PRIVACY POLICY
Last updated: July 7, 2026
1. Introduction
Welcome to UniConnect (“Company”, “we”, “our”, “us”)! This Privacy Policy explains how we collect, safeguard, process, and disclose information that results from your use of our mobile application named UniConnect (together or individually “Service”). We are committed to protecting the data privacy of university students while maintaining an authentic, verified, and safe digital campus community.
2. Information Collection & Firebase Authentication
To register an account and safely navigate our platform, we collect specific personally identifiable parameters. By using the Service, you consent to the processing of:
- University Student Email: Collected during registration to restrict access strictly to authorized university students.
- Phone Number Verification: Account activation requires a valid mobile phone number processed securely via Google Firebase Authentication. This number is processed to transmit one-time SMS verification tokens and enforce strict anti-bot and anti-fraud protocols.
- Profile Metadata: This includes your chosen username, display names, and biography responses provided during setup.
3. Identity Verification & AWS Facial Recognition
AWS Rekognition 3D Liveness Checks: To completely mitigate identity theft, profile cloning, and platform impersonation, UniConnect integrates automated facial recognition tools via Amazon Web Services (AWS). During onboarding, a 3D facial liveness check is performed to analyze real-time video frames or snapshots. This confirms you are a real person matching your active credentials. UniConnect does not permanently store, log, or maintain raw biological biometric templates or structural facial maps on its databases.
4. Application Security & Device-Level Locks
For your enhanced on-device privacy, the Service allows you to enable an app access lock using a localized PIN or your device's native biometric capabilities (such as fingerprint scanning or hardware-level facial recognition). This security layer operates entirely via your smartphone’s native operating system security architecture. UniConnect never reads, intercepts, captures, or transmits your biometric records or security codes.
5. Location Data & Peer Matching
To facilitate interactive campus networking, the Service collects and processes coordinates regarding your location. This geographical tracking is utilized exclusively to compute distances and unlock localized matching features, enabling you to discover and interact with nearby peers. We do not maintain historical tracking logs of your movements, nor do we share location coordinates with marketing or advertising networks.
6. User-Generated Content & Photo Uploads
Our Service hosts media and visual Content you actively choose to publish, including profile pictures, gallery updates, and feed images. By granting device storage or camera access permissions to upload these files, you acknowledge that your profile pictures and shared images will be accessible to other authenticated users in accordance with the application's matching and discovery mechanics.
Private Messaging Confidentiality (Encryption): Direct private text messages between users are fully encrypted. The Company does not read, parse, index, or retain messaging text parameters on its servers once successfully delivered. Message histories are held directly on user endpoints.
7. Safety, Reporting, and Blocking Mechanisms
To enforce a respectful digital space, the Service incorporates dedicated community moderation systems:
- User-Initiated Reporting: Users can flag any profile, uploaded image, or posted content that violates community standards. Reported parameters are routed immediately to system administrators for review and content removal.
- Peer Blocking: You maintain the absolute right to block any user instantly. Activating a block immediately halts all communication, hides all mutual profiles, and cuts off visibility across matching feeds.
- Enforcement Action: Accounts associated with verified harassment, explicit or offensive media, or unauthorized programmatic access will be suspended or permanently terminated.
To learn more about our commitment to user safety, please review our Child Safety Standards & Reporting Policy.
8. Service Providers & Analytics
We may employ third-party cloud infrastructure and performance analysis providers to log software crashes, monitor service uptimes, and diagnose structural stability parameters to maximize system reliability.
9. Data Retention & Account Deletion
Automated Purge Cycle: Users may execute an account deletion request directly within the App profile settings at any time. Upon submission, the account enters an inactive 30-day grace period during which all public profile cards, hosted images, match configurations, and verification mappings are hidden from the platform. You can reverse this by logging back in within the 30-day window. If left untouched for 30 consecutive days, your entire profile—including email references, Firebase phone mapping tokens, photos, matching metrics, and system data logs—is permanently and automatically purged from our servers.
10. Jurisdiction & Governing Law
This Privacy Policy is interpreted and governed in strict compliance with the legal frameworks and data protection acts of Kenya, matching the regulatory standard applied to our Terms of Service.
11. Contact Us
If you have questions regarding this Privacy Policy, your personal rights, or data erasure processes, reach out directly via email to: machariasamuel465@gmail.com.