PRIVACY POLICY FOR UNBOUNDCHAT
PRIVACY POLICY FOR UNBOUNDCHAT

Last Updated: December 30, 2025

UnboundChat ("we", "our", or "the app") is a privacy-focused AI chat application. This Privacy Policy explains how we handle your information.

1. OVERVIEW

UnboundChat is designed with privacy as a core principle. The app operates on a local-first model, meaning your conversations and data are stored on your device, not on our servers. We do not have access to your chat content.

2. INFORMATION WE DO NOT COLLECT

- We do NOT collect your conversations or chat messages
- We do NOT collect your API keys
- We do NOT require account registration
- We do NOT sell any data to third parties
- We do NOT track your location

3. INFORMATION STORED LOCALLY ON YOUR DEVICE

The following data is stored locally on your device and never transmitted to us:

a) Conversations and Messages
All your chat conversations, including text, images, and attachments, are stored in a local database on your device.

b) API Keys
Your API keys (OpenRouter, OpenAI, Google) are stored in encrypted platform-specific secure storage on your device. We never have access to these keys.

c) App Settings
Your preferences (theme, language, voice settings, etc.) are stored locally using standard platform storage mechanisms.

d) Backup Files
If you create backups, they are encrypted with AES-256-GCM using a password you provide. Backup files can be stored locally or in your personal Google Drive account.

4. THIRD-PARTY SERVICES

When you use UnboundChat, your messages are sent to the AI providers you choose to use. These are third-party services with their own privacy policies:

a) OpenRouter (https://openrouter.ai)
When you use OpenRouter models, your messages are sent to OpenRouter's API using your personal API key.

b) OpenAI (https://openai.com)
When you use OpenAI features (GPT models, DALL-E, Whisper, Text-to-Speech), your data is sent to OpenAI's API using your personal API key.

c) Google Cloud
When you use Google's speech-to-text or Gemini models, your data is sent to Google's APIs using your personal API key.

IMPORTANT: We are not responsible for how these third-party providers handle your data. Please review their respective privacy policies:
- OpenRouter: https://openrouter.ai/privacy
- OpenAI: https://openai.com/privacy
- Google: https://policies.google.com/privacy

5. OPTIONAL ANALYTICS

UnboundChat includes optional analytics to help us improve the app. This feature is:
- Enabled by default
- Can be enabled/disabled at any time in Settings
- Does NOT include any conversation content
- Does NOT include your API keys
- Does NOT include any personally identifiable information

If enabled, we may collect:
- App version and platform (Android, iOS, Windows)
- Anonymous device identifier (randomly generated UUID)
- Feature usage statistics (e.g., which features are used most)
- Error logs for debugging purposes
- General device information (OS version, device model)

Analytics data is processed through Supabase and stored securely.

6. GOOGLE DRIVE BACKUP

If you choose to use Google Drive for backups:
- You authenticate directly with Google using OAuth
- We request access only to app-specific folders we create
- We cannot access any other files in your Google Drive
- Backups are encrypted before upload with your security key
- You can revoke access at any time through your Google Account settings

7. VOICE FEATURES

a) Speech-to-Text
- When using OpenAI Whisper: Audio is sent to OpenAI for transcription
- When using device speech recognition: Audio is processed locally or through your device's speech service

b) Text-to-Speech
- When using OpenAI TTS: Text is sent to OpenAI to generate audio
- When using system TTS: Text is processed locally on your device

8. DATA SECURITY

We implement the following security measures:
- API keys are stored in platform-specific encrypted storage
- Backups use AES-256-GCM encryption with PBKDF2 key derivation (100,000 iterations)
- Optional app lock with PIN or biometric authentication
- All network communications use HTTPS/TLS encryption

9. DATA RETENTION AND DELETION

- All local data remains on your device until you delete it
- You can delete individual conversations or all data at any time
- Uninstalling the app removes all locally stored data
- We do not retain any of your personal data on our servers

10. CHILDREN'S PRIVACY

UnboundChat is not intended for use by children under the age of 13. We do not knowingly collect any information from children under 13.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date at the top of this policy. We encourage you to review this Privacy Policy periodically.

12. YOUR RIGHTS

Depending on your jurisdiction, you may have the right to:
- Access your personal data
- Delete your personal data
- Opt-out of analytics collection
- Export your data

Since your data is stored locally on your device, you have full control over it at all times.

13. CONTACT US

If you have any questions about this Privacy Policy, please contact us at:
[Your Contact Email]

14. CONSENT

By using UnboundChat, you consent to this Privacy Policy.