Skip to content
Unbound
Privacy

What we hold, and who can see it

Unbound is a small community site run by three people. This page says exactly what we store, where it goes, and how to get rid of it. If something here is unclear, ask us and we will fix the wording.

Last updated

Who runs this

Unbound is operated by its three founders, listed on the team page. We are not a company. Questions about anything below go to .

Signing in

Accounts are handled by Clerk, an external authentication provider. When you sign up, Clerk stores your email address and whatever credential you sign in with, such as a password or a linked account from another provider. Clerk, not us, holds your password. Their handling of that data is covered by their own privacy policy.

We keep a copy of your Clerk user id and your verified primary email address so we can match your session to your profile. When you change your email address in Clerk, we update our copy.

Your profile

Onboarding asks for a few things, all of which you write yourself and can edit or blank out at any time from your profile settings:

  • Your name
  • Your school or university, and your grade or year
  • What you are building, a short bio, and fun facts
  • Skill and interest tags
  • Whether you are open to pairing requests

Treat all of it as public. Everything in that list appears on the community directory, and the first five profiles are visible to anyone on the internet, signed in or not. The rest sit behind a sign-in wall, which is a speed bump rather than a guarantee: anyone can make an account. Do not put anything in your bio that you would not put on a public web page.

Your email address is the exception. It is never shown on the directory and is never part of the data that page loads.

Pairing requests

When you send a pairing request, we store who sent it, who received it, the reason you wrote, its status, and the times it was sent and answered. The recipient reads your reason. Write it for them.

Email addresses are exchanged on acceptance and only then. While a request is pending, neither side sees the other’s address. If it is declined or cancelled, neither side ever does. Accepting is what releases your address to the other person, and once they have it, they have it. We cannot claw it back.

The newsletter

Signing up stores your email address and, if you give them, your first and last name. We use it to send the Unbound newsletter and nothing else. We do not sell it, rent it, or hand it to anyone outside the three of us.

One address means one subscription. Signing up again with an address already on the list changes nothing and does not overwrite the name on file. To come off the list, email us and we will delete the row. There is no self-serve unsubscribe link yet.

Event signups

When you sign up for an event, we store your name, email, age, and grade/year, along with the fact that you confirmed you’re committed to attending. We use this to plan the event and follow up if details change. We don’t share this with anyone outside Unbound.

Services we hand data to

  • Clerk for accounts and sessions.
  • Neon hosts the database holding profiles, pairing requests, events, event signups, and newsletter signups.
  • Vercel hosts and serves the site, and sees the request metadata any web host sees, including your IP address.
  • Upstash backs rate limiting. Your IP address is used as a counter key on the newsletter and event signup forms so one connection cannot flood signups. It is a key in a short-lived counter, not a record of your visit, and it is never joined to your profile.
  • Sentry receives error reports when something breaks. We have turned off the settings that would send your identity or the contents of your requests, so what it gets is stack traces and the page an error happened on.

Each of these is an independent company with its own privacy policy and its own servers, some outside Canada.

Cookies

Clerk sets cookies to keep you signed in. Those are the only cookies we deliberately set, and blocking them means you cannot stay signed in. We run no advertising trackers, no analytics product, and no third-party pixels. Our hosts may set cookies of their own for routing or security.

Keeping and deleting your data

We keep your profile for as long as your account exists. Deleting your account in Clerk deletes it here too. Clerk tells us the moment you do, and we remove your profile row and every pairing request you sent or received, including the reasons you wrote and the ones written to you. It is a real delete, not a hidden flag, and there is no copy kept behind it.

Newsletter signups are the exception. That list is keyed on an email address and has no link to your account, because you can subscribe without one, so deleting your account leaves your subscription alone. Email us if you want off the list as well.

You can also just ask. If you would rather we deleted your profile without you touching Clerk, write to us. We will confirm from the address on file first, and we aim to do it within a week.

One thing we cannot undo: an email address already released through an accepted pairing request is in someone else’s hands, and deleting your account does not reach it.

Age, and what we have not built

Unbound is aimed at high school and university students, so we expect many members to be under 18. We do not ask for your date of birth and we have no way to verify anyone’s age. If you are under the age at which you can agree to this on your own where you live, read it with a parent or guardian.

We want to be straight about the limits here. We have not built or audited this site against COPPA, GDPR, PIPEDA, or any other privacy regime, and we are not claiming compliance with any of them. There is no age gate, no parental consent flow, no cookie consent banner, and no data export tool. Deleting your account does now erase your profile automatically, but everything else here runs on people rather than tooling. What we do have is a small amount of data, a short list of processors, and an email address a real person reads. If you are a parent, guardian, or member who wants something removed, write to us and we will remove it.

Changes

If we change what we collect or who we send it to, we will update this page and move the date at the top. For anything significant we will say so in the newsletter rather than quietly editing.

Contact

Everything on this page, deletion requests included, goes to . See also the terms of service.