Data & privacy

Hunique is a private space to turn reflection into better conversations. The things you type here are often deeply personal. Your reflections stay on your device. We can't read them. We don't want to.

This page covers both the Hunique app itself and the hunique.ai website you might be reading this on. It explains how the on-device promise works, what happens to the small amount of information that does leave your device when you use AI features, and how we use analytics across both surfaces. It's written to be readable rather than legally padded. If you want the shortest possible version, read the next four paragraphs and stop there.

The short version

Your reflections stay on your device. Everything you type into Hunique - logs, patterns, conversations - is stored only in your browser, on the device you're using. There's no server-side copy. No one at Kaol can read them.

When you use AI features, your input is processed by AI models via our hosting provider's infrastructure. The content isn't stored, isn't logged, and isn't used to train any AI model.

You sign in with your email. We use it only to sign you in and recognise your account between visits. We don't sell, share, or use it for marketing.

We use product analytics on both the website and the app. Before you sign in, those analytics are anonymous - a random device identifier with no link to who you are. After you sign in, they're tied to your account so we can understand individual user journeys. We still cannot see what you write - every character you type in the app is masked before it leaves your device. The screenshot below shows exactly what a recorded session of the app looks like to us.

What a recorded session of the Hunique app looks like to us

A masked session recording of the Hunique app. All text the user typed has been replaced with asterisks.
We can see that a conversation happened. We cannot see what you said. Every character you type in the app is masked before it leaves your device.

How each part works

Your reflections and app data

Everything you create in Hunique - your logs, tracked patterns, conversation history, settings - is stored in your browser's local storage on the device you're using. It never gets copied to any server we run.

The practical implications:

Signing in

To use the Hunique app, you sign in with your email address. The flow is a sign-in code by email - you type your email, we send you a 6-digit code, you type the code back. There's no password to remember and nothing for us (or anyone else) to leak.

What this involves:

You can delete the email we hold by emailing [email protected] - see "Your rights" below.

AI features

When you use an AI feature, your input is sent over an encrypted connection to an AI model via Cloudflare AI Gateway - a service run by Cloudflare, the same company that hosts the Hunique app itself. We route all AI requests through this gateway, which we've configured so that the content of requests and responses isn't logged or stored after processing.

We commit to the following regardless of which specific AI model handles your request:

Cloudflare retains some operational metrics - timestamps, response times, token counts, the name of the model used - for billing and reliability purposes, for up to 3 months. These contain no user content.

If we change which AI models we use, we'll update this page. The commitments above will continue to apply.

Product analytics

We use PostHog, a product analytics service, to understand how Hunique is used across both the website and the app. Analytics data is stored on servers in Frankfurt, Germany, within the EU.

Before you sign in, the record is anonymous: a random device identifier in your browser, with no link to who you are. When you sign in to the app, we tell PostHog the random user ID we generated for your account and attach your email as a person property. From that point on your activity is tied to your account, and any earlier anonymous events from the same browser are stitched in.

What we collect:

What we don't collect:

All user-typed text in the app is masked client-side - in your browser, before anything is sent - so even if something went wrong on our end, no content would reach PostHog.

We also use PostHog's AI-assisted analytics features to help us understand usage patterns more easily. These features process only the analytics data listed above, via PostHog and its sub-processors. They never process anything you type in the app, because your content never reaches PostHog in the first place - the masking happens on your device before any data is sent.


The formal bits

Who we are

Hunique is provided by Kaol Ltd, a company registered in England and Wales under company number 16955479. Our registered address is 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom. We're registered with the UK Information Commissioner's Office under registration number ZC089019.

Kaol Ltd is the data controller for any personal data processed in connection with Hunique. Our Data Protection Officer is Andy Kilner, reachable at [email protected].

Who processes data on our behalf

We use two data processors to provide Hunique:

Both companies have signed data processing agreements with us and are subject to their own UK GDPR obligations. Both may use their own sub-processors to deliver their services; PostHog's current list is at posthog.com/subprocessors.

PostHog offers AI-assisted analytics features which we have enabled. These features only operate on the analytics data described in the "Product analytics" section above, via PostHog and its sub-processors. They never access anything you type in Hunique, because your content never reaches PostHog.

Legal basis for processing

Under UK GDPR, we rely on the following lawful bases:

Under PECR (as amended by the Data (Use and Access) Act 2025, in force from 5 February 2026), storage of and access to data on your device fits two exemptions to the consent requirement:

How long we keep things

Data Retention
Your reflections and app data On your device only, for as long as you choose to keep them. We have no copy.
AI request and response content Not retained.
Your account email and user ID For as long as you have an account. Deleted within 30 days of your request to [email protected].
Sign-in code (OTP) 10 minutes from request, or until first use - whichever comes first.
Sign-in session record 30 days from your most recent activity, refreshed each time you use the app. Deleted immediately on sign-out.
Cloudflare operational metrics Up to 3 months.
PostHog analytics events Up to 12 months.
PostHog session recordings (app only) Up to 30 days.
IP addresses Not retained (discarded before storage).

Your rights

Under UK GDPR you have the right to access, correct, delete, or restrict the use of any personal data we hold about you, to object to processing based on legitimate interests, to data portability, and to complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.

In practice:

We respond to data-rights requests within one month. We don't make automated decisions about you and we don't profile you.

Children

Hunique isn't directed at children under 16 and we don't knowingly collect data from them.

Changes to this page

If we make meaningful changes to how we handle data, we'll update this page and let you know inside the app. The version number and "Last updated" date below always reflect the current version.


Version 0.2 -- Last updated 19 May 2026