Who we are
UNBEHAV (“we”, “us”) operates the UNBEHAV mobile app and the website at unbehav.com. The app and website are available in English and Arabic. Questions about this policy: contact@unbehav.com.
What we collect in the app
- Anonymous account — a device-local credential created with anonymous authentication. No name, email, phone number, or public profile.
- User ID — the anonymous auth identifier that ties your posts and moderation actions together on the server. It is not a real-world identity and can be replaced when you erase your data in Settings.
- Install ID — a device-local key used only for rate limits, abuse prevention, and bans. It is not shown on content, is not used for advertising, and may remain after you clear local app state so safety controls cannot be bypassed that way alone.
- Thoughts and other content you post — text, optional social link (allowed platforms only), and a coarse area id (city or district, depending on your “Show my district” preference). Never a precise GPS coordinate.
- Push tokens and notification preferences — only if you allow notifications. Tokens are delivered via Expo’s push service so we can send the alerts you chose. Notification preferences are stored with your device record.
- Reports — content id, report kind (community or illegal content), optional reason, and your anonymous device identity so we can act on abuse.
- Author mutes (“hide this author”) — stored for your anonymous account on the server and on the device so hidden authors stay filtered for you.
- In-app notifications — short titles and previews (for example about replies) stored for your device until you delete your data or they are no longer needed. Titles may be stored in English and Arabic.
- UI language preference — the interface language you use, so we can show the right text and notifications.
- Local preferences on the device — for example age-screen result, terms acceptance, onboarding status, “Show my district,” and haptics. These stay on the device and are not a public profile.
- Device integrity signals — we may use platform integrity checks (for example Apple DeviceCheck or Google Play Integrity) to reduce automated abuse. This is for security, not advertising.
- Diagnostics — crash and performance reports via Sentry, when enabled for your app version, so we can keep the service running. Not used for advertising.
- IP addresses — processed briefly by our infrastructure (for example rate limiting and request handling). We do not use IPs to build a social profile of you.
We do not run third-party advertising SDKs, advertising analytics trackers, or sell personal data. We do not use your content to train third-party models for advertising.
Location
GPS is resolved on your device to a coarse area (city or district). UNBEHAV’s servers receive only that area identifier for posts (and, for map browsing, approximate map grid cells for loading place names) — never a precise latitude/longitude of your position. We collect coarse / approximate location only, to show your area and attach your posts to it.
If you turn off Show my district in Settings, posts are attached to the city rather than a finer district, so the district is not sent as your post’s area.
The map basemap uses MapLibre with vector tiles from Carto (OpenStreetMap-derived). Like other map apps, tile requests go to that provider and can reflect where the map is centered (including after you use locate-me). That is separate from the area id we store on your posts.
Location purpose: “UNBEHAV uses your location only to find your area (city/district). Your exact location never leaves your device.” Exact GPS is not uploaded to UNBEHAV.
Age screen
On first launch you enter a date of birth so we can enforce a minimum age of 13. The date is checked on your device; only a pass/fail result is stored locally. The birthdate itself is not stored or transmitted.
Website, cookies, and waitlist
The public website is mostly static pages. We do not run advertising pixels, marketing analytics SDKs, or cross-site tracking cookies. Our CDN (Cloudflare) and your browser may process technical data needed to deliver pages securely (for example encryption, caching, and abuse protection). Site administration tools may use access cookies for operators only — not for public visitors.
If you join the beta waitlist with your email, we store that email so we can invite you and send access later. We may also store limited request context: approximate country, region, and city (when provided by Cloudflare), timezone, primary language from Accept-Language, referrer host/path, and user-agent. We do not store your full IP address in the waitlist table.
How we use data
- Provide the map, area feeds, threads, social-link previews, and optional notifications you request
- Moderate content and prevent abuse (reports, rate limits, bans, and device integrity checks)
- Generate area words and editorial readings from anonymous thoughts in an area, where those features are available
- Operate the waitlist and contact you about access
- Secure the service and diagnose outages (infrastructure logs and crash reports)
- Comply with law and respond to lawful requests where required
We process personal data only as needed for these purposes. Depending on where you live, that may rest on different lawful bases — for example providing the service you ask for, our legitimate interests in running a safe public feed and preventing abuse, your consent (such as push notifications or waitlist email), or a legal obligation. We do not process app data for third-party advertising.
Processors
We use service providers who process data on our behalf:
- Supabase — authentication, database, server functions, and related infrastructure logs
- OpenRouter — language-model processing of thought text for assisted content review and, where available, area words and readings (body text may leave our primary host for that purpose)
- Expo — push token delivery for notifications you allow; app update delivery
- Cloudflare — this website, share previews, and approximate geo / request context for the waitlist
- Carto — map basemap vector tiles in the app
- Sentry — crash and performance diagnostics when enabled for your app version
- Apple / Google — platform integrity APIs for abuse prevention; app distribution and push services as provided by the app stores
When you attach an allowed social link, our servers may request public metadata (title, preview image, and similar) from that platform’s public endpoints to build a link card. We do not send your UNBEHAV identity to those platforms for that request.
Public content
Thoughts and replies are public in the product. Area readings and comments on readings, where available, are public too. Share links on the web may show a preview of a thought. Content is not linked to a real name or profile, but it is not private messaging.
Retention and deletion
In the app: Settings → Delete all my thoughts erases your current anonymous account and associated server data — thoughts (posts), replies, article comments (where present), mutes, reactions, reports you filed, in-app notifications, thread mutes, and your device record (including any push token and notification preferences). The app then starts a fresh anonymous session on the device. That is the primary way to erase app content and account data.
You can also remove individual thoughts or replies you authored from your activity lists in Settings; those are removed from public feeds (a post may leave a redacted placeholder so replies stay readable).
For security and abuse prevention we may keep limited records that are not content identity — for example bans or rate-limit counters keyed to an install identifier — for as long as reasonably necessary. The install identifier lives only on the device and in those abuse records; it is not shown on posts and is not used for advertising.
If applicable law gives you a right to receive a copy of personal data we hold about you, email contact@unbehav.com and we will respond as required. In-app deletion is usually the fastest path for ordinary account and content erasure.
To remove a waitlist email, write to contact@unbehav.com.
We may also retain limited records needed for legal compliance or to complete an ongoing abuse investigation, for as long as reasonably necessary.
Your rights (worldwide)
UNBEHAV is available to people in many countries. Online identifiers such as the anonymous user ID and install ID can be personal data under many laws even without a name. Your rights depend on the law that applies to you. We honor applicable rights when you contact us at contact@unbehav.com.
In practice, people commonly can ask us to:
- Access personal data we hold about them (where we can locate it — for anonymous app use we may need enough detail to identify the right records)
- Correct inaccurate personal data
- Delete personal data (in-app Delete all my thoughts for account/content; email for waitlist)
- Object to or restrict certain processing, or withdraw consent where processing was based on consent (for example push notifications — turn them off in system or app settings)
- Receive a copy / portability where the applicable law provides that right (request by email)
- Complain to a supervisory authority in their country or region
Kingdom of Saudi Arabia (PDPL)
If you are in the Kingdom of Saudi Arabia, the Personal Data Protection Law (PDPL) and its implementing rules, overseen by the Saudi Data and AI Authority (SDAIA), may apply. Personal data includes information that identifies or can identify you, which can include online identifiers. Subject to the PDPL, you may have rights to be informed about processing, access your data, request correction or destruction, request a copy in a readable format where applicable, and withdraw consent where processing was based on consent. You may also contact SDAIA regarding complaints under Saudi law. Contact us first at contact@unbehav.com so we can help.
European Economic Area and United Kingdom (GDPR / UK GDPR)
If you are in the EEA or UK, online identifiers can be personal data. Our typical bases for processing include legitimate interests (running an anonymous public feed, security, and abuse prevention), contract / service provision where that framing applies to the service you use, and consent where we ask for it (for example push notifications or optional waitlist email). You may request access, correction, deletion, restriction, or objection, data portability where applicable, and you may lodge a complaint with your local supervisory authority.
United States and other regions
If you live in a U.S. state or another country with privacy laws that grant consumer rights (for example access, deletion, or opt-out of sale/sharing), we will honor those rights as required. We do not sell personal data and do not share it for cross-context behavioral advertising. UNBEHAV is not directed at children under 13.
Children
UNBEHAV is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has used the service, contact us and we will take appropriate steps.
International transfers
We and our processors may store or process data in the Kingdom of Saudi Arabia, the United States, the European Economic Area, and other countries where our infrastructure or providers operate. That means data may cross borders. Where a law requires safeguards for international transfers (including under the Saudi PDPL or GDPR/UK GDPR), we rely on appropriate mechanisms available from our providers and our own practices (for example contractual clauses, provider compliance programs, and security controls). Using a global internet service means your data may be processed outside your home country.
Changes
We may update this policy as the product evolves. The “Last updated” date below will change when we do. Material changes will be reflected on this page; continued use of the service after an update means you accept the revised policy.
Contact
contact@unbehav.com · Terms of use · Contact · Legal & attributions