Privacy Policy
Unicorn Horn turns code written by AI coding agents into live, shareable previews. This policy explains what information we collect when you use Unicorn Horn at unicornhorn.app (the “Service”), how we use it, and the choices you have. The Service is operated by [operator’s legal name] (“we”, “us”).
Information we collect
Account information
When you sign in, our authentication provider, Clerk, gives us your name, email address, profile picture, and the organizations (workspaces) you belong to, along with your role in each.
Content you and your agents create
- Previews: the code files your agent publishes, their titles, the framework, sharing and expiry settings, and a history of up to 20 earlier versions of each preview.
- Screenshots: an image of each preview, rendered on our servers, used for link previews and thumbnails.
- Collections: the names, descriptions and layout of collections you create, and which previews they contain.
Your previews run your code, so don’t put secrets, credentials or other people’s personal information in them. Anyone with a preview’s link can see it unless you restrict it to your organization or disable it.
Agent connections
- API tokens: a name, the first few characters, and a one-way hash of each token you create. We never store the full token after showing it to you once.
- Signed-in clients: for agents that connect with OAuth, the client’s identifier and when it was first and last used.
Email addresses you add for notifications
You can ask us to email other people when a preview changes. We store each address, which changes it should hear about, and whether it has unsubscribed or bounced. Only add people who expect to hear from you. Every email includes a one-click unsubscribe link.
Technical information
Our hosting provider records standard server logs, including IP addresses, browser details and the pages requested, to operate and secure the Service. We don’t use advertising or analytics trackers.
Cookies and local storage
Clerk sets cookies that keep you signed in. They’re necessary for the Service to work, and we don’t use cookies for advertising or tracking. Your browser’s local storage remembers display preferences, such as light or dark mode.
How we use information
- To provide the Service: store, render and share your previews.
- To sign you in and apply your organization’s access rules.
- To send the notification emails you set up.
- To keep the Service secure and reliable, including rate limiting, preventing abuse, and removing content that breaks our Terms.
- To respond when you contact us.
We don’t sell your personal information or use it for advertising.
Who we share it with
We use these service providers to run Unicorn Horn:
- Clerk: sign-in, accounts and organizations.
- Convex: our database, file storage and backend.
- Vercel: hosting and screenshot rendering.
- Resend: sending notification emails.
When someone opens a preview, their browser may also load libraries and fonts from public content delivery networks (such as esm.sh, unpkg, jsDelivr and Google Fonts), which receive their IP address like any website request.
People in your organization can see its previews and collections, and anyone you share a link with can see that preview. We may also disclose information when the law requires it, to protect the Service or its users, or as part of a merger or acquisition.
Our providers may process data outside your country, including in the United States. [transfer safeguards, if serving the EU/UK]
How long we keep it
- Previews and collections stay until you delete them. A preview with an expiry date is hidden when it expires and permanently deleted 30 days later.
- Each preview keeps its 20 most recent earlier versions.
- Revoked API tokens stay listed, so you can see when they were last used, until you delete them.
- Account and remaining workspace data are kept while your account is active. To have it deleted, contact us.
- Records of moderation actions on previews are kept for security and accountability.
Your choices and rights
You can edit or delete your previews, collections and tokens, disconnect signed-in clients, and update your profile in your account settings at any time. Depending on where you live, you may also have the right to access, correct, export or delete your personal information, or to object to how we use it. To make a request, contact us at [contact email].
Security
Previews run in a sandboxed frame, isolated from the app and your account. API tokens are stored only as hashes, and all traffic is encrypted in transit. No system is perfectly secure, but we work to protect your information.
Children
Unicorn Horn is not for children under 16, and we don’t knowingly collect their information.
Changes to this policy
We’ll post any changes here and update the date above. If the changes are significant, we’ll let you know by email or in the app.
Contact
Questions about this policy? Contact [operator’s legal name] at [contact email].