Privacy Policy
Last updated: June 30, 2026
UniPort ("we") respects and protects your personal information. This Privacy Policy is formulated in accordance with applicable laws and regulations including the Personal Information Protection Law of the People's Republic of China (PIPL), the Cybersecurity Law of the PRC (CSL), the Data Security Law of the PRC (DSL), the Regulations on Network Data Security Management, the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA). It explains how we collect, use, store, share, and protect your personal information. Please read each section carefully.
1. Overview and Scope
This Policy applies to the personal information processing activities involved when you use the UniPort website, clients, and related services (collectively, "the Service"). "Personal information" refers to various information related to an identified or identifiable natural person recorded electronically or otherwise, excluding anonymized information. "Personal information processor" refers to us as the organization that determines the purposes and methods of processing. This Policy does not apply to the privacy policies of third-party software you may use; such cases are the responsibility of the respective third parties. If you are under 14 years of age, please read this Policy and use the Service under the supervision of a guardian; processing your personal information requires guardian consent.
2. Personal Information We Collect
We collect only the minimum information necessary to provide the Service, including: (1) Registration and authentication: phone number or email, username, bcrypt-hashed password; (2) Account and order information: subscription records, paid orders, payment method identifiers (full card numbers are not stored); (3) Usage behavior: software download and update records, version information, crash logs, device identifiers; (4) Feedback and notification: content you voluntarily submit, notification preferences; (5) Security and audit: login IP, login time, operation logs. We do not collect personal information unrelated to the Service, nor do we collect unnecessary permission data such as contacts or photo albums from your device.
3. Collection Methods and Legal Basis
Our legal bases for processing personal information include: (1) your consent, e.g., receiving marketing notifications, using the invitation reward feature; (2) necessity for concluding or performing a contract, e.g., account registration, providing software distribution and updates, processing paid orders; (3) necessity for performing statutory duties or obligations, e.g., retaining network logs for no less than six months per CSL, cooperating with regulatory inspections; (4) necessity for responding to public health emergencies or protecting life and health in emergencies. We process your personal information only under the above legal bases, following the principles of purpose limitation and data minimization. If the processing purpose, method, or information type changes, we will re-notify and obtain consent as required by law.
4. Purpose of Use
The personal information collected is used to: (1) provide software distribution, version updates, and download services; (2) authenticate accounts and manage sessions; (3) process subscriptions, orders, and payments; (4) send system notifications, security alerts, and service announcements; (5) improve product experience through aggregated statistics and anonymized analytics; (6) ensure system security, prevent fraud and abuse; (7) handle user feedback and support requests. We will not use your personal information for purposes other than those stated; any change in purpose will be separately notified with consent obtained as required by law. You may disable non-essential notifications (e.g., marketing) at any time via account settings without affecting core service usage.
5. Sharing, Transfer, and Public Disclosure
In principle, we do not share your personal information with third parties. We may share necessary information under the following circumstances: (1) with your separate consent; (2) with commissioned service providers (e.g., SMS providers, email providers, payment gateways), who may only process within the necessary scope and are bound by confidentiality; (3) as required by laws or by administrative or judicial authorities through legal procedures. We will never sell your personal information to any third party. In the event of a merger or acquisition, we will require the successor to continue fulfilling this Policy. Except as above, we will not transfer or publicly disclose your personal information; if necessary, we will inform you of the recipient and purpose and obtain separate consent (unless otherwise provided by law).
6. Information Storage and Protection
Your personal information is stored on servers located within the People's Republic of China (unless otherwise provided by law). We take the following security measures: (1) passwords are stored as irreversible bcrypt hashes; (2) databases use encrypted storage and transport (TLS), with hard isolation by app_id; (3) parameterized queries prevent SQL injection; CSP and HSTS prevent cross-site attacks; (4) all admin operations are recorded in audit logs, with two-factor authentication for critical operations; (5) regular security assessments and vulnerability remediation. We retain personal information only for the shortest period necessary; after account deletion, information is deleted or anonymized within 15 business days, unless otherwise required by law (e.g., network logs retained for at least six months). In the event of an actual or potential leak, tampering, or loss of personal information, we will immediately take remedial measures and notify you and regulatory authorities as required by law.
7. Cross-Border Data Transfer
Personal information collected and generated within the PRC is in principle stored domestically. If cross-border transfer is necessary to provide the Service, we will strictly comply with Articles 38-42 of PIPL through one of the following: (1) passing a security assessment organized by the national cyberspace administration; (2) obtaining personal information protection certification from a professional institution; (3) entering into a standard contract with the overseas recipient and filing it with the provincial cyberspace administration; (4) other conditions stipulated by law. We ensure that overseas recipients provide a level of protection no lower than this Policy, and obtain your separate consent. For users subject to GDPR, cross-border transfers are conducted in accordance with GDPR Chapter V and Standard Contractual Clauses (SCC).
8. Cookies and Similar Technologies
We use httpOnly, Secure cookies to store authentication tokens for session management; these cookies do not contain personally identifiable information and are valid only during the session. We do not use third-party tracking cookies. Website analytics are collected via a self-hosted PostHog service for aggregated statistics and product improvement only, not shared with third-party advertising platforms. You may manage or delete cookies at any time via browser settings, though this may affect login status and some features. Cookie types used include: strictly necessary cookies (authentication sessions) and analytics cookies (PostHog aggregated statistics), none of which involve cross-site tracking.
9. Your Rights and How to Exercise Them
Under PIPL, GDPR, and CCPA, you have the following rights regarding personal information: (1) right to know and decide: understand the purpose, method, and scope of processing, and to limit or refuse processing; (2) right to access and copy: request to view and obtain a copy of your personal information; (3) right to correct and supplement: request correction of inaccurate or supplementation of incomplete information; (4) right to deletion: request deletion when the purpose is achieved, consent is withdrawn, or processing is unlawful; (5) right to data portability: obtain and transfer your personal information in a structured, commonly used format; (6) right to withdraw consent: withdraw previously given consent at any time, without affecting processing before withdrawal; (7) right to object to automated decision-making: refuse decisions with significant impact made solely by automated means; (8) right to explanation: request an explanation of the processing rules. To exercise these rights, email privacy@uniport.app; we will respond within 15 business days.
10. Protection of Minors
We attach great importance to protecting the personal information of minors. If you are a minor under 14, you should read this Policy and use the Service under guardian supervision; processing your personal information requires guardian consent. We take the following special protective measures for minors: (1) establishing dedicated processing rules, collecting only information necessary for the Service; (2) not engaging in commercial marketing to minors through automated decision-making; (3) guardians have the right to access, correct, delete minor's personal information, and withdraw consent. If a guardian discovers we are processing a minor's information without consent, they may contact us to delete it at any time. This Service is not actively offered to users under 14; if such registrations are discovered, we will delete the relevant information as required by law.
11. Policy Updates and Contact
This Policy may be updated from time to time. For material changes (e.g., expanded processing purposes, additional information types, changes in sharing scope), we will notify you 30 days in advance via website announcement or email; if you do not agree with the updated Policy, you may stop using the Service or delete your account, and continued use constitutes acceptance. We have designated a Data Protection Officer (DPO) responsible for privacy matters, contactable at privacy@uniport.app. If you have questions, complaints, or suggestions regarding personal information processing, please contact us first; if unsatisfied with our response, you may file a complaint with the cyberspace administration or other competent regulatory authority. The right of interpretation of this Policy belongs to us.