UUDO
Privacy Policy
Last updated: August 14, 2026
Introduction
This Privacy Policy explains how UUDO (“UUDO”, “we”, “us”) collects, uses, shares, and protects your personal data when you use the UUDO mobile application for iOS and Android (the “App”) and the UUDO website at uudo.app (the “Site”). UUDO is a community platform for university students. The student experience is delivered exclusively through the mobile App; the Site is informational.
The data controller responsible for your personal data is João Pedro Vartanian, who can be reached at privacy@uudo.app.
UUDO is currently in beta. We may add, change, or remove features during this period, and we will keep this policy current as the product evolves.
This policy is written to comply with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, Law No. 13.709/2018, the “LGPD”) and, for users in the European Union and European Economic Area, the General Data Protection Regulation (the “GDPR”).
Personal data we collect
We collect only the data we need to operate UUDO. Depending on how you use the App and Site, this includes:
- Account and identity: your email address and your first and last name.
- Age verification: your date of birth, used once to confirm that you are at least 18. We compute your age on our servers and discard the date immediately — it is never stored in our database and never written to our logs. Only the result of that check is kept.
- Academic profile: your university, your academic program and major, up to two minors, up to five certificate programs, and your expected graduation year.
- Profile content: an optional short bio, a profile photo, and the interests you choose to personalize your experience.
- App preferences: interface settings such as reduced-motion and haptics. These are user-experience preferences only — they are not health or disability data.
- Social activity: the connections (“bonds”) you make, accounts you block, the chat rooms you join, the messages you send, the events you sign up for, the articles you save, and a short-lived record of the content you view.
- Communications: messages you send through in-app chat, support requests together with any screenshots or files you attach to them, and details you submit through forms on the Site (waitlist, contact, research, institution-request, and add-your-university forms), which may include your name, email, phone number, and any message you write.
- Reports you make: if you report another user or a piece of content, we record who or what you reported, the category you chose, and anything you write to explain it.
- Notifications: the title and body text of the notifications we send you, both the ones shown inside the App and the ones delivered to your phone. If you allow push notifications, we also collect a device push token that identifies your phone for delivery, along with the platform and app version it was registered from.
- Technical and security data: records kept in our security and audit logs to protect the platform. Depending on the event, these may include your IP address and device or browser information, or only reduced details such as your email domain and a one-way hash of your email address.
- Website analytics: on the Site only, and only if you accept analytics cookies, standard usage data through Google Analytics and performance data through Vercel. The mobile App contains no advertising or product-analytics trackers.
We do not use profile photos for biometric identification, facial recognition, facial matching, facial search, biometric-feature extraction, or any other Art. 5 II processing. They are stored only for display in the App and Site.
What we do not collect
To keep your data minimal and safe, UUDO does not collect:
- sensitive personal data under LGPD Art. 5 (such as data on health, racial or ethnic origin, religious or political belief, union membership, sex life, or biometric or genetic data);
- a stored copy of your date of birth — we compute your age from it at sign-up and discard it immediately (see “Age verification” above);
- precise location data;
- payment or financial data.
We do not profile you using sensitive data, and we operate no advertising network.
How and why we use your data
We process your personal data for the purposes below, each under a specific legal basis:
| Purpose | Data used | LGPD basis (Art. 7) | GDPR basis (Art. 6) |
|---|---|---|---|
| Create and manage your account; sign you in | Email, name, academic profile | Performance of a contract (V) | Contract (b) |
| Verify your university and keep each university’s community separate | Email domain, university | Performance of a contract (V); legitimate interest (IX) | Contract (b); legitimate interests (f) |
| Personalize the people and content you see | Interests, academic profile, social activity | Consent (I); legitimate interest (IX) | Consent (a); legitimate interests (f) |
| Enable chat and social connections | Chat messages, bonds, blocks, room membership | Performance of a contract (V) | Contract (b) |
| Let you sign up for events and manage event capacity | Event sign-ups, academic profile | Performance of a contract (V) | Contract (b) |
| Send you notifications about events, news and messages | Notification title and body, device push token | Performance of a contract (V); legitimate interest (IX) | Contract (b); legitimate interests (f) |
| Review reports of users or content and keep the community safe | What you reported, the category, your message | Legitimate interest (IX); legal obligation (II) | Legitimate interests (f); legal obligation (c) |
| Send you service and account emails | Performance of a contract (V) | Contract (b) | |
| Protect the platform: security, abuse and fraud prevention, rate limiting | IP address, device information | Legitimate interest (IX); legal obligation (II) | Legitimate interests (f); legal obligation (c) |
| Provide customer support | Your message, email, name, university | Performance of a contract (V); legitimate interest (IX) | Contract (b); legitimate interests (f) |
| Understand product usage in aggregate | Anonymized, grouped statistics (no individual identifiers) | Legitimate interest (IX) | Legitimate interests (f) |
| Measure Site traffic | Analytics cookies (Site only) | Consent (I) | Consent (a) |
Where we rely on consent, you may withdraw it at any time. Our aggregate product statistics are computed with a minimum group size so that no individual can be identified.
Age requirement
UUDO is intended only for university students aged 18 or older. When you sign up we ask for your date of birth, confirm on our servers that you are at least 18, and then discard the date, keeping only the result. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact privacy@uudo.app and we will delete it.
International data transfers
UUDO’s infrastructure and several of our providers are located in the United States, so your personal data is processed outside Brazil and outside the EU/EEA. These transfers are carried out on the basis of our legitimate interests in operating UUDO, subject to oversight by the ANPD (LGPD Art. 33, VIII) and, for EU/EEA users, on the basis of standard contractual clauses or other lawful mechanisms under Chapter V of the GDPR.
How we protect your data
All data is transmitted over encrypted connections (TLS/HTTPS).
Chat messages are encrypted at rest on our servers using AES-256-GCM, with keys held only by our backend, so that access to the database alone does not reveal message content. Extending these protections to message-derived data such as conversation previews, and to locally cached copies on your device, is on our security roadmap.
We offer optional two-factor authentication (TOTP), and we enforce database-level access controls so that each university’s data stays separate.
Chat is not end-to-end encrypted: because messages are encrypted with keys we manage, our systems are technically able to process message content in order to operate the service.
No method of storage or transmission is completely secure, but we protect your data using industry-standard measures.
How long we keep your data
We keep personal data only as long as needed for the purposes described above:
| Data | How long we keep it |
|---|---|
| Account and profile data | Until you delete your account |
| Data after a deletion request | Permanently erased within 30 days |
| Security and audit logs | Kept indefinitely (needed to detect and investigate abuse) |
| Raw content-view records | Deleted within 48 hours |
| Device push token | Revoked when you sign out; deleted 30 days after revocation |
| Push notification content (title and body) | Deleted 30 days after we send it |
| In-app notifications | Deleted 90 days after you read one, or after 180 days if you never do |
| Support requests and any files you attach | Until you delete your account |
| Add-your-university requests | Deleted 90 days after the request is reviewed; a request nobody reviews is closed automatically after 180 days |
| Aggregate, anonymized statistics | Kept indefinitely (no longer identifies you) |
You can cancel a deletion request within 7 days; after that, your data is permanently erased within 30 days. We may keep some data longer where necessary to comply with a legal obligation or to resolve a dispute.
Your rights
Under the LGPD (Art. 18), you have the right to:
- confirm that we process your data, and access it;
- correct incomplete, inaccurate, or outdated data;
- anonymize, block, or delete data that is unnecessary, excessive, or processed unlawfully;
- request the portability of your data to another provider;
- delete data we process based on your consent;
- be informed about the public and private entities with which we share your data;
- be informed about the consequences of refusing to give consent;
- withdraw your consent at any time.
If you are in the EU or EEA, the GDPR also gives you the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing, and withdrawal of consent. To exercise any of these rights, email privacy@uudo.app or delete your account directly in the App. We will respond within the timeframes set by law.
Data Protection Officer (Encarregado)
We have designated a Data Protection Officer to serve as the point of contact between you, UUDO, and the data protection authorities on any question about how we handle your personal data. Under the LGPD (Art. 41) this role is the Encarregado; under the GDPR (Arts. 37–39) it is the Data Protection Officer (DPO).
Our designated Encarregado and Data Protection Officer is João Pedro Vartanian, who can be reached at privacy@uudo.app. You may contact this address to exercise any of the rights described above or to raise any concern about how your personal data is handled.
Calendar
When you add a UUDO event to your device calendar, that information is written only to your phone’s calendar. No calendar data is sent to our servers.
Push notifications
If you enable push notifications, we register a device token for your phone and use it to deliver notifications directly to your device — for example, event reminders, chat messages, and organization join approvals. We send that token, and each notification, directly to Apple’s Push Notification service (APNs); we do not route push notifications through any third-party push service. Push notifications are currently available on iOS only.
- Device push token: a token identifying your device for notification delivery. It is revoked when you sign out and permanently deleted within 30 days of revocation, or immediately if you delete your account.
- Notification content: the title and body text of the notifications we send you are stored on our servers for up to 30 days so that we can deliver them, and deleted immediately if you delete your account. This is separate from the device token above — it is the content of the message itself, not merely the delivery address. The same notification also appears in your in-app notification list, which we keep for longer; see “How long we keep your data”.
Changes to this policy
We may update this policy as UUDO evolves. When we do, we will revise the effective date at the top of this page. For material changes during beta, we will also notify you in the App or by email.
Contact us
For any question about this policy or your personal data, contact the data controller, João Pedro Vartanian, at privacy@uudo.app.