Privacy Policy
Last updated 20 September 2026. This policy covers the UNBND mobile app (Android and iOS) and the backend that serves it.
Who is responsible
UNBND is built and operated by an individual developer. For any privacy question, or to ask what data is held about you, email gucciyd248@gmail.com.
The three roles
Every account is a student, a recruiter or an organizer, chosen at sign-up. The role is fixed for the life of the account and decides what you see and what others see of you. Students join booth queues. Recruiters run a booth's queue and see the students who joined it. Organizers run a fair and see the queues at its booths.
What UNBND collects
Your account
- Email address and password. Authentication is handled by Supabase. The password is stored only as a hash — UNBND never sees or stores it in readable form, and nobody at UNBND can look it up.
- Display name — the name you type at sign-up. If you leave it blank, the part of your email address before the @ is used instead.
- Role (student, recruiter or organizer) and the date the account was created.
Your major — students, optional
A student can pick one major from a standard list (the U.S. Department of Education's CIP 2020 program list). It is stored as a code and is optional: the app works without it. Recruiters at booths you join can see it, and it is included when a recruiter exports their student list.
Your headshot — optional
Students and recruiters can add a photo of themselves. It is optional, you are asked once, and you can skip it, replace it or remove it at any time from Account. Organizers are not offered one. See Headshots in detail below.
Your queue activity
- Which booths you joined, and your place in each queue as a ticket number.
- Timestamps for what happened to each ticket: joined, called, checked in, conversation started, completed, cancelled or expired — including the reason a ticket was cancelled.
- Which recruiter called you, checked you in, or talked to you.
If you are a recruiter or organizer
- Which booths you belong to and the role you hold at each one.
- Content you create: fair name, date and location; company name and description; booth table label, the majors the booth is hiring for, and booth settings.
- Students you star. A recruiter can star a student they met. The star records the student, the booth and the time, and is visible only to the recruiter who made it.
Notifications
- If you allow notifications, UNBND stores a push token for that device — a delivery address issued by the Expo push service — and whether the device is Android or iOS.
- Notifications waiting to be sent are queued on the server with their title and text (for example, "You're up: Acme Robotics — go to Table A1 now") until delivery succeeds or permanently fails. A notification names the company and table, and says where you are in that queue.
Sign-in security records
The authentication service records each sign-in session with the IP address and device/browser identification string it came from, and keeps an authentication audit log of events such as sign-up, sign-in, sign-out and token refresh. These records exist to secure accounts. They are kept by the authentication service and are not shown to recruiters, organizers or other users.
On your device
- Your signed-in session, so you do not have to sign in every time. Signing out removes it.
- A note of whether you chose to skip the headshot prompt, so you are not asked again.
- On Android, the state of the live queue notification, so it only rings when your position actually changes.
- When a recruiter exports a student list, the CSV file is written to the app's cache folder on that recruiter's device and handed to the system share sheet.
The camera
The camera is used to read booth QR codes and, if you choose it, to take your headshot. Nothing from the QR scanner is stored or uploaded — that camera image never leaves your device. A headshot you take on purpose is uploaded, as described below.
Headshots in detail
- Why. So the two people who are about to meet can recognise each other at a crowded fair. A recruiter sees the student's face when they call them and on the student list; a student sees the face of the recruiter who called them.
- How it is made. You take a photo or pick one from your photo library. The app crops it square, shrinks it to 512 pixels and saves it as a JPEG before uploading. Only that processed image is uploaded, not the original file and none of its other photos.
- Where it is stored. In the project's
avatarsfile storage, under a folder named with your account's internal id, as a single file namedavatar.jpg. Uploading a new one replaces the old one. Only you can upload, replace or delete the file at that path. - Who can see it. The app shows it to the people described in the table below. Beyond that, the storage bucket is public: the image file is served over the web to anyone who has its exact address, without signing in. The address contains your account's internal identifier, rather than your name or email. UNBND does not provide a public directory of photos, but the link is not access-controlled and can be shared. Anyone you send the link to, and anyone the app has shown it to whose device cached it, can open it. Do not use a photo you would not be comfortable being seen this way.
- On Android, the queue notification downloads the other person's headshot to draw it in the notification, and keeps it in memory while that notification is on screen.
- How long it is kept. Until you replace it, remove it, or delete your account. There is no automatic expiry.
- Deleting it. Account → Change photo → Remove photo deletes the file and clears the link on your profile. Account deletion also attempts to remove the file. If that storage step fails, account deletion can still finish without removing the photo; the failure is logged but not automatically retried. Contact support if a photo remains accessible. Copies already downloaded to somebody’s device are outside UNBND’s control.
- UNBND does not run face recognition and does not use your photo for anything except showing it to the people below.
Who can see what
Access is enforced on the server, per request, from your signed-in identity — not in the app. What each role can see:
- Other students see nothing about you. Students cannot read each other's tickets, names, photos or majors. A booth's waiting count is a number with no names attached.
- Recruiters at a booth you joined see your display name, your headshot, your major, your email address, your ticket number and its status, and when you were last seen at their fair. They can star you and export that list — including your email address — as a CSV file to anywhere their phone can share a file. This is the point of the app: joining a booth's queue hands the employer your contact details. If you do not want an employer to have your email address, do not join their queue.
- That access does not expire. A recruiter keeps seeing you in their student list for as long as both accounts exist and your ticket history exists, at every fair you met them at.
- Recruiters at booths you never joined see nothing about you.
- The organizer of a fair sees the tickets at that fair's booths and the names, headshots and majors of the students holding them, plus per-booth counts. The organizer does not get student email addresses and has no CSV export.
- Recruiters and organizers can see each other's names within a fair or booth they share. Organizers are not offered a headshot.
- Other app users cannot read your password, push tokens, or sign-in records. Authentication and notification services process the data needed to operate their services.
What UNBND does not collect
UNBND contains no analytics, advertising, attribution or crash-reporting SDK. It does not collect your location, your contacts, your calendar, your photo library beyond the single headshot you pick, microphone audio, an advertising identifier, or any payment information. It does not track you across other apps or websites, does not sell or rent personal data, and does not use your data for advertising. There are no third-party ad or analytics networks in the app.
Two technical notes, for completeness. The app is built with Expo; the Google Play Install Referrer library ships inside one of its components and the app declares the matching permission, but UNBND never calls it and collects no install-referrer data. Apple and Google collect their own crash and performance data from apps on their platforms under their own privacy policies; their collection is separate from UNBND’s app data.
Why UNBND uses this data
- To run the queue: place you in line, show your position, and call you when it is your turn.
- To let the two people meeting recognise each other at the table.
- To send the notifications you asked for.
- To show recruiters and organizers who is at their own booth or fair, and nobody else's, and to let a recruiter keep a record of the students they met.
- To keep accounts secure and to answer your support emails.
Who else processes your data
- Supabase — hosts the database, authentication, file storage and live updates, on infrastructure in the United States.
- Expo push notification service — delivers queue notifications. It receives your device's push token and the title and text of each notification.
- Google (Firebase Cloud Messaging) on Android and Apple (APNs) on iOS — the platform channels each notification passes through. Google's messaging component also registers an app instance identifier for your installation with Google in order to deliver messages.
- Resend — the mail service that delivers account emails, such as the sign-up confirmation.
- Google Fonts — when a recruiter uses the booth's Print / save as PDF sheet, the print preview loads a font from Google's font service, which reveals that device's IP address to Google. No account or queue data is sent.
- Whoever a recruiter shares an export with. A CSV a recruiter exports leaves UNBND entirely. Where it goes after that is up to that recruiter and their employer.
Apart from the student information recruiters and organizers see by design, UNBND does not share your data with anyone else.
Permissions UNBND asks for
- Camera — to scan booth QR codes, and to take a headshot if you choose that. You can decline and still join a queue with a booth code typed by hand.
- Photos — only if you choose a headshot from your library. You can decline.
- Notifications — to tell you when your turn is coming. You can decline and still use the app; the queue updates on screen while UNBND is open.
How long data is kept
- Your account, profile, headshot, major and queue history are kept for as long as your account exists. UNBND does not delete old tickets automatically and has no scheduled clean-up. You can request account deletion at any time — see Delete your account and data.
- Stars and student lists live as long as both accounts do. Deleting your account removes you from every recruiter's list.
- Push tokens are deleted when the delivery service reports the device is no longer registered — for example after you uninstall UNBND — and when your account is deleted.
- Queued notifications are held until they are sent or permanently fail. Rows that failed are kept as a record of the failure, and are deleted with your account.
- Sign-in security records. Sessions end when you sign out or they expire. The authentication audit log is kept by the authentication service, is not cleared when an account is deleted, and can still contain the email address the events belonged to. There is no verified fixed retention period for these entries. If you want them reviewed for removal, say so in your deletion request. Hosting-provider API, auth, and function logs can also contain IP addresses; their retention is plan-dependent and has not been verified.
- Backups. Deleted data may remain in hosting-provider backups until those backups expire. The project’s backup configuration and retention period have not been verified, so UNBND does not promise a specific backup deletion deadline.
- Exports. A CSV a recruiter already exported is not reachable by UNBND and is not deleted when you delete your account.
- Support email. If you email the support address, the message stays in the support inbox as a record of the request and how it was handled.
Where this policy does not state a number of days, it is because no fixed period is enforced in the system. Rather than publish a retention period the code does not keep, UNBND says plainly what triggers deletion.
Your choices
- Delete your account — use Account → Delete account in the app. The request is processed when you confirm; auth logs, backups, exported copies, and a photo whose removal failed may remain as explained above. Or see Delete your account and data.
- Remove your headshot — Account → Change photo → Remove photo.
- Change or clear your major — Account → Major, then pick another or tap Clear.
- Turn off notifications — revoke the notification permission for UNBND in your device settings at any time.
- Turn off camera or photo access — revoke the permission in your device settings.
- Ask what is held about you, or ask for a correction — email the support address.
Security
Traffic between the app and the server is encrypted in transit with HTTPS and TLS, including the live queue connection and every notification sent for delivery. Data at rest is protected by the hosting platform's own storage encryption; UNBND does not add a second layer on top. Passwords are stored only as hashes. Every queue action runs through server-side rules that check what your account is allowed to see and do, and those rules — not the app — are what keeps one account out of another's data. The one deliberate exception is the headshot file, which is served publicly by address as described above. No system is perfectly secure.
Who UNBND is for
UNBND is built for career fairs at colleges and universities. It is not directed to children under 13, and accounts should not be created for them.
This website
This public site uses local assets and system fonts, with no analytics, advertising scripts, or third-party font requests. GitHub Pages hosts it and receives the connection information needed to serve pages, such as your IP address. Email links open your email service.
Changes to this policy
If this policy changes, the updated version is published on this page with a new "last updated" date.