Privacy Policy
Effective August 10, 2026
This Privacy Policy explains what data UniThread ("we," "us") collects, why, and how it's protected. UniThread is an independent student project built for International University of Sarajevo (IUS) students and is not operated by the university. Bosnia and Herzegovina is not an EU member state, but we've aligned this policy with the EU General Data Protection Regulation (GDPR) as our baseline standard, regardless of where a user is located.
1. Who is responsible for your data
The data controller is Belmir Grahic, the individual operator of UniThread, reachable at [email protected]. UniThread is not a large enough operation to be legally required to appoint a Data Protection Officer, but the contact above handles all privacy inquiries directly.
2. What we collect
- Account data: your university email address, username, display name, password (stored only as a salted bcrypt hash — we never store or can see your actual password), and optionally a bio, faculty, and program.
- Content you create: posts, replies, votes, poll answers, direct messages, club chat messages, uploaded photos, videos and files, and bookmarks.
- Anonymous board authorship: when you post anonymously, your identity is stored in a separate, access-restricted record — not in the post itself. See Section 5.
- Technical data: your IP address, used transiently to enforce rate limits (e.g. blocking repeated failed logins) and is not permanently linked to your profile or used for tracking/advertising.
- Push notification data: if you enable push notifications, we store the subscription endpoint your browser or device gives us, only for delivering notifications you'd otherwise see in-app.
- Cookies: a single essential session cookie (httpOnly, so JavaScript can never read it) that keeps you logged in. We do not use advertising or analytics-tracking cookies, and because this cookie is strictly necessary to operate the Service, no cookie-consent banner is required for it.
3. Our legal basis for processing your data
Under GDPR Article 6, we rely on the following legal bases, depending on the data:
- Performance of a contract — account data, content you create, and messages, because we can't provide the Service without them.
- Legitimate interest — technical/IP data for rate limiting and abuse prevention, and moderation records, because keeping the Service safe and functioning benefits the community and is proportionate to the minimal data involved.
- Consent — push notifications, which are strictly opt-in and can be withdrawn at any time by disabling them in your device or browser settings.
- Legal obligation — limited disclosures described in Section 6, where required by law.
4. How we use it
- To operate the Service: show your posts, deliver messages, run club chat, rank the feed.
- To verify you're an eligible student and to secure your account (email verification, password reset).
- To send you transactional email (verification, password reset) and, if you opt in, push notifications. We do not send marketing email.
- To enforce these policies: reviewing reports, moderating abusive content, applying rate limits.
- To keep the Service secure and investigate misuse.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you. Feed ranking (e.g. "hot" sorting) only orders content you can already see — it never restricts your access to anything or makes a decision about you as a person.
5. The Anonymous board — the privacy design
When you post or answer anonymously, the post itself is stored with no author field at all — not hidden in the interface, but genuinely absent from the data returned to any user-facing part of the app. The only place your identity is recorded is a separate, restricted table that ordinary application code never reads from.
That record exists so we can act on abuse reports, remove content you posted if you ask us to, and comply with legal obligations. It is not shown to other users under any normal use of the Service. It may be accessed by the operator, or disclosed, only in the circumstances described in Section 5 of the Terms of Use (legal process, safety, or investigating a Terms violation).
6. Who we share data with, and international transfers
We don't sell your data, and we don't share it with advertisers. We use a small number of service providers who process data only on our behalf, to run the Service:
- Hosting provider (Railway) — runs the application, database, and stores uploaded files.
- Email provider (Resend) — delivers verification and password-reset emails; sees the recipient address and email content, not your password.
- Backup storage — automated nightly database backups are stored with a cloud object-storage provider, encrypted, for disaster recovery.
These providers may process data outside Bosnia and Herzegovina, including in the European Union and/or United States. Where a provider processes data outside the EU/EEA, we rely on the provider's own compliance mechanisms (such as Standard Contractual Clauses or an equivalent adequacy framework) as a safeguard. We select providers that maintain reasonable security and data-protection standards, and each only processes data under our instructions, only to provide their service to us. We may also disclose data where required by law, legal process, or to protect someone's safety, as described in the Terms of Use.
7. How we protect it
- Passwords are hashed with bcrypt; we never store plaintext passwords.
- Sessions use httpOnly, secure cookies — inaccessible to JavaScript, sent only over HTTPS in production.
- Uploaded files are validated (not just by file extension) before being stored, and served only to logged-in users.
- Access to moderation tools and the anonymous-authorship record requires a separate administrator credential.
- Rate limiting protects against brute-force login attempts and abuse.
- Database backups are taken nightly and stored encrypted, for recovery in case of data loss.
8. Data retention
- Account and content data: kept for as long as your account is active. You can delete individual posts/messages, or your entire account, at any time from your profile settings.
- After account deletion: your login credentials and profile are removed immediately; some moderation records (e.g. that a since-deleted post was previously reported or removed for a Terms violation) are retained for a limited period afterward to maintain an audit trail and prevent abuse of deletion to escape accountability.
- Backups: deleted data may persist briefly in encrypted backup snapshots taken before the deletion, until those backups are rotated out on their normal schedule.
- We don't keep personal data longer than necessary for the purpose it was collected for.
9. Your rights under data protection law
Whatever your location, we extend you the following rights over your personal data:
- Access — ask what personal data we hold about you.
- Rectification — correct inaccurate data (most of this you can do yourself in the app).
- Erasure — ask us to delete data we hold about you, including beyond what account deletion already removes ("right to be forgotten").
- Restriction — ask us to limit how we use your data in specific circumstances.
- Portability — request a copy of your data in a structured, machine-readable format.
- Objection — object to processing based on our legitimate interest.
- Withdraw consent — for anything based on consent (e.g. push notifications), at any time, without affecting the lawfulness of processing before the withdrawal.
To exercise any of these, email [email protected]. We'll respond within a reasonable time, generally within 30 days. If you believe your data has been mishandled, you may also lodge a complaint with Bosnia and Herzegovina's Personal Data Protection Agency (Agencija za zaštitu ličnih podataka u BiH), or, if applicable to you, your own country's data protection supervisory authority.
10. Children's privacy
The Service requires you to be at least 18 (see the Terms of Use) and is not directed at children. We don't knowingly collect data from anyone under 16, and would delete any such account and its data if discovered.
11. Changes to this policy
If we make a material change to how we handle your data, we'll make reasonable efforts to let active users know, such as an in-app notice, before the change takes effect.
12. Contact
Questions about this Privacy Policy or your data: [email protected].
See also our Terms of Use.