Unelo

Privacy Policy

Effective and last updated2026-08-28

This policy describes Unelo’s actual translation data flows, storage, providers, consent, and deletion behavior.

1. Scope and provider

This policy applies to the Unelo mobile app, unelo.app, and related text, recorded-audio, and live interpretation services. This version identifies Unelo as the service provider.

Send privacy questions, rights requests, or complaints to chuangfengtech@gmail.com.

2. Anonymous membership and device data

Unelo currently uses Supabase Anonymous Auth. Translation features generally do not require your name, email address, or a public profile.

We process an anonymous member UUID, authentication state and credentials, app version, language and interface preferences, and technical data needed to maintain membership. Authentication credentials are stored in an iOS Keychain item restricted to the device.

3. Translation content you submit

You may submit text, recorded audio, or live audio. The service also produces source and target languages, transcripts, translations, and completion timestamps.

Do not submit content you have no right to process. Avoid passwords, payment-card data, government identifiers, medical records, or other highly sensitive information unless strictly necessary.

4. AI processing paths

Text: submitted text is relayed by Unelo to OpenAI for language detection and translation.

Recording: the audio file is sent to OpenAI for transcription, and the resulting transcript is then translated.

Live: audio is sent to OpenAI Realtime over WebRTC. Cloudflare Workers and Durable Objects manage connection control, temporary state, completion, and recovery. Finalized transcripts are sent through Unelo’s backend for translation and result synchronization.

OpenAI requests may include an HMAC-derived pseudonymous safety identifier and route or usage-job metadata, rather than the member UUID in clear form as the safety identifier.

5. Translation history on your device

Completed Quick and Live History stores source text, translations, languages, timestamps, and Live segments on your device. Unelo currently does not provide cloud History or cross-device History sync.

The local History database does not use CloudKit and is excluded from device cloud backup. You can delete individual records or clear local History. Clearing local History does not cancel an Apple subscription or delete the anonymous member.

6. Server retention and recovery

Quick text and recording results are held in an Unelo server result cache for about 15 minutes for idempotent retry and recovery, then removed by scheduled cleanup. Unelo does not create cloud History from the original recording, but audio size, duration, hash, and usage metadata may remain for metering, deduplication, and operations.

After a retryable failure, the app may retain a recording locally according to server configuration. The current initial setting is up to about one hour; the file is removed after success, abandonment, or expiry.

Finalized Live source text and translations are written to Unelo’s server database for confirmation, metering, and recovery. In the current version, finalized Live content may remain until account deletion unless Unelo applies an earlier lifecycle cleanup.

7. Usage, operations, and errors

We process feature route, text volume, valid recording or Live seconds, points reservation and settlement, model and configuration versions, provider request IDs, token counts, latency, errors, retries, and content-derived hashes.

Live telemetry is allowlisted to necessary state, timing, error, and pseudonymous session-reference fields. It is designed to reject arbitrary transcripts, translations, audio, credentials, or full session IDs.

8. Third-party AI consent and withdrawal

Before content is first sent to a third-party AI service, the app asks for consent to process text, recorded audio, or Live transcripts for speech recognition, language detection, and translation.

Consent is recorded as versioned accepted or revoked events. You may withdraw in Data Management. New provider requests are blocked immediately until you consent again. Withdrawal does not automatically erase records previously retained under this policy or applicable law.

9. Trial eligibility and abuse prevention

The app generates an Apple DeviceCheck token to determine whether a device used a trial. The token is kept only in app memory and relayed through Unelo to Apple to query or update device bits.

The service reads the connection network address and creates a daily rotating HMAC network hash. Trial risk and rate-limit records are generally configured to expire after about seven days and are used to prevent reinstall and mass-claim abuse.

10. Points, subscriptions, and transactions

We process point balances, sources, expiration, usage and reservation events, plan, and entitlement status.

For App Store purchase or restore, the server verifies signed StoreKit transactions and processes transaction IDs, original transaction ID, product, plan, environment, purchase and period dates, renewal, grace, revocation status, appAccountToken correlation, and signed-payload hashes. Unelo does not directly receive your full payment-card details.

11. Service providers

Apple: App Store purchases, subscriptions, refunds, StoreKit verification, and DeviceCheck.

Supabase: anonymous authentication, database, Edge Functions, membership, points, and consent data.

Cloudflare: website and Live networking, Workers, WebSocket/WebRTC control, and Durable Objects.

OpenAI: text translation, recording transcription, Live audio, and translation processing.

Superwall: subscription paywall presentation, paywall trigger origin, and active-subscription status. Providers process necessary data under their terms, privacy policies, and our configuration.

12. Account and data deletion

You may request account deletion in the app. Only after the Supabase anonymous Auth user is deleted does the app clear the local session, History, retry recordings, points and entitlement projections, consent cache, and in-progress work.

Deletion removes short-lived translation caches, Live sessions and segments, and member-linked content from Unelo servers, and clears request fingerprints and audio hashes.

De-linked, content-free usage evidence, accounting events, Apple transactions, and subscription-account evidence may remain for financial integrity, refunds, audit, and legal obligations. Deleting Unelo does not cancel an Apple subscription.

13. Sale, advertising, and analytics

Unelo does not sell or rent personal data and does not use translation content for third-party targeted advertising.

The current app source does not integrate standalone Mixpanel, Firebase Analytics, or Sentry SDKs. Superwall, Apple, Supabase, Cloudflare, and OpenAI may still create service, transaction, security, or operational records for their roles. We will update this policy and App Store disclosures before introducing materially new analytics uses.

14. Security and international processing

We use measures such as encryption in transit, access controls, pseudonymous identifiers, restricted permissions, content-limited telemetry, and deletion workflows. No network, third party, or storage system can guarantee absolute security.

Apple, Supabase, Cloudflare, OpenAI, or Superwall may process data outside your country or region, subject to safeguards required by applicable law and our service arrangements.

15. Choices, children, and updates

You may clear local History, withdraw third-party AI consent, delete the anonymous account, stop using the service, or contact us to request access, correction, or deletion of data reasonably linked to you.

Unelo is not specifically directed to children under 13. Where local law sets a higher age of digital consent, minors should use the service with help from a parent or guardian.

We may update this policy as the product, providers, or law changes. We will provide reasonable notice of material changes and display the current date here.