UniBao collects information you provide and information the app generates to deliver the features you choose:
Account information: email address, password hash, display name, avatar and biography; when you use Apple or Google sign-in, the name, email address and account identifier they provide.
Contact details: WeChat ID, WhatsApp number or other details you provide voluntarily, visible for a limited period only after both users agree to exchange them.
Address and location: a saved home address, listing location text and coordinates generated after you grant location permission; public coordinates are reduced in precision.
Listings and community content: marketplace, housing and service listings, posts, comments and their images.
Customer support content: the category, subject, message and resolution records submitted through feedback, reports or support requests.
Device identifiers: when app notifications are enabled, an APNs token is associated with your account to deliver notifications to this app on this device; if you opt in to diagnostics and PostHog is configured, a random installation UUID is generated for product analytics.
Usage and technical data: access times, service logs, IP address, city selection and security or troubleshooting information.
Optional analytics and diagnostics: the web app currently does not initialise third-party analytics or error tracking. Only if you opt in within the iOS app and the services are configured may PostHog receive product interactions and the installation UUID, and Sentry receive crashes, errors, performance data and related diagnostic context.
2. How we use information
Provide sign-in, publishing, browsing, favourites, contact exchange, community, notifications and customer support.
Detect and respond to fraudulent listings, scams, harassment, abuse and security incidents.
Send essential account emails and notifications you choose to enable.
Analyse product use and diagnose faults after you opt in.
To perform automated content-safety review, we may send Alibaba Cloud DashScope (Qwen) locally redacted listing titles, descriptions and allergen text, risk markers indicating whether location and WeChat/WhatsApp contact fields are present, and up to six images. Exact location and contact-field values are not included in the review text, although images may themselves contain personal information. This data is used only to identify prohibited, fraudulent or unsafe content. If automated review is unavailable, the content enters an access-restricted manual review queue.
Resend processes only the email address and message content needed to deliver essential transactional email. Optional GitHub sync creates an operations alert in an access-restricted private repository containing only the feedback ID, category, source and internal admin link; it does not include the user ID, label, email address, subject or feedback message.
We do not sell personal information. We disclose it only with your consent, to processors needed to provide the service, or where required by law or a valid law-enforcement request.
2.1 Lawful bases for processing
Performance of a contract: creating and maintaining an account and providing publishing, browsing, favourites, contact exchange, messaging, notifications, support and account deletion requested by the user.
Legitimate interests: preventing fraud and abuse, protecting the service and users, moderating content, investigating reports, and maintaining necessary audit and operational logs. We balance these interests against user rights and limit the data to what is necessary.
Consent: optional analytics and diagnostics the user enables, and location or push notifications that require system permission. Consent can be withdrawn in the app or iOS Settings without affecting processing that was lawful before withdrawal.
Legal obligations: responding to valid regulatory or law-enforcement requests, preserving and reporting safety incidents where required by law, and meeting applicable online-safety and data-protection duties.
Automated moderation is used only to decide whether content can be displayed publicly or requires human review; it is not used to make decisions with legal or similarly significant effects. For human appeals and safety complaints, read the Online Safety and Complaints policy.
3. Cookies and local storage
We use necessary cookies and local storage to maintain sign-in, save drafts and remember city, language, notification and diagnostics preferences. Read the Cookie Policy.
4. Your rights and choices
Access, correct, delete or export your profile and content.
Delete your complete account and associated data in Profile → Settings → Delete account.
Turn off notifications or diagnostics in app settings and revoke system permissions in iOS Settings.
Exercise your UK GDPR rights to restrict or object to processing and complain to the UK Information Commissioner’s Office (ICO).
5. Storage and international transfers
Core account, listing and image data is hosted by Supabase in the UK region. The production web service runs on a Vultr server in London; public requests pass through Cloudflare for reverse proxying, TLS and security protection, and Vercel is used only for previews and short-term fallback. Passwords are stored as one-way hashes.
Production automated moderation currently uses the China-region Alibaba Cloud DashScope/Qwen endpoint, so the redacted review text, risk markers and images described above are processed in China. Cloudflare, Resend, GitHub and, when enabled, PostHog and Sentry may also process limited data outside the UK or EEA. Depending on the processing location and provider, we use an applicable Data Processing Agreement (DPA), UK International Data Transfer Agreement or Addendum (IDTA/Addendum), Standard Contractual Clauses (SCCs), or another lawful mechanism, and verify the actual region and transfer safeguards before production release.
6. Service providers
Supabase — database, authentication and storage
Vultr — production web hosting
Vercel — previews and short-term fallback hosting
Cloudflare — reverse proxy, TLS, CDN and security protection, which may process IP addresses and request metadata
GitHub — minimised feedback operations alerts in an access-restricted private repository (optional)
PostHog — opt-in iOS product analytics
Sentry — opt-in iOS crash, error and performance diagnostics
We require service providers that process user data to act only on our instructions and for agreed purposes, and to provide the same or equivalent protection required by this policy and the App Store Review Guidelines.
7. Retention and deletion
We retain service data while an account remains active. After deletion, the account, user-generated content, images and other identifiable information are deleted immediately or within the 30 days needed to complete asynchronous cleanup. Report or audit records required for legal or security obligations are access-restricted and later deleted or de-identified. APNs tokens are removed when notifications are disabled, on sign-out or account deletion. Support, analytics and diagnostics data is retained only as long as needed to resolve the request, complete security or product analysis, or meet legal duties, then deleted or de-identified.
8. Contact us
For privacy questions or to exercise your rights, use the Contact us page and its public support channel.