1. Introduction
UvsU ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our personal development platform and services (collectively, the "Service").
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.
2. Information We Collect
2.1 Information You Provide Directly
We collect information you provide when you:
- Create an account: Name, email address, username, password
- Use the Service: Goals, habits, routines, journal entries, progress data, preferences
- Manage cookie preferences: Your consent choices for analytics and marketing cookies
- Contact us: Support requests, feedback, correspondence
- Participate in surveys: Feedback and opinions about our Service
2.2 Information Collected Automatically
When you access or use our Service, we automatically collect certain information, subject to your cookie consent preferences:
Essential Information (Always Collected):
- Authentication Data: Session tokens, login status
- Security Information: IP address (for fraud prevention), access times
- Core Functionality: Application state, user preferences, settings
Analytics Information (Only with Your Consent):
- Usage Data: Pages visited, features used, time spent, click patterns
- Device Information: Browser type, operating system, device identifiers
- Performance Data: Page load times, error logs, feature interactions
- Analytics Tools: We use PostHog and Google Analytics to understand how you use our Service
Marketing Information (Only with Your Consent):
- Marketing Preferences: Ad interaction data, campaign effectiveness
- Personalization Data: Content preferences for tailored experiences
2.3 Cookies and Similar Technologies
We use cookies and similar tracking technologies to provide and improve our Service. You have full control over non-essential cookies through our cookie consent banner.
Cookie Categories:
1. Necessary Cookies (Always Active)
- Required for authentication and core functionality
- Cannot be disabled as they are essential for the Service to work
- Examples: Session management, security, user preferences
2. Analytics Cookies (Optional)
- Help us understand how you use our Service
- Used to improve user experience and fix bugs
- Tools: PostHog, Google Analytics
- You can opt out at any time through Privacy & Security settings
3. Marketing Cookies (Optional)
- Used for personalized content and advertising
- Track effectiveness of marketing campaigns
- You can opt out at any time through Privacy & Security settings
Cookie Consent Management:
- First-time visitors: You'll see a cookie consent banner when you first visit
- Anonymous users: Your cookie preferences are stored locally on your device
- Authenticated users: Your preferences are saved to your account and synced across devices
- Update anytime: Manage your cookie preferences in Settings → Privacy & Security
2.4 Information from Third Parties
If you choose to connect your account with third-party services (such as OAuth providers for Google or GitHub), we may receive information from those services, such as your profile information and email address, in accordance with their privacy policies.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Service
- Create and manage your account
- Process your transactions and send related information
- Send you technical notices, updates, security alerts, and support messages
- Respond to your comments, questions, and customer service requests
- Communicate with you about products, services, offers, and events
- Monitor and analyze trends, usage, and activities in connection with our Service
- Detect, prevent, and address technical issues, fraud, and illegal activities
- Personalize your experience and deliver content relevant to your interests
- Develop new features and services
- Comply with legal obligations and enforce our terms and policies
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), our legal basis for collecting and using your personal information depends on the data and the context:
- Contract Performance: Processing necessary to provide the Service you requested
- Legitimate Interests: Processing necessary for our legitimate business interests
- Consent: You have given explicit consent for processing
- Legal Obligation: Processing necessary to comply with the law
5. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
5.1 With Your Consent
We may share information when you give us explicit permission to do so.
5.2 Service Providers
We may share information with third-party service providers who perform services on our behalf, such as:
- Cloud hosting and storage providers
- Analytics and monitoring services
- Email and communication platforms
- Payment processors
- Customer support tools
These providers are contractually obligated to protect your information and use it only for the purposes we specify.
5.3 Legal Requirements
We may disclose information if required by law or in response to:
- Legal process (subpoenas, court orders)
- Government or regulatory requests
- Protection of our rights, property, or safety
- Protection of the rights, property, or safety of our users or the public
- Prevention of fraud or illegal activity
5.4 Business Transfers
If UvsU is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
6. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Employee training on data protection
- Secure backup and disaster recovery procedures
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.
7. Data Retention
We retain your personal information for as long as necessary to:
- Provide you with our Service
- Comply with legal obligations
- Resolve disputes and enforce our agreements
When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal or regulatory purposes. Some information may remain in backup copies for a limited period but will not be accessible for regular use.
8. Your Rights and Choices
8.1 Access and Update
You may access, review, and update your account information at any time by logging into your account settings or by contacting us at support@uvsuniverse.com.
8.2 Account Deletion
You may request deletion of your account and all associated personal information by:
- Using the account deletion feature in Settings → Account
- Contacting us at support@uvsuniverse.com
When you delete your account, we will:
- Permanently delete your personal information within 30 days
- Remove all your goals, habits, routines, and journal entries
- Delete your cookie consent preferences
- Anonymize any analytics data (cannot be tied back to you)
8.3 Marketing Communications
You may opt out of receiving promotional emails by:
- Following the unsubscribe link in any promotional email
- Updating your email preferences in account settings
- Contacting us at support@uvsuniverse.com
Note: Even if you opt out of promotional emails, we may still send you important transactional or administrative messages (e.g., password resets, service updates, security alerts).
8.4 Cookie Preferences and Tracking
You have full control over how we use cookies:
Managing Cookie Consent:
- During first visit: Accept, reject, or customize cookies via our consent banner
- Anytime after: Update preferences in Settings → Privacy & Security → Cookie Preferences
- Browser settings: Configure your browser to block or delete cookies (note: this may affect Service functionality)
Cookie Management Options:
- Accept All: Enable all cookies including analytics and marketing
- Reject All: Disable all non-essential cookies (only necessary cookies remain active)
- Customize: Choose which cookie categories to enable
- Withdraw Consent: You can withdraw consent at any time; analytics will stop immediately
Impact of Disabling Cookies:
- Necessary cookies cannot be disabled (required for the Service to function)
- Disabling analytics cookies will stop all tracking.
- Disabling marketing cookies will prevent personalized advertising
- Your cookie preferences are respected across all your devices (for authenticated users)
Anonymous Users:
- Cookie preferences are stored locally in your browser
- When you create an account, your preferences are automatically saved to your account
- You maintain full control over cookies without needing to create an account
8.5 Do Not Track Signals
We respect browser "Do Not Track" (DNT) signals. If your browser sends a DNT signal, we will:
- Treat it as if you have rejected all non-essential cookies
- Not enable analytics or marketing tracking
- Only use necessary cookies required for the Service to function
8.6 Additional Rights (GDPR/CCPA/Data Protection Laws)
- Right to Access: Request a copy of all personal information we hold about you, including account information and user data, cookie consent history and preferences, and analytics data associated with your account
- Right to Rectification: Request correction of any inaccurate or incomplete personal information
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal information when the data is no longer necessary for the purposes it was collected, you withdraw consent, you object to processing and there are no overriding legitimate grounds, the data has been unlawfully processed, or deletion is required to comply with a legal obligation
- Right to Restriction of Processing: Request that we limit how we use your data in certain circumstances
- Right to Data Portability: Receive your personal information in a structured, commonly used, and machine-readable format (JSON export available in Settings → Data Management)
- Right to Object: Object to processing of your personal information for direct marketing purposes (we will stop immediately), analytics and tracking (manage via cookie preferences), or processing based on legitimate interests
- Right to Withdraw Consent: Withdraw your consent at any time for cookie consent (via Privacy & Security settings), marketing communications (via email preferences), or optional data processing (via account settings). Note: Withdrawal does not affect the lawfulness of processing before withdrawal
- Right to Lodge a Complaint: File a complaint with your local data protection authority if you believe we have violated your privacy rights
Exercising Your Rights:
- Most rights can be exercised directly through your account settings
- For additional assistance, contact us at support@uvsuniverse.com
- We will respond to all requests within 30 days (or as required by applicable law)
- We may ask you to verify your identity before processing your request
Cookie Consent Records:
We maintain records of your cookie consent choices, including categories consented to (necessary, analytics, marketing), date and time of consent, IP address when consent was given (for GDPR compliance), browser/device information, and consent version (to track policy changes).
You can view and update your consent history at any time in Settings → Privacy & Security.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.
When we transfer information outside of the EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission or other legally recognized transfer mechanisms.
10. Children's Privacy
Our Service is not intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children under these ages.
If we learn that we have collected personal information from a child under the applicable age without verification of parental consent, we will take steps to delete that information as quickly as possible. If you believe we have collected information from a child, please contact us immediately.
11. Third-Party Links and Services
Our Service may contain links to third-party websites, applications, or services that are not owned or controlled by UvsU. This Privacy Policy does not apply to those third-party services.
We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you access.
12. Do Not Track Signals
Some web browsers incorporate a "Do Not Track" (DNT) feature. Because there is not yet a common understanding of how to interpret DNT signals, our Service does not currently respond to browser DNT signals. We continue to monitor developments in this area.
13. California Privacy Rights (CCPA)
If you are a California resident, you have specific rights regarding your personal information:
- Right to Know: Request disclosure of personal information collected, used, and shared
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the sale of personal information (we do not sell your information)
- Right to Non-Discrimination: Not be discriminated against for exercising your rights
To exercise these rights, please contact us at privacy@uvsuniverse.com. We will verify your request and respond within 45 days.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.
We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date at the top of this policy
- Sending you an email notification (for material changes)
Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
We will respond to your request within a reasonable timeframe, typically within 30 days.