Privacy
In force from 20 September 2026.
Last updated 26 September 2026.
The short version: this website collects nothing about you. The tools store what you put into them and the account you sign in with, so that they can work — and nothing is sold, tracked or used for advertising.
- 1
Who is responsible
unhingged is run by Balogh Zoltán Sándor, 2030, Érd Huba utca 18. For the data described here, that is the “controller” — the one who decides why and how it is used — except where section 5 says otherwise.
Questions and requests: legal@unhingged.com.
- 2
What this covers
This website, unhingged.com, and the tools that live under it: Vizu, Terms, Timeit, Mockit, at vizu.unhingged.com, terms.unhingged.com, timeit.unhingged.com, mockit.unhingged.com. They share one sign-in, so they share one policy.
It does not cover websites that use a tool — a site with Vizu comments on it, an app that checks Terms — which have their own policies.
- 3
This website
unhingged.com itself sets no cookies, stores nothing in your browser, has no forms, runs no analytics and loads nothing from third parties — the fonts are served from this site.
Like any website it is delivered by a hosting provider (Vercel), which necessarily sees your IP address and basic request details to send you the page and keep the service secure.
- 4
Your account
You sign in to the tools through Clerk, our authentication provider — with a Google, GitHub or Apple account, or an email address and password, depending on what a tool offers. Clerk handles the sign-in; we receive your name, email address and profile picture, and never see your password.
It is one account across all the tools. Clerk sets the cookies needed to keep you signed in; they are strictly necessary and are not used for advertising or tracking.
- 5
What each tool stores
Vizu. Your workspaces and their members, and the comments left in them: the text, any files attached, the address of the page and a description of the element the comment is pinned to, and the author’s name, profile picture and email address. Inviting someone stores their email address.
Terms. Your workspaces and members, the documents you upload, and their versions. API keys are stored only in hashed form. For every acceptance it records the user ID your application sends (meaningless to us), the document and version, the time, and the IP address and browser user agent of the request.
Those acceptance records belong to the workspace owner, who decides why they are collected; we store them on the owner’s behalf, as a processor. If a record is about you, the owner is the one to ask.
Timeit. The events you create and the answers given to them: a name and the times marked. Guests answer with just a name; if the organiser has asked to email everyone the final time, a guest may leave an email address, which is used for that and nothing else. A guest’s edit key and your light/dark preference are kept in your own browser’s local storage, not on our servers.
Mockit. Your workspaces and members, the OpenAPI documents you upload — kept in the database as text, not as files — with their settings and any answers you have pinned. Mock URLs are public by design: anyone who has the id can call them, and what they answer is what the spec or your pins say. Every call is logged for seven days: the method, path and query string, the status and timing, the seed used and the caller’s browser user agent — not their IP address, and not the request body. Inviting someone stores their email address.
- 6
Why, and on what basis
To run the tools you asked to use: showing your comments, checking who accepted what, finding the hour everyone is free. Where the GDPR applies, that is the performance of our agreement with you. Keeping the service secure and working — logs, abuse prevention — rests on our legitimate interest in doing so.
We do not sell personal data, show advertising, build profiles, or make automated decisions about you.
- 7
Email
We send email only when a tool needs to: an invitation to a workspace, a note to an organiser that someone answered, the final time of an event if the organiser asked for it. There is no newsletter and no marketing email. These messages are sent through Resend.
- 8
Who else handles it
We use a small number of providers to run the tools. Each one only processes data to provide its service to us:
- Clerk — sign-in and accounts.
- MongoDB Atlas — the database the tools’ data lives in.
- Vercel — hosting, and storage for uploaded files (documents in Terms, attachments in Vizu).
- Resend — sending the emails described above.
These companies are based in the United States, so your data may be processed there. Where the GDPR applies, such transfers rely on the safeguards those providers offer, such as the EU standard contractual clauses.
- 9
How long we keep it
For as long as the workspace, event or account it belongs to exists. You can delete your own events, comments and workspaces in the tools, and you can ask us to delete your account and what is attached to it.
One exception is deliberate: in Terms, published versions and acceptance records are an audit trail and cannot be edited or removed one by one — that is the point of them. Deleting the workspace deletes its acceptance records with it.
- 10
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to limit or object to how we use it, or to hand it to you in a portable form. Write to legal@unhingged.com and we will answer within a month.
If you are in the EU or the UK you also have the right to complain to your data protection authority. We would rather you told us first, so we can fix it.
- 11
Children
The tools are made for people at work. They are not aimed at children, and we do not knowingly collect data from anyone under 16.
- 12
Changes
When this policy changes, the date at the top changes with it. If a change matters — a new provider, a new kind of data — we will say so in the tools before it takes effect. See also the terms of service.