Privacy Policy
Last updated: October 4, 2026
This policy describes how we collect, use and protect your information when you use token.unifyai.us (the "Service"), and the rights you have over it.
Who we are
Unify Token is a UnifyAI product operated by FelixSphere LLC, 6 Karen Ct, CA 94010, United States ("we", "us"). For the purposes of the GDPR, FelixSphere LLC is the data controller.
What we collect
Server logs
Our load balancer records each request: the time, the IP address, the path, the status code and the browser's user agent. These logs are kept for up to 90 days and are used only to operate and secure the Service.
Accounts
Accounts are created by us, by invitation. For each account we hold an email address, an optional display name, a password hash (argon2id; we never store the password itself) and the times the account was created and last changed.
Sessions
When you log in we set one cookie, __Host-ut_session, which identifies your session for 12 hours. It is strictly necessary for the signed-in pages and is set only after you log in. Logging out removes it.
What we do not collect
This site runs no analytics, no advertising or tracking scripts, and loads nothing from a third party. It sets no cookie until you log in, and it does not use local storage.
How we use your information
- To provide the Service and keep your account secure.
- To detect and prevent abuse, such as repeated failed log-in attempts.
- To contact you about your account when you have asked us to or when the Service requires it.
Who we share it with
The Service is hosted by Amazon Web Services in the United States (us-east-1), which processes data on our behalf. We do not sell your personal data, and we disclose it otherwise only where the law requires.
Retention
Account data is kept while the account exists and deleted when the account is removed. Server logs expire after at most 90 days. Session cookies expire after 12 hours.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict its processing, and to complain to a supervisory authority. Under the GDPR we process account data to perform our agreement with you and server logs in our legitimate interest in running a secure service. To exercise any right, email us at the address below.
Security
Data is encrypted in transit (TLS) and at rest. Passwords are stored only as argon2id hashes. Access to production systems is limited to the people who operate them.
Children
The Service is not directed at anyone under 16, and we do not knowingly collect data from them.
Changes
We will post any change to this policy on this page and update the date above.
Contact
By email: contactus@felixsphere.com