Privacy Policy
Effective 9 July 2026 · Version 2026-07-09.v1
This Privacy Policy explains what data UniOps collects, what we do with it, who we share it with, and how you can control it. We try to collect the minimum data needed to run the Service well, and to be honest about the parts we have to route through infrastructure providers. UniOps is an unusual product: to give your team shared access to tools without sharing passwords, our software handles the login sessions and, in some cases, the network traffic of those tools. This Policy describes that in plain terms.
1. Who controls your data
UniOps, Inc. (a Delaware, USA corporation) is the data controller for personal data we collect about you as a visitor to our public website and as an account holder. For data processed inside a workspace, including anything about how workspace members use tools, UniOps acts as a processor on behalf of the workspace owner, who is the controller. If you are a workspace member using an account your employer or team set up, direct data-subject requests to your workspace owner first; we will help them respond.
Contact for privacy matters: team@uniops.app.
2. What we collect
Account and identity data
- Email address, display name, and password hash (we never store your password in plain text).
- Two-factor secret (encrypted at rest) and backup codes (hashed).
- Email-verification timestamp and the IP address and user-agent of the verification request.
Workspace and tool configuration
- Workspace name, plan, billing email, owner mapping, role and permission assignments.
- Which tools a workspace has connected, their health state, and rotation timestamps.
- Audit-log entries describing actions taken in the workspace (who did what, when, and from which IP, with the IP stored as a salted hash).
Shared-tool access material
This is the core of what UniOps does, so we describe it directly. To let authorized members open a connected tool without seeing its password, our desktop app captures and our servers store the sign-in state for that tool:
- Session cookies for each connected tool, and for some tools the tool's browser local storage, session storage, and IndexedDB records (these are where some tools keep their login tokens).
- Optionally, tool login credentials (username and password) and one-time-password (2FA) seeds and backup codes, where your workspace chooses to store them so the Service can sign in or re-authenticate on your behalf.
- Optionally, a shared account your workspace designates for a provider (for example a shared Google account), stored the same way.
All of this material is encrypted at rest with workspace-scoped keys wrapped by an AWS-KMS master key, is transmitted only over TLS, and is used only to open the relevant tool for members your workspace has authorized. It is never sold, never used for advertising, and never shared with other workspaces. You control which tools and credentials exist; removing a tool purges its stored access material.
Network routing of tool sessions
To keep shared tool sessions stable and to present a consistent connection to each tool, traffic from your tool sessions is routed through third-party network providers rather than straight from your device:
- Most tool traffic egresses through a commercial proxy network (currently Webshare, and for some tools Bright Data). These providers carry your tool-session traffic and see connection metadata for it.
- For a limited set of higher-protection tools, traffic is routed through an unblocking service (currently Decodo) that establishes the secure connection to the tool on your workspace's behalf. In that mode the service processes the full content of those tool requests and responses in order to return the page to you.
These providers act as our subprocessors under written agreements and are listed at Subprocessors. We do not route your traffic through them for any purpose other than operating the tool session you asked to open.
Workspace activity and usage measurement
If you use UniOps as part of a workspace, the Service measures activity so your workspace admins can understand tool usage and time worked. This is workspace data, controlled by your workspace owner. We record:
- Presence and active time: when you are signed in and active, and how much of that time is spent in a connected tool versus elsewhere in the app. Measurement pauses while your machine is idle, asleep, or locked.
- Tool usage: which connected tools you open and for how long, as session counts and minutes per day.
- Desktop application usage: for members who run the desktop app, how long specific desktop applications are open and in the foreground. This covers applications the Service tracks by default and any additional applications you or your admin choose to add. We measure only whether an application is running and frontmost and for how long.
- Certain sensitive in-tool actions: for a small, defined set of tools (for example advertising platforms), a record that a sensitive action occurred, such as a billing or payment-method change, together with a limited set of whitelisted fields needed for an audit trail.
We do not capture the contents of your work. We do not record the web pages or URLs you browse, page titles, screenshots, keystrokes, message contents, or the contents of any file or application. This usage data is aggregated per member per day and shown to your workspace admins in the usage dashboard. It is used only for usage analytics within your workspace.
Device and connection data
- Session records store the IP address and user-agent of your app sessions, used to secure your account and investigate abuse.
- The desktop app reports its version and last-seen time so we can support and update it.
- Server access logs (URL, status code, response time, hashed IP, user-agent).
- Error and performance reports collected via Sentry. Request context is redacted before it leaves our servers to drop session tokens, auth headers, cookies, and known secret-bearing fields. Error reports may include a short, masked replay of the page where an error occurred, with all text and media masked.
Billing data
- Plan, seat count, addon list, renewal date, last-payment status, and identifiers from our payment processor.
- We do not store full payment-card numbers. Our processor (Whop) tokenizes payment instruments; we keep only the tokenized handle and display details such as the last 4 digits and card brand.
Communications and support
- Transactional email we send you (verification, password reset, invitations, tool-relink alerts, receipts, exports) via our email provider.
- If you opt in to SMS alerts, the mobile number you provide and a record of your consent, sent via our SMS provider. See section 13.
- Support requests you send us and our replies.
Cookies, pixels, and marketing analytics
Our public website uses a small number of cookies and, where enabled and permitted, third-party advertising and analytics tags from Meta (Facebook) and X (Twitter) to measure the performance of our marketing. These tags can set their own cookies and can receive identifiers such as a hashed version of your email, hashed account identifier, click identifiers, and the value and plan of a purchase. How these load depends on your region and your consent choice, described in section 6 and in our Cookie Policy. These tags also load on signed-in pages, other than inside the embedded desktop shell, subject to the same region and consent rules.
3. How we use it
- Operate the Service: authenticate you, open connected tools for authorized members, coordinate concurrent access, and render the dashboard.
- Measure workspace usage: provide your admins the presence, time, and usage analytics described above.
- Bill and renew: verify seat counts, process renewals, and prevent payment fraud.
- Secure: detect abuse, rate-limit attackers, and investigate incidents.
- Support: respond to your requests with enough context to help.
- Improve: understand which features are used, at a coarse level.
- Market: measure the performance of our advertising, subject to your choices in section 6.
- Comply with law: respond to lawful requests, meet tax obligations, and similar.
We do not sell your personal data for money. We do not train machine-learning models on your workspace data without an explicit, separate opt-in. Our sharing of website identifiers with advertising platforms may qualify as "sharing" or a "sale" under some US state privacy laws; section 6 tells you how to opt out.
4. Legal bases (GDPR / UK GDPR)
- Contract: processing necessary to provide the Service you or your workspace signed up for, including handling tool sessions and credentials.
- Legitimate interest: security, fraud prevention, service operability, and basic operational telemetry.
- Consent: non-essential cookies, advertising tags, and marketing email. You opt in and can withdraw at any time.
- Legal obligation: tax records, and KYC where required by our payment processor.
Where UniOps acts as a processor for workspace data, your workspace owner is responsible for having a lawful basis for the collection and for providing any notices its members require. See section 11.
5. Subprocessors
We use the companies listed at Subprocessors to provide the Service. Each is bound by a data-processing agreement that limits what it can do with the data we send it, and that page states the categories of data each one receives.
We notify workspace owners by email or in-product banner at least 30 days before adding a new subprocessor with material access to workspace data. If you object, you can cancel your subscription before the new subprocessor takes effect.
6. Advertising, "sharing," and your choices
On our public website we may use advertising and analytics tags from Meta and X, and a related server-to-server measurement connection, to understand which ads lead to signups and purchases. Depending on your region and choice, these can receive a hashed email, a hashed account identifier, advertising click identifiers, and purchase details. Under laws such as the California Consumer Privacy Act as amended (CPRA), this activity can be treated as "sharing" for cross-context behavioral advertising. We do not sell or share the contents of your workspace, and we do not knowingly share personal information of anyone under 16.
Your choices:
- In the EEA, UK, and Switzerland, advertising and non-essential analytics tags load only after you choose "Accept all" in our cookie banner. If you do not accept, they do not load.
- In the United States and elsewhere, these tags load by default. You can opt out by sending a recognized opt-out preference signal such as Global Privacy Control from your browser, which we honor as a valid opt-out for the browser that sends it, and you can control how Meta and X use advertising data through the ad-preference settings in your account on those platforms.
- You will not be denied service or charged a different price for exercising these choices.
7. How we share data
- With subprocessors, only to the extent needed to run their part of the Service.
- With advertising platforms, only the website measurement identifiers described in section 6, and only subject to your choices there.
- With workspace owners, admins, and other members, for the data inside that workspace, including the usage measurements in section 2.
- With law enforcement when compelled by valid legal process. We push back on overbroad requests and notify the affected customer unless legally barred.
- With a successor in a merger, acquisition, or asset sale, subject to the commitments in this Policy.
We do not share your workspace data or account data with data brokers, and we do not share it with third-party marketers.
8. International transfers
Our primary infrastructure runs in the United States. If you access UniOps from the European Economic Area, the United Kingdom, or Switzerland, your data will be transferred to and processed in the United States and other countries where our subprocessors operate. We rely on the EU Standard Contractual Clauses, and the UK and Swiss equivalents, as the legal mechanism for these transfers.
9. Retention
- Active account and workspace data: kept while your account or workspace is active.
- Stored tool access material: kept while the tool is connected; purged when the tool is removed or the account is deleted.
- Soft-deleted accounts and workspaces: retained for 7 days in a recoverable state, then hard-deleted. See Account settings for self-serve deletion.
- Usage and activity measurements: retained to power your workspace analytics; deleted with the workspace.
- Audit logs: retained for 18 months for security investigations, then deleted.
- Billing records: retained for 7 years to satisfy tax requirements.
- Cookie-consent decisions: retained for up to 26 months to evidence consent.
- Data export blobs: deleted 7 days after download, or 7 days after they were built if not downloaded.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to opt out of certain sharing, and to object to certain uses including direct marketing.
- Access and export: use "Export my data" in Account settings. We email a one-time link to a JSON download of your account, memberships, audit, consent, and ToS-acceptance history.
- Delete: use "Delete my account" in Account settings. We hard-delete after the 7-day grace window.
- Opt out of ad sharing: see section 6.
- Other requests (correction, restriction, objection, or an authorized-agent request): email team@uniops.app. We respond within the time the applicable law requires, and within 45 days for US state-law requests. We will not discriminate against you for exercising a right.
- You can complain to your local data-protection authority. In the EU that is the supervisory authority where you live; in the UK, the ICO.
11. Workspace members and workplace monitoring
If your workspace owner is your employer or team, note that the usage and activity measurements in section 2 (presence, active and worked time, tool usage, and desktop application usage) are visible to your workspace admins. UniOps provides these measurements to the workspace; the workspace owner decides how to use them and is the controller for that use. Your workspace owner is responsible for giving you any notice and obtaining any consent that the law where you work requires. If you have questions about how your workspace uses this data, contact your workspace owner.
12. Security
Workspace secrets and stored tool access material are encrypted at rest with workspace-scoped keys wrapped by an AWS-KMS master key, and each secret is bound to its workspace so it cannot be decrypted out of context. Network traffic to UniOps is TLS-only with modern ciphers. Database access is restricted to bastioned administrators, and access to KMS and to the bastion is logged. We run automated dependency scanning and periodic security reviews, and we operate a coordinated vulnerability-disclosure program. To report a vulnerability, email team@uniops.app. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.
13. Mobile and SMS messaging
If you opt in to SMS alerts (for example tool-relink notifications), we collect the mobile number you provide and a record of your consent, and we send messages through our SMS provider. Mobile opt-in data and consent are never shared with or sold to third parties or affiliates for their marketing or any other purpose. Message and data rates may apply, and message frequency varies. Reply STOP to opt out at any time, or HELP for help. Carriers are not liable for delayed or undelivered messages.
14. Children
UniOps is not directed to children under 16, and we do not knowingly collect data from them. If you believe a child has provided us data, contact team@uniops.app and we will delete it.
15. Changes
We may update this Policy from time to time. We will change the version stamp at the top, and for material changes we will notify you by email or in-product banner at least 14 days before the change takes effect.
16. Contact
Privacy questions: team@uniops.app. Security reports: team@uniops.app.