Privacy Policy

Last updated: August 2026

This policy explains what UNC collects about you, why, how long we keep it, and what you can make us do with it. It is written to be read rather than to be impenetrable — if any part of it is unclear, ask us and we will explain it in plain terms.

It covers the UNC mobile application, unctech.co, and the related services we operate (together, the "Service"). The UNC Foundation is the data controller for the personal data described here.

1. What we collect

1.1 Information you give us

  • Account details: name, email address, username, and password (stored only as a bcrypt hash)
  • Profile details: date of birth, country, phone number, avatar
  • Identity verification (eKYC): government-issued ID document, and a liveness selfie
  • Trust Circle contacts you nominate for account recovery
  • Linked social accounts, where you choose to connect them
  • Anything you send us in support messages or in-app chat

1.2 Information collected automatically

  • Device type, operating system, and device identifiers
  • Usage data: features used, session length, mining activity
  • Log data: IP address, access times, and pages viewed
  • Push notification tokens, so we can tell you when a session ends
  • Signals used to detect bots and duplicate accounts, including device fingerprinting and behavioural patterns

1.3 What we deliberately do not collect

We do not collect your seed phrase, because UNC does not use one. We do not ask for your password, PIN, or 2FA codes outside the app's own login screens — and nobody from UNC will ever ask you for them by message, email, or call.

2. Why we use it, and our legal basis

PurposeLegal basis
Creating and running your accountPerformance of a contract
Identity verification (eKYC) and preventing duplicate accountsLegal obligation and legitimate interests
Fraud, bot, and abuse detectionLegitimate interests
Security monitoring and incident investigationLegitimate interests
Service notifications (session ended, funds received)Performance of a contract
Marketing messagesConsent — withdrawable at any time
Meeting AML and sanctions obligationsLegal obligation

We do not sell your personal data, and we do not share it with third parties for their own advertising.

3. Who we share it with

  • Identity verification providers, who process your ID document and selfie to confirm you are a real, unique person
  • Infrastructure providers who host our servers and databases
  • Push and email providers, to deliver notifications you have asked for
  • Law enforcement and regulators, where we are legally required to respond
  • A successor entity, if UNC is ever acquired or merged — you would be told before your data moved

Every processor is bound by contract to use your data only for the purpose we engaged them for.

4. How long we keep it

  • Account data: for as long as your account is open
  • eKYC records: typically five years after the account closes, because anti-money-laundering law requires retention
  • Transaction and ledger records: retained for audit purposes; on-chain records, once mainnet is live, are permanent and cannot be deleted by anyone
  • Security and access logs: generally up to 12 months
  • Support correspondence: up to 24 months

5. How we protect it

All traffic is encrypted in transit using TLS. Passwords and wallet PINs are stored only as bcrypt hashes, so they cannot be read back by us or by anyone who obtains the database. Access to identity documents is restricted to staff who need it for verification. Sign-in attempts, reset codes, and PIN entries are rate limited and locked after repeated failures, and changing your password or PIN immediately invalidates every existing session on every device.

The full set of controls is described on our Security page. No system is perfectly secure, and we will not claim otherwise. If a breach occurs that is likely to put your rights at risk, we will notify you and the relevant regulator without undue delay, and within 72 hours where the law requires it.

6. Your rights

Depending on where you live — and in full if you are in the UK, EU, or EEA — you have the right to:

  • Access a copy of the personal data we hold about you
  • Correct anything inaccurate
  • Delete your data, except where we are legally required to keep it (eKYC records being the main exception)
  • Export your data in a portable, machine-readable format
  • Object to or restrict processing based on legitimate interests
  • Withdraw consent at any time, where consent was the basis
  • Complain to your local data protection authority

To exercise any of these, email privacy@unctech.co. We respond within 30 days. We will not charge you for a request or treat you differently for making one.

One honest limitation: once mainnet is live, on-chain transaction records are permanent and outside anyone's control, including ours. We can delete your account data from our systems; we cannot delete a blockchain entry. Please factor that in.

7. International transfers

UNC operates globally, so your data may be processed outside your country. Where data leaves the UK or EEA, we rely on Standard Contractual Clauses or an equivalent safeguard to keep the same level of protection with it.

8. Children

The Service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

9. Cookies

Our website uses cookies for essential functionality and anonymised analytics. See our Cookie Policy for the detail and your choices. The mobile app does not use advertising cookies.

10. Changes to this policy

When we change this policy we update the date at the top. For changes that materially affect your rights we will notify you in the app or by email before they take effect, rather than relying on you to notice.

11. Contact

Privacy questions and data requests: privacy@unctech.co
Security reports: security@unctech.co
Everything else: our contact page