Privacy Policy
We believe privacy is a right, not a feature. Here's exactly how Uno handles your data.
Overview
EthicCode built Uno on a simple promise: your data is yours. This Privacy Policy explains exactly what we collect, why we collect it, how we use it, and what rights you have. We've written it to be read by humans, not just lawyers.
Uno is the centralized identity and authentication platform for EthicCode products (CRM, AI, ERP, Docs, Mail, Meet, and others). When you create a Uno account, this policy governs how your identity data is handled across all connected products.
What we collect
Account Information
When you create a Uno account, we collect your email address. That's it. We don't require a name, phone number, or any other personally identifiable information to sign up.
Authentication Data
To verify your identity securely, Uno issues one-time codes (OTP) and magic links. These are single-use, expire quickly, and are never logged after verification.
Session Data
We store session tokens to keep you signed in. Each session record includes a device/browser identifier, approximate IP address (for geographic context), and a timestamp. You can view and revoke any session at any time from your account dashboard.
Connected App Data
When you authorize an EthicCode product through Uno (OAuth), we log which apps you've granted access to, what scopes were approved, and when. You can revoke any connection at any time.
Usage & Technical Data
We collect standard server logs including IP addresses, request timestamps, and response codes to operate and secure the platform. These logs are retained for 30 days and then automatically deleted.
What we do NOT collect
We do not use third-party advertising trackers. We do not build behavioral profiles. We do not sell your data. We do not use fingerprinting technology.
How we use your data
We use the data we collect strictly to operate Uno. Specifically:
Authentication & Security — To verify your identity, detect suspicious sign-in attempts, and send you security alerts if your account is accessed from a new location or device.
Session Management — To maintain your signed-in state across EthicCode products and give you visibility and control over every active session.
Product Access — To authorize your access to connected EthicCode products through OAuth tokens, scoped to exactly the permissions you approved.
Communication — To send transactional emails only: OTP codes, magic links, security alerts, and product notifications directly related to your account activity. We do not send marketing emails without explicit opt-in.
Service Improvement — Aggregated, anonymized usage patterns (not linked to individual accounts) help us improve reliability and performance.
Data storage & retention
Where your data lives
Uno infrastructure is hosted on servers within the European Union and India, depending on regional configuration. Data is encrypted at rest (AES-256) and in transit (TLS 1.3+).
Retention periods
Account data is retained for as long as your account is active. If you delete your account, your email address and all associated data are permanently deleted within 30 days.
Session logs are retained for 90 days, then automatically purged. Server access logs are retained for 30 days.
OTP codes and magic links are single-use and deleted immediately after verification (or upon expiry if unused).
Your rights
You have comprehensive rights over your data, regardless of your location:
Access — Download a complete export of all data Uno holds about you from your Account → Data & Privacy page.
Correction — Update your email address and any other account information at any time.
Deletion — Permanently delete your account and all associated data. Deletion is irreversible and completes within 30 days.
Portability — Export your data in machine-readable JSON format at any time.
Revocation — Revoke access to any connected app or active session instantly from your account dashboard.
Objection — You can object to any processing of your data. Contact us at letstalk@ethiccode.in and we will respond within 30 days.
If you're located in the EU/EEA, you additionally have rights under GDPR, including the right to lodge a complaint with your local data protection authority.
Security
Security is core to Uno's architecture, not an afterthought.
Authentication — Password-free by design. OTP codes and magic links are cryptographically signed, single-use, and expire within 10 minutes.
Token security — OAuth tokens are signed with RS256 keys, automatically rotated, and stored in secure HTTP-only cookies. Refresh tokens are single-use and invalidated on rotation.
Transport — All data in transit is encrypted with TLS 1.3. HSTS is enforced with a minimum max-age of one year.
Storage — All sensitive data is encrypted at rest using AES-256. Cryptographic keys are managed in a hardware security module (HSM).
Monitoring — We maintain audit logs of all authentication events and administrative actions. Suspicious activity triggers automatic alerts.
If you discover a security vulnerability, please report it responsibly to letstalk@ethiccode.in. We are committed to responding within 48 hours.
Children's privacy
Uno is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will delete it promptly.
If you believe a child under 16 has created an account, please contact us at letstalk@ethiccode.in.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
Your continued use of Uno after changes take effect constitutes your acceptance of the updated policy. If you disagree with any changes, you may delete your account before they take effect.
Contact us
If you have questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
Email: letstalk@ethiccode.in
Response time: We aim to respond to all privacy inquiries within 5 business days.
For data deletion or export requests, you can also use the self-service tools in your Account → Data & Privacy page, which process instantly.