UniiChat · Terms of Service · Prices
Privacy Policy
Version 2026-10-07.2
This policy says what personal data Higher Order Computing Company, a Delaware corporation, 8 The Green, Ste B, Dover, DE 19901, USA ("HOC", "we", "us") collects when you use UniiChat (uniichat.com, the unii terminal app and the iOS app), what we do with it, and your rights. HOC is the controller of this data. Words defined in the Terms of Service mean the same here. UniiChat is only for people 18 or older.
1. What we collect
Account. Your email address, or your GitHub login, id and verified email if you sign in with GitHub; your HOC account number; when and from which IP address and browser you accepted these terms.
Your chat. Everything in your chat: your messages and images; what Unii reads or runs on your devices (commands, their output, files, and screenshots if you turned on computer use); Unii's replies and its agents' logs; the summaries AI models write of all this; and the names of the computers where unii is open. Your chat may hold anything you choose to put in it, including sensitive information about you or others. A voice note you record goes to OpenAI to become text, and is not kept.
Payments. Stripe collects your card details directly; we never see the full number. We keep the card brand and last four digits, Stripe's references, and the amount, date and status of each payment, refund and dispute, with the IP address and browser of the purchase.
iOS app. If you use it: each purchase made in it, as the App Store signs and sends it to us (product, price and currency, date, Apple's transaction number, and a number tying it to your account; Apple keeps your payment details); and, if you allow notifications, your phone's push token, kept with that sign-in until you sign out or delete your account.
Usage. For your account: each model call we bill (when, what it was for, the model and its settings, its tokens or seconds, its cost), each charge, its amount and the product it was for, and your balance or debt. No chat content.
Technical data. The IP address and browser of each sign-in, kept with your consent record. Our web server's access log records the time, IP address, page and browser of each request; our server's log records errors and service events, not your messages. Once a day the unii terminal asks bend-lang.com, our release server, for the latest version, sending its version, operating system and CPU type (and so its IP address), never your account. It also says whether that computer has ever run its own UniiChat server; UNII_NO_TELEMETRY=1 turns that off. A server you run yourself (unii serve) sends us nothing but that check.
Cookies. One cookie keeps you signed in; signing in with GitHub uses BendAI's sign-in cookies at bend-lang.com. The site keeps a few notes in your browser: that its intro played and a message you have not sent yet. We use no analytics, advertising or tracking cookies.
2. How we use it
- To run the Service: sign you in, answer you, build and keep the summaries, run what Unii does on your devices, and keep your credit and charges right (legal basis: contract).
- To take payments, give receipts and refunds, and handle disputes (contract; legal obligation).
- To keep the Service and its users safe: prevent fraud, abuse and attacks, and enforce our Terms (legitimate interests).
- To write to you about your account and the Service, including legal notices. We send no marketing.
- To follow the law, keep tax and accounting records, and defend legal claims (legal obligation; legitimate interests).
We do not train AI models on your data, sell it, share it for advertising, or profile you. No decision with legal or similar effect on you is made by automated means alone; if an automated fraud check blocks a payment, a person will review it on request. No one at HOC reads your chat unless you ask us to, or it is needed to investigate abuse or a security problem, or the law requires it.
3. Who we share it with
Only service providers that work for us, under contracts that limit their use of it, and only what each needs:
- Anthropic and OpenAI (USA): the AI models. Each call sends them what Unii needs to answer: your recent messages, summaries, images and tool output, and your voice notes, to turn them into text. When Unii searches the web, the query goes through their search service. Their API terms bar them from training on it; they may keep it up to 30 days to detect abuse, longer if the law or an abuse investigation requires.
- Vercel (USA): only when Anthropic or OpenAI can take no more of our calls, a call may go through Vercel's AI Gateway, which passes it to the same company's model. Vercel deletes what it carries once the call ends, keeping only each call's metadata (time, model, token counts).
- DigitalOcean (USA): our servers and DNS, which store your account and chat.
- Stripe (USA, Ireland): payments. Stripe also uses payment data as its own controller to prevent fraud and meet its legal duties (Stripe's policy).
- Resend (USA): sends your sign-in emails.
- Apple (USA), only if you use the iOS app: it sells credit bought there, as its own seller under Apple's policy, and carries notifications to your phone, each holding the start of Unii's reply.
- GitHub (USA), only if you sign in with it, under GitHub's policy.
Your account is an HOC account shared with BendAI (bend-lang.com), so HOC's credit system there holds your account, payments and charges. We also disclose data when the law requires it, to protect people or our rights, to a successor in a merger or sale of our business (with notice), or when you ask us to.
4. Where it goes
We are in the United States and keep your data there. Our providers may process it in the US and other countries. Where the law of your country requires safeguards for data sent abroad (for example the EU, UK or Brazil), we rely on the standard contractual clauses our providers offer, or on another lawful means.
5. How long we keep it
- Your chat and account: until you delete your account. Deleting removes your chat, summaries, images and sessions from our servers at once; any backup copy is overwritten within 30 days.
- Financial records (payments, charges and the calls they paid, refunds, disputes, tax data) and consent records: five years after the transaction or the closing of your account, whichever is later, as tax and accounting laws require. After deletion they are linked only to an anonymous account number and Stripe's reference.
- Server logs: kept on our server until it rotates them out by size, access logs at most 10 years; the version checks, until we delete them. They hold no chat content.
- Sign-in links: they work for 15 minutes (an install link once, for 24 hours).
We keep data longer only when a law, a legal hold or an open dispute requires it.
6. Your rights
Wherever you live, you can see your account and every charge (menu), download all your data in a machine-readable file (menu, Export Memory, or /export), and delete your account with everything in it (menu, Delete account, or /delete). You can also write to contact@higherorderco.com to access, correct, delete or get a copy of your data, to object to or restrict a use of it, or to withdraw consent. We will confirm it is you, normally with a link to your account's email, and answer within the time your law allows (one month in the EU and UK, 15 days in Brazil, 45 days in California). You will not be treated worse for using these rights. An authorized agent may act for you with proof.
European Union and United Kingdom. You have the rights of the GDPR and UK GDPR, including to complain to your data protection authority (in the UK, the Information Commissioner's Office).
Brazil. You have the rights of art. 18 of the LGPD (Lei 13.709/2018), including to complain to the ANPD. Our contact for data protection matters (encarregado) is contact@higherorderco.com.
California and other US states. In the last 12 months we collected: identifiers (email, GitHub login, IP address); commercial information (purchases, balance, charges); limited payment information; internet activity (server logs); and the content of your chat, which may hold sensitive personal information. We collect it from you, your devices, GitHub and Stripe, for the purposes in section 2, and disclose it to the providers in section 3 for those purposes only. We do not sell or share personal information, as California law defines those words, and we use sensitive personal information only to provide the Service. We honor Global Privacy Control signals as an opt-out of sale or sharing, though we do neither.
7. Security
We use encryption in transit, keep session tokens only as hashes, and limit who at HOC can reach our servers. Card details never reach us. No system is perfectly secure; your email account (or GitHub account) is the key to your UniiChat account, so protect it. Note that unii can act on the computers where it is open (Terms, section 3).
8. Children
UniiChat is not for anyone under 18. If you believe someone under 18 has given us personal data, write to contact@higherorderco.com and we will delete it.
9. Changes
We may update this policy. We will post the new version here with its date and, for important changes, tell you by email first.
10. Contact
Higher Order Computing Company, 8 The Green, Ste B, Dover, DE 19901, USA. contact@higherorderco.com.