UniSphere legal

Privacy Policy

How UniSphere collects, uses, shares, protects, and retains personal information.

Effective date
September 28, 2026
Service
unisphereconnect.com and app.unisphereconnect.com
Operator
Unisphere Connect LLC

At a glance

This summary highlights important points. The complete Policy below provides the details.

  • UniSphere collects school-account, profile, academic, project, collaboration, messaging, safety, device, and service-usage information needed to run the Service.
  • Ordinary profiles, projects, people discovery, and feed activity are generally visible only to verified Members at the same participating school. Private messages are limited to conversation participants and authorized reviewers when necessary.
  • UniSphere does not sell personal information, does not use private-message content to select ads, and does not use Member Content to train general-purpose generative AI models without a separate express opt-in.
  • Current core service providers include Supabase for authentication and data services, Resend for transactional authentication email, Vercel for hosting, PostHog for limited server-side product analytics, and Sentry for scrubbed diagnostics.
  • Members may submit privacy requests by email. UniSphere provides access, correction, deletion, portability, and appeal rights when applicable law requires them. Settings also provides self-service JSON export and immediate account deletion with no recovery period.
  • The Service is for people age 18 or older and is initially offered only in the United States.

Scope and who controls your information

UniSphere is operated by Unisphere Connect LLC (the "Operator," "we," "us," or "our"). This Privacy Policy (the "Policy") explains how the Operator handles personal information through the UniSphere websites, web application, communications, and related services that link to this Policy (the "Service").

If the Operator later reorganizes or transfers the Service to another legal entity, the successor may become responsible for the information described here. We will update the operator information and provide notice when required.

This Policy does not govern a participating school's own systems, a Member's independent project or off-platform activity, or third-party sites and services linked from UniSphere. Those parties control their own practices. The Terms of Service govern use of the Service and define capitalized terms not defined here.

Information we collect

Account and verification information

We collect your school-issued email address, email domain, internal account and profile identifiers, login and verification status, verification timestamps, authenticated session information, account role, onboarding status, and account creation and update times. Before completing signup, you must affirm that you are at least 18; once implemented, UniSphere will record the result and timestamp of that affirmation rather than collecting a date of birth. UniSphere uses passwordless one-time codes, so we do not ask you to create a UniSphere password. Our authentication and email-delivery providers process the one-time code and related authentication records.

We use the school-email domain to associate your account with a participating school. Verification confirms control of the address at that time; it does not independently verify enrollment, age, identity, academic standing, or other school status. We may collect additional verification information if reasonably necessary to prevent fraud or resolve an account request, and will explain the request at collection.

Profile and academic information

You provide profile information such as your real name, handle, avatar, headline, biography, major or program, second major, minor, graduation year, skills, interests, project-category preferences, courses and academic terms, and links to portfolios, code repositories, professional profiles, or other sites. Some fields are optional, but missing information can reduce matching and discovery features.

UniSphere does not ask for grades, transcripts, student identification numbers, government identifiers, financial-account information, precise location, biometric templates, health records, or protected demographic information for ordinary use. You may nevertheless reveal sensitive information in free-text fields or messages. Please do not submit information that is unnecessary for collaboration or that you are not authorized to share.

Project and collaboration information

We collect project titles, summaries, descriptions, categories, commitments, schedules, tags, desired skills, team-size targets, roles, role descriptions, project images, membership and ownership records, join requests and their messages, decisions, project updates, completion status, and related timestamps. Completed or archived project rosters may become part of a durable proof-of-work record for the team.

We also collect connection requests and decisions, block relationships, feed events, notifications, and related interaction records. These records allow us to deliver the actions you request, enforce school boundaries and blocks, prevent duplicate or abusive requests, and show relevant activity.

Messages and conversation information

We collect direct and project conversation membership, message content, sender and conversation identifiers, delivery order, creation, edit, and deletion times, read state, mute state, and participant-join times. Message content is used to deliver conversations and may be accessed by authorized personnel only for a valid operational, safety, security, legal, or support purpose, including when content is reported.

UniSphere does not use private-message content for advertising, ordinary profile matching, or general-purpose generative-AI training. Conversation participants can copy, screenshot, or share what they receive, so no technical control can guarantee that a recipient will keep a message confidential.

Reports, moderation, support, and feedback

If you report a profile, project, message, or update, we collect the report reason, details, the reported item, relevant context, an evidence snapshot of the item at the time of reporting, status, actions taken, and related identifiers and timestamps. An evidence snapshot may preserve text or profile and project information even if the original is later edited or deleted. Moderation records may include reviewer identity, status changes, and a pre-redaction copy of a reported message.

When you contact support or submit product feedback, we collect your message, feedback type, page path, app version when available, account and school identifiers, resolution status, and our communications with you. If you appeal a moderation or privacy decision, we collect the appeal and information needed to review it.

Images and files

We collect profile images and project cover images you upload. UniSphere processes these files to validate the format, remove unnecessary file characteristics, resize or re-encode them, store them, and generate time-limited links for authorized viewing. We do not use profile images to create facial-recognition or biometric-identification templates.

Device, network, session, and security information

When you use the Service, we and our providers automatically receive information such as IP address, request headers, browser and device type, operating environment, requested page or API path, referring page where available, timestamps, session and authentication cookies, response status, and diagnostic or security events. Hosting providers may infer a general region from an IP address to route traffic and protect the Service; UniSphere does not request precise device location.

For login abuse prevention, UniSphere converts the submitted email address and request IP address into one-way SHA-256 fingerprints and stores the fingerprints with timestamps for rate limiting. The rate-limit record does not store the raw email address or raw IP address in those fields, although infrastructure logs and the authentication system may process them separately.

Product analytics and diagnostics

UniSphere currently sends a limited set of server-side product events to PostHog when a project is posted or completed and when a join request is sent or accepted. These events can include an internal Member identifier, school identifier, project or request identifier, project category, role or member counts, whether a role was selected, and event time. We configure these events not to create PostHog person profiles and do not send user-authored project text or private-message content in these events.

UniSphere uses Sentry for production error and performance monitoring when configured. Diagnostic records may include stack traces, page or API URL, release and environment information, timing, device or browser characteristics, and an internal user identifier. Our configuration removes cookies and authorization headers, does not send default personally identifying information, and replaces user details with the internal identifier before transmission. An unusual error can still contain unexpected information, so access is restricted and retention is limited.

Information from other people and organizations

Other Members provide information about you when they invite you, request to join your project, add you to a project, message you, connect with you, report content involving you, or identify you in shared project history. A participating school currently provides or confirms only information needed to configure eligibility, such as the school's name and approved email domains, unless a separate written agreement and notice authorize more. UniSphere does not obtain student rosters, grades, or education records from schools for ordinary Member accounts.

How we use information

We use personal information for the following purposes:

  • Provide the Service, create and maintain accounts, authenticate sessions, verify school-email eligibility, store files, deliver messages and notifications, and support project and connection workflows.
  • Display profiles, projects, roles, updates, participation records, and other Member-directed content to the audiences described in this Policy.
  • Search, filter, rank, and recommend people, projects, roles, and feed activity using school, profile, academic, taxonomy, project, connection, membership, and first-party activity signals.
  • Protect Members and the Service, enforce rules and blocks, rate-limit activity, detect fraud and misuse, investigate reports, preserve evidence, moderate content, and maintain audit records.
  • Respond to support, privacy, copyright, safety, and legal requests; communicate transactional notices; and send marketing only as permitted by law and your choices.
  • Measure whether the product works, diagnose errors, test and improve features, understand aggregate usage, conduct research, and create deidentified or aggregated statistics.
  • If advertising or sponsorships launch later, select and measure them as described in an updated version of this Policy without using private-message content.
  • Comply with law, valid legal process, tax and accounting requirements, and requests from authorities; establish, exercise, or defend legal claims; and complete a merger, financing, acquisition, or transfer.

We may use deidentified or aggregated information for research, reporting, service improvement, and business planning. We will not attempt to reidentify information that we maintain as deidentified except to test whether deidentification is effective or as otherwise permitted by law.

Matching, ranking, and artificial intelligence

UniSphere uses automated rules and scoring to organize search results, calculate compatibility, rank projects and people, recommend roles, generate feed activity, and prevent abuse. Relevant signals may include school, major or program, graduation year, courses, skills, interests, project categories, desired role skills, connections, project membership, and first-party activity. We do not intentionally use protected demographic information or private-message content for ordinary matching.

These systems support discovery and do not make decisions that produce legal or similarly significant effects such as admission, grading, employment, lending, housing, insurance, or access to essential services. Members and project owners make their own collaboration decisions.

UniSphere does not use Member Content, including profiles, projects, images, reports, or private messages, to train general-purpose generative artificial-intelligence models without a separate, specific, and affirmative opt-in. If we introduce an optional AI feature that needs to process Content, we will provide a feature-specific notice describing the data, purpose, provider, retention, and controls before use.

Who can see information in the Service

Verified Members at your school

Ordinary Member profiles, people discovery, non-draft projects, project roles, project updates, project participation, and feed activity are generally available to verified and onboarded Members assigned to the same participating school. Search and compatibility features use the same school boundary. Draft projects are limited to their owner and authorized service personnel until published.

Project owners and relevant participants can see join requests and decisions. Connection participants can see request and status information. Notification recipients can see the related notification. Blocking can reduce discovery and interaction between accounts, but it does not erase information already received or prevent every form of indirect visibility through a shared project.

Conversation participants and authorized reviewers

Direct and project messages are available to current conversation participants. A Member who leaves or is removed from an active project can lose access to the project conversation. Authorized UniSphere personnel and service providers may access messages or other restricted information only when reasonably needed for support, safety, security, system operation, legal compliance, or a valid report. Report reviewers can see the reported item and limited relevant context.

Marketing surfaces

Demo projects may appear on the public marketing site and are labeled as demos. A real Member project may appear publicly only after the project owner gives a separate affirmative promotional consent identifying the content to be displayed. We do not include school email addresses, private messages, or unrelated profile details in that public view. The owner can withdraw consent for future display, subject to reasonable removal time and copies outside UniSphere's control.

Schools

A school does not automatically receive administrative access to Member profiles, projects, messages, reports, or analytics merely because its email domain is eligible. If UniSphere later provides a school dashboard, institution-sponsored program, or school-licensed service, we will use a separate agreement, appropriate access controls, and additional notice where required.

How we disclose information

Other Members and people you direct us to

We disclose information to other Members according to the product visibility and actions described above. We also disclose information when you direct us to, such as when you link an external profile, send a message, join a team, contact an advertiser, or authorize public project promotion.

Service providers

We use vendors to host, authenticate, store, transmit, secure, analyze, monitor, communicate, and support the Service. Current core providers as of the effective date include:

  • Supabase for authentication, database hosting, file storage, and real-time message delivery.
  • Resend for transactional authentication email delivery through the configured Supabase mail service.
  • Vercel for application hosting, network delivery, deployment, and infrastructure logs.
  • PostHog for the limited server-side product events described above.
  • Sentry for scrubbed error and performance diagnostics.

Providers may process information only for the contracted service, security, compliance, and support purposes permitted by their agreements and applicable law. They may use their own subprocessors. We may replace or add providers as the Service changes and will update this Policy when a change materially affects Member information.

Advertisers and sponsors

UniSphere does not currently display third-party advertising. If advertising or sponsorships launch later, UniSphere may provide placement information and aggregated or deidentified campaign reports only after updating this Policy and implementing any required controls. We will not give advertisers private-message content or a Member's school email address or direct profile identifier unless the Member chooses to interact and authorizes the disclosure or the disclosure is otherwise clearly explained at the point of action.

We may preserve or disclose information when we reasonably believe it is necessary to comply with law, a subpoena, court order, or other valid process; respond to an emergency involving danger of death or serious physical injury; report suspected exploitation or abuse; protect the rights, safety, property, and security of Members, UniSphere, schools, service providers, or the public; investigate fraud or violations; or establish, exercise, or defend legal claims. We review legal demands and may narrow or challenge them when appropriate and legally permitted.

Business transfers

We may disclose information to advisers, investors, lenders, and counterparties in connection with incorporation, financing, due diligence, a merger, acquisition, reorganization, sale of assets, bankruptcy, or transfer of the Service. We will use reasonable confidentiality protections and require a successor to honor this Policy for previously collected information unless it provides legally sufficient notice and choices for a change.

No sale or cross-service targeted advertising

UniSphere does not sell personal information for money or other valuable consideration as a sale is defined by applicable U.S. privacy law. UniSphere also does not share personal information for cross-context behavioral advertising or process personal information for targeted advertising based on activity across nonaffiliated websites or services. We have not engaged in those practices during the 12 months before this Policy's effective date.

Advertising practices

The standard Service is free to Members. As of the effective date, UniSphere does not display third-party advertising in the Service and does not collect ad impressions, clicks, or campaign-performance data. Before launching advertising or sponsorship measurement, UniSphere will update this Policy, disclose the providers and data involved, and implement any legally required consent or preference controls.

UniSphere will not use private-message content to select or measure ads, permit advertisers to place third-party cross-site tracking pixels or software in private messages, or provide advertisers with lists of Members for independent targeting. If a future practice qualifies as a sale, sharing, or targeted advertising under applicable law, UniSphere will provide advance notice and required opt-out controls before beginning that practice.

An ad or sponsored link can take you to a third-party site. That third party can collect information under its own privacy policy when you visit or interact. UniSphere does not control the third party's practices, claims, or security.

Cookies and similar technologies

UniSphere and its authentication and hosting providers use cookies and similar browser storage that are necessary to keep you signed in, refresh and verify authenticated sessions, protect against misuse, remember limited settings, route requests, and maintain application state. Blocking necessary cookies can prevent login or core features from working.

As of the effective date, UniSphere sends the product analytics described above from its servers and does not use PostHog browser cookies or third-party advertising cookies in the authenticated application. Infrastructure providers may use necessary technologies to operate and secure their services. We will update this Policy and provide any required consent or preference controls before adding optional tracking technologies.

Some browsers offer Do Not Track or Global Privacy Control signals. There is no uniform response required for every signal and context. Because UniSphere does not currently sell personal information or use it for cross-service targeted advertising, an opt-out signal does not change those practices. Where applicable law requires a supported signal to control a future covered practice, we will honor it as required.

Retention and deletion

We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, maintaining shared records, protecting safety and security, resolving disputes, and complying with law. Unless a longer or shorter period is required for a specific record, our standard retention periods are:

  • Active account and profile records. Kept while the account remains active. When a Member completes self-service deletion, UniSphere immediately ends live Service access and replaces the active profile with a non-discoverable neutral record, subject to the shared-record and restricted-retention exceptions below. There is no grace period or account-restoration period.
  • Shared project history. When an owned project has an eligible active teammate, the deleting owner must select that teammate as the new owner. If other membership history exists but no teammate is currently eligible, an unfinished project is automatically archived and a completed or archived project remains as historical proof under a neutral “Deleted account” owner. A project with no other member history is removed from the active project board. These records are kept only as needed to preserve collaborators’ coherent shared history.
  • Messages. Kept while needed to provide the conversation. On account deletion, the Member’s message bodies are immediately replaced in ordinary Member access with a neutral deletion notice. The message row, timestamp, and delivery order remain to preserve conversation order and read state. Restricted report evidence or legal copies may remain under the periods below.
  • Reports and moderation evidence. Generally kept for two years after a report is closed. We may keep serious safety, fraud, repeat-abuse, legal-hold, or enforcement records longer when reasonably necessary and proportionate.
  • Product feedback and support records. Generally kept for up to 24 months after resolution, with longer retention when needed to document a commitment, dispute, or recurring defect.
  • Product analytics. Identifiable server-side event records are kept for up to 24 months, after which they are deleted or deidentified. Aggregated statistics that no longer identify a Member may be kept longer.
  • Diagnostics and infrastructure logs. Ordinary application and hosting logs are generally kept for up to 30 days, and Sentry diagnostic events for up to 90 days, unless a security investigation or legal need requires longer retention.
  • Rate-limit and security fingerprints. Authentication and anti-abuse fingerprints are generally kept for up to 30 days after the applicable rate-limit window, unless connected to an active abuse or security investigation.
  • Uploaded images. Account deletion removes profile images and images attached only to removed solo projects from active use and initiates removal from active storage. Replaced or deleted files are otherwise removed from active storage within a reasonable operational period. Residual encrypted backup copies can remain for up to 90 days.
  • Backups and disaster recovery. Residual copies can remain for up to 90 days and are isolated from ordinary use until overwritten, except when restoration is necessary.

We may retain information longer when required by law, valid legal process, tax or accounting rules, a litigation hold, safety needs, fraud prevention, or the need to establish or defend claims. We may retain deidentified information indefinitely if it cannot reasonably be linked back to a person and we maintain it in deidentified form.

Deletion from active systems does not guarantee removal from copies made by other Members, public search caches, or third parties. Self-service deletion takes effect immediately after the Member confirms the exact account handle and selects a valid successor for each transferable project. The fallback rules above archive or retain shared projects when no active successor exists, so the absence of a transfer target does not prevent deletion.

Security

UniSphere uses administrative, technical, and organizational safeguards designed for the sensitivity and stage of the Service. These include passwordless authentication, server-side identity and school derivation, row-level database access controls, school-scoped authorization, restricted storage with time-limited file links, rate limits, input validation, secret separation, monitoring, diagnostic scrubbing, and role-based access for moderation and administration. Service providers use encryption in transit and at rest for supported systems.

No system is completely secure. Members should protect their email account, authenticated devices, and one-time codes; use accurate links; avoid sharing secrets or unnecessary sensitive information; and promptly report suspected unauthorized access to support@unisphereconnect.com. If a security incident affects personal information, we will investigate and provide legally required notices.

Your choices and privacy rights

Account and content controls

You can review and update many profile fields in the Service, download a JSON copy of account information, delete your account through Settings, choose whether to provide optional information, manage project content and connections, mute conversations, block Members, withdraw a pending request where available, replace or remove images, and control eligible communications. Public promotion of a real project requires separate consent, which the project owner can withdraw for future display.

Transactional messages such as login codes, security notices, project activity, and material policy notices are part of operating the Service and may continue while your account is active. You can opt out of promotional email using the message's unsubscribe method or by contacting us, but the opt-out does not stop necessary service messages.

Rights under applicable law

Depending on where you live and whether the relevant law applies to UniSphere, you may have rights to ask UniSphere to take one or more of the following actions, subject to identity verification and lawful exceptions:

  • Confirm whether we process personal information about the Member and provide access to it.
  • Correct inaccurate personal information.
  • Delete personal information, subject to shared-record, safety, security, legal, and other permitted exceptions.
  • Provide a portable copy of account information in a reasonably usable format when technically feasible.

Additional state rights

Residents of certain states may have additional rights when the relevant law applies, including the right to know categories, sources, purposes, and recipients; opt out of a sale, targeted advertising, or certain profiling; limit particular uses of sensitive personal information; use an authorized agent; appeal a denied request; and receive equal service without unlawful discrimination. UniSphere does not currently sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising across nonaffiliated services, or conduct profiling that produces legal or similarly significant effects.

How to submit a request

Email legal@unisphereconnect.com with the subject "Privacy Request" and describe the right you want to exercise. Include the account email address and handle, but do not email a one-time code, password, government identification document, or other unnecessary sensitive information. We may ask you to verify control of the account email or authenticated session and to provide information reasonably needed to match the request to our records.

We will confirm and respond to a verifiable request within the time required by applicable law. When no law sets a deadline, we will aim to respond within a reasonable period based on the request's scope and available systems. Where permitted, we may extend a deadline, deny a request, or charge a reasonable fee for a manifestly unfounded, excessive, repetitive, or technically infeasible request, and will provide any explanation required by law.

An authorized agent may submit a request where law permits. We may require proof of signed authorization and may also verify the request directly with the Member. If we deny a request, a person entitled to appeal may email legal@unisphereconnect.com with the subject "Privacy Appeal" within 30 days of the decision. We will not unlawfully discriminate against anyone for exercising a privacy right.

California and other state disclosures

This section provides additional transparency for California residents and may also help residents of states with similar notice requirements. It applies to the extent the relevant law covers UniSphere.

Categories collected and disclosed

During the 12 months before the effective date, UniSphere collected the categories below from Members, devices, service providers, and other Members, except that advertising-interaction information will be collected only after advertising launches. We disclose these categories for the business purposes described in this Policy:

  • Identifiers. Name, handle, school email and domain, internal identifiers, IP address or fingerprint, session identifiers, and linked-profile addresses.
  • Customer-record and user-content information. Account communications, profile fields, project and role information, messages, reports, feedback, images, and shared records.
  • Internet or electronic activity. Login, session, page and API requests, product events, interactions, notification and read state, device or browser information, diagnostics, and ad interactions after advertising launches.
  • Approximate geolocation. General region inferred from IP address by infrastructure providers for routing, security, and aggregate analysis; not precise device location.
  • Professional and education-related information. School affiliation, program or major, minor, graduation year, courses and terms, skills, interests, project roles, and collaboration history.
  • Inferences. Compatibility, ranking, recommendation, anti-abuse, and interest signals derived from the categories above.
  • Sensitive personal information. Account-login credentials or session information and the contents of private messages. UniSphere uses these only for service delivery, authentication, security, safety, support, and legal compliance and not to infer personal characteristics.

We disclose these categories to the Member-directed recipients, service providers, legal and safety recipients, and business-transfer recipients described above. We do not sell or share these categories for cross-context behavioral advertising. We do not knowingly sell or share the personal information of people under 16, and the Service does not permit accounts for anyone under 18.

UniSphere does not offer a financial incentive or price or service difference in exchange for personal information. California residents can use the request process above to exercise applicable rights to know, access, correct, delete, limit, opt out, or use an authorized agent.

People under 18

The Service is intended only for people age 18 or older. Signup must require an affirmative 18+ attestation, but UniSphere does not independently verify age merely because a person controls a school email address. UniSphere does not knowingly permit Member accounts for anyone under 18 and does not permit a parent to consent to an underage account. If we learn that an underage person created an account, we may suspend the account, request limited age-verification information, and delete the account and personal information, subject to safety, legal, and shared-record exceptions. Contact legal@unisphereconnect.com if you believe an underage person is using the Service.

Schools, education records, and FERPA

UniSphere is an independent service and is not a school, school official, or institutional records system solely because it accepts a school email address. Information a Member voluntarily provides to UniSphere is not automatically an official education record maintained by the school. Members should not upload grades, transcripts, student records, protected research, or other school-controlled information unless authorized and the Service is appropriate for that use.

If a school later contracts with UniSphere to process education records or provide an institutional function, the separate agreement will define the school's and UniSphere's roles, permitted uses, access, security, retention, deletion, and any rights required by the Family Educational Rights and Privacy Act or other applicable law. That agreement and a supplemental notice will control for the covered institutional data if they conflict with this general Policy.

United States service and future international expansion

The Service is initially offered for use in the United States. UniSphere and its providers may process and store information in the United States. U.S. law may differ from the law where a person is located. We may restrict access from outside the United States. Before intentionally offering the Service in another country or region, we will evaluate applicable requirements and provide any regional notices, lawful transfer mechanisms, consent controls, or other protections required for that launch.

Changes to this Policy

We may update this Policy as the Service, providers, laws, and practices change. We will post the updated version with a new effective date. If a change materially expands how we use or disclose previously collected personal information or materially reduces Member choices, we will ordinarily provide at least 30 days' advance notice by email, in-product notice, or another reasonable method and obtain consent when required by law. We may make a change effective sooner when reasonably necessary for safety, security, legal compliance, or to correct an error, with notice as soon as practicable.

Contact UniSphere

Privacy questions and requests: legal@unisphereconnect.com. Mailing address: Unisphere Connect LLC, 551 E Apache Blvd, Apt 1228, Tempe, AZ 85281.

General support and account access: support@unisphereconnect.com

Please do not include one-time login codes, government identifiers, financial information, or unnecessary sensitive information in an email request.

Privacy Policy · UniSphere