Unusual

Privacy Policy

Unusual Privacy Policy

Last Updated: February 20, 2026

This Privacy Policy explains how Pacific Intelligence Works, Inc. d/b/a Unusual (“Unusual,” “we,” “us,” or “our”) collects, uses, and discloses personal information when you visit our websites or use our services. It also explains choices and rights you may have. This Policy is incorporated into our Terms of Service.

1) Scope and Roles

1.1 What this Policy covers

This Policy applies to personal information we process about: (a) visitors to our websites and marketing pages, (b) prospects and business contacts, and (c) users of our platform.

This Policy uses defined terms consistent with our Terms of Service (accessible at unusual.ai/legal/terms-of-service). Key data categories referenced in this Policy include "Customer Content," "Insights/Outputs," "Service Data," "Feedback," and "Aggregated Data," each as defined in the Terms of Service.

1.2 Controller vs. Processor

We process Customer Content and Insights/Outputs under the licenses and rights described in our Terms of Service (Section 4). This includes using Customer Content, Insights/Outputs, Service Data, and Feedback to operate, improve, and develop the Services and our other products, including training and improving our models and algorithms. When we use such data for purposes beyond delivering the Services to you, we implement safeguards described in Section 4.4 of the Terms, including not making your Insights/Outputs directly available to other customers. We own all Aggregated Data and may use it for any lawful purpose.

2) Information We Collect

2.1 Data you provide to us (controller context)
2.2 Information in Customer Content (processor context)

Materials you or your users upload or generate in the Services (e.g., product/brand docs, reference copy for “Content for AI” pages, notes from alignment meetings). You should not upload regulated or sensitive data (e.g., PHI, PCI, precise geolocation, data about children, special categories) unless we have a signed addendum expressly permitting it.

2.3 Automatic data (controller context)
2.4 Payment information

We use third-party processors (e.g., Stripe). We do not retain full card numbers; processors handle them under their own policies.

2.5 Service Data

We automatically collect data generated through your interaction with the Services, including usage logs, feature interaction data, session analytics, performance metrics, query volumes, telemetry, and technical diagnostics ("Service Data"). Service Data does not include the substance of Customer Content or Insights/Outputs but may include metadata about their creation and use. We are the controller of Service Data.

2.6 Feedback

We collect suggestions, enhancement requests, recommendations, ideas, feature requests, bug reports, evaluations, and other feedback regarding the Services that you or your users provide, whether verbally (including during recorded calls and meetings), in writing, through surveys, or through the Services ("Feedback"). We are the controller of Feedback. Feedback is not treated as your Confidential Information regardless of any designation to the contrary, as described in Section 8.3(f) of the Terms of Service.

3) Sources of Personal Information

4) How We Use Information (Controller)

We use personal information in our controller capacity to:

We do not use personal information for ad personalization or cross-context behavioral advertising.

5) How We Process Customer Content (Processor)

When acting as your processor/service provider, we:

For clarity, our use of Customer Content for the platform improvement and development purposes described in Section 4 above and Section 4.3 of the Terms of Service is conducted in our controller capacity under the licenses granted by Customer, not in our processor capacity.

6) AI Providers and Model Handling

7) Disclosures of Personal Information

We disclose personal information to:

We do not sell personal information and do not share personal information for cross-context behavioral advertising.

8) International Data Transfers

We may transfer personal information to the United States and other countries where we and our providers operate. Where required, we rely on Standard Contractual Clauses or comparable transfer mechanisms and implement appropriate safeguards. If we certify under a recognized data-transfer framework, we will reflect that on this page.

9) Security

We implement reasonable and appropriate technical and organizational measures, including access controls, encryption in transit (and at rest where applicable), logging/monitoring, vulnerability management, and workforce confidentiality obligations. No method of transmission or storage is 100% secure.

10) Retention

We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and for legitimate business purposes. For Customer Content, retention follows the DPA and your instructions. For Service Data and Feedback, we retain such data for as long as necessary to fulfill the purposes described in this Policy, including product improvement, model training, and development of our Services. Aggregated Data may be retained indefinitely.

11) Your Choices

12) Your Rights (Region-Specific)

12.1 California (CPRA) and certain U.S. states

Subject to exceptions, you may have the right to know/access, delete, correct, port, and opt out of sale/share (not applicable to us at this time). You also have the right to limit the use/disclosure of sensitive personal information (we do not use sensitive PI for purposes requiring this right). If we deny a request, you may submit an appeal by replying to our decision email.

For purposes of the CCPA/CPRA, our use of Customer Content, Service Data, and Feedback for model training and service improvement as described in this Policy constitutes a "business purpose." We do not "sell" or "share" (as defined under the CCPA/CPRA) Service Data or Feedback.

12.2 EEA/UK/Switzerland (GDPR)

Where we act as controller, our legal bases include contract, legitimate interests (e.g., security, product improvement, model/algorithm improvement, benchmarking, B2B communications), consent (where required), and legal obligations. You may have rights to access, rectify, erase, restrict, object, and portability. You may lodge a complaint with your local supervisory authority.

12.3 Exercising your rights

If we are controller, contact us at founders@unusual.ai. If we are processor/service provider, contact your organization’s administrator; we will assist them in fulfilling requests.

13) Cookies and Similar Technologies

We use only the cookies and similar technologies necessary to operate and measure the Services (e.g., session, security, and basic analytics). We do not use them for ad personalization. See your browser’s help for how to control cookies.

14) “Content for AI” Hosting

If you use our optional hosting of reference pages (e.g., a subdomain with brand/reference content):

15) Children

Our websites and Services are not directed to children under 16, and we do not knowingly collect personal information from children.

16) Changes to this Policy

We may update this Policy from time to time. The “Last Updated” date reflects the latest changes. Material changes will be posted on this page, and your continued use of the Services after the effective date constitutes acceptance.

17) Contact Us

Pacific Intelligence Works, Inc. d/b/a Unusual

San Francisco, California, USA

founders@unusual.ai