Legal

Privacy Policy

A plain-language outline of the data Unstuck Me needs to work.

Information we process

Account email and Firebase identity, private plan and wall content you save, and limited product events when analytics is explicitly enabled. A no-signup demo plan is stored in that browser unless you choose to create an account and import it. Product events can include an anonymous/session identifier, route and referring source, approximate country or region derived from the network request, browser/device category, screen size, language, timezone, and performance or error category.

How data is used

Data is used to authenticate you, save your private walls, prevent abuse, diagnose reliability, and understand product use and acquisition. Task titles, descriptions, details, request bodies, raw IP addresses, and raw error messages are not included in analytics events.

Anonymous feedback

The optional feedback survey sends your rating and comment to our support inbox through Resend to improve the experience. We do not attach your name, email, account identifier, Plan content, or analytics/session identifiers. The survey is excluded from session replay and interaction analytics. Please do not include personal information in your comment. Feedback is queued privately for delivery and scheduled for deletion from the app database after 30 days; mailbox and email-provider retention are separate. Short-lived, keyed network counters help prevent spam, are kept separately from feedback, and are scheduled for deletion after 24 hours. Infrastructure services still process ordinary connection information.

AI plan processing

Depending on the request, OpenAI or DeepSeek processes your task description, current plan, relevant notes and refinement instructions to generate or update a plan. Some requests use both providers, and requests needing current information may use web search. OpenAI API requests have response storage disabled; this does not mean zero retention. OpenAI does not use API data for training unless explicitly opted in, and standard abuse-monitoring logs may retain prompts and responses for up to 30 days. DeepSeek has separate data-use and retention terms; OpenAI-specific guarantees do not apply to DeepSeek. DeepSeek's terms describe possible use of inputs and outputs to improve its services and technology. Do not submit credentials or information you do not want an external AI provider to process.

When you open a Plan, OpenAI may analyze relevant saved check-ins, measurements and reflections to suggest optional insights. Insights are stored privately with your Plan, refreshed when their source changes, and removed when the Plan or account is deleted. They do not change your Plan automatically.

Unstuck Me records one-way request fingerprints, routing decisions, token usage and estimated costs, not raw plan text or hidden model reasoning in analytics or application logs. Successful responses may be cached briefly to prevent duplicate charges. Validated research briefs, including relevant quoted context, may be stored privately for reuse for up to 30 minutes from consultation. Expired briefs are no longer used; database cleanup is asynchronous. Plan and account deletion also remove their associated brief cache.

Glimmer assistant processing

When you write to the Glimmer box, Unstuck Me sends that message together with a snapshot of your active plans, their moves, dates and practice status for that request. That snapshot is processed by Muse Glimmer, an open-weight model that runs on a personal computer operated by Unstuck Me in the United States, not by an external AI provider. The connection is encrypted and reaches that computer through a Cloudflare tunnel that accepts only this app's own service credential; Cloudflare carries and authorises the request, and does not perform the processing. Your text is held in memory for the request. That computer keeps a short operational log of timings, model name and outcomes, not your plan text.

Your request, the assistant's reasoning, the steps it took and the resulting changes are stored privately under your account so you can undo a change and so support can diagnose a failure. They are removed when the plan or the account is deleted. If the assistant decides a plan itself should change, that part is prepared by the AI providers described above, so their terms apply to it.

Glimmer is optional: everything else in Unstuck Me works without it, and when that computer is offline the box says so. Nothing you write is used to train any model.

Service providers

Google Cloud and Firebase provide hosting, authentication, and account storage. OpenAI and DeepSeek provide AI plan generation and refinement. Cloudflare provides the authenticated tunnel that carries Glimmer assistant requests to the computer that runs the model. If you turn on notifications, the push service operated by your browser's maker (for example Google, Apple or Mozilla) delivers them; the message is encrypted so that only your browser can read its text, and that service sees that a message was sent to your device. IPWhois, or an explicitly configured IPinfo account, processes an IP address transiently on the server to return approximate geography and network information; the address is not stored in analytics. PostHog receives selected product events with a random browser identifier or an opaque account identifier, not your email or Plan text. Privacy-masked session replay records interactions, scrolling and interface structure to diagnose usability problems. Inputs and private user-generated text are masked before transmission; generic controls and public homepage copy remain visible. Network bodies, credentials and automatic exception recording are not captured. PostHog tracking respects Do Not Track and Global Privacy Control signals. Like any network service, the provider receives connection information; IP-based enrichment is disabled. Contact support for provider-side analytics deletion requests.

Retention and deletion

Browser demo content remains until browser storage is cleared or the demo is imported. Active account and wall data remains until you delete it. Signed-in users can permanently delete their Firebase identity, private walls, task content, profile, and identifiable first-party analytics from the Account page. Account deletion does not accelerate a provider's independent abuse-log retention period. Anonymous aggregate counters may remain because they cannot be tied back to the deleted account. Provider backups and operational logs, if configured, follow their separately managed retention settings. Support can help if the in-app flow cannot be completed.

Questions? Contact support.