Legal
Privacy Policy
How UnitFactor collects, uses and protects information when you use UnitX on the web, on your phone, and through our API. The short version: we use your information to run the service you signed up for, we do not sell it, we do not show ads, and we do not use your content to train AI models.
Effective 19 September 2026
Contents
- 1. Who we are
- 2. Information we collect
- 3. How we use information
- 4. Legal bases (EEA, UK and similar laws)
- 5. How we share information
- 6. How long we keep information
- 7. How we protect information
- 8. International transfers
- 9. Your rights and choices
- 10. The mobile apps
- 11. Cookies and local storage
- 12. Children
- 13. Changes to this policy
- 14. Contact us
1. Who we are
UnitX is a work-management platform operated by UnitFactor ("we", "us"). This policy covers the UnitX website, the web application, the UnitX mobile apps for iOS and Android, the UnitX browser extension, and the UnitX API (together, the "Service").
Two roles matter here. For your account, billing and our own website, UnitFactor decides how information is used and is the data controller. For the content an organization puts into its workspace (its projects, tasks, documents, messages, files and records), the organization is in charge and UnitFactor processes that content on its behalf, following its instructions and our agreement with it. If you use UnitX through your employer or another organization, their privacy notice also applies, and some requests (for example, deleting workspace content) are for them to decide.
2. Information we collect
Information you give us:
- Account details: your name, email address, and password (stored only as a salted hash). If you turn on two-factor authentication we store your authenticator secret encrypted; if you register a passkey we store its public key, never a private key.
- Workspace content: everything you and your colleagues create or upload, such as projects, tasks, comments, documents, messages, forms, files, time entries, and CRM, support and HR records.
- Communications: messages you send us through the contact form or by email, and the details you include in them.
- Integrations and imports: when you connect another tool (for example to migrate from Trello, Jira, ClickUp or Asana, or to sync data), the access tokens you authorize, which we store encrypted, and the data you choose to bring in.
Information collected automatically when you use the Service:
- Sessions and security records: IP address, browser or device type, and the time you signed in, so you can see and revoke your signed-in devices and so we can detect misuse.
- Activity and audit records: which actions were taken in a workspace and by whom (for example, "task moved to Done"), which power activity feeds, notifications and the audit log.
- Mobile devices: if you allow notifications, the push notification token for your device, its platform (iOS or Android) and the app version. The token is deleted when you sign out on that device.
Information from others:
- Colleagues: someone in your organization may invite you, assign you work, or mention you, which puts your name and email in their workspace.
- Billing: our payment provider tells us whether a subscription is active, how many seats it covers, and the billing contact. We never receive or store full card numbers.
- Single sign-on: if your organization uses SSO or SCIM, your identity provider sends us your name, email and group membership.
We do not collect location, contacts, photos, health or fitness data, or browsing history, and the UnitX apps contain no advertising or third-party analytics code.
3. How we use information
- To provide the Service: signing you in, storing and showing your workspace, syncing it between web and mobile, and running the automations and integrations your organization sets up.
- To notify you: in-app, by email and, if you allow it, by push notification, according to your notification settings and your organization’s policies.
- To keep the Service secure: detecting abuse, protecting accounts, enforcing plan limits and investigating incidents.
- To bill paid plans, through our payment provider.
- To support you: answering questions and fixing problems you report.
- To improve the Service, using aggregated information about how features are used and how the Service performs, never the content of your workspace.
- To meet legal obligations and enforce our Terms of Service.
We do not sell personal information, we do not use it for advertising, and we do not use workspace content to train AI models. If your organization turns on AI features with its own model provider, the content those features need is sent to that provider to produce the result, under your organization's agreement with that provider.
4. Legal bases (EEA, UK and similar laws)
Where the law requires a legal basis, we rely on:
- Contract: to provide the Service you or your organization signed up for.
- Legitimate interests: to keep the Service secure, to prevent fraud, and to improve it, balanced against your rights.
- Consent: for push notifications (which you grant in your phone’s settings and can withdraw there at any time) and for any optional marketing email.
- Legal obligation: where we have to keep or disclose information by law.
6. How long we keep information
We keep account information while your account is open. Workspace content is kept for as long as the organization keeps it: administrators can delete content, set retention policies that remove records after a period they choose, and place legal holds that stop deletion.
When an account or workspace is closed, we delete or anonymize its information within 90 days, except for encrypted backups (overwritten within 90 days) and records we have to keep for legal, tax or security reasons. Security logs are kept only as long as they are useful for protecting the Service.
7. How we protect information
- All traffic between your browser or phone and the Service is encrypted in transit (HTTPS and secure WebSockets).
- Each organization’s data is separated at the database level using row-level security, so one workspace cannot read another’s records even if application code makes a mistake.
- Stored integration credentials and two-factor secrets are encrypted at rest.
- You can protect your account with two-factor authentication or passkeys, see every device you are signed in on, and sign any of them out.
- The mobile apps keep your sign-in tokens in the phone’s secure storage (iOS Keychain or Android Keystore), can lock behind Face ID, Touch ID or fingerprint, and never have access to your biometric data itself.
No system is perfectly secure. If we learn of a breach that affects your information, we will tell the affected organizations and people as the law requires. To report a security issue, email admin@unitfactor.org.
8. International transfers
UnitX and its service providers may process information in countries other than yours, including the United States. Where the law requires it, we protect these transfers with appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
9. Your rights and choices
Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict how we use it, and to withdraw consent. You can:
- Update your name, password, two-factor settings and notification preferences in your account settings.
- Turn push notifications off in your phone’s settings, and sign devices out from the Account screen or the web app.
- Delete your account by following the steps on our account deletion page, or by emailing admin@unitfactor.org from the address on the account. We verify the request and complete it within 30 days. If your account belongs to an organization, its administrator can also remove you, and content you created in that workspace stays with the organization.
- Make any other privacy request by emailing admin@unitfactor.org. If your request concerns an organization’s workspace, we may pass it to that organization, because it decides what happens to its content.
We will not treat you differently for exercising these rights. If you are in the EEA or the UK, you may also complain to your local data protection authority.
California residents: we do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information for purposes that require an opt-out.
10. The mobile apps
The UnitX apps for iOS and Android ask for only two permissions, and both are optional:
- Notifications, so you can be told about assignments, mentions and approvals. You can turn them off at any time in your phone’s settings.
- Face ID, Touch ID or fingerprint, to unlock the app. The check happens on your phone; the app only learns whether it succeeded.
To work offline, the app keeps a copy of recently viewed items on your phone and removes it when you sign out. Changes you make while offline are stored on the phone until they are sent.
12. Children
UnitX is a workplace tool and is not directed to children. You must be at least 16 to use it. If we learn that we hold information about a child under 16, we will delete it.
13. Changes to this policy
We may update this policy as the Service changes. We will change the effective date above, and for material changes we will give notice in the Service or by email before they take effect. This policy should be read with our Terms of Service.
14. Contact us
Questions, requests or complaints about privacy: UnitFactor, admin@unitfactor.org.