← Registration

Privacy Policy

Version 1.0 · 10 September 2026

Summary: UniGo processes account and application-planning data for matching, roadmaps, document storage and application packs. We do not sell application data. Current monetisation uses contextual advertising only; grades, finances, citizenship, essays, uploads and university preferences are not used to target ads.

Before public launch: replace [LEGAL NAME], [LEGAL ADDRESS], [PRIVACY EMAIL] and obtain jurisdiction-specific legal review.

Controller

[LEGAL NAME OF UNIGO OPERATOR]
[LEGAL ADDRESS]
[PRIVACY EMAIL]

Age

Current registration is 16+. Under-16 use requires a future jurisdiction-appropriate guardian-consent and age-assurance flow.

Data

Account/security data; education profile; citizenship/residence; household, income, budget and savings; achievements, projects, essays and uploaded files; essential session/security data; consent records.

Purposes and legal bases

Account operation, university matching, roadmaps, affordability/funding planning, storage/export, support, security and legal compliance. Where GDPR/UK GDPR applies, bases may include contract/pre-contract steps, legitimate interests for proportionate security, legal obligation and consent.

AI

Profile Match Scores and AI recommendations are planning guidance, not admission probabilities or guarantees. UniGo does not intend solely automated decisions with legal or similarly significant effects.

Advertising

UniGo may show contextual, non-profiled ads. Application/profile data is not used for behavioural ad targeting and is not sold to advertisers. If non-essential ad/analytics identifiers or personalised ads are added later, required consent/opt-out controls must be implemented first. Profiling ads must not be shown to minors where prohibited.

Cookies/storage

Essential authentication/session technology and local storage for preferences may be used. Non-essential advertising/analytics cookies are not part of this prototype.

Vendors/transfers

Operational vendors may process data under appropriate terms. Restricted international transfers should use legally recognised safeguards such as adequacy or SCCs where required. Russian-citizen data may additionally be subject to localisation/cross-border rules.

Retention and rights

Keep data only as needed. Depending on jurisdiction, users may have rights to access, correction, deletion, restriction/objection, portability, consent withdrawal, ad/sale-sharing opt-outs and regulator complaints.

Regional framework

Depending on users and establishment: EU GDPR/DSA, UK GDPR/Children’s Code, US COPPA/state laws, California privacy law, China PIPL, Brazil child/adolescent digital rules and Russia 152-FZ may apply. This baseline does not itself guarantee worldwide compliance.

Feedback