Local-first

Your day stays on your device.

This page states Unlook’s privacy design precisely: what lives on your computer, what is never observed at all, what a diagnostic may contain, and where the honest limits are. No comfort words — the design contract, in plain language.

In development · every claim below is designed behaviour, to be matched exactly by the shipped product

“Unlook is local-first. The focus schedule, sessions, opportunities, Moments, outcomes, settings, and meaningful wellness history stay on the device. Creating an account does not turn that local record into cloud data. The commercial service knows whether an opaque account may use paid features; it does not learn what the person was doing, which applications were open, when each break occurred, or what Camera Labs observed.”
— Unlook’s data-flow contract

The ledger

What stays on the device

Everything Unlook records lives in one local database on your computer — an ordered ledger of facts, with verified backups and a recovery path that treats your history as the thing worth protecting.

History
Sessions, opportunities, Moments, outcomes, and corrections — an ordered factual ledger. Durations come from the engine’s own monotonic measurement, never reconstructed by subtracting wall-clock timestamps.
history_events
Settings & schedule
Your rhythm, working days and hours, quiet hours, every preference. A separate boundary: deleting history does not silently delete these.
local_settings
Daily summaries
Disposable local-day projections — valid focus time, Moment counts, natural pauses, longest uninterrupted focus, provisional Healthy Screen Day status. Rebuildable, and deletable at any time.
daily_summaries
Engine checkpoints
Where the engine was, so a restart or an update resumes honestly instead of guessing.
engine_checkpoint
Backups
Consistent snapshots, each verified before it is trusted. An update keeps the pre-migration backup until the new version passes its health checks.
verified snapshots
Recovery
“A failed or interrupted migration opens the recovery path; it never silently creates a new empty database.” A damaged database is preserved byte-for-byte, a verified backup is restored to a separate candidate, and you are offered recovery, export, and support before any reset.
preservation-first
Sign-in credentials
If you ever create an account, refresh credentials live in the operating system’s protected store — never in renderer storage, the history database, URLs, or logs.
OS credential store

By design

Never observed — not just never sent

Most privacy pages tell you what a product doesn’t share. The stronger claim is what it never reads. Unlook counts focus from your presence at the keyboard; the engine has no view into what you are doing there.

  • Window titles
  • URLs and browsing
  • Typed content
  • Documents on your screen
  • Screenshots
  • Which applications you run
“The engine must not inspect typed content, document content, URLs, application titles, or camera data to calculate V1 focus time.”
— an engine requirement, verbatim

Unlook is not employee-monitoring software, parental control, or a tamper-proof enforcement system — and it is not medical software. It counts your focus; it does not police your screen.

The product’s own answer, from Settings → Data and privacy: what Unlook keeps, and what it never collects.

The network boundary

What never leaves

Three things are designed never to cross the network: your wellness history, camera media, and payment details. There is no cloud sync waiting to quietly change that.

  • Wellness history

    The account service’s own data schema is prohibited from containing schedules, sessions, opportunities, Moments, daily summaries, window titles, URLs, typed content, camera data, or derived wellness history. There is nowhere on Unlook’s side for your record to land.

  • Camera media

    Frames, landmarks, embeddings, and gaze traces are never stored and never transmitted. The camera process is designed with no network access at all.

  • Payment details

    Payment happens in a provider-hosted browser flow. The desktop app never receives card or bank credentials, and it cannot create a charge on its own.

Planned · no commercial service is live today

What the commercial service would learn

When accounts exist, the service knows one thing: whether an opaque account may use paid features — signed entitlement state, nothing more. Not what you were doing, which applications were open, when each break occurred, or what Camera Labs observed. Creating an account does not turn your local record into cloud data, and the design deliberately refuses to turn commercial infrastructure into a wellness-data sync service.

Diagnostics

Diagnostics, honestly

“Unlook diagnoses named system failures, not the person’s work or wellbeing behavior.” Four channels — only one is on by default, and it never leaves the machine.

  • Essential local diagnosticsOn · local onlyAllow-listed events only, under a rolling 7-day / 20 MiB cap. Visible in settings and deletable at any time with “Delete now”.
  • Remote crash reportsOff by defaultA separate, unchecked choice. Withdrawable at any time — withdrawal stops future collection immediately and deletes queued reports.
  • Product analyticsOff by defaultA separate opt-in, never implied by the crash-report choice or by anything else.
  • Support bundleManual · previewedBuilt only when you ask for it, shown to you in full first, and sent only when you explicitly send it.

In settings, remote sharing is two separate controls with exact names:“Share crash reports” and“Share anonymous product analytics.” Both start unchecked. Neither is bundled with terms acceptance, trial activation, camera consent, or the other control.

Every diagnostic event is assembled from a closed allow-list — schema version, event name, app version, OS family, architecture, day bucket, outcome, a bounded symbolic error code, a duration bucket. No exact timestamp or raw duration enters the record, and the logger cannot accept arbitrary text.

And trying Unlook starts no tracking at all: the preview and onboarding start no trial, no camera use, no remote crash reporting, and no analytics.

Ownership

Yours to keep

A wellness record is only yours if you can take it with you — or make it disappear. Both controls are documented, local, and deliberately kept outside the paywall.

Export

unlook-history · v1 · JSON + CSV

A documented, portable copy of your history: UTF-8 JSON as the authoritative record, with a spreadsheet-friendly CSV view. It requires no active subscription and no access to account systems. “Exporting changes nothing. Your history stays exactly where it is.”

Delete

local · no account needed

Local deletion works without an account and is independent of account deletion. “Removes what is on this computer. Your account stays.” The scope is shown as real counts before you confirm, and you are offered an export first.

If a subscription ends, history becomes read-only — nothing is taken away. Everything you recorded is still here, and you can read it, export it, or delete it whenever you like. The export file records that state honestly, asaccessState: “expired-read-only”.

Stated plainly

Honest boundaries

A privacy page that only lists strengths is an advertisement. These are the limits of the design, at full contrast.

  1. 01

    Local protection is your OS’s protection

    The local database is not separately encrypted. V1 relies on your operating-system account and full-disk encryption to protect data at rest — worth switching on if you haven’t. On a shared account, your record is as private as that account.

  2. 02

    Deletion has legal edges

    Account deletion revokes sessions, removes Unlook’s commercial link, and requests deletion from its providers. Records payment providers must keep by law — tax, fraud, accounting — may be retained by them. Unlook never shows “deleted everywhere” while offline or while a request is still pending.

  3. 03

    Not offline forever

    The engine and your history work offline. A trial, though, needs periodic online confirmation, and paid use carries a bounded offline grace period — designed to end about a week after the last server verification.

  4. 04

    Update checks say a little

    Checking for an update sends the release channel, app version, operating system, and architecture — nothing else. The staged-rollout identifier stays on the device and is not analytics.

Before launch

A design contract, not a certificate

Unlook has not launched. Every claim on this page describes the designed behaviour of a product still being built — which is why the language here is “designed so that” rather than “certified that”. No external security review, penetration test, or legal assessment has happened yet, and this page will not pretend otherwise. You will not find “GDPR compliant”, “audited”, or “zero telemetry” here; where a slogan would overstate, this page states the narrow fact instead.

The contract cuts the other way too. Unlook’s own security acceptance gate requires that at launch, “privacy copy and processor records match the exact shipped behavior.” If the shipped product ever differs from this page, the page is wrong and must change. The formal privacy policy is written against the shipped product, not before it.

Camera Wellness Labs

The strictest boundary

Unavailable in this version · experimental, not part of the core product

If Camera Wellness Labs ships, it is optional and off by default. The camera is used at brief, explicitly opted-in moments only — a check at the start of a session, and during an active Eye Reset — on the device, video only, with a visible indicator whenever it is on; the camera process has no network access and no audio. It never stores or transmits imagery: no frames, no landmarks, no embeddings, no gaze traces. What survives a check is one derived word. “Words only. No images were ever kept.”

The camera never affects whether a Moment counts — low confidence is a neutral answer, not a demerit — and the core product never depends on camera access.

The full Labs story →