Privacy

Last updated 22 September 2026.

unsav•d is built by two people. This page says what we keep, where it goes and how to get rid of it, in the plainest words we can manage. It is not legal advice, and we are not lawyers.

Who we are

unsav•d is run by Ben Hofferber and Yeji, in Toronto, Canada. We are the ones responsible for what this page describes, under Canada’s privacy law, PIPEDA, and under the GDPR if you are in the European Union or the United Kingdom. Write to the address at the foot of this page for anything about it.

What we keep

Your email address. It is how you sign in and how we reach you.

Your name, where you are, and what you said you were hoping to get out of unsav•d. You give us those on the early-access form and confirm them on the welcome step the first time you sign in.

Whether you ticked the box that says we may write to you, and when you ticked it.

The reels you save: the Instagram link, the caption, the name of whoever posted it, and a copy of the cover image. We keep our own copy of the cover because Instagram's image links expire within days, and a library of blank squares is no library.

A one-line summary, a type and a few tags, written by a language model from the caption and the cover.

Your own words about a reel: the categories you make, the titles you give and the notes you write.

A record of each sign-in session, so you stay signed in between visits.

A token for each device you let send reels in, which is the browser extension and the phone shortcut. We store a hash of it rather than the token itself, so nothing in the database can send on your behalf.

Anything you file on the requests list inside the app.

Why we keep it

Each of those is kept for one of five reasons, and nothing is kept for a reason not on this list.

  • To run your library: the reels, the summaries and tags, your categories, titles and notes, and the device tokens that let reels in.
  • To sign you in and keep you signed in: your email address and the session records.
  • To let you in and to reach you: your name, where you are, what you hoped to get out of it, and the newsletter box.
  • To make it better: the analytics and recordings described below, which show us where it is hard to use.
  • To keep it safe and paid for: the request logs and the daily ceilings.

We rely on your agreement for the newsletter and for the recordings, on the arrangement between us for the rest of running the app, and on our own interest in keeping it working for the logs and limits. We do not sell any of it, and we do not use it to advertise to you or to anyone else.

How reels get in

Two ways, and you start both of them.

The browser extension reads the link and the cover of each reel as you scroll past it on your own Instagram saved page, and sends those to your library. It never scrolls for you. There are no timers and no page fetches: it sees what passes under your own scrolling and nothing else.

The iPhone shortcut and the share sheet send one link at a time, when you share a reel to unsav•d.

Nothing is read from Instagram beyond the reels you save. We hold no Instagram login of yours and have no connection to your account.

What we send elsewhere

The caption and the cover image of each reel go to a language model, through OpenRouter, which writes the summary and the tags. Nothing about you goes with them: the model is shown the reel, not who saved it. What the model providers behind OpenRouter do with what they are sent is covered by OpenRouter's own terms.

The rest of the list is short.

  • Railway hosts the app and the database, in the United States.
  • Resend sends the two emails we send: your sign-in code and your invite.
  • OpenRouter routes the model calls described above.
  • Vercel hosts this website.
  • PostHog gets analytics from this website. It records which pages you looked at and when you left them, and the clicks and form submissions its browser library records by default. Each of those carries what any web request carries: your rough location from your address, your browser and the page you came from. Until you fill the early-access form you are anonymous to it and no profile is made for you. Sending the form adds one event, carrying your email address, name and location, whether the app stored the sign-up, and any campaign values in the link you arrived on. It does not carry what you wrote in the last box, only whether you wrote anything.

The app reports to PostHog too, so we can see where it is hard to use. Inside your library that is: which pages you open and when you leave them; a recording of your session, which is what was on your screen and where you tapped, with anything you type masked out; and one event per thing you do to your library, such as saving reels, filing, ignoring or deleting them, and the enrichment finishing. Those events carry counts and kinds only: how many reels, which action, whether the model answered. They never carry a caption, a link, a search you typed, your address or your notes. All of it is filed under your account id, the same id your library rows carry, so we can follow one person’s path and not just a crowd. A recording does show what was on your screen, and in a library that is the reels you saved.

Signing in

You sign in with a six-digit code we email you. There is no password, so there is no password of yours for us to keep or for anyone to take.

Email

The sign-in code and the invite go out because you asked to sign in or because we let you in. Anything else, meaning the occasional note about what we have been building, goes out only if you ticked the newsletter box.

To stop it, untick that box on your details page in the app, or reply to any message and say so. We will take you off.

Leaving, and taking your library with you

Both live on the settings page in the app.

Export hands you a JSON file of what we hold about you: your details, your saved reels with their summaries and tags, your categories, your titles and your notes.

Delete asks you to type a phrase to confirm and then to enter a code we email you, because it cannot be undone. It removes your rows: your account, your details, your library, your categories, your notes, your sessions and your device tokens. A reel nobody else is keeping goes with them, and so does its cover.

Logs and limits

The server keeps request logs for a limited period on Railway. They are how we see what broke and how we notice somebody flooding the app. There are daily ceilings on how many reels one account can add and how many summaries it can ask for, which is what keeps a bad day from becoming an expensive one.

Cookies

The app sets one cookie of its own, which is your sign-in session. It is what keeps you signed in between visits and it does nothing else. PostHog sets its own, on this website and in the app, to tell one visit from the next and to tie a recording to a session. There are no advertising cookies and nothing from an ad network anywhere on either.

Where it lives

The app, the database and the cover images are on Railway in the United States, and the analytics are in PostHog’s United States region. The emails go through Resend, and this website is on Vercel, both of which also run there. So what we keep about you is stored and processed in the United States, whatever country you are in, and is subject to the laws there while it is.

How long we keep it

  • Your library, your details and your account: until you delete them, or ask us to.
  • A sign-in code: ten minutes, or until it is used. A sign-in session: about a week from your last visit, and then you sign in again.
  • Request logs on the server: up to a month, and then they are gone.
  • Analytics events and session recordings: for the period PostHog keeps them, which is longer for events than for recordings. Ask, and we remove what PostHog holds under your account as well.
  • Your place on the early-access list: until you ask to be taken off it. Deleting your account leaves the list entry but takes back the approval, so nobody can walk back in on your address without us letting them.

What you can ask of us

You can see what we hold about you, correct it, take a copy of it, or have it deleted. Most of that you can do yourself: your details page and the settings page in the app are the correction, the export and the delete. Whatever you cannot do from there, write to us and we will do it, and we will answer within a month. You can withdraw your agreement to the newsletter at any time by unticking the box, and to the recordings by asking us to turn them off for your account.

If you think we have handled something badly and we have not put it right, you can complain to the Office of the Privacy Commissioner of Canada, or, if you are in Europe or the United Kingdom, to the data protection authority where you live.

Age

You have to be at least 16 to use unsav•d. If we learn that somebody younger has an account, we will delete it and what came with it.

When this page changes

The date at the top moves whenever we change this page. A change that matters, meaning something new we keep or somewhere new it goes, we will also put in front of you: a note in the app, or an email if you are on the list for those. A change that only reads better will not wake anyone.

Asking us something

Write to hello@unsavd.com. If you want to know what we hold, or want it gone and would rather we did it ourselves, that is the address.

unsav•d is a small personal project, run by two people in the evenings. This page says what the app does rather than what a lawyer would have us say, and it is not legal advice.