LEGAL

Privacy Policy

Last updated: July 1, 2026

1. Introduction

Unbound Security, Inc. ("the Company," "we," "us," or "our") operates the website getnubound.com (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to information we collect through the Service and through direct communications with you.

Unbound Security, Inc. develops and operates an inline data-loss prevention product designed to intercept and classify content that employees submit to generative AI tools such as ChatGPT, GitHub Copilot, Claude, and Gemini, catching secrets, customer records, and proprietary source files before they leave the organization. This policy covers information collected through the getnubound.com marketing website and inquiry flows -- not the processing that the Company's browser extension and classification API perform on behalf of enterprise customers under separate service agreements.

We are based at 530 Lytton Avenue, Suite 200, Palo Alto, CA 94301 and can be reached at [email protected].

2. Information We Collect

2.1 Information You Provide

We collect information you submit directly, including:

  • Contact details (name, work email, phone) when you fill out the demo request or contact form on getnubound.com;
  • Company information you choose to share (employer name, role, employee count bracket, and the AI-tool context you describe);
  • The content of any messages you send us at [email protected].

2.2 Information Collected Automatically

When you visit getnubound.com, we automatically collect limited technical information:

  • IP address and approximate location (city/region level);
  • Browser type, operating system, device class;
  • Pages visited, referring URLs, time on page;
  • Cookie and similar identifiers (see Section 5).

We do not collect or process prompt content, employee data, or any payload handled by the Unbound browser extension or classification API through this website.

2.3 We Do Not Knowingly Collect Children's Data

getnubound.com is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.

3. How We Use Information

We use the information we collect to:

  • Respond to demo requests and product inquiries from security teams and IT leaders evaluating Unbound;
  • Operate, maintain, and improve getnubound.com;
  • Send service updates and, where required, obtain your consent before marketing communications;
  • Understand which AI-tool risk scenarios resonate with our audience so we can improve documentation, blog content, and product positioning;
  • Detect, investigate, and prevent fraud or abuse;
  • Comply with legal obligations.

We do not sell personal information for monetary value. We do not use visitor data to train AI or machine learning models. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see your state's section below.

4. Sharing of Information

We share personal information only with:

  • Service providers acting on our behalf (for example, hosting infrastructure, transactional email delivery, and self-hosted web analytics) under contractual confidentiality terms;
  • Authorities, when required by law or to protect rights, safety, or property;
  • A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy.

We do not sell personal information to third parties. We do not share inquiry or contact data with any advertising network or data broker.

5. Cookies and Tracking

We use cookies and similar technologies to operate the site, remember preferences, and measure usage. For details and choices, see our Cookie Notice.

6. Data Retention

We retain personal information only as long as needed for the purposes described in this Policy, to comply with legal or accounting obligations, and to resolve disputes. Demo-request and inquiry records are retained for 24 months from last contact; inactive marketing-list contacts are purged after 24 months. Server access logs are retained 90 days and then aggregated. Information you ask us to delete is removed within 45 days subject to legal exceptions.

7. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including TLS encryption in transit, restricted-access databases, and least-privilege access controls. No system is perfectly secure; we cannot guarantee absolute security. Because Unbound is an AI-DLP security company, we treat the security of our own infrastructure with the same rigor we apply to the product.

8. Your General Rights

Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.

9. California Residents (CCPA / CPRA)

Under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"), California residents have specific rights regarding personal information collected about them. This section supplements the rest of the Policy.

9.1 Categories We Collect

In the past 12 months, we have collected the following categories of personal information defined under Cal. Civ. Code §1798.140: identifiers (name, work email, IP address); commercial information (service inquiries and demo requests); internet activity (browsing on getnubound.com); and inferences drawn from the above for service-improvement purposes. We do not collect sensitive personal information as defined under Cal. Civ. Code §1798.140(ae) -- such as government ID, precise geolocation, financial account credentials, health information, or biometric data -- through the getnubound.com website.

9.2 Sources, Purposes, Disclosure

We obtain this information from you directly and through automatic site instrumentation. We use it to operate and improve the Service, respond to security-team inquiries about Unbound's inline AI-DLP capabilities, communicate with you, and meet legal obligations. We disclose it only to service providers under written contract and to legal authorities where required.

9.3 Your CCPA / CPRA Rights

  • Right to Know: request the categories and specific pieces of personal information we have collected about you in the past 12 months.
  • Right to Delete: request deletion of personal information we collected from you, subject to legal exceptions.
  • Right to Correct: request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: we do not sell personal information; we do not "share" it for cross-context behavioral advertising as defined under CPRA.
  • Right to Limit Use of Sensitive PI: we do not use sensitive personal information for purposes beyond those permitted without authorization.
  • Right to Non-Discrimination: we will not deny services, charge different prices, or provide a different level of service because you exercised a right.

9.4 How to Exercise

Submit a verifiable request by emailing [email protected] with the subject line "California Privacy Request." Include enough detail for us to verify you are the person whose information is the subject of the request. We respond within 45 days, with a possible 45-day extension for which we will notify you.

9.5 Authorized Agents

You may designate an authorized agent to make a request on your behalf. The agent must provide proof of authorization; we may also require you to verify your identity directly.

9.6 "Shine the Light"

California Civil Code §1798.83 entitles California residents to request information regarding our disclosure of personal information to third parties for direct marketing. We do not disclose personal information for third-party direct marketing.

9.7 Do Not Track and Global Privacy Control

Under the California Online Privacy Protection Act (Cal. Bus. & Prof. Code §22575), we disclose how we respond to "Do Not Track" (DNT) browser signals. Because there is no common industry standard for interpreting DNT signals, we do not currently respond differently to them. We do not authorize third parties to collect personally identifiable information about your activity across different websites when you use the Service. We honor an opt-out preference signal sent by a platform or browser that complies with the CPRA, such as the Global Privacy Control (GPC); when we detect a GPC signal, we treat it as a valid request to opt out of the sale or sharing of personal information for that browser or device.

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.

11. Contact

Questions, requests, or complaints can be sent to:

Unbound Security, Inc.
530 Lytton Avenue, Suite 200, Palo Alto, CA 94301
Email: [email protected]
Phone: +1 (650) 381-0148