Privacy Policy
1.Introduction
UniBot ("UniBot", "the App", "we", "us", "our") is a companion app for university students in Azerbaijan, operated by Aslan Mammadrzayev ("the Developer"), who is the data controller for the processing described here. This Privacy Policy explains what information the App collects, why, how we protect it, and the choices and rights you have. It covers the UniBot mobile app, its home-screen widgets, our backend service, and our optional Telegram bot.
By creating an account or using the App, you agree to the collection and use of information as described here. If you do not agree, please do not use the App.
2.Information we collect
2.1Account information
When you sign in with Google or Apple, we receive your name, email address, and profile photo (if available) from that provider, together with an authentication token that lets us recognize you on future visits. UniBot has no public self-service password registration — every account is created through Google or Apple Sign-In. During or after onboarding you may also tell us your university and preferred interface language (Azerbaijani, Russian, or English).
2.2University e-journal credentials
For most partner universities (currently UNEC, AzTU, BDU, and AMU/ATU), you connect your account by entering the username and password you already use for your university's own electronic journal or student portal. We use these credentials to sign in to your university's system on your behalf and retrieve your grades, attendance, schedule, exams, and study materials — the same information you could see by logging in yourself.
Your e-journal password is encrypted (AES-256-GCM) before it is stored on our servers, and is decrypted only in memory, at the moment we need to sign in to your university's portal.
ASOIU (ADNSU) works differently. Because that portal requires a CAPTCHA challenge that cannot be solved on a server, the login and all data retrieval happen directly on your device inside the App. Your ASOIU credentials never reach our servers; they are stored only on your device, in the operating system's secure keystore (iOS Keychain / Android encrypted storage).
We are an independent tool, not affiliated with, endorsed by, or operated by any university. Your university remains the sole source of official academic records.
2.3Academic data and background access
We store a copy ("snapshot") of the academic data we retrieve so the App can still show something useful when your university's portal is temporarily unavailable, and so we can show trends over time such as grade history and GPA forecasts.
Please read this carefully. If you turn on grade-change alerts or class reminders, our servers will sign in to your university portal periodically in the background, using your stored credentials, even when you are not using the App. This is what makes it possible to notify you that a grade appeared or that a class is starting soon. These background checks are automated, are limited to reading your own academic pages, and run only while the corresponding feature is enabled.
You can stop background access at any time by turning those notifications off in the App, or by disconnecting your e-journal entirely (Profile → disconnect), which also deletes the stored credentials.
2.4Device permissions you control
The App asks for the following permissions only when you use the feature that needs them, and you can revoke any of them in your device settings:
- Calendar — to export your class schedule into a dedicated calendar on your device. We write events to that calendar; we do not read or upload your other calendar data.
- Photos — to let you attach a screenshot to a bug report or suggestion. Only the image you pick is uploaded.
- Notifications — to deliver the alerts you have turned on.
If you add a UniBot home-screen widget, a summary of your schedule is stored on your device so the widget can display it outside the App.
2.5Teacher directory and reviews
We maintain a directory of teachers built from information already present in university e-journals and on public university websites (name, department, faculty, subjects taught, and similar public professional details). If you submit a rating or written review, we store it together with your account, star rating, and comment. You may post anonymously — your name is then hidden from other users, but we keep it internally to moderate content and confirm reviews come from real students. Reviews are held for moderation and are reviewed by a person before they are published. We may combine your class enrolment history (from the e-journal) with your review to mark it as "verified".
2.6Internships
Internship and job listings shown in the App are aggregated automatically from public third-party job boards and career pages; we do not send any of your personal information to those sources. If you save a listing, we store that choice against your account so it is available across your devices.
2.7Subscriptions and payments
Premium subscriptions are sold through the Apple App Store or Google Play and managed by RevenueCat, our subscription provider. We never see or store your payment card details — Apple, Google, and RevenueCat handle billing. We receive and store subscription status (which plan is active, when it renews or expires) and a record of subscription events, so we can unlock Premium features and resolve billing disputes.
2.8Notifications
If you enable push notifications, we store a device push token (issued by Expo and Firebase Cloud Messaging) and a record of the notifications sent to you — including their title and text — so we can avoid duplicates and show your notification history in the App. Note that a grade-change alert contains the subject and score it refers to.
2.9Telegram bot (optional)
If you choose to link your Telegram account, we store the connection between your UniBot account and your Telegram chat so we can deliver updates there too. You can unlink it at any time.
2.10Support and feedback
If you contact support or submit feedback or a bug report through the App, we store your message, any screenshot you attach, and basic technical context (app version, operating system, device platform, and language) so we can reproduce and fix the issue and reply to you.
2.11Advertising
Free-tier use of the App includes ads served through Google AdMob. Depending on your region and your consent choices, AdMob may process advertising identifiers and other device signals to show personalized or non-personalized ads; that processing is governed by Google's own privacy policy. Where required (for example in the EEA and the UK), we show a consent form before requesting ads. On iOS, the system also asks for your permission to track before any advertising identifier is used. You can revisit your choice at any time from Settings → Privacy Options in the App. Premium subscribers do not see ads.
2.12Device and diagnostic data
Like most apps, we automatically receive some technical information — device model, operating system version, app version, crash reports, an installation identifier, and similar diagnostics — needed to keep the App working reliably.
3.AI-assisted features
Some content is processed by third-party AI providers strictly to power a feature you use — for example, translating a teacher review into another interface language, or extracting structured details (role, location, deadline) from a public internship listing. These providers receive only the specific content needed for that feature. They never receive your account credentials, your e-journal password, or your grades.
4.Automated processing and forecasts
The App automatically computes analytics from your academic data — averages, GPA estimates, projected end-of-semester results, and comparisons against anonymized cohort statistics from other students. These are informational estimates produced by simple arithmetic models, not decisions about you. They have no legal or similarly significant effect, are not shared with your university or any employer, and are not official academic records.
5.How we use your information
- To create and secure your account, and to connect to and refresh your university e-journal data on your behalf.
- To operate core features: dashboard, schedule, grades and attendance, GPA analytics and forecasts, teacher ratings, internships, discounts, and academic calculators.
- To send the notifications you have opted into and to respond to support requests.
- To detect, prevent, and investigate fraud, abuse, or security incidents — for example fake reviews, or unauthorized attempts to use your e-journal connection.
- To produce aggregate, non-identifying statistics (such as course averages and teacher ratings) shown to other students, and to improve the App.
- To show ads to non-subscribers, and to manage and validate Premium subscriptions.
6.Legal bases for processing
Where the GDPR or a similar law applies to you, we process your information on these bases: performance of a contract (providing the features you sign up for); your consent (optional features such as notifications and background e-journal checks, personalized ads, Telegram linking, and device permissions); our legitimate interests (keeping the App secure, preventing abuse, producing aggregate statistics, and improving the product); and compliance with legal obligations.
7.Who we share information with
We do not sell your personal information. We share it only as needed to run the App:
- Your university's own e-journal system — only your login credentials, sent directly to authenticate as you (see section 2.2).
- Google (Sign-In, Firebase Cloud Messaging, Google Mobile Ads) and Apple (Sign-In, App Store subscriptions) — for the features above, under their own privacy terms.
- RevenueCat — to manage and validate App Store and Google Play subscriptions.
- Cloudflare (object storage) — to host images you or we upload, such as a feedback screenshot.
- Expo — to deliver push notifications.
- AI providers, for the narrow features described in section 3.
- Telegram — only if you choose to link your Telegram account.
- Authorities, where disclosure is required by law, to enforce our Terms, or to protect the rights, safety, or property of UniBot, our users, or others.
We do not share your e-journal password, or the content of your academic records, with advertisers or data brokers.
8.Retention and account deletion
We keep your account information for as long as your account is active. When you delete your account (Profile → Delete Account), we immediately:
- replace your name and email address with anonymized placeholders and remove your profile photo;
- revoke all active sessions and unlink your Google and Apple sign-in, so the account can no longer be signed into;
- disconnect your university e-journal and delete your stored encrypted credentials, your cached portal session, and your cached academic snapshots; and
- remove the link between your account and your Telegram chat; and
- revoke your devices' push notification tokens.
What we keep, and why. The account record itself is retained in a deactivated, de-identified state rather than erased from the database. Records that reference it — historical grade and attendance observations, teacher reviews you posted, class enrolment records, notification history, and support tickets — are also retained, because deleting them would corrupt the aggregate statistics other students rely on (course averages, teacher ratings) and would remove reviews other students are reading.
These retained records no longer carry your name, email address, or photo, but they remain technically linked to the deactivated account identifier. We therefore describe this as pseudonymization, not full anonymization, and we would rather say so plainly than overstate what deletion does. Teacher reviews you published remain visible.
If you want a specific review taken down, or want your remaining records erased entirely rather than pseudonymized, email [email protected] and we will do so, except where we are legally required to keep a record.
9.Data security
We encrypt your university e-journal password at rest with AES-256-GCM, and all traffic between the App and our servers uses TLS. On your device, session tokens and any locally held credentials are kept in the operating system's secure keystore. Access to production systems is restricted to those who need it to operate the service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we protect your information using industry-standard safeguards.
10.Your rights and choices
Depending on where you live, you may have the right to:
- access a copy of the personal information we hold about you;
- correct inaccurate information, such as your name, university, or language;
- delete your account and associated personal information, as described in section 8 — from the App (Profile → Delete Account) or by emailing us;
- withdraw consent at any time for optional features (notifications, background e-journal checks, personalized ads, Telegram linking, e-journal connection) without affecting the lawfulness of processing before withdrawal;
- object to or restrict certain processing, and request data portability, where applicable law grants these rights; and
- lodge a complaint with your local data protection supervisory authority if you believe we have handled your information unlawfully.
To exercise any of these rights, contact [email protected]. We may need to verify your identity before acting on a request, and we aim to respond within 30 days.
Advertising choices: manage ad-personalization consent any time from Settings → Privacy Options in the App. You can also limit ad tracking through your device settings (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Privacy → Ads).
11.Children's privacy
UniBot is intended for university students and is not directed at children. You must be at least 16 years old to use the App. We do not knowingly collect personal information from anyone under 16; if we learn that we have, we will delete it.
12.International data transfers
Our infrastructure and service providers may process data outside the country where you live, including countries whose data-protection laws differ from your own. Where required, we rely on appropriate safeguards for such transfers.
13.Changes to this policy
We may update this Privacy Policy as the App evolves. We will update the "Last updated" date above and, for material changes, give notice in the App. Continued use of the App after a change takes effect means you accept the updated Policy.
14.Contact us
Questions or requests regarding this Privacy Policy:
Aslan Mammadrzayev
[email protected]