Univea

Privacy

Last updated: August 1, 2026

Data controller

The data controller is Matteo Firinaiu, who runs Univea as a personal project, with no registered company behind it. For any request about your data, write directly to matteo@mitik.ai, or reach out through the Feedback page if you'd rather not use email.

Legal bases

To verify your email address, create and manage your account, send verification codes, and let you publish and manage reviews, we process the data necessary to carry out the Terms of use and the steps you ask for before registering, under Article 6(1)(b) GDPR. To prevent spam, fraud, abusive access, and anomalous use, we process technical identifiers and essential security data based on our legitimate interest in protecting the service, under Article 6(1)(f). When necessary, we process data to comply with legal obligations, under Article 6(1)(c), or to establish, exercise, or defend our rights, based on our legitimate interest.

What we collect

To verify you're a university student we ask for an institutional email address: without it, you can't create or verify an account, or publish a review. Your address is kept on your account record, together with an identifier derived through a cryptographic function, which we use internally to link reviews, sessions, and other site features without needing to read the email itself.

How we use your email

Your email is used to send you the verification code (via the Resend service), to identify your account, and, if you choose to stay signed in, to show it back to you in your browser session. It's never shown publicly or linkably attached to the reviews you publish: those stay associated only through the derived identifier, not the address itself.

Reviews

Reviews are published without showing your name or email address. Internally they stay linked to a pseudonymous identifier derived from your email, which lets you manage your reviews from the Profile page and helps us prevent abuse. This makes them pseudonymized data, not anonymous in a technical or legal sense: they remain personal data as long as that link exists.

Technical data

Our application database never stores your IP address in plain text: we temporarily keep a pseudonymous identifier derived from it, used only to prevent abuse (spam, repeated submissions). The providers behind our hosting, email delivery, and abuse-prevention infrastructure may still process your IP address and other log data under their own policies, independently of our application code.

Cookies and similar technologies

We only use technical cookies necessary for the service to work: one to remember your chosen language, valid for 1 year, and one authentication cookie holding a session identifier, valid for 90 days. The authentication cookie doesn't contain your email address and is configured so scripts running in the browser can't read it. We don't use advertising or profiling cookies, or third-party analytics tools.

Data retention

Expired verification codes and session tokens are deleted automatically by the system. IP hashes used for abuse prevention are deleted within 7 days of being created. Your email address stays attached to your account until you ask us to remove it, or until the account has been inactive for several years: we periodically review accounts inactive for more than 3 years to consider deleting them. Reviews are kept until you delete them yourself. If you delete your account, its reviews are deleted too, unless you explicitly choose to keep them in permanently anonymous form: in that case we remove every technical link that could trace them back to your account or let anyone manage them again. Our database provider (Neon) also keeps point-in-time restore backup copies for up to 24 hours, independently of deletions made at the application level.

Recipients and transfers

We rely on external providers that process data on our behalf: Vercel for site hosting, Neon for the database, and Resend for sending verification emails, to which we disclose the recipient's address, the email content, and related technical delivery data. Emails may be sent through infrastructure located in the European Union, but Resend keeps some service data in the United States, including email metadata, logs, and API records; Resend also relies on sub-processors, including Amazon Web Services. Providers process data on our behalf under data processing agreements. When data is transferred outside the European Economic Area, we rely on GDPR safeguards such as the Data Privacy Framework, adequacy decisions, or standard contractual clauses, depending on the mechanism that applies to each provider. We don't sell or share your data for advertising purposes.

Third-party content in reviews

If a review contains a third party's personal data (for example, a teacher's) that you believe should be removed, write to matteo@mitik.ai or reach out through the Feedback page, stating which review, your reason, and your contact details: we review every report by hand, confirm we received it, and tell you the decision we made. The rules on what a review may contain are set out in the Terms of use.

Your rights

Where applicable under the law, you have the right to ask us for: access to the data we hold about you, correction of inaccurate data, deletion, restriction of processing, objection to processing based on our legitimate interest (stating grounds relating to your particular situation), and portability of data you gave us directly. You can edit or delete your own reviews from the Profile page; for any other request, write to matteo@mitik.ai. We may ask you to verify your identity, for example by proving access to the email on your account, before acting on a request. We typically respond within a month, with a possible extension for particularly complex requests.

Minimum age

Univea is reserved for users who are 18 or older. Holding a university email address isn't a reliable age check. If we learn the service is being used by a minor, we suspend the account and take the steps needed to delete its data, except what's needed to handle the report and comply with legal obligations.

No profiling

We don't carry out profiling or make decisions based solely on automated processing that would produce legal effects or similarly significantly affect you.

Contact

For any question about this policy, write to matteo@mitik.ai or reach out through the Feedback page.