Last updated: August 28, 2026
UniMela is a campus platform for university students — a marketplace, campus services (food, housing, tuition, ride sharing, lost & found), reviews, events, and announcements. You sign in with your university Google account. This policy explains what information UniMela handles and what happens to it.
Account information. When you sign in with Google, UniMela receives and processes:
Your account also stores your preferred language, time zone, sign-in timestamps, verification state, and your acceptance of the Terms of Service and Privacy Policy.
Older email-and-password sign-up endpoints still exist in the system and the registration form still renders, but Google Sign-In is the documented way to use UniMela.
Profile information. Your profile can include your display name, an optional username, bio, department, campus, graduation year, university, profile and cover photos, your marketplace rating and review counts, and your verification status.
Content you post. Listings and their photos, food, housing, tuition, ride-sharing and lost & found posts, course and faculty reviews, event registrations, messages and their attachments, and reports you submit — with any evidence files you attach.
Verification documents. If you submit a verification request, the documents you upload (such as student ID, enrollment certificate, transcript, or university-email proof) are stored and shown to assigned reviewers.
Some information is public by nature: your marketplace listings, food/housing/tuition/ ride-sharing posts, reviews, and public profile are visible to other students. Your name (or chosen display name) appears next to your posts, and buyers and sellers you interact with can see the conversation between you.
Your profile has visibility controls. You can set your overall profile visibility, and separately control whether your department, marketplace rating, and reviews are shown. Verification documents are not public — they are visible to assigned reviewers only.
You can review most of this yourself: your profile page shows you what others see.
UniMela uses Google Sign-In. When you sign in, Google gives UniMela an ID token, which UniMela verifies — including requiring that your email is verified at Google. UniMela then uses your email domain to determine your university and affiliation. Beyond the data described above, UniMela does not receive or store your Google password. Google's own handling of your Google account is covered by Google's privacy policy.
Every upload — listing photos, profile pictures, message attachments, verification documents, report evidence — goes through the same storage pipeline: the file is validated, checked for viruses (ClamAV), and recorded with its filename, type, size, image dimensions, checksum, and processing status. Images may be stored in additional sizes for faster loading.
Files are stored through UniMela's storage pipeline — on local storage in the development environment, and on the configured production storage provider (Cloudflare R2) when deployed with it. When you delete a file or post, it is removed from view and marked as deleted in the system; physical cleanup of the underlying stored files is handled by a later cleanup process rather than happening instantly.
Messages you send to another student — including any attachments — are stored so your conversation works, and are visible to the other person in that conversation. UniMela is in-app only: UniMela does not send you email, SMS, or push notifications. In-app notifications appear inside the app, and you can manage them per category in your settings.
You can report content or people. Reports and any attached evidence are stored and can become moderation cases, which moderators review; appeals are also supported. To keep the platform safe and secure, UniMela keeps audit records of security and moderation actions — these record who acted, on what, when, the network IP address and browser user agent involved, and what changed. Audit records are kept for 365 days.
The app reports very limited technical telemetry when something goes wrong: a category label (for example "script error") and a rough page-load number. These are counted in UniMela's own monitoring dashboard — no user identifiers, page URLs, message content, or error text are included, and the raw reports are not stored. Your browser sends at most 10 such error reports per visit.
Server logs are kept for operating the service. Sensitive values — such as authorization headers, cookies, passwords, and tokens — are removed from logs before they are written.
UniMela uses a small amount of first-party browser storage to work. There are no advertising or third-party tracking cookies.
Account deletion. You can request account deletion from Settings. Deletion immediately signs you out everywhere, and your account enters a 30-day grace period during which you can cancel. After the grace period, the account is marked as deleted in the system.
A current limitation, stated honestly: the self-service deletion step confirms your identity with your password. Accounts created through Google Sign-In do not have a password, so this verification step can currently fail for Google-only accounts. If that happens to you, reach out through the Help/FAQ desk (see below) so your request can be handled manually.
"Deleted" means removed from the platform and marked as deleted in the system's records — UniMela does not promise the instant physical erasure of every stored copy of every record. Content you post (listings, messages, reviews, and so on) uses the same approach: deleting removes it from view and marks it deleted.
How long things are kept. The implemented retention rules are: the 30-day account-deletion grace period described above, and 365 days for security/moderation audit records. Beyond those, UniMela does not currently define fixed retention periods for ordinary content such as messages, listings, or reviews — they are kept while your account and the platform use them, and removed from view when deleted.
UniMela is for students and staff of supported universities. Sign-in is restricted to approved university Google accounts — your university email domain determines whether you can join and whether you join as a student or staff member.
If this policy changes, the updated version will be published on this page with a new "Last updated" date. Continuing to use UniMela after a change means the updated policy applies to your use of the platform.
For privacy questions or requests, use the in-app Help/FAQ desk — the same place you go for other support. Requests about your account or data are handled there.
Visit the Help / FAQ page.