Last updated: August 2026
This policy explains what UNC collects about you, why, how long we keep it, and what you can make us do with it. It is written to be read rather than to be impenetrable — if any part of it is unclear, ask us and we will explain it in plain terms.
It covers the UNC mobile application, unctech.co, and the related services we operate (together, the "Service"). The UNC Foundation is the data controller for the personal data described here.
We do not collect your seed phrase, because UNC does not use one. We do not ask for your password, PIN, or 2FA codes outside the app's own login screens — and nobody from UNC will ever ask you for them by message, email, or call.
| Purpose | Legal basis |
|---|---|
| Creating and running your account | Performance of a contract |
| Identity verification (eKYC) and preventing duplicate accounts | Legal obligation and legitimate interests |
| Fraud, bot, and abuse detection | Legitimate interests |
| Security monitoring and incident investigation | Legitimate interests |
| Service notifications (session ended, funds received) | Performance of a contract |
| Marketing messages | Consent — withdrawable at any time |
| Meeting AML and sanctions obligations | Legal obligation |
We do not sell your personal data, and we do not share it with third parties for their own advertising.
Every processor is bound by contract to use your data only for the purpose we engaged them for.
All traffic is encrypted in transit using TLS. Passwords and wallet PINs are stored only as bcrypt hashes, so they cannot be read back by us or by anyone who obtains the database. Access to identity documents is restricted to staff who need it for verification. Sign-in attempts, reset codes, and PIN entries are rate limited and locked after repeated failures, and changing your password or PIN immediately invalidates every existing session on every device.
The full set of controls is described on our Security page. No system is perfectly secure, and we will not claim otherwise. If a breach occurs that is likely to put your rights at risk, we will notify you and the relevant regulator without undue delay, and within 72 hours where the law requires it.
Depending on where you live — and in full if you are in the UK, EU, or EEA — you have the right to:
To exercise any of these, email privacy@unctech.co. We respond within 30 days. We will not charge you for a request or treat you differently for making one.
One honest limitation: once mainnet is live, on-chain transaction records are permanent and outside anyone's control, including ours. We can delete your account data from our systems; we cannot delete a blockchain entry. Please factor that in.
UNC operates globally, so your data may be processed outside your country. Where data leaves the UK or EEA, we rely on Standard Contractual Clauses or an equivalent safeguard to keep the same level of protection with it.
The Service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
Our website uses cookies for essential functionality and anonymised analytics. See our Cookie Policy for the detail and your choices. The mobile app does not use advertising cookies.
When we change this policy we update the date at the top. For changes that materially affect your rights we will notify you in the app or by email before they take effect, rather than relying on you to notice.
Privacy questions and data requests: privacy@unctech.co
Security reports: security@unctech.co
Everything else: our contact page