Unflatten · Legal
Privacy Policy
Effective 2026-09-28
Who we are
Unflatten, Inc. operates unflatten.com, scry.io, and pairwiseratio.org (together, "the services"). For anything in this policy, contact hi@scry.io.
What we collect
Account information. When you create an account: your email address and authentication credentials.
Billing information. Payments are processed by Stripe. We receive transaction records (amounts, timestamps, payment status) but never store full card numbers ourselves.
Usage records. Queries, API requests, spend, and operational logs.
We keep these to run and improve the service, meter billing accurately, and prevent abuse.
The record of a query contains the statement text, a hash of its shape, its parameters,
the row count, the bytes returned, the costs, and the request's IP address and client
software identifier. It does not contain the result rows.
A statement over public relations may be answered from a shared result cache whose
entries live at most 300 seconds, and the market status endpoint may publish the text
of a statement once five distinct accounts send it within 60 seconds. A query sent
with x-scry-max-staleness: 0 stays out of both.
A query sent with the x-scry-zero-retention header is settled without
its text or its result: the usage record keeps the account, the time, the relations
named, the amount billed, and the request's IP address and client software
identifier, and the reply is never entered into the shared result cache.
Cookies and local storage. Used only for sessions and preferences (such as theme). We run no third-party advertising or analytics trackers. Our pages load static assets through third-party networks (Cloudflare), which see standard request metadata such as your IP address.
The public corpus
Scry indexes publicly available internet content — forums, papers, social archives, government records — stored separately from account data. Public material can include information identifiable people posted publicly; being public does not place it outside privacy law. To ask about, correct, or request removal of corpus content that concerns you, see removal & copyright requests or write to hi@scry.io.
How we use information
To provide, operate, secure, and improve the services; to meter and bill usage; and to respond when you contact us. We do not sell personal information. We share it only with processors acting on our behalf (Stripe for payments, Cloudflare and our hosting providers for infrastructure) and when the law requires it.
Model providers. Text you submit to a model-backed tool goes to that
model's provider as a processor: the metered
embedding lane (voyage-4-lite) and the hosted rerank tier send
the text, query, and documents of that call to Voyage AI; the fast and quality rerank tiers, and a rerank directive on a query, send the query,
the directive, and the documents or cells being ranked to TypeSafe, whose Jev model
reads them; the chat tool sends its messages to OpenRouter and the model vendor it
routes to. The local embedding lane (voyage-4-nano) runs on our
infrastructure and sends nothing out, and so does the model that answers a rerank
when TypeSafe cannot. Each
provider holds what it receives under its own API terms; the x-scry-zero-retention header governs our records of a query, not a
provider's.
SMS
Scry customer SMS covers support replies and account or service updates the recipient requests. A separate staff program covers operational alerts. Both require explicit consent — see SMS enrollment and terms. We use mobile numbers and consent records to provide these messages, honor opt-outs, and meet legal obligations. We share them with messaging providers acting on our behalf only as needed to deliver and manage the program. We never sell or share mobile numbers or SMS opt-in data with third parties or affiliates for marketing or promotional purposes.
Retention and deletion
We keep account data while your account is active and usage records as long as they are needed for billing integrity and abuse prevention. Login sessions and one-time tokens, with the IP address and client software recorded at login, are deleted within 30 days of expiring or being revoked. To request access to or deletion of your personal data, email hi@scry.io.
Security
All traffic to the services is encrypted in transit. Access to production systems is restricted and credentialed. Found a vulnerability? See the security and vulnerability disclosure policy.
Changes
We will post any changes to this policy on this page with a new effective date.