# Privacy Policy for Uniphy
Last Updated: 10.07.2026
Uniphy is committed to protecting your privacy. Our core philosophy is "Local-First": your personal data belongs on your device by default. This policy explains what data is processed, how it is used, and what choices you have, including when you interact with our AI assistant, opt into our optional Cloud Sync feature, or use the app with advertising and usage analytics enabled.
1. Data Controller
Uniphy is based in Germany. For any questions regarding your data, you can contact us at:
Email: info@uniphy.world
2. The "Local-First" Principle
By default, Uniphy does not use cloud storage for your personal entries.
- Memories & Tracking: All habits, health data, and AI "memories" are stored exclusively on your local device unless you choose to enable Cloud Sync (see Section 4).
- Photos: Any images you attach to your entries remain on your device.
- No Account Required: Registration is entirely optional. You can use the full Uniphy experience without creating an account.
Note: Without Cloud Sync enabled, we cannot recover your data if you lose your device or delete the app. We recommend using your OS-level backup (such as iCloud or Android Backup).
3. AI Assistant
Uniphy includes an AI assistant that can use OpenAI, Google Gemini, or DeepSeek, depending on the model selected in the app. To generate responses, the assistant reads relevant data from within your Uniphy app (such as habits, entries, and metrics) and sends the required context to the selected provider through Uniphy's backend.
What this means for your data:
- Data sent to the selected AI provider: When you interact with the AI assistant, relevant content from Uniphy may be included in the prompt in order to provide personalised responses.
- Provider handling: The selected provider processes the prompt under its privacy terms. OpenAI: https://openai.com/policies/row-privacy-policy/, Google: https://policies.google.com/privacy, DeepSeek: https://www.deepseek.com/privacy.
- Our role: Uniphy acts as the sender of prompts to the selected provider. We do not independently store the content of your AI conversations on our servers.
- No training by Uniphy: We do not use your data to train any AI models ourselves.
4. Optional Cloud Sync & Account
You may optionally create a Uniphy account to enable Cloud Sync. This feature allows you to back up your data, restore it, and sync it across multiple devices.
What we store:
- When Cloud Sync is enabled, your Uniphy data (entries, habits, health data, preferences, and similar app content) is uploaded to and stored in our backend database as a backup.
How we use it:
- We store your data solely for the purpose of backup and synchronisation. We do not access, analyse, read, resell, share, or use your data in any way beyond providing this storage service to you.
- Our staff do not review the contents of your data.
What we collect for your account:
- To create an account, we collect the provider user ID, email address, sign-in provider, platform, app version, and a device identifier used for sync and notification delivery. Authentication tokens are used to verify sign-in and are not included in data exports.
Data retention:
- Your cloud data remains stored until you delete it from within the app or delete your account. Upon account deletion, all associated data is permanently removed from our servers within 30 days.
No account, no upload:
- If you never create an account or never enable Cloud Sync, no account profile or Cloud Sync copy of your entries is stored. Technical service requests, advertising, analytics, and AI processing are still handled as described in the other sections of this policy.
5. Location & Weather Services
To provide weather widgets, the app accesses your device location.
- Your location may be sent to Uniphy's backend to query weather or nearby-place services. Place lookup responses and approximate query coordinates may be cached to improve performance.
- Location-journal history remains on your device unless Cloud Sync is enabled. Uniphy does not sell location data.
6. Advertising & Usage Analytics (Google)
Uniphy uses Google services for advertising and pseudonymous usage measurement. Except for feedback that you voluntarily submit as described below, these integrations are not used by Uniphy to send your personal entries, AI conversations, memories, photos, health data, or precise location to Google for advertising or analytics.
- Google Mobile Ads (AdMob): Users without Premium access may see ads delivered through Google Mobile Ads. Google may process technical app and device information, IP address for ad delivery, and advertising identifiers or similar signals where permitted. The app requests the required advertising consent and, on iOS, App Tracking Transparency permission before allowing personalised advertising. If consent or tracking permission is not granted, Uniphy requests non-personalised ads. Non-personalised ads may still require technical processing by Google to deliver and measure ads.
- Firebase Analytics: We use Firebase Analytics to understand app usage through events such as screens viewed, features used, onboarding steps, and purchase actions. We do not attach names, email addresses, account identifiers, personal entries, AI conversation content, memories, photos, or health data to these usage events. Firebase Analytics may generate an app-instance identifier and process device, app, approximate-location, and event information so that aggregated usage statistics can be produced.
- Anonymous feedback: If you choose to submit feedback to the developers through the app, the text you enter (limited to 100 characters) is sent through Firebase Analytics with a feedback event. Uniphy does not attach your name, email address, or account identifier to this feedback. Please do not include identifying or sensitive personal information in feedback text.
- No Uniphy advertising or analytics profile: Uniphy does not use these services to identify you personally, sell your data, or build a profile from the private content you store in the app.
- Google's handling of data: Google processes data received through these services under its own terms and privacy policies. More information is available at https://policies.google.com/privacy and https://firebase.google.com/support/privacy.
7. Third-Party Services
We do not sell your data. We use third parties only when technically necessary:
- OpenAI, Google Gemini, and DeepSeek: Power the selectable in-app AI assistant models. See Section 3.
- Google Mobile Ads (AdMob) and Firebase Analytics: Deliver advertising to non-Premium users and provide aggregated usage statistics as described in Section 6.
- Weather Services: To provide local weather information.
- Infrastructure Providers: We use hosting and server infrastructure to operate the Cloud Sync backend. These providers process data only on our behalf and under confidentiality obligations.
8. Legal Basis (GDPR)
In accordance with the GDPR (DSGVO), we process data based on:
- Art. 6(1)(b) GDPR: Processing necessary for the performance of the app's features (e.g., Cloud Sync, AI assistant functionality).
- Art. 6(1)(a) GDPR: Your explicit consent, where applicable (e.g., when you create an account and enable Cloud Sync, grant health data permissions, consent to advertising technologies, or permit tracking for personalised ads).
- Art. 9(2)(a) GDPR: Explicit consent for processing health data (granted when you allow permissions for Apple Health or Google Fit).
9. Your Rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten").
- Restrict how we process your data.
- Data portability receive a copy of your data in a structured, machine-readable format.
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint with your local data protection authority.
For local-only users: Uniphy does not hold your locally stored entries. Google may nevertheless process technical advertising or analytics data as described in Section 6.
For Cloud Sync users: To submit a formal data request, contact us at info@uniphy.world.
10. Data Security
We apply commercially reasonable technical and organisational measures to protect data stored in our Cloud Sync backend against unauthorised access, loss, or disclosure. Connections to our servers are encrypted in transit.
11. Children
Uniphy is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us at info@uniphy.world and we will delete it promptly.
12. Changes to This Policy
We may update this policy as Uniphy evolves. When we make material changes, we will update the "Last Updated" date at the top of this document. We encourage you to review this policy periodically.