Privacy Policy
Unomaas (say it “Uno Mas”) is a chat app with a personal AI agent. You chat one-to-one with another person, and each of you can bring your own AI agent into that chat. You can also give your agent tasks, like reminders and errands. Unomaas is operated by Zuhair Ahmed in Fremont, California, USA (“Unomaas”, “we”, “us”). This policy explains what we collect when you use the Unomaas apps for Android and iPhone, the web app at unomaas.ai/app and this website, how we use it, who we share it with, and the choices you have. It works together with our Terms of Service.
The short version: we collect what we need to run your account, your chats and your agent. We don’t sell your information, we don’t show ads, and we don’t search your contacts. Your agent can’t buy anything without your PIN approval. Calendar sharing is off until you turn it on, and even then we store only free and busy times, never event names. Photos and voice messages you choose to send stay on our server. A voice note can be turned into text there, and that audio is not sent to a separate transcription company. If you ask your agent to remember something about you, that short note stays on your account. Your agent can use it for you, and it is not shared with the other person or their agent. You can turn memory off or delete those notes. If you join the beta from this website, we store the store email you give us only to add you on Google Play or TestFlight, and you can remove it with that same email. You can ask us to delete your data at any time.
- What we collect
- How chats and agents work
- How we use information
- AI processing with Amazon Bedrock
- Purchases and merchants
- Calendar free/busy
- Who we share it with
- How long we keep it
- Security
- Your choices and rights
- California privacy rights
- Children
- Where data is processed
- Changes to this policy
- Contact
1. What we collect
Information you give us
- Account details. Your US mobile phone number, the display name you choose, an optional email address, and confirmation that you are 18 or older. You also set a PIN, which we store only as a one-way hash, never in readable form. We don’t use your optional account email to sign you in or to contact you.
- Agent settings. Your agent’s name and voice, whether away mode is on, whether memory is on, and the “about me” notes you write for your agent (up to 500 characters).
- Agent memory. Short notes your agent saves when you ask it to remember something, or when you tell it a lasting preference about yourself (for example that you are vegetarian, your usual coffee, or the airline you fly). Up to 100 notes, each up to 200 characters. Memory is on until you turn it off in Settings.
- Messages. The messages you send in your chats, including any links in them, and the messages agents write in those chats. This includes photos and voice messages you choose to send, a text transcript of a voice message when our server can make one, a quote when you reply to a specific message, and emoji reactions you add.
- Agent tasks. The instructions you give your agent for reminders, follow-ups and errands, and when they should run.
- Purchase decisions and spending caps. The spending caps you set, and your approve or deny decisions on purchases your agent proposes.
- Reports and blocks. If you report a message or a person, or block someone, we keep a record of it.
- Website feedback. If you use the feedback form on this website, we store your note, its category, the page you sent it from, your browser type and, only if you add it, your email address so we can reply. The form does not require an account.
- Beta sign-up. If you use Join the beta, we store the platforms you pick (Android, iPhone, or both), the Google account email you use for the Play Store and/or the Apple ID email you use for TestFlight, an optional first name, and your confirmation that you are 18 or older. We use those emails only to add you to the Play closed test or to TestFlight. We do not send you email from Unomaas. The form does not create an account. You can remove the signup by sending the same email on that page. You can also email zuhairahmed@gmail.com and ask us to delete it.
Information created when you use Unomaas
- Agent activity log. Each step your agent takes on a task or a purchase: the tools it used, their inputs and results, policy checks, approval requests and decisions, and errors. This log exists so you (and we, when you ask for help) can see exactly what your agent did.
- Purchase records. For purchases you approve: the merchant, item, price, status and order reference.
- Usage and cost records. How many AI model calls and tokens your agent used, so we can enforce daily limits and keep costs in check.
- Devices and sessions. A device identifier generated by the app, sign-in sessions, and, for browsers linked by QR code, a browser label from its user agent, the time it was last active and, during linking only, the IP address of the browser that asked to link.
- Push notification tokens. If you allow notifications in the phone app, a token that lets us send notifications to that device.
- Browser push subscriptions. If you turn on notifications in the web app, we store a browser push subscription for that browser. We store it only when you turn notifications on, and we delete it when you turn them off, sign out of that browser, remove that linked device, or delete your account. A web notification names who it is from. It does not include the message, a photo, a transcript, or purchase details.
- Read status. When you last read each chat, so we can show unread counts and read receipts.
- Security and server logs. IP addresses and request details in our web server logs, and short-lived counters used for rate limits (for example, how many sign-in codes were requested from a phone number or an IP address). For website feedback and for beta sign-up we store only a salted hash of your IP address, not the address itself.
What we don’t collect
We don’t access your phone’s contacts or address book, we don’t use advertising identifiers or third-party ad or analytics trackers, and Unomaas doesn’t collect or store payment card numbers. We don’t collect calendar event titles, locations, notes, attendees, or calendar names. We don’t upload your photo library or record the microphone unless you choose to send a photo or a voice message. The app and web app keep your sign-in tokens and settings on your device so you stay signed in; this website does not set tracking cookies.
2. How chats and agents work
- One-to-one only. Every chat on Unomaas is between exactly two participants. A chat with another person starts when one of you accepts the other’s invite link.
- Practice chat. You can also open one practice chat with Pip, a demo contact Unomaas operates. Pip is not another person, is labeled Demo everywhere in the app, and cannot be searched, invited, or reported as a user. Pip does not count as a signed-up person. Messages in that chat are stored the same way as other chats, and they are deleted when you delete the practice chat or your account. Pip’s own lines are short prepared replies. Your agent’s replies in that chat are sent to our AI provider and count against the same daily limits as your other chats. Pip cannot approve a purchase or confirm a time on a calendar. A purchase in that chat can only use the test merchant, and it still needs your PIN.
- Agents in a chat. Each person has their own AI agent, and the agents of the two people in a chat can take part in it. An agent joins in when its owner mentions it by name, or when its owner has turned on away mode and the other person sends a message.
- Who can see your messages. Messages in a chat are visible to the other person in that chat and to the agents taking part in it. When an agent replies, it reads the recent messages in that chat (up to the last 40), its owner’s “about me” notes, and a small set of that owner’s saved memory notes, and those are processed by our AI model provider as described below. An agent cannot read your other chats. It does not receive the other person’s memory notes.
- Agent memory stays with you. A note is saved only from your own message to your own agent, for example “@Nova remember I’m vegetarian” or “@Nova I always fly United”. It is not saved from the other person’s messages, from web pages, or from tool results. Your agent confirms in that chat when it saves or forgets a note. Later it may use a note to act for you, and it is instructed not to reveal, quote, or list your notes to the other person. You can ask it in chat to forget something. In Settings → Memory you can see every note, delete one, delete them all, or turn memory off. Off means nothing is saved and nothing saved is used. Deleting your account deletes the notes.
- Photos. You can send a photo from the camera or from pictures you pick. We store the photo and a small thumbnail with that chat. Only the two people in the chat can open it, and only while they are signed in. Your agent may be shown the picture when it replies in that chat, as described in the AI section. We do not upload the rest of your photo library.
- Voice messages and transcripts. You can record a voice message in a chat. We store the audio with that chat, and only the two people in the chat can play it. When transcription is turned on, our own server turns the audio into text with an open-source speech-to-text program that runs on that server. The audio is not sent to a transcription company or any other third party for speech-to-text. The transcript is stored on the message. Both people in the chat can read it. The agents in that chat can read it as text, the same way they read other messages in that chat, and only as part of that chat. If transcription is off, the note is too long, the daily limit is reached, or the transcript cannot be made, the voice message still sends and still plays; it just has no transcript. A transcript is not approval for your agent to buy or book anything.
- Reactions and replies. You can add one reaction to a message (heart, thumbs up, laugh, surprise, sad, or thanks). Tapping it again removes it. Both people in the chat can see the counts. Agents do not add reactions, and a reaction is not sent to the model and does not send a notification. You can reply to a specific message. The quote shows a short snippet, or “Photo” or “Voice note”. If that message is gone, the quote says the original is unavailable. When your agent answers a reply, the quoted text from that same chat is included so it knows what you are answering. That does not let the agent purchase or book without your approval.
- Agent messages are labeled. Messages written by an agent are stored and shown as coming from that agent, never as coming from its owner.
- Tasks you give your agent. When your agent runs a reminder or errand for you, it works from your instructions and the tools it is allowed to use, and every step is recorded in your activity log.
3. How we use information
- to create and secure your account, verify your phone number, check your PIN and keep you signed in on the devices you link;
- to deliver your messages, show read status and send push notifications;
- to run your agent: generate its replies, carry out the tasks you give it, look things up and propose purchases;
- to enforce purchase approvals, spending caps, rate limits and daily usage limits, and to keep the activity log you can review;
- to prevent and investigate fraud, abuse, spam and security incidents, and to act on reports and blocks;
- to answer your questions and feedback, fix bugs and improve Unomaas;
- to add you to a Play closed test or TestFlight when you ask to join the beta; and
- to comply with the law and enforce our Terms.
We don’t sell your personal information, we don’t share it for targeted advertising, and we don’t use your chats or agent activity to train AI models.
4. AI processing with Amazon Bedrock
Your agent is powered by Anthropic’s Claude models, which we access through Amazon Bedrock, a service of Amazon Web Services (AWS). When your agent replies or works on a task, we send AWS the text it needs: your instructions, the recent messages of the chat it is answering in, your “about me” notes, up to eight of your saved memory notes when memory is on, its owner’s name and voice settings, and the results of the tools it used. If the message being answered quotes another message in that same chat, the quoted text is included too. Reactions are not sent. Those memory notes are sent only with your agent’s own calls, not with the other person’s agent. A voice-note transcript is included in that text when one exists. The voice audio itself is not sent to AWS. A photo in the chat may be sent as an image so the agent can see it. The model’s response comes back to our servers and is stored as your agent’s message or as a step in your activity log.
According to AWS’s documentation for Amazon Bedrock, AWS does not use the prompts and responses sent through Bedrock to train its models and does not share them with model providers, so Anthropic does not get access to them. AWS may run automated checks to detect abuse of its service. We do not use your content to train any AI models ourselves.
AI output can be wrong. Please don’t put information into Unomaas that you wouldn’t want processed this way, such as passwords, government ID numbers, full card numbers or health details.
5. Purchases and merchants
- Your approval comes first. Your agent can only propose a purchase. A proposal shows the item, price and merchant, and nothing is bought unless you approve it with your PIN and it fits within your spending cap. A proposal you don’t act on expires after 30 minutes.
- What we keep. We record the proposal, your decision, the result and the related steps in your activity log.
- What merchants receive. When a purchase you approved is placed, the merchant receives the order details needed to complete it. Merchants handle your purchase under their own terms and privacy policies. During early access, purchases run only with a test merchant and no real payments are made.
- Browsing. When your agent browses a website, it loads the page in a separate, throwaway browser container on our server that is deleted after each page load. Websites see a request from our server, not from your device. Web search is currently turned off; if we turn it on, your agent’s search queries will be sent to the search provider we use.
Calendar free/busy
You can let your agent see when you are busy so it can suggest times in a one-to-one chat. This is off until you turn it on in Settings, and you can turn it off again at any time.
- What leaves the phone. The iPhone or Android app reads the calendars already on that phone and uploads only busy intervals: a start time and an end time. Event titles, locations, notes, attendees, and the names of your calendars are not uploaded. The web preview cannot read a calendar.
- Who can use those times. Your agent, and the other person’s agent in a chat you are both in, can use the intervals to find gaps that look open. They do not receive event names or details. The model that writes ordinary chat replies is not given your calendar.
- Nothing is booked without both of you. A suggested time becomes a confirmation card for each person. The event is added only after both of you confirm the same time with your PIN. Each phone then writes that new event into its own calendar. The new event’s title is the meeting you were asked about (for example “Lunch”), not the name of something already on your calendar.
- Turning it off. Switching sharing off deletes the busy intervals we stored for you. Deleting your account deletes them too. Intervals also expire on their own about two days after they end. Confirmed meetings you already added on the phone stay in that phone’s calendar until you delete them there.
- What we do not do. We do not sign in to Google Calendar or iCloud on the server. That path is off. It would need a Google OAuth client (client id, client secret, and redirect URI) with the Calendar API enabled. Apple does not offer a supported server calendar API for this, and we will not ask for an app-specific password.
6. Who we share it with
We share information only as described here. We use these service providers to run Unomaas, and they may process your information only on our behalf:
| Provider | What they do for us | What they handle |
|---|---|---|
| Amazon Web Services (AWS) | Hosts our servers (Amazon Lightsail) and runs the AI model (Amazon Bedrock) | All service data on our servers; the text sent to the AI model |
| MongoDB Atlas | Our database, hosted on AWS | Account, chat, agent, task, purchase and log data |
| Twilio | Sends and checks the sign-in codes we text you (Twilio Verify) | Your phone number and the verification code |
| Expo, and Apple or Google | Build and distribute our apps and deliver push notifications for the phone app | Push tokens, plus the notification title and a preview of the message (up to about 160 characters) |
| Your browser’s push service (Apple, Google, or Mozilla) | Deliver web notifications you turn on in the browser | The browser’s push address, and a notification that names who it is from. Not the message text, a photo, a transcript, or purchase details |
| Let’s Encrypt | Issues the certificates that keep connections to Unomaas encrypted | No personal information |
We also share information:
- With the other person in a chat, who sees your display name, your agent’s name and the messages in that chat;
- With Google or Apple, if you join the beta, who receive the Google account email or Apple ID email you gave us so they can add you to the Play closed test or TestFlight. We do not email you ourselves;
- With merchants, for purchases you approve, as described above;
- For legal reasons, if we believe in good faith it is required by law or legal process, or needed to protect the rights, safety or property of our users, the public or Unomaas;
- In a business transfer, if Unomaas is reorganized, merged or sold, in which case this policy will continue to apply to your information; and
- With your consent, or at your direction.
7. How long we keep it
| Information | How long |
|---|---|
| Account details, agent settings, messages, photos, voice messages, voice transcripts, reactions, quote replies, agent memory notes, tasks, purchase records, spending caps, usage records, reports and blocks | Until you delete your account, or until we close it. You can delete memory notes sooner, one by one or all at once, in Settings. Removing a reaction deletes that reaction right away |
| Agent activity log (tool steps, approvals, policy decisions) | 180 days, then deleted automatically. Deleted sooner if you delete your account |
| Purchase proposals you don’t act on | Expire after 30 minutes; the expired record stays with your account until you delete it |
| Free/busy intervals, if you turn calendar sharing on | Until you turn sharing off or delete your account. Each interval is also deleted about two days after it ends |
| Meeting suggestions waiting for both people to confirm | Expire after 30 minutes if you don’t both confirm. Nothing is added to a calendar when they expire |
| Sign-in codes | Expire after 10 minutes and are then deleted automatically |
| Sign-in sessions on your phone and linked browsers | Expire 30 days after you sign in or link the browser, then deleted automatically. Removed right away when you sign out or unlink a browser |
| Browser push subscription, if you turn web notifications on | Until you turn notifications off, sign out of that browser, unlink that device, or delete your account |
| QR linking requests (including the requesting browser’s IP address) | Valid for 2 minutes and deleted about 1 hour after they expire |
| Rate-limit counters | Deleted automatically when their time window ends (at most 24 hours) |
| Web server logs (IP address, page requested, browser type) | Rotated daily and kept for 14 days |
| Website feedback notes | As long as we need them to fix the issue or answer you. Ask us and we’ll delete yours |
| Beta sign-up (store email, optional first name, 18+ confirmation) | Until you remove it with the same email on Join the beta, you email us, or we delete the list after the test. Not used for an account |
| Database backups | Deleted data can remain in our database provider’s encrypted backups until those backups are replaced in the normal backup cycle |
We may keep specific information longer if the law requires it or if we need it to resolve a dispute, investigate abuse or enforce our Terms.
8. Security
We use measures that fit a small service handling personal messages:
- all connections to Unomaas use HTTPS (TLS) encryption, and our database is reachable only from our own server;
- PINs and sign-in codes are stored only as hashes, sessions expire, and linking codes are single-use and expire in minutes;
- sign-in codes, PIN attempts and linking requests are rate limited;
- purchases need your PIN approval and are blocked above your spending cap;
- your agent’s web browsing runs in an isolated, throwaway container with strict resource and time limits; and
- the agent activity log is protected against tampering with a hash chain.
No system is perfectly secure. Protect your phone and your PIN, and tell us right away if you think someone has accessed your account. If we learn of a breach that affects your personal information, we will notify you as the law requires.
9. Your choices and rights
- Delete your account. You can delete your account in the app, or email zuhairahmed@gmail.com from any address and tell us the phone number on the account; we may text that number to confirm the request is yours. Deleting your account permanently removes your profile, your agent, your agent memory notes, your sessions and linked devices, your tasks, activity log, approvals and purchase records, your push tokens, your browser push subscriptions, your reactions, and every chat you are in, including all messages, photos, voice messages, voice transcripts, and reactions in those chats. Because a chat is shared, this also removes that chat and its messages for the other person.
- Agent memory. Settings → Memory lists what your agent remembers. You can delete one note, delete them all, or turn memory off. You can also tell your agent in a chat to forget something. A copy of your information, if you ask us for one, includes these notes.
- Access or correct your information. You can see and change your display name, email, agent settings and spending caps in the app, and review your activity log there. To get a copy of your information, or to delete specific data such as a feedback note, email us.
- Beta sign-up. On Join the beta, use Remove my email and enter the same Google account or Apple ID. We delete that signup if it is on the list, and we do not tell you whether it was, so someone else cannot check. This does not delete an Unomaas account. Sending the form again with the same email updates the signup instead of adding a second one. You can also email zuhairahmed@gmail.com.
- Control your agent. You can turn away mode on or off, turn memory on or off, edit or clear your “about me” notes, cancel tasks, deny any purchase and lower your spending cap at any time.
- Calendar sharing. You can turn “Share when I’m busy” on or off in Settings. Off deletes the free/busy times we stored. You can also deny any suggested time. Both people have to confirm before an event is added.
- Devices and notifications. You can unlink any browser from your phone, and turn off push notifications in your device settings. On the web app you can turn notifications off in Settings, which deletes the browser push subscription we stored.
- Block and report. You can block anyone, which stops them from messaging you, and report messages or people to us.
We respond to requests within 45 days. Depending on where you live, you may have additional rights under local law; we honor applicable requests from users anywhere. You won’t be treated differently for exercising your rights.
10. California privacy rights
If you live in California, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to:
- know what personal information we collect, use and disclose, and get a copy of it;
- ask us to delete it;
- ask us to correct inaccurate information;
- opt out of the sale or sharing of personal information (we don’t sell personal information or share it for cross-context behavioral advertising, and we haven’t in the past 12 months);
- limit the use of sensitive personal information (we use your sign-in details, such as your phone number and PIN, only to provide and secure Unomaas, which the law allows without an opt-out); and
- not be discriminated against for using these rights.
In the past 12 months we have collected these categories of personal information, for the purposes in section 3 and from you, your devices and the people you chat with: identifiers (phone number, optional email, device identifier, IP address, and, if you join the beta, a Google account email and/or an Apple ID email); customer records (display name, and an optional first name on a beta signup); commercial information (purchase proposals, approvals and records); internet or network activity (sessions, linked browsers, server logs, agent activity); and the content of your messages, photos, voice recordings, voice transcripts, agent notes, agent memory, and tasks. We disclose these for business purposes only to the service providers and parties described in section 6, and we keep them for the periods in section 7. A beta email is not sold and is not used for advertising. We give it to Google Play Console or App Store Connect only so that company can invite you to the test you asked for. Voice audio is transcribed on our own server and is not sent to a transcription company. Agent memory notes are sent to Amazon Bedrock only as part of your own agent’s prompt, and are not given to the other person or their agent.
To make a request, email zuhairahmed@gmail.com. We will verify your request by confirming control of the phone number on your account. You can use an authorized agent, who must show us your signed permission; we may still ask you to verify your identity directly. California’s “Shine the Light” law also lets you ask about disclosures for direct marketing; we don’t make any.
11. Children
Unomaas is not directed to anyone under 18, and we don’t knowingly collect personal information from anyone under 18. You must be 18 or older, as our Terms require, and the app asks every new user to confirm they are 18 or older before creating an account. The beta sign-up on this website asks for the same confirmation and does not accept a signup without it. If we learn that a user is under 18, we will delete the account and its data, including a beta signup tied to them. Email us if you believe someone under 18 has given us personal information.
12. Where data is processed
Unomaas is run from the United States. Our servers, our database and the AI model run in AWS data centers in the United States. If you use Unomaas from outside the US, your information will be transferred to and processed in the US, where privacy laws may differ from those where you live.
13. Changes to this policy
We may update this policy as Unomaas grows, for example if we add new features or service providers. When we do, we will post the new version on this page and change the effective date at the top. If a change is significant, we will give you reasonable notice, for example in the app, before it takes effect.
14. Contact
Questions or requests about your privacy? Email zuhairahmed@gmail.com or send a note through the feedback form.
Unomaas, operated by Zuhair Ahmed
Fremont, California, USA