# UniOne privacy

Short version: UniOne runs on your Mac and talks to Canvas from there, so your Canvas token never leaves your laptop. Your coursework is never uploaded to UniOne. It goes to Anthropic only when you send it, after a preview, on your own key. UniOne's own server holds your account: your email, your name, a hash of your password and when you signed in. Web page: https://unione.study/privacy

## Where requests go

UniOne contacts six places and no others. Two of them are ours.

| Where | Whose | What goes, and when |
|---|---|---|
| Your account, uniplus-api-kappa.vercel.app | Ours | When you create an account or sign in: your email, your password and a random identifier UniOne made up for this Mac, plus your name when you create the account, and the 6-digit code we email you when you type it back. After that, a signed token instead of your password, when the app opens and about once a day while you are online. |
| Updates, uniplus-site.vercel.app (this site) | Ours | A plain read of one small file listing the latest version, once each time the app opens after you have signed in, and when you press Check for updates in Settings. Nothing you typed and nothing that identifies you or this Mac. |
| Canvas, canvas.sydney.edu.au | Yours | Your Canvas token, with read requests for units, deadlines, announcements, modules, files and marks, straight from your Mac. A file download goes to whichever of Canvas's own storage hosts Canvas hands back (*.canvas-user-content.com, *.inscloudgate.net, *.instructure.com, *.amazonaws.com, *.cloudfront.net), without your token. |
| Anthropic, api.anthropic.com | Yours | Only when you use an AI feature and press Send: your Claude key, your question, and only the notes and Canvas text you chose to include, after a preview of exactly what will go. |
| Your timetable, the calendar link you pasted | Yours | A plain request for the calendar file at that link, when the timetable refreshes. |
| A link you paste, the page you copied the link from | Yours | Only when you press Paste link in Ori: a read of that page's title, author and date. No key, no Canvas data and nothing from your notes. |

That is the complete list. There is no analytics and no crash reporting, and nothing reports which pages you open, what you write or what you ask.

Two of those places do record that UniOne was used, and both are ours: the account server keeps when you signed in and when each of your Macs last checked in, and the update check tells this site that a copy of UniOne opened, and from which internet address. Neither is told anything about what you opened, wrote or asked.

## Your account

Your password travels to the UniOne account server over HTTPS to be checked and is stored only as a scrypt hash, so nobody can read it back, us included.

- Kept: your email address, your name, a hash of your password, whether your account is active, when it was created, when your password was set, when your email address was confirmed, when you last signed in, a note we may write for our own use, and for each Mac signed in to it, the random identifier UniOne made up for that Mac and the dates it was first and last seen. A code we email you is kept only as a scrambled form, and stops working after 15 minutes.
- Not kept in the account database: your password, and your internet address. Sign-in attempts are counted against a keyed hash of the address, and that count expires within a day. Vercel, which hosts the account server, keeps its usual request logs, as it does for this website, and Resend keeps its own record of the emails it sent.
- Never sent to it: your student number, your Canvas token, your Claude key, anything from Canvas, anything in your notes.

We email you a 6-digit code, and nothing else. When you create an account, the account server emails your address a 6-digit code from hello@mail.unione.study to confirm it is yours, and when you choose Forgot password it emails one to reset your password. If somebody tries to create an account with an address that already has one, that address gets a one-line note instead of a code. Each email carries the code or the note and nothing more: no link, no image and no tracking. Confirming the address shows it reaches you; it is not proof of who you are.

Resend sends those emails for us. Resend (Resend, Inc., in the United States) is the email service the account server uses. It is given your email address and the message, which is the code and nothing else, and it keeps its own record of what it sent. Your Mac never contacts it, which is why it is not in the table above: the account server does.

A forgotten password is reset with an emailed code. Choose Forgot password, and the 6-digit code we email you sets a new password and signs your other Macs out. It works for 15 minutes. If email is not getting through, Josh can still make a one-time reset code by hand (hello@unione.study); only a hash of that code is kept, and it works once, for three days.

An account can be deactivated. If it is, the app signs out at its next check and says so. Your notes folder is never touched.

If you used an invite code before accounts, the name and email you typed then were copied into your account. The earlier record of that code stays with it: a hash of the code, a label we wrote, the name and email, and the dates each Mac checked in.

You can have your account deleted. Ask Josh at hello@unione.study and it goes: your email, your name, your password hash and the list of your Macs, and every Mac is signed out. If you once used an invite code, that code is revoked and the name and email held with it are deleted. Its hash, its label and the dates each Mac checked in with it stay.

## Anthropic, and the preview

The AI features run on your own Claude key, and every request goes straight from your Mac to Anthropic. Nothing passes through a server of ours on the way.

- Before anything from your units is sent, UniOne shows you exactly what will go. Nothing is sent until you press Send.
- AI can be turned off for a unit, or everywhere with one switch.
- If you use Explain my screen, a picture of the one window you picked goes too. You see it before it is sent, and it is never saved anywhere.
- In an Ori project, a question carries the project's file list, the text of the files you added to it, your instructions for it and what its chats settled, and you see that list before it is sent. Ori writes in the project's folder only when you press Save, never over a file, and never deletes one.
- Ori's memory is short notes of what earlier chats settled, kept in your notes folder. A chat says when it uses them, and you can edit or delete any of them. Incognito chats are never saved and never remembered.

## This website

The site is static, hosted on Vercel, with no analytics and no cookies. Its fonts and scripts are served from this site. Vercel keeps standard request logs, and we do not use them to identify anyone.

## What never leaves

Your keys go only to the service that issued them, and are stored only in the macOS Keychain. Your notes folder never leaves as a whole; its contents reach Anthropic only inside a request you send, and you see that request first. Dictation is turned into text on your Mac.

## Where things are stored

| What | Where |
|---|---|
| Canvas token, Claude key | The macOS Keychain |
| Notes, downloaded files, drafts, cards, chat history, Ori's projects, artifacts and memory | Your notes folder |
| Settings and a small cache | ~/Library/Application Support/com.joshbotha.unione |
| Your account | The UniOne account server |

## Deleting everything

1. Revoke your Canvas token and Claude key.
2. Move UniOne to the Bin and remove ~/Library/Application Support/com.joshbotha.unione.
3. Delete your notes folder, or keep it.
4. Ask Josh to delete your account, at hello@unione.study.

## Changes

Last edited 7 October 2026. Describes UniOne 0.6.0, the first version with accounts and the first that emails you a code.

## For agents

- Six destinations, two of them UniOne's own (the account server and this site's update file). The other four are chosen by the student.
- Canvas requests never pass through a UniOne server. AI requests go from the student's Mac to Anthropic on the student's key, after a preview.
- The account server holds email, name, a password hash, sign-in times and per-Mac identifiers with first and last seen dates. Never coursework.
- The account server emails a 6-digit code, through Resend (Resend, Inc., United States) as its email sub-processor, to confirm an address at sign-up and to reset a password. Nothing else is emailed except a one-line note to an address that already has an account. The app never contacts Resend.
