Privacy policy
Unitcore keeps your budget, your tasks and your lists in one place, and lets an AI assistant work with them on your behalf. That only works if it is obvious what is stored, where it goes, and how to take it back. This page is that.
Who we are
Unitcore is run by Denis Popov, a self-employed developer (autónomo) registered in Spain, who decides what happens to the data described below.
- NIF — Z4045078G
- Address — Anaitasuna kalea 11, 48903 Barakaldo (Bizkaia), Spain
- Email — support@unitcore.io
Write to support@unitcore.io about anything on this page.
What we store
Your account. An email address and a password, both held by our authentication
provider — we never see the password, only a hash it keeps. If you signed in through
another provider, the display name and avatar it gave us. A member tag, shaped like
UC-XXXX-XXXXXX, which is how other people add you to a space without knowing your email
address. You can replace the tag whenever you like from the account menu.
What you put in. Transactions and the lines inside them: title, date, amount, currency, category. Tasks and their lists, notes, labels, due dates and assignees. Categories you create, and whether each one counts as money in or money out. All of it is content you wrote, and none of it is examined by us for any purpose other than showing it back to you.
Who you share with. The spaces you belong to, who else is in them, who owns each one, and invitations sent or received — including the tag they were addressed to and whether they were accepted, declined or taken back.
Connected applications. For each AI assistant or other client you connect, the name it registered under, the address it returns to, when you connected it, and whether you gave it permission to write. You can see this list, and revoke any entry on it, under Settings → Applications.
What we do not do
There is no analytics script on this site, no advertising network, no third-party tracker of any kind. We do not sell or rent your data, we do not build a profile of you, and nothing you store here is used to train a machine learning model of ours or anyone else's.
Cookies
Three small things are kept in your browser, and none of them track you:
- A session cookie, set when you log in, so the next page knows it is still you. Clearing it logs you out. There is no way to offer an account without this one.
- A language cookie (
NEXT_LOCALE), written only when you pick a language from the menu, so the choice survives your next visit. - A theme preference, kept in local storage rather than a cookie, so the page does not flash the wrong colours before it loads.
That is the whole list, which is why this site has no cookie banner: there is nothing to consent to beyond what the service needs to run.
Who else can reach your data
Other members of your spaces. A space is a circle of people, and everything in it is visible to everyone in it — every transaction, every task, and everything you add later. Your personal space has only you in it and cannot be shared. Leaving a space, or removing someone from one you own, takes effect immediately; it does not retract what they already saw.
Our infrastructure providers. The database, authentication and file storage run on Supabase; the site itself is served by Vercel. Both process data on our instructions and under their own published terms. Nobody else has access, and access inside the database is enforced by row-level security rather than by application code, so a bug in this website cannot hand one account another account's rows.
What an AI assistant sees
This is the part worth reading twice.
When you connect an assistant — Claude, ChatGPT, or any other client that speaks MCP — you approve it on a consent screen, and from then on it acts as you. Anything you can read, it can read. If you granted write access, anything you can change, it can change. There are no partial permissions beyond that one choice.
What follows from that:
- Whatever the assistant reads from Unitcore is sent to the company that operates the assistant, and is handled under their privacy policy, not this one. We have no visibility into what they keep, how long they keep it, or whether they use it to improve their models. Read their policy before you connect them.
- The connection is made with a token that belongs to you and can be withdrawn by you. Revoking it under Settings → Applications kills the refresh token immediately; an access token already issued keeps working for up to an hour.
- A connected client can never delete a space, a membership or your profile. Those need the website, where a human sees a confirmation dialog first.
If none of that is a trade you want to make, do not connect an assistant. Everything on the site works without one.
How long we keep it
Your content stays until you delete it. Deleting a transaction, a task or a space removes it from the database; a task goes to a trash you can empty, and emptying it is final. Deleting your account removes your profile, your tag, your personal space and everything in it, along with every connected application. Content in a shared space that other people still belong to stays with that space.
Encrypted backups held by our database provider roll over on their own schedule, so a deleted row can persist in a backup for up to 30 days after it disappears from the service.
What you can do
You can see and correct everything about you from inside the app, and export or delete it on request. Specifically:
- See it — every page of the app is a view of your own rows, and a connected assistant can read them all back to you.
- Correct it — edit anything you wrote, rename or delete a space you own, replace your member tag.
- Withdraw access — revoke any connected application, leave any shared space.
- Take it with you, or delete the account — write to support@unitcore.io from the address on the account. We answer within 30 days.
If you are in the EEA or the UK, these are your rights under the GDPR — access, rectification, erasure, restriction, portability and objection — and you may complain to a supervisory authority if you think we have mishandled them. Ours is the Spanish one, the Agencia Española de Protección de Datos; you may also go to the authority of the country you live in.
Security
Passwords are hashed by our authentication provider and never reach us. Traffic is HTTPS-only. Every query runs as the account that made it, and the rules that decide which rows an account may touch live in the database itself — the same rules apply whether a request comes from this website or from a connected assistant. Automated checks run against those rules on every change to them.
No service is perfectly secure. If you find a hole, tell us at support@unitcore.io before you tell anyone else.
Children
Unitcore is not intended for anyone under 16, and we do not knowingly hold data belonging to a child. If you believe a child has an account here, write to us and we will remove it.
Changes
The date at the top of this page is the version in force. If we change something that affects what happens to your data, we will say so on the site before it takes effect, and you will always be able to close the account instead of accepting it.
Contact
support@unitcore.io. A person reads it.