Legal

Privacy policy

This policy explains how UniMap processes personal data in the iOS app and on this website.

Last updated: 23 September 2026

Requests sent through the website

The beta access, institutions, companies and contact forms collect your email address, the type of request, the page it was sent from and the time you agreed to be contacted. Your name, institution or company and message are kept if you fill them in; the organisation is required for institution and company requests.

We use this data to reply to your request and to arrange beta access or the conversation you asked for. Submitting a form does not create an account, does not automatically send an invitation and does not subscribe you to a newsletter. Requests are only accessible to UniMap’s authorised global administrators.

To limit abuse we use temporary counters and a protected identifier derived from the IP address, without storing the raw IP address in the requests table. You can ask for your request to be deleted, or withdraw your consent to be contacted, at the address below.

What data we process

Account and profile data: name, email address, phone number, date of birth, profile photo, bio and the account’s internal identifier.

Academic data: university, faculty, specialisation, master’s programme and year of study.

Content provided by authorised users, including announcements and the images attached to them.

Technical and usage data: app version, device model, operating system version, session identifier, announcement views and interactions, sign-ins and audit logs.

How we use the data

We use the data for sign-in, showing your academic profile, filtering relevant content, managing roles, providing the maps and improving the app’s stability.

Precise location is only accessed with your iOS permission and is used to centre the map and identify nearby buildings. UniMap does not use it for advertising and does not keep it in your profile.

We do not sell personal data, we do not show ads and we do not track you across apps or websites.

Providers and transfers

Supabase provides the authentication, database and storage infrastructure. Apple provides app distribution, TestFlight and operating system services. Google may process data when you choose to sign in with Google.

These providers process data under their own terms and security measures. Data may be processed outside the European Economic Area, with the applicable contractual safeguards.

Retention and security

We keep data for as long as the account is active and for as long as needed to run the service, meet legal obligations, prevent abuse and defend our rights. Technical logs and institutional content may have different retention periods.

We use access control, row-level security rules, encrypted connections and keep privileged keys separate from the mobile app. No system can guarantee absolute security.

Your rights

You can ask to access, correct, export, restrict or delete your data, and you can object to certain processing. You can update your profile in the app.

You can permanently delete your account from My account → Settings → Permanently delete account. Deletion removes your profile, roles, sessions and associated personal data. Institutional content that must be kept is anonymised.

You can withdraw location and notification permissions at any time in iOS Settings. You also have the right to lodge a complaint with the competent data protection authority.

Contact

For questions or requests about your personal data, write to cosmintrricaa@gmail.com.