Last updated 17 September 2026 · Hex Innovation Limited
Unlok sits between your team and every model it uses, so we are careful about what we keep. This policy says exactly what that is, in plain language.
Unlok is built and operated by Hex Innovation Limited. This policy explains what we collect when you use the Unlok website, the Unlok app, the API gateway, the CLI, the editor extension, the Browser Agent and the chat connectors (together, the Service), why we collect it, and the choices you have.
For data you send through the Service on behalf of your organisation, your organisation is the controller and we process it on their instructions. For your own account and for visits to this website, we are the controller.
Account details. Your name, email address, a hashed password, email verification codes, password reset tokens and the settings you choose. If you sign in with GitHub we receive the profile details GitHub shares for that connection.
Sessions. When each sign in was created, last used and expires, so you can review active sessions in your settings and end any you do not recognise.
Request metadata. For every request routed through the gateway we record the model requested, the model chosen, token counts, cost, timing, the routing decision and which credential was used. This is what powers your usage dashboard, billing and the audit log.
Prompts and responses. Whether we keep the content of a request is controlled by your logging level. At none we keep no content. At metadata only, the default, we keep the metadata above and no content. At full we keep the prompt and the response so you can review them in the dashboard. Content also passes through the semantic cache and the security checkpoint in order to serve repeated requests and block leaked secrets.
Optimus memories. The memories your team saves or that Optimus distils from sessions, along with any workspace rules and policies you write. Workspace admins can set how long memories and session summaries are retained.
Connected repositories. When you connect a GitHub repository we read its contents live to answer questions and to scan for exposed secrets. We store the connection, the findings, and not a copy of your code.
Provider credentials. If you bring your own keys for a model provider we store them encrypted at rest and use them only to send your workspace's requests to that provider.
Billing. Your plan, wallet balance, ledger entries and invoices. Card details go straight to our payment processors and never touch our servers.
Support and forms. Anything you send us through the Enterprise contact form or a support conversation.
We use the data above to:
We do not use your prompts, responses or memories to train models, and we do not sell personal data.
Account data is kept while your account is open. Request metadata is kept for billing and audit purposes for as long as your workspace needs it. Prompt and response content kept under the full logging level, memories and session summaries follow the retention windows your workspace sets, and are removed when those windows expire. Provider credentials are deleted the moment you remove them. When you close your account we delete or anonymise your personal data, except where we must keep records for tax, accounting or legal reasons.
Data is encrypted in transit and at rest. Provider keys and GitHub tokens are envelope encrypted with their own key. Access to production systems is limited to the people who operate them. The security checkpoint scans outbound requests so that credentials in a prompt are caught before they leave your workspace. No system is perfectly secure, so if you believe your account has been compromised, end your sessions in settings and contact us.
You can view and update your profile, change your logging level, end sessions, remove provider keys, disable models, delete memories and export usage from your account. Depending on where you live you may also have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, contact us as described below. We will respond within thirty days.
If you are in the United Kingdom or the European Economic Area, we transfer data outside those regions only with appropriate safeguards in place, such as standard contractual clauses.
The Service is for people aged eighteen and over. We do not knowingly collect data from anyone younger. If you believe a child has given us personal data, contact us and we will delete it.
When we change this policy we update the date at the top and, for changes that matter to you, we tell you by email or with a notice in the app before they take effect.
Questions about privacy go to Hex Innovation Limited at info@unlokai.io. Our Terms of Service set out the rest of the agreement between us.
The operational layer between your team and every AI model it touches.