Privacy Policy
Effective: 2026-07-20 · Last updated: 2026-08-03
1. Who we are
The Unnamed Corp ("Unnamed", "we", "us") is a Delaware corporation operating as a custom software studio. This policy covers the marketing site at theunnamed.dev, the Unnamed platform (the "Platform"), and data we handle while delivering engagements ("Services"). For the data described here, Unnamed is the controller. Where we process personal data inside a client's systems under a Statement of Work ("SOW"), we act as a processor on the client's instructions; that processing is governed by our Data Processing Agreement, not this policy.
This policy does not cover our open source software. Downloading or running it creates no account and sends us no data; see the Open Source Policy for what those projects do and do not talk to.
Privacy questions and rights requests: legal@theunnamed.dev.
2. What we collect
Information you provide directly: name, email address, company, and project details when you use the contact or start-a-project forms; account details (name, email) when you register for the Platform; content you enter into the Platform; and billing details when you purchase Services. Payments are handled by Stripe, and we never store full card numbers on our servers.
Information collected automatically: error and performance reports via Sentry (which may include IP address and device/browser metadata) and server logs (IP address, user agent, timestamps). We use only the strictly necessary cookies described in our Cookie Policy. We do not use analytics, advertising, or cross-site tracking technologies.
Information from third parties: if you schedule a discovery call, Google Calendar/Meet shares scheduling details (name, email, meeting time) with us. If you connect a GitHub or Discord account to the Platform, we receive the profile and repository or identity details you authorize. If you email us, we receive and store your message and address.
We do not collect special-category (sensitive) data on our own behalf and ask that you not submit it through our forms.
3. How and why we use it
We use personal data to: respond to inquiries and proposals; authenticate accounts and operate the Platform; deliver Services under an SOW; invoice and collect payment; send transactional email (account, billing, and engagement notifications); monitor errors and improve reliability; and meet legal obligations. We do not sell or share personal information, and we do not use it for third-party advertising.
4. AI-assisted features
Parts of the Platform use AI to assist our own team's work, for example drafting proposal text, summarizing an engagement's status, and ranking follow-up actions. These features run on Amazon Bedrock within our AWS account. Prompts may include business-contact and engagement data (such as a contact's name, company, and correspondence history). AWS does not use content submitted to Bedrock to train its models or share it with model providers. These features assist human decisions; they do not make automated decisions that produce legal or similarly significant effects about you.
5. Legal bases (EEA/UK visitors)
| Processing activity | Legal basis |
|---|---|
| Responding to contact/intake submissions | Legitimate interest (responding to your request) |
| Account creation, authentication, Platform operation | Performance of contract |
| Invoicing and payment via Stripe | Performance of contract; legal obligation |
| Transactional email | Performance of contract |
| Error monitoring (Sentry) | Legitimate interest (reliability and security) |
| AI-assisted internal workflows | Legitimate interest (operating our business efficiently) |
| Marketing communications | Consent (opt-in; withdraw anytime) |
6. Sharing and subprocessors
We share personal data only with our subprocessors (currently AWS, Stripe, Amazon Cognito, Google, Sentry), each bound by its own data protection terms; with professional advisers under confidentiality; when required by law or valid legal process; or with your explicit consent. If Unnamed is involved in a merger, acquisition, or sale of assets, personal data may transfer as part of that transaction, and we will notify you before your data becomes subject to a different privacy policy. We notify Platform customers of material subprocessor changes with at least 30 days notice.
7. Cookies and tracking
We set only strictly necessary cookies: session cookies for authentication (Amazon Cognito) and short-lived cookies that secure sign-in redirects. We use no analytics, advertising, or cross-site tracking cookies, which is why you see no cookie consent banner: there is nothing optional to consent to. Full details, including cookie names and lifetimes, are in the Cookie Policy.
8. Retention
| Data | Retention |
|---|---|
| Contact/intake form submissions | 12 months after last activity |
| Inbound email (raw message archives) | 180 days |
| Application logs | 90 days |
| Error reports (Sentry) | 90 days |
| Account data | Life of the account, then deleted within 90 days of a deletion request |
| Billing records | 7 years (tax and accounting obligations) |
| Engagement data processed under an SOW | Per the SOW and DPA |
9. International transfers
We host on AWS in the United States (us-east-1 region), so personal data is stored and processed in the US regardless of where you access our services from. Where the GDPR or UK GDPR applies to data you send us, we rely on the European Commission's 2021 Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), supplemented by the technical safeguards described in section 12. Each of our subprocessors likewise offers SCC-backed transfer terms, and several are certified under the EU-US Data Privacy Framework.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, restrict or object to processing, and withdraw consent. We do not discriminate against you for exercising these rights.
United States. Residents of California and other states with comprehensive privacy laws have rights to know, access, correct, delete, and obtain a portable copy of their personal information, and to opt out of sale, sharing, and targeted advertising. We do not sell or share personal information, do not engage in targeted advertising, and do not process sensitive personal information for inferences, so there is nothing for an opt-out or Global Privacy Control signal to switch off. California residents may also designate an authorized agent to submit a request.
EEA/UK. You have the rights described in Articles 15 through 22 of the GDPR, and you may lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).
To exercise any right, email legal@theunnamed.dev. We verify requests against the account or correspondence they concern and respond within 30 days (45 days for US state-law requests, extendable once where the law allows).
11. Children's privacy
Our services are sold to businesses and are not directed to children. We do not knowingly collect personal data from anyone under 16, and we do not knowingly collect any personal data from children under 13. If you believe a child has provided us data, contact us and we will delete it.
12. Security
We encrypt data at rest (AES-256) and in transit (TLS 1.2+), enforce MFA on authentication, follow least-privilege access control, and keep immutable audit logs. Our full security practices, including breach handling, are documented internally and provided to customers on request. If a breach affects your personal data, we will notify you and any required regulator without undue delay.
13. Changes to this policy
We will post updates here with a revised effective date, and give at least 30 days notice of material changes by email (for account holders) or a site banner.
14. Contact
The Unnamed Corp · Privacy questions and rights requests: legal@theunnamed.dev · General: info@theunnamed.dev