Unfed Space Privacy Policy

Last updated: 21 September 2026


1. Controller and contact

The controller of your personal data is Twój Wuja, a sole proprietorship entered in the Polish CEIDG register under the business name Twój Wuja Jakub Sroka, ul. Marszałkowska 58, 00-545 Warszawa, Poland, NIP 7511744403, REGON 387212660 (we, Unfed).

For anything concerning personal data, including exercising your rights, write to support@unfed.space. We have not appointed a data protection officer. Personal-data matters are handled by the controller personally: the system described in § 8 may prepare a draft reply, but a person makes the decision and sends the reply.

This document fulfils the information duties of Articles 13 and 14 GDPR and the requirements of the Polish Act on Providing Services by Electronic Means and the Electronic Communications Law.

2. Who this policy is for

Unfed processes the data of four groups of people. Find yours:

Who you are Sections that apply to you
A. An artist with an Unfed account (or in the process of creating one) § 3 to § 6, § 9 to § 17
B. A visitor of an artist's page (name.unfed.space) or of unfed.space § 5, § 11 to § 17
C. A waitlist subscriber (form on unfed.space) § 7, § 11 to § 17
D. Someone who wrote to us (support@unfed.space) or reported content § 8, § 11 to § 17
A person visible in a photo an artist published § 5.6, § 14

3. Artists: what data, why and on what basis

3.1. Data we process

Data Source Notes
Instagram profile: account identifier, username, display name, bio, profile picture, follower count, post count Instagram's interface (API), after your authorisation Refreshed at every sync
Posts: photos, videos, captions, dates, links to the posts Instagram's interface We store our own copies of the files (several sizes, WebP format, video poster frames) so your Space does not depend on Instagram being available
Instagram access token Instagram, at authorisation Lets us read your account on your behalf. Encrypted at rest, never logged, displayed or shared. Refreshed automatically; after three failed refreshes we email you to reconnect
Email address and its confirmation status From you, during setup Recovery route to your account (§ 4 of the Terms)
Space configuration: address, craft, city, country, language, specialisations, booking-button settings, theme, sections, AI setting From you, partly proposed automatically from your bio (§ 6)
Content added in Unfed: manually added works, work titles and descriptions (including ones you edited), FAQ questions and answers, links, shop items, announcements From you
Manually added works: photo and video files you upload in the dashboard From you Limits: 10 MB per photo, 60 MB per video
Billing data: Paddle customer and subscription identifiers, plan, subscription status, payment-event identifiers Paddle, via notifications We do not receive card details or your billing address; Paddle holds them (§ 9)
Invite programme: who invited you, whom you invited, invitation status, granted Premium days and their expiry From your use § 10
Your Space's stats: aggregate numbers (visits, sources, AI-crawler visits, booking taps, most-viewed works) Computed nightly from the data described in § 5 Contain no data about individual visitors
Dashboard usage: which dashboard screens you open, the actions you take, errors you run into, the outcome of setup and Space builds, invite-programme steps; together with your account identifier, Space address, plan and language Generated by us when you use the dashboard Stored in PostHog in the European Union. No cookie and no browser script: our server sends the events. You can object (§ 3.2)
Communication preferences: weekly-summary opt-out, product-news consent (if you give it) From you
Sessions and sign-in tokens Generated by us Session valid 30 days; sign-in link valid 15 minutes, single-use, stored as a hash
Technical data: IP address, request headers, request identifiers in server logs From your browser Infrastructure logs (Cloudflare), kept briefly, for security and diagnostics
Sync and job state: last-sync dates, errors, Space build progress Generated by us

3.2. Purposes and legal bases

Purpose Legal basis (GDPR)
Creating and running your account, building your Space from your posts, making it publicly available, syncing with Instagram, the dashboard and editing, the booking button, stats, the invite programme, messages necessary for the Service (email confirmation, sign-in link, live notice, reconnect request) Contract: Art. 6(1)(b)
Preparing titles, descriptions and draft FAQ answers with AI (§ 6) Contract: Art. 6(1)(b); only while you have not turned AI drafting off for your Space (work descriptions) or when you trigger generation yourself (FAQ)
Handling payments and plans (passing your identifier to Paddle, receiving subscription status) Contract: Art. 6(1)(b); legal obligation for accounting records: Art. 6(1)(c)
Weekly Space summary by email Legitimate interest: Art. 6(1)(f) (keeping you informed about a service you use); you can opt out at any time in the dashboard or with the link in the message
Understanding how the dashboard is used, to run and improve the Service (the "Dashboard usage" data in § 3.1) Legitimate interest: Art. 6(1)(f). You can object at any time by writing to support@unfed.space: from then on we stop recording your dashboard usage and delete what we had already recorded
News about Unfed Consent: Art. 6(1)(a), together with consent to electronic marketing communication (Polish Electronic Communications Law). Consent is voluntary, never pre-ticked, and can be withdrawn at any time
Security, abuse prevention, error diagnostics, enforcing the Terms (logs, token encryption, usage limits, detecting abuse of the invite programme) Legitimate interest: Art. 6(1)(f)
Handling complaints, notices and claims Legitimate interest: Art. 6(1)(f); legal obligations under the Consumer Rights Act and the Digital Services Act: Art. 6(1)(c)

3.3. Voluntariness

Providing data is voluntary, but connecting your Instagram account and providing an email address are necessary to use Unfed. Without them we cannot build or maintain your Space.

3.4. Your Space is public

Everything you publish in your Space (works, bio, city, specialisations, FAQ, links, shop, announcements) is open, indexed by search engines and read by the crawlers of AI assistants. That is the purpose of the Service. We do not actively hand this content to search engines or AI providers; we make it publicly available the way any website is, and we notify search engines of new addresses (the IndexNow protocol, a sitemap). Unpublishing your Space stops public access, but copies previously saved by search engines or other services disappear at their pace, not ours.

4. Cookies

We use only cookies that are necessary for the Service to work or to carry out an action you asked for. We use no advertising or cross-site tracking cookies, and for that reason we show no consent banner.

Name Purpose Lifetime Where
unfed_session Keeps you signed in to the dashboard 30 days app.unfed.space
unfed_oauth_state Protects Instagram sign-in against forgery (CSRF) 10 minutes app.unfed.space
ui_lang Remembers your chosen dashboard language (PL/EN) 12 months app.unfed.space
unfed_ref Remembers whose invite link you arrived through, so the invitation is counted when you create an account (§ 10) 30 days .unfed.space

All are first-party cookies, marked HttpOnly and Secure (except ui_lang). You can delete them in your browser; deleting unfed_session signs you out. Artist pages (name.unfed.space) set no cookies. Our infrastructure provider (Cloudflare) may set a cookie needed for attack protection; it is strictly necessary and exempt from consent.

5. Visitors of artist pages and unfed.space

  1. No cookies, no profiling. We collect visit statistics with PostHog in a mode that uses no cookies and writes nothing to your browser's storage. Your IP address is neither sent nor stored (disabled in the script), we do not record sessions, we do not track you across sites, and we do not link visits: every visit is a new, anonymous session to us.
  2. What we record: the page view (an address in the unfed.space domain), the page type, how you arrived (search engine, AI assistant, Instagram, direct) based on the referrer header, campaign parameters in the address (UTM), scroll depth, a tap on the booking button or an outbound link, and your browser language. This data is stored on PostHog servers in the European Union.
  3. Crawlers and AI assistants. At the network edge we recognise, by client name (user agent), visits by search-engine and AI-assistant crawlers and record them as events (crawler name, page address). This does not concern people.
  4. Infrastructure logs. Cloudflare, which delivers the pages, processes the IP address and request headers for security, attack protection and content delivery. Logs are kept briefly.
  5. What the artist sees: only aggregate numbers computed once a day (how many people visited the Space, from which sources, how many booking taps, which works were viewed most, which AI crawlers read the pages). The artist sees no data about any individual person.
  6. If you are in a photo. The artist who published the photos is responsible for publishing them; the artist is the controller of the decision to publish your likeness, and the artist is who to ask about its basis. We store and display the photos as a hosting provider on the artist's instructions. If you believe your likeness was published without consent, write to the artist (contact details on their Space) or to us at support@unfed.space; we will handle the notice under § 11 of the Terms and, where justified, hide the photo.
  7. Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in measuring whether artist pages are visited and in the security of the infrastructure. We assessed that the way we measure (no cookies, no IP, no linking of visits, no recording) does not override your rights and freedoms. You can object (§ 15); in practice the simplest way is to block analytics scripts in your browser, which we respect. If you are an artist and mean the record of your dashboard usage, your objection route is in § 3.2.

6. How we use AI

  1. Provider. For text generation and image analysis we use Anthropic's models (Anthropic, PBC, USA) through its business API. Under the terms of that API, Anthropic does not use submitted data to train its models and keeps it only for a limited time for abuse detection, after which it is deleted.
  2. What goes to Anthropic, and when:
    • When you connect your account: the text of your Instagram bio and name, to propose your craft, city, language and specialisations, which you then confirm or correct. This single step runs regardless of the AI setting, because you choose the setting a moment later; it does not include photos.
    • When your Space is built and synced (only while AI drafting is on): the photo of a work (in a reduced size) and its caption, to prepare a title and a description. This covers up to your 300 newest works; older ones get a template title. On Free it covers only the 6 visible works.
    • When you tap "Generate" or "Regenerate": the same for a single work, or your own answer to an FAQ question, from which a draft answer is written.
    • Messages to support@ (§ 8).
  3. What we do not do. We do not profile you, do not evaluate your work, and do not make decisions about you with legal or similarly significant effects solely by automated means (Art. 22 GDPR). AI prepares text proposals that you edit and publish as your own.
  4. Turning it off. You can turn AI drafting of descriptions off during setup and later in the dashboard. Once off, photos are not sent to Anthropic; work pages use your Instagram caption and a template title.

7. Waitlist (unfed.space)

If you joined the waitlist: we process your email address, chosen craft, page language, the date and source of signup, and the text and date of your marketing consent. The basis is consent (Art. 6(1)(a) GDPR and the Polish Electronic Communications Law) to messages about Unfed's launch, early access and news. The data is held by Kit (Kit.com, USA). You withdraw consent with the link in any message. We delete the data when you withdraw consent, and at the latest 12 months after Unfed launches if you have not become a user. If you become a user, the waitlist consent does not carry over to your account; news messages on your account are sent only with separate consent (§ 3.2).

8. Correspondence and notices

  1. support@unfed.space is Unfed's single contact address: support, legal matters, personal data and content notices. Messages arrive in a Google Workspace mailbox and are handled by a system in which: (a) an automation (Make) creates a Trello card from every message; (b) an Anthropic model classifies the topic and drafts a reply; (c) a person reads the draft and decides whether to send it; no reply is sent automatically. Personal-data requests, legal matters and content notices are handled by the controller personally. We process your email address, name, the content of the message and the thread history. Excerpts of threads whose draft needed correction may be saved as examples in a spreadsheet (Google Sheets) so that later drafts are better; we remove identifying data from them where possible.
  2. Content notices (§ 11 of the Terms): we process the notifier's data and the content of the notice in order to handle it, inform the parties and demonstrate compliance with the Digital Services Act.
  3. Basis: contract, if you write as a user (Art. 6(1)(b)); otherwise our legitimate interest in answering correspondence and defending claims (Art. 6(1)(f)) and legal obligations (Art. 6(1)(c)). Period: 24 months after the matter is closed, unless the defence of claims requires longer.

9. Payments: Paddle

Paid plans are sold on our behalf by Paddle (Paddle.com Market Limited, Judd House, 18-29 Mora Street, London EC1V 8BT, United Kingdom, and its affiliates) as Merchant of Record. Paddle is an independent controller of the data you provide at checkout (name, email, billing country and address, VAT number, card details) and processes it under its own privacy policy (paddle.com/legal/privacy). We receive: the customer and subscription identifiers, the chosen plan, the subscription status, event identifiers and, for the invite programme, confirmation that a payment date was moved. We pass your account and Space identifiers to Paddle to link the payment to the plan.

10. The "Invite friends" programme

  1. If you arrive through someone's link: we store the inviting person's Space name in the unfed_ref cookie (§ 4), and the page shows you their display name and profile picture so it is clear who invited you. If you create an account, we record the attribution to that person; if not, the cookie expires after 30 days.
  2. If you invite: you see in the dashboard the display names and statuses of people who arrived through your link (joined, published their Space), and when someone publishes their Space you receive an email with their display name and Space address. You never see their email address.
  3. The invited person sees who invited them (display name, Instagram profile picture, Space address). They see no other data about the inviter.
  4. Basis: contract (Art. 6(1)(b)), and for detecting abuse our legitimate interest (Art. 6(1)(f)).

11. Recipients of data

We do not sell personal data. We use providers that process data on our behalf under data-processing agreements, and we deal with parties that are independent controllers. We pass on only what a given function needs.

Recipient Role What it processes Where
Cloudflare, Inc. (USA) Processor All infrastructure: application servers (Workers), database (D1), files (R2), cache (KV), page delivery, attack protection, logs Global network; data at rest in Cloudflare regions
Anthropic, PBC (USA) Processor Content described in § 6 and § 8 USA
PostHog, Inc. (USA), EU cloud Processor Visit statistics (§ 5) and dashboard usage (§ 3) European Union (Frankfurt)
Resend, Inc. (USA), EU region Processor Sending email from Unfed (address, message content, delivery status); open and click tracking disabled European Union
Paddle.com Market Limited (UK) Independent controller Payments (§ 9) United Kingdom, USA
Meta Platforms Ireland Limited (Ireland) / Meta Platforms, Inc. (USA) Independent controller (data source) Your Instagram account, which we read through the API; sign-in through Instagram; the data-deletion mechanism Under Instagram's privacy policy
Kit (Kit.com / ConvertKit LLC, USA) Processor Waitlist (§ 7) USA
Google Ireland Limited (Ireland) Processor The support@ mailbox (Google Workspace), the examples spreadsheet (§ 8) European Union, USA
Atlassian (Trello) Processor The support@ ticket queue (§ 8) European Union, USA
Make (Celonis Make, Czech Republic) Processor The automation handling support@ (§ 8) European Union
Public authorities, courts, legal advisers Independent controllers Where the law or the defence of claims requires

12. Transfers outside the European Economic Area

Some providers are established in the USA or process data there (Cloudflare, Anthropic, Kit, Resend, PostHog as a company, Meta Platforms, Inc., Google, Atlassian). Transfers take place on the basis of the European Commission's adequacy decision for the EU-US Data Privacy Framework for providers certified under it, and otherwise on the basis of the European Commission's Standard Contractual Clauses together with supplementary measures. Paddle is established in the United Kingdom, which is covered by an adequacy decision. Statistics data (PostHog) and email sending (Resend) are stored in the European Union. You can obtain a copy of the safeguards used by writing to support@unfed.space.

13. How long we keep data

Data Period
Account, Space, works, media, configuration, FAQ, links, shop, announcements, stats, invite programme, preferences Until you delete your account; deletion is immediate and complete (§ 14)
A work you deleted on Instagram Hidden at the next sync, copy deleted after 30 days
A work you deleted in the Unfed dashboard Immediately
Instagram access token Until account deletion or until you revoke authorisation in Instagram
Sign-in session 30 days from sign-in, or until sign-out
Sign-in / email-confirmation link 15 minutes, single-use
Billing data held by us (identifiers, status) Until account deletion; payment-event identifiers without a link to the account after its deletion
Accounting records (at Paddle and in our books: receipts issued by Paddle on our behalf) 5 years from the end of the tax year (legal obligation)
Infrastructure logs (Cloudflare) Briefly, measured in days
Visit statistics (PostHog, anonymous session data) 7 years; aggregate numbers in your dashboard until account deletion
Dashboard usage (PostHog) Until account deletion or until you object (§ 3.2); PostHog completes the deletion within days
Data at Anthropic Up to 30 days, solely for abuse detection, then deleted
Waitlist Until consent is withdrawn, at the latest 12 months after Unfed launches
Correspondence and notices 24 months after the matter is closed, unless the defence of claims requires longer
Product-news consent (text and date) Until withdrawn, then 3 years as evidence that consent existed

14. Deleting your account and data

  1. In the dashboard: Profile, "Delete account". Deletion is immediate and complete: the Space stops being available; we delete works and media, configuration, FAQ, links, shop, announcements, stats, email address, Instagram token, sessions and tokens, invite-programme history, and the account record itself. The Space address returns to the pool. You see a confirmation with a deletion code. The same command deletes the record of your dashboard usage at PostHog; PostHog completes that deletion within days.
  2. Through Instagram: remove Unfed in Instagram's settings (Apps and websites) and submit a data-deletion request; Meta forwards it to us automatically, we perform the same complete deletion and return a confirmation code you can check on the status page.
  3. By email: support@unfed.space.
  4. After deletion, no data of your account remains with us except: (a) Paddle's accounting records, if you bought a plan (legal obligation); (b) correspondence, if you wrote to us (§ 8); (c) infrastructure backups, overwritten on the provider's cycle and not used to restore individual accounts. Copies of your pages saved by search engines and other services disappear at their pace.

15. Your rights

You have the right to: access your data and obtain a copy; rectification; erasure; restriction of processing; portability of data processed on the basis of contract or consent (at your request we provide your content in a commonly used format); object to processing based on legitimate interest, including the weekly summary and the record of your dashboard usage; withdraw consent at any time, without affecting the lawfulness of earlier processing.

To exercise these rights, write to support@unfed.space. We respond without undue delay and at the latest within one month. We may ask you to confirm your identity, for example by writing from the email address linked to the account.

You have the right to lodge a complaint with a supervisory authority: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, Poland (uodo.gov.pl), or the supervisory authority of the country of your habitual residence, place of work or place of the alleged infringement.

16. Security

We store the Instagram access token encrypted; sign-in links are stored as hashes; tokens and links never reach logs. All communication is over HTTPS. Access to the infrastructure is limited to the controller and protected by multi-factor authentication. The dashboard signs you out after 30 days. We do not store payment-card data.

17. Age

Unfed is intended for people aged 18 or over. We do not direct the service at children and do not knowingly collect their data. If we learn that an account belongs to a minor, we will delete it.

18. Changes to this policy

If we change this policy in a way that materially affects you (a new purpose, a new recipient, a new category of data), we will notify you by email (if you have an account) at least 14 days in advance. The current version is always available at app.unfed.space/legal/privacy and on unfed.space, with the date of the last update at the top.