Privacy notice
Effective July 18, 2026
UnyCode is the controller of the personal data described here. For privacy requests or questions, email hello@unycode.ai.
What we collect
During private access, we collect the email address you submit to the waitlist. Our hosting providers also process standard request data such as IP address, user agent, timestamps, and security logs. Rate-limit identifiers are one-way keyed hashes rather than raw IP addresses.
If you use account or paid access, we also process account identifiers, membership tier and status, subscription dates, Stripe customer and subscription identifiers, and hashed desktop session tokens. Max team administration also stores team names, member and invited email addresses, roles, seat counts, and hashed invitation tokens. Stripe processes payment details; UnyCode does not store full card numbers.
Why we use it
We use waitlist data to provide the launch and access updates you requested. We use account and membership data to provide and secure the service, verify entitlements, prevent abuse, support customers, and meet legal obligations.
Our legal bases are your consent for waitlist email, performance of a contract when you create a paid account, our legitimate interests in securing and improving the service, and compliance with law where required. You may withdraw waitlist consent at any time.
Who processes it
We use service providers including Vercel for website hosting, Supabase for database and authentication infrastructure, and Stripe for billing. They process data under their own terms and data-protection commitments. We do not sell personal data or share it for cross-context behavioral advertising.
Providers may process data outside your country. Where required, transfers rely on recognized safeguards such as adequacy decisions or standard contractual clauses.
Retention and security
Waitlist data is kept until private access ends, you ask us to delete it, or no later than 12 months after public launch if you do not become a customer. Rate-limit records are designed for seven-day retention and are pruned during normal service operation. Account, security, and transaction records are kept only as long as needed for the service, fraud prevention, dispute handling, and applicable accounting or legal duties.
We use access controls, row-level database security, hashed bearer tokens, transport encryption, and bounded security logging. No internet service can guarantee absolute security.
Your choices and rights
You can unsubscribe from launch emails using the link in an email or by contacting us. Depending on where you live, you may also request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and may complain to your local data protection authority. We may need to verify your identity before completing a request.
Cookies, children, and changes
UnyCode does not use advertising or cross-site tracking cookies. Account sign-in uses strictly necessary authentication cookies when account access is enabled. UnyCode is intended for professional developers and is not directed to children under 16. We will update this notice before materially changing how data is used and will change the effective date above.