Privacy Policy
Effective April 18, 2026
Updated July 9, 2026
1. Introduction and Scope
Official Unofficial, Inc. ("Official Unofficial," "we," "us," or "our") provides the Uno iOS application, the Makechain protocol and developer tools, and the websites at officialunofficial.com and makechain.net (collectively, the "Services"). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have. It applies to personal information we process as a controller (in some jurisdictions, "business") when you interact with the Services.
This Policy does not apply to content you broadcast to, or information you submit directly to, public, decentralized networks (including Farcaster and Makechain). Those networks are operated by third parties and their contents are public by design and may be retained indefinitely by any participant.
2. Information We Collect
2.1 Information you provide
- Account and profile: username or handle, display name, bio, profile image, links, email address if you provide one, and any connected wallet address or similar identifier.
- Authentication material: passkeys, public keys, signed messages, session tokens, and (where we manage an app-level signer on your behalf) encrypted signer-key material.
- User content: casts, replies, reactions, direct messages where the feature exists, uploads, and any metadata you submit with them.
- Communications: messages you send to support, feedback, survey responses, and records of correspondence.
- Payments and transactions: if we offer paid features, limited transaction metadata processed by our payment processor; we do not collect or store full payment card numbers.
2.2 Information collected automatically
- Device and technical: device model, operating system and version, app version, language, timezone, crash logs, and diagnostic identifiers.
- Usage: features accessed, screens viewed, actions taken, referral URLs, and performance metrics.
- Network: IP address and derived approximate location (typically at the city or region level). We do not use precise GPS location unless you explicitly grant that permission.
- Cookies and SDKs: on our websites we use a small number of cookies and similar technologies; in Uno we use mobile SDK identifiers for analytics and crash reporting. See Section 6.
2.3 Information from third parties
- OAuth and wallet providers: when you authenticate via a wallet, passkey provider, or social login, we receive a public identifier (e.g., wallet address) and other information you authorize that provider to share.
- Public networks: we read publicly available information from Farcaster hubs, Makechain, and associated indexers to render your and others' public profiles and content.
- Analytics and fraud prevention: our analytics and abuse-prevention providers may share aggregated, derived, or inferred information about how the Services are used and whether activity looks suspicious.
3. How We Use Information
We use personal information to:
- operate, maintain, and provide the Services, including authentication, profile rendering, feeds, search, and content delivery;
- personalize the experience, including recommendations and discovery features that are central to Uno;
- communicate with you about the Services, respond to support requests, and send administrative or security notices;
- with your consent or as otherwise permitted, send push notifications, emails, or other marketing communications;
- measure, analyze, and improve the Services, including diagnostic and crash analytics and product research;
- detect, prevent, and investigate fraud, abuse, spam, security incidents, and violations of our Terms and applicable law;
- comply with legal obligations, establish or defend legal claims, and enforce our rights and agreements; and
- with your direction, share or publish information (for example, by broadcasting a post to a public network).
We do not use personal information to train third-party generative AI models. If we develop or fine-tune models using personal information, we will describe that activity and any opt-out or consent mechanism in advance.
4. Legal Bases for Processing (EEA, UK, Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and UK GDPR:
- Performance of a contract (Art. 6(1)(b)) — to provide the Services you request, including account creation, authentication, content delivery, and support.
- Legitimate interests (Art. 6(1)(f)) — to operate, secure, analyze, and improve the Services; prevent fraud and abuse; enforce our Terms; and for limited internal business administration. You may object to processing based on legitimate interests.
- Consent (Art. 6(1)(a)) — for certain analytics, marketing communications, push notifications, optional cookies, and use of precise location. You can withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation (Art. 6(1)(c)) — to comply with applicable law, court orders, and regulatory requirements.
- Vital interests (Art. 6(1)(d)) and public interest (Art. 6(1)(e)) — rarely, and only where necessary (e.g., to protect a person's life).
5. How We Share Information
- Service providers (sub-processors): cloud hosting, storage, and CDN; analytics and crash reporting; push notification delivery; email and messaging; customer support; fraud and abuse prevention; and professional advisors. A current list of material sub-processor categories is in Section 12 and will be updated in this Policy.
- At your direction: content and profile data you instruct us to broadcast or share, including publication to Farcaster and Makechain.
- With other users: information you make public through the Services, such as your profile, posts, and interactions.
- Legal, safety, and compliance: to comply with a valid legal process, to enforce our Terms, or to protect the rights, safety, or property of Official Unofficial, our users, or the public.
- Business transfers: in connection with a merger, acquisition, reorganization, financing, or sale of assets, or in the event of bankruptcy, subject to customary safeguards.
- Aggregated or de-identified information that cannot reasonably be used to identify you.
We do not "sell" personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and we extend that commitment to residents of other U.S. states with comparable laws.
6. Cookies and Similar Technologies
On our websites we use a limited set of cookies and similar technologies for authentication, security, preferences, and basic analytics. Where required, we ask for consent before setting non-essential cookies, and we honor Global Privacy Control (GPC) signals as an opt-out of "sale" or "sharing" for residents of jurisdictions (including California, Colorado, and Connecticut) that require it. You can manage browser cookies through your browser settings and mobile advertising identifiers through your device settings.
7. Your Rights and Choices
7.1 Rights under U.S. state privacy laws
Depending on where you live, you may have rights under applicable U.S. state privacy laws, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Florida (FDBR), Delaware (DPDPA), Iowa (ICDPA), New Jersey (NJDPA), Tennessee (TIPA), Indiana (ICDPA), Kentucky, Maryland (MODPA), Minnesota (MCDPA), Nebraska, New Hampshire, Rhode Island, and other applicable state privacy laws. These rights typically include the right to:
- know what personal information we process and request a copy;
- correct inaccurate personal information;
- delete personal information, subject to legal exceptions;
- opt out of "sale," "sharing," or "targeted advertising" (we do not engage in these activities);
- opt out of certain profiling or automated decision-making, where we engage in it;
- limit the use of sensitive personal information;
- appeal a denial of a privacy request;
- not be subject to unlawful discrimination for exercising rights.
7.2 Rights under EEA, UK, and Swiss law
If the GDPR or UK GDPR applies to you, you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing, as well as the right to withdraw consent and to lodge a complaint with your local supervisory authority (including in the Member State of your residence, place of work, or the alleged infringement). A list of EU data protection authorities is available at edpb.europa.eu. In the United Kingdom, the supervisory authority is the Information Commissioner's Office at ico.org.uk.
7.3 How to exercise your rights
You can make a privacy request by emailing privacy@officialunofficial.com or by using in-product controls where available. We will respond within the time required by applicable law. We may need to verify your identity before acting on your request, which may include asking you to confirm information we already hold or to sign a message from a wallet associated with your account. If we deny your request in whole or in part, you may appeal by replying to our response within the period specified in that response; if we deny the appeal, we will tell you how to contact the appropriate regulator.
7.4 Authorized agents
You may designate an authorized agent to make a request on your behalf. We may require written authorization signed by you, and we may require you to verify your identity directly with us.
8. Data Retention
We retain personal information only for as long as needed for the purposes described in this Policy, including to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. When personal information is no longer needed, we delete, anonymize, or aggregate it. Specific retention periods depend on the type of data and applicable legal requirements; for example, we typically retain account records for the life of the account plus a short tail, server logs for up to 90 days, and legal/financial records as required by applicable law. Information broadcast to a public network cannot be retrieved or deleted by us.
9. Children's Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact privacy@officialunofficial.com and we will take appropriate steps to delete it. Some features may require you to be older (see the Terms of Service, Section 2).
10. International Data Transfers
We are based in the United States and process information in the United States and other countries where we or our sub-processors operate. When we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been designated as providing an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (Module 2 or Module 3, as applicable), the UK International Data Transfer Addendum or the UK International Data Transfer Agreement, and the Swiss Federal Data Protection and Information Commissioner's recognized mechanisms. You may request a copy of these safeguards by emailing privacy@officialunofficial.com.
11. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information against unauthorized or unlawful processing, accidental loss, destruction, or damage. See our Security and Vulnerability Disclosure page for additional detail and for our safe-harbor terms for security researchers. No method of transmission or storage is 100% secure.
12. Service Providers and Third Parties
We rely on the following service providers to operate the Services:
- Apple Inc. — App Store distribution, in-app purchases, and related developer services for iOS.
- Google LLC (Google Play) — Play Store distribution and related developer services for Android, if and when offered.
- Google Cloud Platform — cloud hosting, storage, and infrastructure.
- Cloudflare, Inc. — content delivery, DNS, and network security.
- PostHog Inc. — product analytics and session diagnostics.
- Functional Software, Inc. (Sentry) — error monitoring and crash reporting.
- 650 Industries, Inc. (Expo / EAS) — mobile build, submission, and over-the-air update infrastructure.
We do not use any service providers other than those listed above. If we add or remove a provider, we will update this section and the "Last updated" date.
13. California Disclosures; Do Not Track; Global Privacy Control
Shine the Light. California Civil Code § 1798.83 permits California residents to request information about our disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing.
Do Not Track. Our websites do not respond to "Do Not Track" browser signals because there is no common industry standard. We do honor Global Privacy Control signals as described in Section 6.
14. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will provide reasonable advance notice, including by posting a notice in the Services, updating the "Last updated" date, and/or emailing the address associated with your account. Your continued use of the Services after the changes take effect constitutes your acceptance of the updated Policy, except where additional consent is required by law.
15. Contact
For questions, requests, or complaints about this Policy or our privacy practices, contact:
Official Unofficial, Inc.
Attn: Privacy
116 Remsen St.
Brooklyn, NY 11201
United States
privacy@officialunofficial.com
EU / UK representative. For purposes of GDPR Article 27 and UK GDPR, our designated representative is Andy Won, who can be reached at andy@officialunofficial.com. EEA and UK data subjects may contact the representative directly in connection with matters related to the processing of their personal information.
© 2026 Official Unofficial, Inc. All rights reserved.