Privacy Policy

Version 1.1 · Last updated: June 18, 2026 · Effective: June 18, 2026

UniTalk ("UniTalk", "we", "our", "us") operates the UniTalk mobile app and related services (the "Service") — a verified, course-based chat platform for university students. This policy explains what we collect, why, how we share it, and your choices. We aim to comply with Canada's PIPEDA and Quebec's privacy law (Law 25), and Apple's App Store requirements.

In plain terms: We collect what's needed to run course chats, DMs, and study features. We don't sell your data, show ads, or track you across other apps. AI features send some of your content to OpenAI and Tavily. UniTalk is not end-to-end encrypted. Deleting your account disables access immediately and removes your personal info within 10 days, while keeping your past messages in anonymized form ("Deleted User").

1. Who we are & contact

Operator: UniTalk.
Person in charge of personal information: UniTalk Privacy Officer.
Contact: team@unitalk.ca

We maintain internal governance practices covering the retention, destruction, and handling of personal information, and the handling of privacy questions and complaints. To exercise a privacy right, or to raise a question or complaint, contact our Privacy Officer at the address above.

2. What we collect

Account & profile: your name, university email, university, and optionally your year, major, bio, LinkedIn URL, and profile photo. We do not store your password — sign-in is handled by our provider, Supabase Auth.

Content you create: messages in course chats, project chats, and direct messages — including text, images/files, and voice messages; polls and votes; calendar events; syllabi you upload and the text we extract from them; and questions/images you send to our AI assistant, Younen. Images you upload may contain embedded metadata (such as EXIF, which can include the time taken and, if your device records it, location). We do not currently strip this metadata, so please avoid uploading images with sensitive embedded data.

Verification, safety & technical: one-time email verification codes; reports you file and users you block; a record that you accepted our Terms/Privacy Policy (with date and IP address); your push-notification token (if enabled); and IP address and request metadata (for example, device OS version, app version, request timestamps, and standard HTTP headers) used transiently for security and abuse-prevention; and limited server error logs.

We do NOT collect: phone number, location/GPS, your contacts, advertising identifiers (IDFA), third-party analytics or crash SDKs, cookies (in the app), or payment information (the app is free).

3. How we collect it

Directly from you; from your device with your permission (camera, photo library, microphone for voice messages, Face ID for optional sign-in, notifications); and automatically in limited form (IP, request metadata, logs).

If you enable Face ID, biometric authentication is performed entirely by iOS on your device. UniTalk does not receive, collect, or store your face data or any biometric information.

4. Why we use it

  • Provide the Service: accounts, real-time messaging, chats and DMs.
  • Verify you're a student (match your email to your university; send a code).
  • Power AI study features (see Section 5).
  • Notifications, safety/moderation, security, reliability, and legal compliance (for example, responding to lawful requests, meeting our obligations under PIPEDA and Quebec's Law 25, and enforcing our Terms).

We rely on your consent (given at sign-up) and on processing necessary to provide the features you use — for example, delivering your messages and running course chats. You can withdraw consent (Section 11).

5. AI (Younen) and third-party AI processing

UniTalk includes an AI study assistant, "Younen," plus AI that verifies courses and reads syllabi. Your AI requests are not private to UniTalk — relevant content is sent to AI vendors to generate a response.

  • OpenAI receives your Younen prompt and any attached image, plus context we assemble: your university, year, major, course list, upcoming events, the extracted text of your course syllabi, and degree-requirement information. Syllabus/course text is also sent for extraction and verification.
  • Tavily receives web-search queries generated to look up courses, professors, or requirements — these can include your university, major, and course terms.

OpenAI API inputs and outputs are not used to train OpenAI's models by default, and OpenAI may retain them for up to 30 days to provide the service and detect abuse (unless a different retention setting applies). Tavily processes search queries under its own terms.

Before you use Younen for the first time, we ask for your explicit consent to this third-party AI processing. You can decline; if you do, Younen and related AI features are unavailable to you. We send only the context needed. Please avoid entering unnecessary personal information into Younen. AI answers may be inaccurate — always confirm important dates and academic requirements with official university sources. See our AI Transparency page.

6. Sharing & third parties

We do not sell, rent, or trade your personal information, and we don't use it for advertising. Your name and profile photo are visible to members of your shared chats and DM recipients; your year, major, courses, and LinkedIn appear on your profile only per your visibility settings.

We share limited data with service providers that process it only on our behalf:

ProviderPurpose
SupabaseDatabase, authentication, file storage
RenderApp & real-time server hosting
OpenAIAI model processing for Younen & syllabus extraction
TavilyWeb search for AI features
Expo & Apple (APNs)Push-notification delivery (sender name + course code only)
Email provider (SMTP)Verification & account emails

All service providers are bound by data-processing agreements, may use your information only to provide services to us, and may not use it for their own purposes. Some providers rely on their own infrastructure subprocessors (for example, Supabase runs on Amazon Web Services); those subprocessors are likewise contractually bound to protect your data.

We may disclose information if required by law or to protect the safety of users or the public, including reporting unlawful content to authorities.

7. Retention & account deletion

We keep your data while your account is active. You may request deletion at any time (Profile → Edit Profile → Delete Account). Once you confirm:

  • Immediately: your access is disabled, your sessions are revoked, notifications stop, your profile is hidden, and your course and direct-message access is removed. Deletion is final and cannot be undone.
  • Within 10 days: your personal profile information and account identifiers are deleted or anonymized — including your profile photo and any voice recordings you sent — and your sign-in credentials are destroyed.
  • Messages you posted in shared chats remain but appear as authored by "Deleted User," so conversations stay readable for others — they are no longer linked to your identity. Shared syllabi remain associated with the relevant course.

Certain limited records may be retained longer only where reasonably necessary to comply with applicable law, respond to valid legal process, maintain security, investigate abuse, or resolve disputes. If you want specific messages removed first, delete them individually before requesting deletion, or email team@unitalk.ca. Residual copies may persist in encrypted backups, which are rotated and overwritten on a recurring cycle (typically within 30 days). Server logs are kept no longer than necessary for security and reliability — typically 30 to 90 days — then deleted.

8. Security

Sign-in is handled by Supabase Auth (we never store your password). Data is encrypted in transit (TLS) and stored encrypted at rest. UniTalk is not end-to-end encrypted — our servers process message content to deliver it, keep the community safe, and power AI features. Access to message content within UniTalk is restricted to authorized personnel (our operators) and only where necessary for safety, moderation, legal, or technical-support purposes. No system is perfectly secure; we cannot guarantee absolute security. If a confidentiality incident occurs that presents a risk of serious injury, we will promptly notify affected users and the relevant regulators (such as Quebec's Commission d'accès à l'information), consistent with Law 25 and PIPEDA.

9. Future data uses (not active today)

Today UniTalk does not sell, share for advertising, or license your personal information. If we ever explore privacy-respecting monetization, we will — before any such use takes effect — update this policy and our App Store disclosures, give you clear advance notice, and provide a consent or opt-out where required. We will never sell your private messages, university email, authentication data, or syllabus contents, and we won't make material new uses through a silent change.

10. Children & age

UniTalk is for post-secondary students 16 or older. We use university-email verification as our primary mechanism to confirm users are post-secondary students, which also serves as a practical age check (university accounts are generally held by people 16 or older). It is not directed to children under 13, and we don't knowingly collect their data. If we learn that a user is under 13, we will promptly delete their account and associated data. Contact team@unitalk.ca if you believe a child under 13 has an account.

11. Your rights

You may access, correct, or delete your information; withdraw consent; request a copy of the personal information you provided in a structured, commonly used, machine-readable format (e.g., JSON); and object to or ask us to restrict certain processing. To protect your account, we may ask you to verify your identity before acting on a request. Email team@unitalk.ca (we respond within 30 days), or use Privacy Choices, which summarizes how to manage notifications, profile visibility, and account deletion. You may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).

12. International transfers

Our providers may process data in Canada, the United States, and other jurisdictions where they or their subprocessors operate. When personal information is transferred or accessed outside Quebec, we assess the transfer — including, where required by law, a privacy impact assessment — and rely on contractual and security safeguards to protect it. By using the app you consent to this processing, which we carry out consistent with applicable Canadian and Quebec law.

13. Regional notices (California & EU/UK)

California: We do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA). California residents may contact team@unitalk.ca to exercise applicable rights, and we will not discriminate against you for doing so.

European Union / United Kingdom: UniTalk is operated in Canada and intended for students at Canadian universities; we do not specifically target users in the EU or UK. Where EU/UK data-protection law applies to you, our legal bases are your consent and performance of the service you request, and you may have rights to access, rectify, erase, port, object to, or restrict processing, and to complain to your local supervisory authority.

14. Changes

We may update this policy. For material changes we'll give notice in-app or by email before they take effect and update the "Last updated" date. We won't use silent changes to authorize materially new uses of your data.

15. Contact

Contact: team@unitalk.ca