UUDO

UUDO

Privacy Policy

Last updated: August 14, 2026

Introduction

This Privacy Policy explains how UUDO (“UUDO”, “we”, “us”) collects, uses, shares, and protects your personal data when you use the UUDO mobile application for iOS and Android (the “App”) and the UUDO website at uudo.app (the “Site”). UUDO is a community platform for university students. The student experience is delivered exclusively through the mobile App; the Site is informational.

The data controller responsible for your personal data is João Pedro Vartanian, who can be reached at privacy@uudo.app.

UUDO is currently in beta. We may add, change, or remove features during this period, and we will keep this policy current as the product evolves.

This policy is written to comply with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados, Law No. 13.709/2018, the “LGPD”) and, for users in the European Union and European Economic Area, the General Data Protection Regulation (the “GDPR”).

Personal data we collect

We collect only the data we need to operate UUDO. Depending on how you use the App and Site, this includes:

  • Account and identity: your email address and your first and last name.
  • Age verification: your date of birth, used once to confirm that you are at least 18. We compute your age on our servers and discard the date immediately — it is never stored in our database and never written to our logs. Only the result of that check is kept.
  • Academic profile: your university, your academic program and major, up to two minors, up to five certificate programs, and your expected graduation year.
  • Profile content: an optional short bio, a profile photo, and the interests you choose to personalize your experience.
  • App preferences: interface settings such as reduced-motion and haptics. These are user-experience preferences only — they are not health or disability data.
  • Social activity: the connections (“bonds”) you make, accounts you block, the chat rooms you join, the messages you send, the events you sign up for, the articles you save, and a short-lived record of the content you view.
  • Communications: messages you send through in-app chat, support requests together with any screenshots or files you attach to them, and details you submit through forms on the Site (waitlist, contact, research, institution-request, and add-your-university forms), which may include your name, email, phone number, and any message you write.
  • Reports you make: if you report another user or a piece of content, we record who or what you reported, the category you chose, and anything you write to explain it.
  • Notifications: the title and body text of the notifications we send you, both the ones shown inside the App and the ones delivered to your phone. If you allow push notifications, we also collect a device push token that identifies your phone for delivery, along with the platform and app version it was registered from.
  • Technical and security data: records kept in our security and audit logs to protect the platform. Depending on the event, these may include your IP address and device or browser information, or only reduced details such as your email domain and a one-way hash of your email address.
  • Website analytics: on the Site only, and only if you accept analytics cookies, standard usage data through Google Analytics and performance data through Vercel. The mobile App contains no advertising or product-analytics trackers.

We do not use profile photos for biometric identification, facial recognition, facial matching, facial search, biometric-feature extraction, or any other Art. 5 II processing. They are stored only for display in the App and Site.

What we do not collect

To keep your data minimal and safe, UUDO does not collect:

  • sensitive personal data under LGPD Art. 5 (such as data on health, racial or ethnic origin, religious or political belief, union membership, sex life, or biometric or genetic data);
  • a stored copy of your date of birth — we compute your age from it at sign-up and discard it immediately (see “Age verification” above);
  • precise location data;
  • payment or financial data.

We do not profile you using sensitive data, and we operate no advertising network.

How and why we use your data

We process your personal data for the purposes below, each under a specific legal basis:

PurposeData usedLGPD basis (Art. 7)GDPR basis (Art. 6)
Create and manage your account; sign you inEmail, name, academic profilePerformance of a contract (V)Contract (b)
Verify your university and keep each university’s community separateEmail domain, universityPerformance of a contract (V); legitimate interest (IX)Contract (b); legitimate interests (f)
Personalize the people and content you seeInterests, academic profile, social activityConsent (I); legitimate interest (IX)Consent (a); legitimate interests (f)
Enable chat and social connectionsChat messages, bonds, blocks, room membershipPerformance of a contract (V)Contract (b)
Let you sign up for events and manage event capacityEvent sign-ups, academic profilePerformance of a contract (V)Contract (b)
Send you notifications about events, news and messagesNotification title and body, device push tokenPerformance of a contract (V); legitimate interest (IX)Contract (b); legitimate interests (f)
Review reports of users or content and keep the community safeWhat you reported, the category, your messageLegitimate interest (IX); legal obligation (II)Legitimate interests (f); legal obligation (c)
Send you service and account emailsEmailPerformance of a contract (V)Contract (b)
Protect the platform: security, abuse and fraud prevention, rate limitingIP address, device informationLegitimate interest (IX); legal obligation (II)Legitimate interests (f); legal obligation (c)
Provide customer supportYour message, email, name, universityPerformance of a contract (V); legitimate interest (IX)Contract (b); legitimate interests (f)
Understand product usage in aggregateAnonymized, grouped statistics (no individual identifiers)Legitimate interest (IX)Legitimate interests (f)
Measure Site trafficAnalytics cookies (Site only)Consent (I)Consent (a)

Where we rely on consent, you may withdraw it at any time. Our aggregate product statistics are computed with a minimum group size so that no individual can be identified.

Age requirement

UUDO is intended only for university students aged 18 or older. When you sign up we ask for your date of birth, confirm on our servers that you are at least 18, and then discard the date, keeping only the result. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact privacy@uudo.app and we will delete it.

How we share your data

We do not sell your personal data, and we never share it for third-party advertising. Within UUDO, other users at your university can see your public profile and activity; users at other universities cannot — each university community is isolated.

If your university partners with UUDO, the institution and its authorized administrators can view aggregated, anonymized statistics about student engagement through an administrative dashboard — for example, demographic breakdowns and engagement trends. These statistics are grouped and computed with a minimum group size so that no individual student can be identified, and administrators do not see your individual profile, messages, or activity through this dashboard. We provide these aggregate insights on the basis of our legitimate interest in helping universities understand and support their communities.

We rely on the third-party providers listed below to operate UUDO; they process personal data only to deliver their service to us. As UUDO is in beta, we are in the process of formalizing data-processing agreements with each provider.

ProviderPurposeData shared
SupabaseCloud hosting, database, authentication, and storageAll account, profile, and app data
ResendSending account and service emailsName, email
Cloudflare TurnstileBot and abuse protection on Site formsIP address
UpstashRate limiting to prevent abuseIP address
Atlassian JiraHandling support requestsYour support message, name, email, university, and any files you attach
Apple (APNs)Delivering push notifications to iOS devicesDevice push token, notification title and body
Google Analytics (Site only)Website traffic measurement, with your consentUsage data, cookie identifiers
Vercel (Site only)Website hosting and performanceUsage and performance data

International data transfers

UUDO’s infrastructure and several of our providers are located in the United States, so your personal data is processed outside Brazil and outside the EU/EEA. These transfers are carried out on the basis of our legitimate interests in operating UUDO, subject to oversight by the ANPD (LGPD Art. 33, VIII) and, for EU/EEA users, on the basis of standard contractual clauses or other lawful mechanisms under Chapter V of the GDPR.

How we protect your data

All data is transmitted over encrypted connections (TLS/HTTPS).

Chat messages are encrypted at rest on our servers using AES-256-GCM, with keys held only by our backend, so that access to the database alone does not reveal message content. Extending these protections to message-derived data such as conversation previews, and to locally cached copies on your device, is on our security roadmap.

We offer optional two-factor authentication (TOTP), and we enforce database-level access controls so that each university’s data stays separate.

Chat is not end-to-end encrypted: because messages are encrypted with keys we manage, our systems are technically able to process message content in order to operate the service.

No method of storage or transmission is completely secure, but we protect your data using industry-standard measures.

How long we keep your data

We keep personal data only as long as needed for the purposes described above:

DataHow long we keep it
Account and profile dataUntil you delete your account
Data after a deletion requestPermanently erased within 30 days
Security and audit logsKept indefinitely (needed to detect and investigate abuse)
Raw content-view recordsDeleted within 48 hours
Device push tokenRevoked when you sign out; deleted 30 days after revocation
Push notification content (title and body)Deleted 30 days after we send it
In-app notificationsDeleted 90 days after you read one, or after 180 days if you never do
Support requests and any files you attachUntil you delete your account
Add-your-university requestsDeleted 90 days after the request is reviewed; a request nobody reviews is closed automatically after 180 days
Aggregate, anonymized statisticsKept indefinitely (no longer identifies you)

You can cancel a deletion request within 7 days; after that, your data is permanently erased within 30 days. We may keep some data longer where necessary to comply with a legal obligation or to resolve a dispute.

Your rights

Under the LGPD (Art. 18), you have the right to:

  • confirm that we process your data, and access it;
  • correct incomplete, inaccurate, or outdated data;
  • anonymize, block, or delete data that is unnecessary, excessive, or processed unlawfully;
  • request the portability of your data to another provider;
  • delete data we process based on your consent;
  • be informed about the public and private entities with which we share your data;
  • be informed about the consequences of refusing to give consent;
  • withdraw your consent at any time.

If you are in the EU or EEA, the GDPR also gives you the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing, and withdrawal of consent. To exercise any of these rights, email privacy@uudo.app or delete your account directly in the App. We will respond within the timeframes set by law.

Data Protection Officer (Encarregado)

We have designated a Data Protection Officer to serve as the point of contact between you, UUDO, and the data protection authorities on any question about how we handle your personal data. Under the LGPD (Art. 41) this role is the Encarregado; under the GDPR (Arts. 37–39) it is the Data Protection Officer (DPO).

Our designated Encarregado and Data Protection Officer is João Pedro Vartanian, who can be reached at privacy@uudo.app. You may contact this address to exercise any of the rights described above or to raise any concern about how your personal data is handled.

Supervisory authority

If you believe we have not handled your personal data properly, you can lodge a complaint with the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados — ANPD) at gov.br/anpd. Users in the EU/EEA may complain to their local data protection authority.

Cookies and similar technologies

The Site uses essential cookies to function and, only with your consent, Google Analytics cookies to measure traffic. You can accept or decline analytics cookies through the cookie banner. The mobile App does not use advertising cookies; it stores limited data on your device to keep you signed in and to cache content for performance.

Calendar

When you add a UUDO event to your device calendar, that information is written only to your phone’s calendar. No calendar data is sent to our servers.

Push notifications

If you enable push notifications, we register a device token for your phone and use it to deliver notifications directly to your device — for example, event reminders, chat messages, and organization join approvals. We send that token, and each notification, directly to Apple’s Push Notification service (APNs); we do not route push notifications through any third-party push service. Push notifications are currently available on iOS only.

  • Device push token: a token identifying your device for notification delivery. It is revoked when you sign out and permanently deleted within 30 days of revocation, or immediately if you delete your account.
  • Notification content: the title and body text of the notifications we send you are stored on our servers for up to 30 days so that we can deliver them, and deleted immediately if you delete your account. This is separate from the device token above — it is the content of the message itself, not merely the delivery address. The same notification also appears in your in-app notification list, which we keep for longer; see “How long we keep your data”.

Changes to this policy

We may update this policy as UUDO evolves. When we do, we will revise the effective date at the top of this page. For material changes during beta, we will also notify you in the App or by email.

Contact us

For any question about this policy or your personal data, contact the data controller, João Pedro Vartanian, at privacy@uudo.app.