Scope and operator status
This notice describes the code in the UnlistFast repository as of the last-updated date. The repository does not identify a company or other legal operator for a public deployment. It therefore cannot describe the separate practices of an unknown website host, CDN, or service operator.
There are no project-run accounts, paid plans, hosted vaults, or customer support system in the current release.
The marketing site
The site code has no account form, payment form, analytics SDK, advertising pixel, or application-set cookie. The theme control may store unlisted-theme in your browser’s local storage; it contains only the choice light or dark. Choosing the automatic theme removes it, and browser storage controls can remove it at any time.
Loading any public website necessarily sends network information to its host. A host or CDN may log an IP address, user agent, requested URL, time, and security events even when the site application has no analytics. The providers and retention period depend on the eventual deployment and are not yet known.
The project code does not use browser signals such as Do Not Track or Global Privacy Control to change behavior because it contains no cross-site behavioral tracking. An eventual host must separately disclose its own practices.
References to OpenAI, ChatGPT, Anthropic, Claude, and open-weight models are editorial examples. The marketing site does not collect or send profile data to those providers or use them as embedded services.
The local vault
The self-hosted app stores the profile and contact information you enter, residency choices, broker listings and URLs, jobs, letters, redacted activity events, settings, screenshots, and evidence hashes in a local SQLite vault and evidence directory. The project does not operate an account backend or telemetry collector that receives a copy.
The database and evidence directory use owner-only filesystem permissions. They are not encrypted by UnlistFast. A device administrator, malware running as your user, another program you grant access, or an independent backup may still expose them.
The current UnlistFast project does not train models on vault profiles, evidence, or request history. It does not operate a telemetry or training-data collector for those records.
Current outbound-data boundaries
- Dry agent. The current CLI only accepts the dry driver. It does not visit broker pages, submit requests, run verification visits, or call an AI provider.
UNLISTED_DRIVER=liveis rejected at startup. - Dormant adapters. Deterministic Playwright code and a read-only Anthropic extraction adapter remain in the source tree, but neither is an activation path in the current build. Configuring an Anthropic API key alone does not send a page or profile to Anthropic.
- Your manual transfers. A generated letter stays local until you send it using a separate service. If you open a broker page or submit a request yourself, that recipient can receive connection metadata and the profile, listing, or request values you choose to provide.
A future reviewed live release could create new broker or model provider transfers and would require this notice to change first. For the dormant Anthropic adapter, review Anthropic’s current privacy policy and commercial terms for the API before enabling it.
Retention and deletion
UnlistFast does not automatically prune local activity events, letters, or screenshots. They stay in the local vault until you use the app’s Delete local vault control or remove a separately exported copy yourself.
The deletion control refuses to run while an agent job is active, then removes the database, SQLite journal files, the project migration backup, and the marked evidence directory. It cannot recall a request already sent, delete a recipient’s records, clear browser or host logs, or erase an independent device or cloud backup.
Your choices and rights
Because the current app is self-hosted, you control the local vault: you can inspect it, stop using it, delete it, and remove exports or backups you control. Requests already delivered to a broker or mail provider through your own action must be handled with that recipient.
Privacy rights depend on the operator, processing, location, and law. No project operator or privacy contact has been designated, so this repository cannot currently receive a rights request for an unidentified public deployment. That deployment must name its operator and publish a working rights-request channel before launch.
Changes to this notice
The effective and last-updated dates will change when the project’s data flows or this notice materially change. A public operator must also state how it will announce material changes and retain prior versions where the law or its commitments require that.
Reference points: California Business and Professions Code § 22575 and the official GDPR text. Citation does not mean either law necessarily applies to a particular deployment.