UNET

Privacy Policy

Effective date: September 13, 2026

Privacy Policy

UNET is developed and operated in Poland. This Privacy Policy explains what data the current client and service process, what stays on your device, what may be sent to third parties for specific features, and what controls you have. UNET complies with the General Data Protection Regulation (GDPR).

1. Information We Process

1.1 Account and Security Data

  • Username and authentication material. During registration and login, the app sends your username, public authentication key, key salt, and key-derivation parameters needed for cryptographic challenge-response login. Your plaintext password is not sent to our servers.
  • Security features you enable. If you turn on two-factor authentication, we process the data required to generate and verify TOTP setup. If you configure a recovery key, we process the recovery public key, encrypted recovery data, and related key parameters.
  • Session and device labels. Authentication flows may include your app version and a human-readable device name so you can manage sessions and recognize devices later.
  • Anti-abuse checks. Registration currently uses proof-of-work and hCaptcha to reduce automated abuse.

1.2 Profile, Content, and Settings Data

  • Profile information. You may provide a display name, bio, avatar, private/public account status, mention settings, DM privacy rules, and reply visibility.
  • Content you create. Posts, comments, media uploads, voice messages, topic selections, place attachments, and other content you intentionally publish or send through the service.
  • Saved posts and comments. The references to posts and comments you save are stored on the server so your saved items can be synced across your devices. Only the reference metadata is stored; the underlying content is the same content you choose to save.
  • Reports and moderation input. If you report a post, comment, or account, we process the report reason and any description you include.
  • Preference data. The app stores and syncs settings such as notification preferences, recommendation controls, hidden topics, muted keywords, anonymous likes, and privacy-mode state.

1.3 Messaging and Notification Data

  • Direct-message encryption data. The app registers your public DM encryption key with the server. To support reinstall and multi-device restore, the app can also upload an encrypted backup blob of the private DM key that can only be decrypted with key material derived on your device.
  • Push registration data. Depending on the notification mode you choose, we may process a random per-device ID, an FCM token, or a UnifiedPush endpoint with related delivery fields such as VAPID/auth data.
  • Notification content and routing. When notifications are delivered, the selected provider or transport may process the title, body, and routing payload needed to deliver them.

1.4 Product Analytics

  • First-party usage events. The current app can send product analytics events to UNET's own backend. These events may include a session ID, event type, platform, app version, locale, screen name, and a limited event payload.
  • User control. You can disable analytics in the app settings. Enabling Privacy Mode also turns analytics off.

1.5 Data Stored Locally on Your Device

  • Securely stored session data. Access tokens, refresh tokens, key salt, session IDs, multi-account metadata, and DM key material are stored locally on your device, using secure storage where the platform supports it.
  • Local settings and caches. The app also stores notification mode, biometric-login toggle, recommendation client settings, chat-backup settings, and other local state needed for the app to work well.
  • User-created backups. If you export DM encryption keys or create chat backups, those backup files are created on your device and remain wherever you choose to store them.

1.6 Server-Side Session Data

  • IP addresses. When you authenticate, your IP address is collected from the connection and encrypted using AES-256-GCM into your session metadata. This is used for session management, rate limiting, and abuse prevention.
  • Device information. The server receives your User-Agent string, a device name you provide, and a device identifier. The device ID is SHA-256 hashed before storage. All device metadata is encrypted in session records.
  • Browser session identifiers and device public keys may also be stored as part of session metadata for additional security and device binding.

1.7 Analytics Events

  • When enabled, the server receives analytics events that may include a session ID, event type, platform, app version, locale, screen name, a limited JSON payload, and a country code derived from the connection.
  • Analytics events are forwarded to a separate analytics microservice backed by ClickHouse for aggregated processing.
  • Analytics are disabled by default for authenticated users. You must explicitly opt in. Enabling Privacy Mode also disables analytics.

1.8 Feed and View Tracking

  • Post view counts are tracked using anonymous one-way SHA-256 hashes. No user ID is stored in the view deduplication table. Views are rate-limited to 60 per minute per user, and the author's own views are not counted.
  • You can disable view counts being shown on your posts through the `show_view_counts` setting in the app.
  • When Privacy Mode is off and analytics are enabled, feed impression events containing post ID and position may be sent for recommendation improvement.

1.9 Encrypted Content at Rest

  • Post content, comments, bio, and website text are encrypted server-side with AES-256-GCM before being written to the database. The decryption keys are managed server-side and are not accessible through direct database access.
  • GIF URLs are also encrypted separately.

2. Permissions and On-Device Processing

  • Photo library and files. Used when you select media to upload or attach.
  • Camera. Used for QR web-login scanning and optional camera capture for image/video posting or messaging flows.
  • Microphone. Used when you record voice messages.
  • Notifications. Used to display local and remote notifications when you enable them.
  • Biometrics. Used only through the operating system if you enable biometric unlock or login. UNET does not receive your biometric template.

The app requests these permissions only when you use the related feature. It does not access contacts, and it does not use camera, microphone, or location in the background.

For JPEG uploads, the client strips EXIF and comment metadata before upload. That includes common fields such as GPS coordinates, camera model, and timestamps.

3. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation, UNET processes personal data on the following legal bases:

  • **Legitimate interests (Art. 6(1)(f) GDPR).** Product analytics, spam and abuse detection, ban-evasion prevention, and service improvement are based on our legitimate interest in operating and securing the service.
  • **Consent (Art. 6(1)(a) GDPR).** Where required by law, we will ask for your consent before processing data for specific purposes, including optional federation when you enable it. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • **Legal obligation (Art. 6(1)(c) GDPR).** We may process personal data to comply with applicable legal obligations.

4. How We Use Information

  • Creating and authenticating accounts.
  • Maintaining sessions and allowing session revocation.
  • Delivering posts, comments, follows, direct messages, and notifications.
  • Applying privacy settings, moderation actions, blocks, and report handling.
  • Running recommendation controls and feed personalization when you use those features.
  • Improving app stability and product behavior through first-party analytics, if enabled.
  • Detecting spam, abuse, ban evasion, and other security issues.
  • Delivering federated content and related ActivityPub activities when you enable federation.

5. Direct Messages and Encryption

UNET direct messages are end-to-end encrypted in the current app. The service stores the public encryption key needed to route encrypted messages and may store an encrypted backup blob of your private DM key so your device can restore it later.

End-to-end encryption protects message content, but it does not hide all metadata. The service still needs to process metadata such as participants, message timing, delivery/unread state, and notification-routing data.

Direct messages are available only between UNET accounts. There is no DM interoperability with fediverse / remote accounts.

6. Sharing, Disclosure, and Third Parties

We do not sell or rent personal data to advertisers or data brokers.

We may share or expose data only in the following limited ways:

  • Other users. Content from public accounts is visible to other users. If you switch to a private account, followers must be approved before they can view protected posts.
  • Fediverse / ActivityPub. If you enable federation, profile information, posts, comments, media, follows, likes, and other interactions may be delivered to independent remote servers and their users. Those servers are not controlled by UNET and may retain or further redistribute copies according to their own policies.
  • OVH S3-compatible object storage. Media files you upload (images, videos, voice messages, audio, avatars, banners) and data exports are stored on OVH S3 infrastructure.
  • PostgreSQL and Redis. Your data is stored in a PostgreSQL database and cached in Redis for performance. Both are operated by UNET and subject to the same access controls.
  • BullMQ. Background job processing such as video transcoding and data export generation uses BullMQ queues backed by Redis.
  • Go Analytics Microservice (ClickHouse). If analytics are enabled, anonymized aggregate events are forwarded to a separate analytics pipeline for product improvement.
  • Arachnid Shield. Photo and video uploads are scanned for CSAM material by Arachnid Shield before storage, as required by applicable law.
  • Cloudflare. UNET uses Cloudflare as a CDN and proxy. Cloudflare processes connection metadata (IP, TLS version, request timing) for routing and DDoS protection.
  • GIPHY. The GIF search feature communicates with GIPHY's API. Your search queries are sent to GIPHY when you look for GIFs, subject to GIPHY's privacy policy.
  • Lingvanex. On-demand post translations are processed by Lingvanex. The post content you choose to translate is sent to Lingvanex for that purpose.
  • Registration protection. hCaptcha is used during registration to prevent automated abuse.
  • Legal compliance. We may disclose information if required by applicable law or a binding legal order.

7. Fediverse and Federation

Federation with the fediverse is optional. When disabled, your account remains local to UNET for ActivityPub delivery purposes.

  • After you enable federation, data such as profile information, posts, comments, media, follows, likes, and other interactions may leave UNET and be processed by independent servers.
  • Even if your account is private, some federated delivery may still occur depending on approved followers and remote recipients.
  • UNET does not own or control those remote servers and therefore does not control 100% of federated copies of your data.
  • If you disable federation or delete your account, we delete or stop processing the relevant data on UNET systems and send deletion-related ActivityPub signals to inform remote servers. We take reasonable steps to do so, but we cannot guarantee that every remote server will honor those signals or permanently erase copies.
  • Remote-server privacy, retention, moderation, and security practices are outside UNET's control.

8. International Data Transfers

UNET is operated from Poland within the European Economic Area. When we use third-party services (such as push notification providers) that may involve data transfers outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses adopted by the European Commission or adequacy decisions by the European Commission under Art. 45 GDPR.

9. What We Do Not Collect or Use

  • We do not require your real name, email address, or phone number to create an account.
  • We do not use third-party advertising SDKs, ad pixels, or behavioral ad trackers.
  • We do not access contacts or run background camera/microphone/location collection.
  • We do not store your plaintext password.

10. Your Rights Under GDPR

If you are located in the European Economic Area, you have the following rights under the GDPR:

  • **Right of access (Art. 15 GDPR).** You may request confirmation whether we process your personal data and obtain a copy of the data we hold about you. This includes an end-to-end encrypted export of your account data upon request.
  • **Right to rectification (Art. 16 GDPR).** You may request that we correct inaccurate or incomplete personal data.
  • **Right to erasure (Art. 17 GDPR).** You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent and no other legal basis applies. Account deletion can also be initiated directly from the app. Erasure on UNET systems does not guarantee erasure of federated copies already held by independent remote servers.
  • **Right to restriction of processing (Art. 18 GDPR).** You may request restriction of processing under certain conditions.
  • **Right to data portability (Art. 20 GDPR).** You may request receipt of your personal data in a structured, commonly used, and machine-readable format and have it transmitted to another controller. UNET provides an end-to-end encrypted data export feature for this purpose.
  • **Right to object (Art. 21 GDPR).** You may object to processing based on legitimate interests, including profiling for analytics. You can disable analytics entirely in your app settings.
  • **Right to withdraw consent.** Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal. You can disable federation in the app where that control is available.
  • **Right to lodge a complaint.** You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. The competent authority for UNET is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO) in Poland.

To exercise your rights, contact us at [email protected]. We will respond within the timeframes required by applicable law. We may need to verify your identity before processing your request.

11. Your Controls and Choices

  • Privacy controls. You can switch between public and private account, manage DM privacy, control who can mention you, configure reply visibility, and manage blocked users.
  • Privacy Mode. A comprehensive privacy setting that clears IP addresses from all active sessions, requests deletion of analytics events, blocks media uploads, zeros out content embeddings, clears the seen posts cache, and blocks external API requests from the client.
  • Federation control. You can enable or disable federation where the product exposes that setting. Disabling federation stops new ActivityPub delivery from UNET but does not guarantee removal of copies already held by remote servers.
  • Analytics control. Analytics are disabled by default for authenticated users. You can review and change your analytics preference at any time in the app settings.
  • View count control. You can disable view counts being displayed on your posts through the app settings.
  • Recommendation controls. You can hide AI-generated content and NSFW content; manage hidden topics and muted keywords; and tune multiple recommendation settings.
  • Notification controls. You can choose notification categories and delivery mode, including FCM, UnifiedPush, WebSockets, or no push delivery.
  • Security controls. You can enable two-factor authentication, configure a recovery key, revoke sessions, and view session details including associated IP and device information.
  • Data export. You can request an end-to-end encrypted export of your account data. The export is encrypted with your public key (NaCl box + secretbox) and stored temporarily in S3 for 7 days.
  • Deletion. You can delete your account from the app. The current client also includes an inactivity-based auto-delete option that you can enable yourself, with a configurable grace period ranging from 3 to 1095 days. A warning notification is sent 7 days before auto-deletion.
  • Backup/export tools. The current mobile client includes export tools for DM encryption keys and chat backups.

12. Data Retention

  • Account and profile data are retained while your account exists, unless you delete specific items earlier.
  • Posts, comments, and other content remain until you delete them or delete your account.
  • Push registrations and session data remain until they expire, are replaced, or are removed during logout, device unregistration, or account deletion.
  • Refresh tokens are valid for up to 30 days from last use (sliding window) with an absolute maximum of 30 days from creation.
  • You can have up to 50 concurrent sessions. When the limit is reached, the least recently used session is revoked.
  • Data exports are stored in S3 for 7 days and then automatically deleted.
  • S3 orphan files (media no longer referenced in the database) are cleaned up after 1 hour.
  • Post view hash data is stored anonymously using one-way SHA-256 hashes. No user ID is associated with individual view records.
  • Local backups and exported files remain on your device or chosen storage location until you remove them.
  • If you enable inactivity-based auto-delete, server-side deletion follows the schedule you selected.
  • Federated copies held by independent remote servers are retained according to those servers' own policies and are outside UNET's retention schedule.

13. Children's Privacy

UNET is not intended for children under 13. If we learn that we have unintentionally processed data from a child under 13, we will remove it. If you believe this has happened, contact [email protected].

14. Changes to This Policy

We may update this Privacy Policy when the product changes. The updated version will be posted on this page with a new effective date.

15. Data Controller and Contact

**Data Controller:**

Maksym Taranenko

Email: [email protected]

We are committed to protecting your privacy and processing your data in accordance with the General Data Protection Regulation (GDPR).

If you have questions about this Privacy Policy or wish to exercise your GDPR rights, please email us at [email protected].

You also have the right to lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland

16. Server-Side Encryption and Security

UNET applies encryption at multiple layers to protect your data:

  • **Content at rest.** Post content, comments, bio, website text, and GIF URLs are encrypted server-side using AES-256-GCM before being written to PostgreSQL. The encryption keys are managed server-side and are not accessible through raw database access.
  • **Session metadata.** IP addresses, User-Agent strings, device names, and other session metadata stored in refresh tokens are encrypted with AES-256-GCM using a per-session encryption key.
  • **Direct messages.** DM content is end-to-end encrypted. The server only stores encrypted payloads and cannot decrypt message contents.
  • **Data exports.** GDPR data exports are encrypted with your public key using NaCl box (curve25519-xsalsa20-poly1305) combined with secretbox before being stored in S3.
  • **Device binding.** Sessions can be cryptographically bound to a specific device using Ed25519 key proofs during refresh token rotation.

17. Account Deletion

17.1 User-Initiated Deletion

When you delete your account from the app, the deletion is verified through a cryptographic challenge signed with your private key. Upon successful verification, the following data is permanently removed in a single transaction:

  • Preferences and signals (topic preferences, hashtag preferences, recommendation settings, engagement data, muted keywords, not-interested signals)
  • Social data (notifications, follow requests, follows, blocks, reports, appeals, audit logs)
  • Interactions (likes, reposts, comment likes, saved posts, saved comments, post comment permissions, profile music tracks)
  • Content (comments, posts with cascading media and mentions)
  • Messenger data (messages, conversations)
  • Authentication data (refresh tokens, push tokens)
  • The user record itself

If any step fails, the entire deletion is rolled back to prevent partial data loss.

If federation was enabled, we also send deletion-related ActivityPub signals and take reasonable steps to inform remote servers about the deletion. We do not guarantee that independent remote servers will process those signals or permanently remove federated copies.

Deleting your account permanently ends access to optional account features tied to that account.

17.2 Inactivity-Based Auto-Deletion

You can enable automatic account deletion after a period of inactivity. Available grace periods are 3, 7, 14, 30, 90, 180, 365, 730, or 1095 days. A warning notification is sent 7 days before the scheduled deletion. The system re-verifies your last activity timestamp immediately before deletion to prevent race conditions.

If you have questions about the deletion process or need assistance, please contact [email protected].