Privacy Policy
Last updated: September 30, 2026
ungic (“we”, “us”) is a web tool at app.ungic.com where your own AI assistant (Claude, ChatGPT or another client that supports MCP connectors) designs mobile app prototypes. This policy explains what we collect, why, who else processes it and how to get it deleted. The short version: we keep what the service needs to work, we do not sell data, we do not show ads, and ungic never sends your projects to an AI model itself.
1. What we collect
- Account: your email address, and your name and profile picture if you sign in with Google. For email sign-in we send you a one-time link.
- Your content: projects, screens, specifications, design settings, file history, images and PDFs you upload, comments and review decisions.
- Workspaces: who is a member of which workspace, their roles and pending invitations (including the invited email address).
- Connected AI apps: when you connect an AI assistant we store the access tokens it uses and the name of the app (for example “Claude” or “ChatGPT”), so you can see what is connected.
- Technical data: IP address, browser type and request logs, used for security and rate limits; the time you and your share links were last active.
- Messages to us: what you write in the “Contact us” form, with your name and email.
We do not use advertising trackers or third-party analytics on the site or in the app.
2. How we use it
- To run the service: sign you in, store and render your projects, show live changes to your team, produce screenshots and exports.
- To keep it safe: rate limits, abuse prevention, debugging.
- To send service emails: sign-in links, invitations, and notices before an inactive or archived project is deleted. We do not send marketing email.
- To answer you when you contact us.
Where the GDPR applies, our legal bases are performing our contract with you (running the service), our legitimate interests (security, abuse prevention, improving reliability) and your consent where we ask for it.
3. Your AI assistant
ungic is a connector: your AI assistant calls ungic’s tools to read and write your project. Everything the assistant reads through those tools — specifications, screens, screenshots, uploaded files — is processed by the provider of that assistant (for example Anthropic for Claude, OpenAI for ChatGPT) under your agreement with them and their privacy policy. We do not choose that provider and we do not control what it keeps. Connect only assistants you trust with the project.
4. Who else processes data
We use a small number of providers to run ungic. Each receives only what its job needs:
- Hosting — our application servers and database.
- Cloudflare (R2 storage) — uploaded files, previews and exports.
- Google — “Sign in with Google” (if you use it), and Google Fonts: designs load their fonts from Google’s servers, which see your IP address.
- An email delivery provider — to deliver sign-in links, invitations and notices.
- Pixabay and Pexels — when a design asks for a stock photo, we send the search words (never your identity) and cache the image.
We do not sell or rent personal data. We may disclose data if the law requires it, or to protect the service and its users from fraud or abuse.
5. Share links and teams
Members of a workspace see its projects. If you turn on a project’s share link, anyone with the link can open the prototype, and — if you allow it — leave comments and approve screens under a name they type. Turn the link off at any time to stop access.
6. Cookies
We use only the cookies the app needs: a session cookie that keeps you signed in, and a short-lived cookie that protects the Google sign-in step. The browser also stores small preferences (theme, open panels) in local storage on your device. No advertising or cross-site tracking cookies.
7. How long we keep data
- Projects stay while you use them. A project with no activity for 90 days is scheduled for deletion; we email the workspace first and delete it 30 days later unless someone opens it. Archived projects are deleted 30 days after archiving.
- File history older than 30 days is thinned out; cached build files are removed after 30 days.
- Deleted projects and their files are removed from storage when the deletion runs.
- Account data stays until you ask us to delete your account.
- Logs and rate-limit records are kept for a short time, usually days.
- Contact messages stay in our mailbox as long as needed to answer and follow up.
8. Your rights
You can export any project as a zip from the app, and delete projects and workspaces yourself. You can also ask us to access, correct, export or delete your personal data, or to delete your whole account — write to us through the contact form. We answer within 30 days. If you are in the EU/UK you can also complain to your data protection authority.
9. Security
Traffic is encrypted (HTTPS). Sign-in links work once and expire in 15 minutes. Designs run in an isolated sandbox. Access to projects is checked on every request. No system is perfectly secure; if we learn of a breach that affects you, we will tell you.
10. Children
ungic is not meant for children under 16, and we do not knowingly collect their data. If you believe a child has an account, contact us and we will delete it.
11. Changes
We may update this policy as the service changes. We will change the date at the top, and tell signed-in users about significant changes before they take effect.
12. Contact
Questions or requests about privacy: use the Contact us form on ungic.com or in the app.