LevelUp Unlocked

Privacy Policy — LevelUp Unlocked

Effective date: July 5, 2026

This policy explains how LevelUp Unlocked ("we", "us") handles data across two things:

1. This website, levelupunlocked.ai — our marketing site, and 2. LevelUp Email — the Gmail-organizer app you install and run on your own computer.

The most important fact comes from how the app is built: it is sold bring-your-own-keys (BYOK) and runs locally with your Google account and your Anthropic (Claude) API key. Because of that, the data people most want kept private — the contents of your email — never leave your machine and are never sent to us.


1. The short version


2. The website (levelupunlocked.ai)

Browsing the site is passive: we do not set advertising or analytics cookies, and we do not run third-party tracking or fingerprinting scripts.

The only personal data the site collects is what you choose to submit:

Those submissions are delivered to us through Web3Forms (a form-delivery service) and arrive in our inbox at signups@levelupunlocked.ai. We use them only to contact you about what you signed up for. We don't sell them or use them for unrelated advertising.


3. The app: what never leaves your computer

The following are processed only locally and are never transmitted to us:

Stays local Where it lives on your machine
Email content, subjects, attachments Your Gmail account + a local SQLite cache (data/)
Sender / recipient email addresses, contacts Same
Your classifications, labels, VIP lists, drafts Local SQLite database (data/)
Your Anthropic (Claude) API key Local config (.env / settings.json)
Your Google OAuth tokens & client secret Local credentials/ folder (file-permission restricted)
Your dashboard PIN Stored only as a scrypt hash, locally

Uninstalling the app and deleting its data folder removes all of this. We hold no copy because we never received one.


4. The app: what our services do receive

Only the following leaves your machine, and only for the purposes described.

4.1 License verification (required for a paid license)

To confirm your license is valid, the app contacts our license service and sends:

We store your license key, the email address you used to purchase, and the set of machine identifiers that have activated the license (with timestamps), so we can enforce reasonable activation limits and support you. We already know your purchase email because you bought the product; we do not receive your name, your Google account, or any email data here.

4.2 Remote-access tunnel (optional — only if you enable it)

If you choose to reach your dashboard from your phone, the app provisions a personal Cloudflare Tunnel. To do so it sends our provisioning service your install ID (a random identifier), your license key, and the machine identifier above. We store a hashed license key, the install ID, the machine identifier, and the tunnel's technical details so the same computer always gets the same tunnel.

The tunnel carries encrypted traffic between your phone and your own laptop. Its contents — your dashboard and your email — are not visible to us; we operate the plumbing, not the payload. If you never enable remote access, none of this data is sent.

4.3 Usage analytics (opt-in, OFF by default)

If — and only if — you turn analytics on, the app sends anonymous, categorical usage events. Every event carries a random install ID, the app version, and a timestamp, plus closed-set fields such as: your operating system family (e.g. "darwin"), which setup step was reached, an email category label (e.g. "newsletters"), an account index (0, 1, 2 — never an account name or address), durations, counts, and success/failure booleans.

The event schema forbids free-text and personal fields by construction: the data types reject anything that looks like an email address, key, or name, and an automated test plants decoy personal strings to prove they cannot reach the wire. The random install ID is never linked to your license or purchase email. We use this only to understand which features work and where setup gets stuck.

4.4 Crash reports (opt-in, OFF by default)

If you turn crash reporting on, unexpected errors are sent to our error-tracking provider with personal data scrubbed: a categorized error type, the app version, and a sanitized stack trace. Email content and addresses are not included.


5. What we never collect


6. Third parties (subprocessors)

Running the product involves a few services. Note that the two services touching your email are reached with your own accounts and keys — we are not a party to them.

Provider Role What it sees
Anthropic (Claude) AI classification, briefing, drafting Email content you process — sent with your API key, directly from your computer under your Anthropic agreement. We are not in this path.
Google (Gmail API) Reading and labeling your mail Your mailbox — accessed with your Google account and OAuth client. We never receive your token.
Cloudflare License service, tunnel provisioning, optional tunnel transport, analytics ingestion, website DNS License key + machine ID; tunnel/install metadata; opt-in anonymous analytics. No email content.
Neon Database for the license service License keys, purchase emails, activation machine IDs.
Sentry Crash reporting (only if you opt in) Scrubbed, categorized error reports. No email content.
Web3Forms Delivers website signup / workshop forms to us The email address and form fields you submit on the website.
Vercel Hosts the website Standard web-server request logs for the marketing site.

We do not sell or rent any data to anyone, and we do not use your data for advertising.


7. How long we keep things


8. Your choices and rights


9. Security

Credentials and tokens are stored locally with restricted file permissions; your dashboard is protected by a PIN you set; the optional remote tunnel is encrypted end to end; license keys are stored only as hashes on our side; and the analytics pipeline is contract-tested to keep personal data out. No system is perfectly secure, but the BYOK architecture means the highest-risk data simply isn't ours to lose.


10. Children

LevelUp Email and this website are intended for adults and are not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children.

11. International users

Our service infrastructure may process the limited operational data in this policy in countries other than yours. By using the product you understand this data may be handled in those locations under this policy.

12. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected here with a new effective date, and surfaced in the app where appropriate. Continued use after an update means you accept the revised policy.

13. Contact

Questions, requests, or concerns about privacy:

This policy is governed by the laws of the State of California, USA, without regard to its conflict-of-laws rules.