Your business is your business.
Privacy is not a feature we added. It is how Unlocked was built from the start — your conversations, your data and your payment details, all under your control.
For the full UK GDPR detail, see our Privacy Notice.
Four promises we keep, by design.
The principles below shape how the platform is engineered — not the small print you click past.
- 01
Your conversations are yours.
Everything discussed in a mentoring session stays between you and your mentor. We do not record sessions, we do not listen in, and we do not mine session content for any purpose. The platform facilitates the connection — it does not surveil it.
- 02
Your business data is not our product.
The briefs you submit, the challenges you describe, and the details of your business are used for one thing only: matching you with the right mentor. We do not sell your data, we do not share it with third parties, and we do not use it to train models or build profiles for advertising.
- 03
Your payment details never touch our servers.
All payments are processed by Stripe, an independently audited PCI Level 1 payment processor. Your card number is never stored on our servers, never logged, and never visible to our team. Stripe handles the transaction; we handle the mentoring.
- 04
You control your account.
You can view, export or delete your data at any time. If you close your account, your information is removed. No dark patterns, no retention tricks, no "we keep your data for 7 years just in case." You leave, your data leaves.
How we handle your data, area by area.
- Session briefs
- Visible only to you, your mentor, and the Unlocked support team when you request help with matching. Never used for marketing or analytics.
- Mentor matching
- Based on the expertise you request, not behavioural profiling. We match on what you tell us you need — not on what we infer from your activity.
- Communications
- Messages are encrypted in transit and when stored, and are never copied into emails or notifications. The Unlocked team does not read your conversations. They are not end-to-end encrypted: see how your messages are protected, below.
- Authentication
- Accounts are secured via AWS Cognito with SRP-based authentication. Passwords are never stored in plaintext and are never visible to our team.
- Infrastructure
- The platform runs on AWS in the EU (eu-west-1). All traffic is encrypted in transit. Messages, calendar access tokens and stored files are also encrypted at rest. Access to production systems is limited to the people who run the service.
- Third parties
- We use Stripe for payments and AWS for infrastructure. We do not use third-party analytics platforms that track individual users. No data is sold or shared for advertising.
How your messages are protected.
Messages are encrypted while they travel and while they are stored. Our team does not read your conversations.
- Step 1
You send a message
It travels from your device to our servers over an encrypted connection (HTTPS).
- Step 2
We lock it
Before it is saved, our server encrypts it with AES-256, a widely used encryption standard.
- Step 3
It is stored locked
The database only holds scrambled text. The key is kept apart from it, in AWS Secrets Manager.
q8ZtK1m0Xv4eP…Rw=
- Step 4
Unlocked for the conversation
When you or the person you are messaging open it, it is unlocked and sent to you over HTTPS.
Who can read your messages
- You and the person you are messaging
- Yes
- The conversation is between the two of you.
- Unlocked staff using the platform
- No
- The platform does not let our team open conversations between businesses and mentors.
- Our support team
- Limited
- Only conversations you have with Unlocked support, so that we can help you.
- Anyone with a copy of our database
- No
- Without the key, they would only see scrambled text.
- The people who run our systems
- Limited
- Because we hold the key, a small number of people with access to our production systems could technically unlock messages. They only do so to keep the service running, to look into a concern you report, or where the law requires it.
- Emails and notifications
- No
- They tell you who has written to you, never what they said.
What this is not
Messages are not end-to-end encrypted. With end-to-end encryption, only the devices in a conversation hold the key. We hold the key for your messages, which is what lets us run the service and help if you report a problem. If this ever changes, we will update this page. For the formal detail, see section 9 of our Privacy Notice.
Questions about how we handle your data? Write to hello@unlockedexpertise.com.
EB UNLOCKED LTD · Registered in England · UK VAT registered