Clear identity fields
Each form visibly indicates whether a name or email is requested, so contributors can make an informed choice before submitting.
Authorized workspace administrators can read submitted messages.
UnspokenBox minimizes identifying information, avoids advertising trackers, and encrypts stored submission content. No online system can promise absolute anonymity or immunity from attack.
Each form visibly indicates whether a name or email is requested, so contributors can make an informed choice before submitting.
Authorized workspace administrators can read submitted messages.
Raw IP addresses are not attached to submissions by the application. UnspokenBox does not add advertising trackers, device fingerprinting, or third-party analytics to submission pages. Hosting, network, and security providers may maintain their own operational logs.
The application supports HTTPS when the deployment is correctly configured and encrypts stored messages, identity fields, attachment names, and supported attachments with organization-specific keys.
Feedback, encrypted attachments, and survey responses are scheduled for removal after 12 months. Cleanup timing depends on the retention process, and limited copies may remain temporarily in backups or operational records.
These terms explain how UnspokenBox works, the safeguards we provide, and the shared responsibilities that help keep feedback channels trustworthy.
Last updated: 27 July 2026UnspokenBox provides tools for collecting feedback, ideas, questions, concerns, survey responses, and other communications. By creating an account, administering a workspace, or submitting through a public link, you agree to use the service lawfully and in accordance with these terms.
Do not use UnspokenBox to threaten, harass, impersonate, distribute unlawful material, expose another person’s sensitive information without a lawful basis, interfere with the service, probe for vulnerabilities without written authorization, or evade reasonable usage and security controls.
Organizations control their prompts, optional identity fields, access settings, recipients, and responses to submissions. Workspace administrators are responsible for providing appropriate notices, limiting administrator access, protecting account credentials, responding lawfully and fairly, and meeting applicable employment, privacy, whistleblowing, recordkeeping, and data-residency requirements.
We use safeguards designed to reduce unnecessary exposure, including randomly generated public-link tokens, application-level encryption for supported stored content, organization-specific encryption keys, access controls, retention rules, and controls intended to reduce caching and logging on sensitive routes. HTTPS must also be correctly enabled and maintained in the production deployment.
These measures reduce risk but do not eliminate it. UnspokenBox does not guarantee absolute security, anonymity, confidentiality, uninterrupted access, or protection against every attack. A compromised device or server, malicious software, stolen credentials, misconfiguration, service-provider failure, or systems outside our control may expose information.
UnspokenBox is designed to avoid attaching raw network addresses to submissions and to let people omit their name and email unless a form clearly requests them. This meaningfully reduces direct identification within the UnspokenBox administrator interface.
However, anonymity can depend on the sender’s environment. An employer, school, network operator, device administrator, internet provider, security gateway, or other organization may operate systems outside UnspokenBox that record activity or inspect traffic. Timing, writing style, voluntarily supplied details, attachments, managed devices, and workplace procedures may also reveal identity. Users seeking additional privacy should use a personal device and connection they trust, avoid identifying details, and review the form before submitting.
UnspokenBox is not an end-to-end encrypted messaging service. Authorized workspace administrators can read submissions, and the application must decrypt and process content to provide the service. Anyone who gains unauthorized control of a relevant account, device, server, or encryption key may be able to access information despite our safeguards.
Hosting, email, payment, network, storage, and security providers may process limited information as needed to operate their services. Their availability, security, retention, and logging practices are not entirely controlled by UnspokenBox.
Public links contain high-entropy access tokens intended to make accidental discovery impractical. Organizations should still share links carefully and use passcodes or expiry controls when additional access restriction is appropriate. Anyone who receives a working link and any required passcode may be able to view its prompt and submit a response.
Submission data is currently scheduled for removal after 12 months, unless it is deleted earlier or a different lawful arrangement applies. Anonymous reply conversations are scheduled for removal after 30 days without activity. These periods describe the application’s retention rules, not a promise of deletion at an exact moment: cleanup depends on scheduled processes, and limited copies may remain temporarily in backups, logs, or records kept for security, legal, or operational reasons. Organizations should export or remove data according to their own obligations.
Customers are responsible for maintaining appropriate exports or backups of information they need to retain, protecting their account credentials, keeping their recovery email current, and preserving access to authorized administrators. UnspokenBox is not a permanent archival or backup service.
To the fullest extent permitted by applicable law, UnspokenBox does not guarantee that deleted, expired, corrupted, overwritten, inaccessible, or otherwise lost data can be recovered. We also cannot guarantee restoration of an account when ownership cannot be verified, recovery information is unavailable, security requirements cannot be satisfied, or the encryption material required to recover content is no longer available. Although we may provide reasonable support when practical, we are not responsible for recreating, retrieving, or restoring lost data, submissions, encryption keys, or account access, except where responsibility cannot lawfully be excluded.
Paid plans are billed according to the price and billing period shown at checkout, which controls if it differs from marketing copy. Taxes may apply. Usage limits, storage allowances, attachment limits, and fair-use thresholds form part of the selected plan and may be enforced technically. Payment processing is provided by a third party. Unless required by law or stated at checkout, fees already paid are not automatically refundable. We may restrict abusive or unusually burdensome usage to protect the service.
The service is provided without a guaranteed uptime or response-time commitment unless a separate written agreement says otherwise. Maintenance, security incidents, email filtering, third-party failures, or events beyond reasonable control may cause interruptions, delayed or missing notifications, or data loss. Email alerts and replies are convenience features and should not be the only method used for urgent, emergency, legal, safeguarding, or whistleblowing matters.
We may improve, replace, limit, or discontinue features. Where practical, we intend to give advance notice of material changes affecting paid customers, but we do not promise notice when an urgent security, legal, or operational change is required.
We may suspend access when reasonably necessary to address unlawful activity, abuse, non-payment, security risk, or material breach of these terms. Account holders may stop using the service at any time, subject to their billing commitment and applicable deletion or export procedures.
Questions, security concerns, and abuse reports can be sent to support@unspokenbox.com. Please do not include sensitive submission content in an ordinary email.