of the task and its subtasks is erased from active storage. A service record of the task itself is kept — a snapshot of its content that makes it possible to restore something deleted by mistake.
Deleting your account. This erases the account and everything belonging to it: tasks, subtasks, contexts, transcripts, audio recordings, service records of deleted tasks, your personal recognition dictionary, sign-in sessions and settings. Technical and backup copies are deleted automatically within a limited period. You can delete your account in the app settings.
9. Who we share data with
- OpenRouter — the text of a language model request (Section 7).
- Telegram — if you sign in through Telegram or use the bot. Telegram receives what that connection requires and handles it under its own policy.
- Our email provider — the recipient address and message body when we send you a sign-in code or link.
- External addresses you configure yourself. If you set up an action that sends data to an external system, that data goes to the address you specified. The recipient is responsible for what happens next.
Our providers may be located outside the country you are in. We do not sell your data and do not hand it to third parties for their own purposes. Data may be disclosed in response to a binding legal request made through due process.
10. Your rights
You have the right to learn what data about you is processed, to request its correction, restriction of processing or erasure, to withdraw consent, and to lodge a complaint with the competent data protection authority.
Some of this is available directly in the app: editing tasks and transcripts, deleting individual tasks, deleting your account. For anything else, write to privacy@unloads.me or privacy@unloads.ru. So that we do not disclose data to the wrong person, send the request from your account’s email address or otherwise reasonably confirm that the account is yours.
Where consent is the basis, we have to be able to show what exactly you consented to. Every switch of the “Anonymous statistics” toggle is therefore written to an append-only consent journal: the version number of this policy, a checksum of its text, the moment of the decision, the jurisdiction, the purpose of processing and — for consent withdrawn — the moment of withdrawal. The journal is appended to, never rewritten: a withdrawal adds a record instead of erasing the earlier one. Its records are as anonymous as the statistics themselves: they are tied to the install identifier, not to your account. You can request an extract for your own consent at the addresses in this section.
11. How we protect data
Traffic between the apps and the server runs over an encrypted connection. Credentials are stored as hashes. Access to production systems is limited to the people whose work requires it.
No service can promise absolute security, and we do not promise it. If a breach affecting your data occurs, we will notify you and the competent authority in the manner and within the deadlines set by law.
12. Children
The service is not directed at children under 16, and we do not knowingly collect their data. If you learn that a child is using the service without a parent’s or guardian’s consent, write to privacy@unloads.me or privacy@unloads.ru and we will delete the account.
13. Changes to this policy
We may change this policy — for example, if the data we process or the providers we use change. A new version is published on this page with a new version number and effective date.
We will announce material changes in the app or by email before they take effect. Previous versions stay published in the revision archive.