Security at unfill.io
What happens to your recording, how it's protected, and how long we keep it. For everything we collect and your rights, see the privacy policy.
Encryption in transit
All connections to unfill.io and our API use TLS 1.2 or 1.3. Older protocols are rejected.
Encryption at rest
Files in storage, including uploaded recordings and generated decks, are encrypted with AES-256 (Amazon S3 server-side encryption, SSE-S3), and the database is encrypted at rest with AWS RDS encryption.
How long we keep your files
| Data | Retention |
|---|---|
| Uploaded recordings | Automatically deleted about 24 hours after upload. An S3 lifecycle rule deletes each file 1 day after upload; AWS runs these deletions once a day, so occasionally removal can take up to about 48 hours. |
| Transcript text and deck history (slide text) | Deleting a deck in My decks removes its slides and file. Transcript text stays until you ask us to delete it (privacy@unfill.io). |
| Generated PowerPoint files | Removed after 30 days. Download a copy to keep it. |
| Your account | Kept until you ask us to delete it. Email privacy@unfill.io. |
You can delete any deck yourself, at any time, from My decks.
Model training
Your recording is used only to build your deck, and we don't train any model on it. The AI and transcription services we use don't train their models on your recordings, transcripts or decks.
Subprocessors
These companies process data on our behalf to run the service.
| Company | What it does for unfill.io |
|---|---|
| Amazon Web Services (AWS) | Hosting and file storage |
| Anthropic | AI processing: turns the transcript into slide content. Anthropic's commercial terms don't use API data for training. |
| Deepgram | Transcription |
| Stripe | Payments for Pro. Card details go to Stripe, not to us. |
| Plausible | Cookieless website analytics |
Deleting your account
Email privacy@unfill.io from the address on your account, and we'll delete your account and its data. The same address is the place to report a security issue.