Skip to main content
Ubikas
Demo

Privacy Statement

Welcome to the Ubikas Privacy Statement. This is where we describe how we handle your "Personal Data", which is information that is directly linked or can be linked to you. It applies to the Personal Data that Ubikas SpA processes as the "Data Controller" when you use the Ubikas mobile app, this website, or the operations dashboard (collectively, the "Services"). The short version: we do not sell your data, we do not follow you across other apps and websites, and we never record what you type. The detail is below.

Effective September 7, 2026

End User Notice: Campus Affiliations

You create your own Ubikas account, and Ubikas remains the Data Controller for it. That does not change when you affiliate with a university or college (an "Institution").

What does change is who can see your activity on that Institution's campuses. Its administrators can see:

  • the places, photographs and details you submit on their campuses, together with your account as the submitter;
  • moderation decisions affecting members of their Institution; and
  • audit records for actions taken within their Institution.

They cannot see your location, what you search for, or your activity on another Institution's campuses. For campus data the Institution itself publishes, and for moderation decisions its staff take, the Institution acts as an independent controller and its own privacy policy applies alongside this one.

Personal Data We Collect

Personal Data is collected from you directly, automatically from your device, and from a small number of third parties. What we process depends on how you use the Services and on the permissions you grant.

From you

  • Account Data: your account identifier, email address, first and last name, profile picture and campus affiliation, received from WorkOS when you sign in.
  • User Content: the places, photographs, descriptions, aliases, schedules, closures, accessibility tags and contact details you submit, stored with your account as the submitter.
  • Consent Records: which consent you granted or withdrew (location or marketing), where in the app you did it, the version of the wording you saw, and when. This is how we demonstrate that your choices were respected.
  • Enquiry Data: if you write to us through the contact form on this website, your name, email address, institution, country and the campus size you select, together with any campaign parameters carried by the link that brought you to the form. We use it to answer you.

Automatically

  • Geolocation Information: precise device location, in the foreground only, and only while both your operating system permission and the in-app location consent are granted. It is held in memory to draw your position and the compass on the map. It is not transmitted to our servers and not stored. The one exception is that when you submit a new place, the coordinates of that place are sent with the submission.
  • Service Usage Information: every request to our API is logged with your IP address, the request method and path, the response status, the time taken, and a random request identifier. Request bodies and authentication headers are never logged.
  • Anti-Abuse Session Counters: a short-lived session records how many searches, place lookups, map tiles and snapshots it has used, so that we can stop abuse. It holds counters only — never which place was searched or opened. For anonymous visitors it carries a hash derived from IP address and browser user agent. It expires after 15 minutes.
  • Diagnostics: crash reports and a 10% sample of performance traces from the mobile app, sent to Sentry only after your saved preference loads and while the control is on. They include the error type and stack, screen route names, your account identifier, the technical campus identifier and mode, and app version, build and update data. Logger messages and structured values, personal names, email addresses, free text, precise coordinates, image keys and tokens are removed before sending. IP collection is disabled, and there is no session replay or profiling. Diagnostics are switched off entirely in development builds.
  • Product Analytics: while the "Share Usage Data" switch is on, the mobile app sends PostHog a record of the steps you take: onboarding, signing in and out, opening search, a search ending, selecting a result, viewing, saving or sharing a place, starting and completing a submission, changing campus, and the screen you are on. These events carry identifiers and counts, never content — a place or campus identifier, a category, the position of a result, how many results came back, and the length of a search query. They never carry the text you typed, and never a place or campus name. Your account identifier is attached. Your name, email address and profile picture are not. Location lookup from IP address is disabled, there is no session replay, and analytics are switched off entirely in development builds. This website sends the same service a smaller set: which section you scrolled to, which FAQ you opened, which call to action you clicked, and whether you started or abandoned the contact form. Cookies explains what the website stores on your device, and what it does not.
  • App Open Counts: a count of cold app starts, collected anonymously by Expo and not linked to your account.

From third parties

  • Your identity provider: WorkOS supplies the Account Data above when you sign in, and confirms your campus affiliation.
  • Other users: other people may reference you when they submit content or report an issue.

Stored only on your device

Saved places, recent searches, place history, favorite campuses, onboarding state and the encrypted offline campus cache stay on your phone. There is no favorites table and no search-history table in our database. Uninstalling the app removes all of it.

What We Do Not Collect

Being specific about the absences matters as much as listing the collection:

  • No advertising identifiers, no cross-app tracking, and no App Tracking Transparency prompt — there is nothing to ask permission for.
  • No record of what you type. A search reaches our analytics as the length of the query and nothing else, and no table in our database records what you searched for, viewed or tapped. What the analytics events do carry is set out under Personal Data We Collect.
  • No demographic data. No gender, no date of birth, no nationality — we ask nothing about who you are beyond a name and an email, and nothing about your age beyond the minimum in the Terms of Service.
  • No contacts, calendar, health data or microphone audio.
  • No push notifications; the Services have no notification provider.
  • No payment information. The student app is free.

We do not sell Personal Data, and we do not share it with advertisers or data brokers.

Processing Purposes: How We Use Your Personal Data

We process Personal Data for the following purposes:

  • Service Provision: operating your account, showing you campus data, and publishing what you submit.
  • Navigation: drawing your position on the map, on the device, while location consent is granted.
  • Content Moderation: reviewing submissions before they are published, and acting on content that breaks our terms.
  • Safety and Security: detecting and preventing abuse, applying rate limits, and verifying that anonymous visitors are human.
  • Troubleshooting: identifying and resolving crashes and performance problems.
  • Product Measurement: understanding which parts of the Services are used and where people get stuck, so that we can improve them.
  • Answering Enquiries: replying to a message you send us through the contact form.
  • Communication: sending you technical notices, security alerts and administrative messages, and marketing only where you asked for it.
  • Complying with legal obligations: responding to data subject requests, and retaining consent and audit records.

When carrying out these activities we practise data minimization and use the minimum amount of Personal Data required.

Sharing of Personal Data

We may share Personal Data with the following recipients:

RecipientWhat forWhere
WorkOSSign-in and identityUnited States
SupabaseThe database holding accounts and campus dataSão Paulo, Brazil (sa-east-1)
CloudflareAPI and website hosting, image and map storage, rate limiting, bot verification, and cookieless website analyticsGlobal edge network
SentryCrash and performance diagnostics from the mobile appUnited States
PostHogProduct analytics for the website and the mobile appUnited States
ExpoOver-the-air app updates and anonymous app-open countsUnited States
ResendDelivering contact-form enquiries to our sales mailboxUnited States
Apple, GoogleDistributing the app through their storesUnited States
  • Subprocessors and Service Providers: the vendors above provide services on our behalf and are bound by contractual obligations to protect the security, privacy and confidentiality of your information.
  • Institutions: where you are affiliated with an Institution, we share the information described in End User Notice: Campus Affiliations with its administrators.
  • Other Users and the Public: content you submit to a campus is visible to other users of that campus and, where the Institution publishes its map publicly, to the public.
  • Competent Authorities: we may disclose Personal Data to law enforcement, regulators or courts in response to lawful requests, or to protect the rights and safety of Ubikas and its users.

Lawful Bases for Processing Personal Data

We process Personal Data in compliance with Ley 19.628 and Ley 21.719 in Chile, and with the GDPR where it applies, ensuring a lawful basis for each processing activity:

  • Contractual Necessity: processing required to fulfil our obligations to you under the Terms of Service — running your account, showing you campus data, and publishing what you submit.
  • Consent: precise location, and marketing communications. Where we rely on consent you may withdraw it at any time, and the app keeps working without it.
  • Legitimate Interests: crash and performance diagnostics, product analytics, request logging, rate limiting and bot verification, all of which serve our interest in a service that stays available, works, and is free of abuse; answering an enquiry you send us; and keeping a deleted account from being recreated. Diagnostics and product analytics are on by default, and each has its own switch in the app. We rely on this basis only where it is not overridden by your rights and freedoms.
  • Legal Obligation: retaining consent and audit records, and responding to lawful requests.

Your Choices

The controls below are in the app, under Profile → Privacy.

  • Location. Off until you turn it on. Two switches must agree: the operating system permission and the Ubikas location consent. Turning either off stops location being read at all. Search, directions to a place and the campus map all keep working without it — you will simply not see your own position.
  • Marketing. Off unless you opt in.
  • Your contributions. You can ask us to take down anything you have submitted, at any time.
  • Your account. You can delete it yourself. Deletion is permanent and the same email address cannot open a new account afterwards, so read what deletion does first.
  • Diagnostics. On until you turn them off. The "Send Crash Reports" switch in the app stops crash and performance data leaving your device; nothing further is sent from the moment you turn it off. Diagnostics already received stay with Sentry until its retention window expires, or write to privacy@ubikas.app to have them removed sooner.
  • Usage data. On until you turn it off. The "Share Usage Data" switch, next to the one above, stops product analytics leaving your device. The app works exactly the same without it. Events already received stay with PostHog until its retention window expires, or write to privacy@ubikas.app to have them removed sooner.

Your Privacy Rights

Depending on where you live, you have specific legal rights regarding your Personal Data. Under Ley 19.628 and Ley 21.719 these are the rights of access, rectification, cancellation and opposition. Where the GDPR applies, you also have:

  • the right to access the data collected about you
  • the right to rectify or update inaccurate or incomplete Personal Data
  • the right to erase or limit the processing of your Personal Data under specific conditions
  • the right to object to processing based on our legitimate interests
  • the right to withdraw consent, where processing is based on your consent
  • the right to receive your Personal Data in a structured, commonly used and machine-readable format

To exercise these rights:

  • Deletion is self-service, in the app, under Profile → Privacy. It takes effect immediately and it is permanent: the same email address cannot open a new account afterwards. Read what deletion does before you start.
  • Rectification is self-service too — edit your profile in the app.
  • Everything else, including a copy of your data, restriction, objection or a complaint, goes to privacy@ubikas.app. There is no self-service export yet, so we assemble copies by hand.

We aim to respond within 30 days. To verify your identity for security, we may request additional information before addressing your request. Depending on your region, you also have the right to complain to the Chilean data protection authority or to your local supervisory authority in the European Economic Area.

What Deletion Actually Does

Being precise about this matters more than sounding thorough, so here is exactly what happens.

DataWhat happens
Consent records, audit log entries, campus affiliations, moderation recordsDeleted outright.
Your account recordAnonymised, not removed. The email is replaced with a placeholder and the name and profile picture are cleared. The record itself remains so that content already published does not break.
Submissions still awaiting reviewDeactivated.
Places, photographs and events of yours already approvedStay published on the campus map, attributed to the anonymised account rather than to your name. Write to us if you want specific contributions taken down as well.
Diagnostics already sent to SentryNot reached by deletion. They carry your former account identifier until they age out of Sentry's retention window. We do not forward deletion requests to Sentry automatically — ask us and we will do it by hand.
A record that the account was deletedKept indefinitely. It holds a one-way hash of your email address and the date it was deleted, and nothing else — no name, no account identifier, and no address anyone can read back out of it. It exists so that a deleted account cannot be recreated. That also means the same email address cannot be used to open a new account afterwards. Deletion is permanent, so please be sure before you start it.
Anything stored only on your phoneRemoved by uninstalling the app.

International Data Transfers

Ubikas is operated from Chile, but stores and processes Personal Data in a variety of locations. Our database is hosted in São Paulo, Brazil. The other recipients listed above are based in the United States or operate globally. Your Personal Data is therefore processed outside Chile and outside the European Economic Area.

When we transfer Personal Data from the European Economic Area, the United Kingdom or Switzerland to countries that have not been recognized as providing an adequate level of protection, we generally rely on the standard contractual clauses published by the European Commission, to help protect your rights and enable those protections to travel with your data.

Security and Retention

We use administrative, technical and physical controls to protect your Personal Data. Everything is encrypted in transit. The database and the image store use the encryption at rest provided by our hosting platforms. Our API is the only internet-facing surface; the service that reads the database is internal and unreachable from the internet. Access is scoped by role and by Institution, sensitive operations write to an append-only audit log, and sign-in tokens are held in your device's secure storage.

If you believe you have found a vulnerability, our Coordinated Disclosure of Security Vulnerabilities policy explains how to report it.

On retention:

  • Account and profile data is retained while your account is active, and anonymised on deletion as described above.
  • Consent, audit, affiliation and moderation records are retained while your account exists and deleted when you delete your data. We do not currently run an automated purge on a fixed schedule, so we are not promising you one.
  • Anti-abuse session counters expire after 15 minutes and delete themselves. Signed links to a place expire after two minutes.
  • Web session cookies last 5 minutes; the refresh cookie lasts 30 days.
  • Diagnostics are retained by Sentry under its retention window.
  • API request logs are retained under our hosting provider's log retention.
  • Enquiries sent through the contact form are retained while we are in contact with you about them, and the copy delivered to our sales mailbox is retained with our email provider.
  • The record that an account was deleted is kept indefinitely. It is a one-way hash of an email address and a date, and what deletion does explains why it outlives everything else.

Our Use of Cookies and Tracking Technologies

Short version: This website remembers your language, and asks once whether analytics may use your device's storage. Decline and we still count the visit, but nothing is stored.

  • This website sets one cookie without asking, NEXT_LOCALE, which remembers whether you chose English or Spanish.
  • Website analytics are provided by PostHog. Until you answer the banner, and afterwards if you decline, they run in cookieless mode: no cookie, no local storage, and no identifier on your device. If you accept, PostHog sets a cookie and a local storage entry so we can tell a returning visitor from a new one.
  • The web version of the app uses two session cookies to keep you signed in. Both are httpOnly, so no script can read them.
  • The mobile app uses no cookies. Sign-in tokens are held in the iOS Keychain or the Android Keystore.

What cookieless mode means. Rather than putting an identifier on your device, PostHog works out a temporary one on its servers by hashing your IP address, your browser's user agent, and the site you are on together with a secret that is replaced every day and then destroyed. Once the day's secret is gone the hash cannot be traced back, and the next day the same visit produces a completely different one. It is enough to tell one visit apart from another; it is not enough to follow you.

If you decline, nothing about the site changes and nothing is stored except the record of your refusal, which is what stops us asking again on every page. We set no advertising cookies, and we do not track you across other websites.

You can change your mind by clearing this site's data in your browser, which resets the question.

Information for Minors

The Services are built for campus communities and are not intended for individuals under the age of 14. You must be at least 14 to hold your own account; below that age, a parent or guardian must set it up and consent on your behalf.

We do not collect dates of birth and therefore cannot verify age. If you become aware that a minor has provided us with Personal Data, please notify us at privacy@ubikas.app and we will close the account and delete the data.

Changes to This Statement

We may periodically revise this Privacy Statement. If there are material changes, we will provide at least 30 days' prior notice by updating this website or sending an email to the address associated with your account. Where a change requires your consent, we will ask for it rather than assume it.

Contact Us

Contact us by emailing privacy@ubikas.app. Our address is:

Ubikas SpA — RUT 78.364.498-3 Dublé Almeyda 2621, Santiago Chile

For security reports, write to security@ubikas.app. For questions about the Terms of Service, write to legal@ubikas.app.