Your data, plainly
What we store, what we deliberately don't, and what happens when you leave.
What we store
- Who you are: name, email, and which space you belong to — the minimum an invite needs.
- What your org uploads: the audio and documents your leaders publish, kept in encrypted object storage, scoped to your org.
- Engagement: that an item was played or opened, and how far — this powers "continue where you left off" and your leader's completion view. We treat engagement as personal data.
What we deliberately don't
- No tracking across apps or the web. No third-party advertising SDKs, no data brokers, no selling — ever.
- Analytics without identity: our operational metrics record an outcome, a duration and an org — never a member's name, never a file name.
- Prospect pages (when sharing ships) collect no PII beyond an optional self-entered first name.
How it's protected
- Stream links expire in 30 minutes; download grants are re-checked on your org's schedule.
- Offline copies are encrypted on the device and stop working when membership ends — automatically.
- Restricted material can require Face ID / biometrics to open, at your org's choice, and access to it is recorded for the org.
When you leave
- Delete your account in the app (You → Delete account) or from this page. Personal data, including engagement history, is removed within 30 days.
- Org deletion is owner-only with a typed confirmation, a 7-day change-your-mind window visibly counted down in the app, then a full purge on our side. Connected provider content is disconnected, never deleted.
Questions about any of this: privacy@umydia.com.
UMYDIA