Privacy Policy
This Privacy Policy explains what UC Nexus SARLAU (“we”, “us”, the “Operator”) collects when you use the OmniLink+ iOS application or visit https://www.ucnexus.net, why we collect it, how long we keep it, and what you can ask us to do with it.
1. Who we are
Controller: UC Nexus SARLAU
Product: OmniLink+ (iPhone / iOS)
Website: https://www.ucnexus.net
API host used by the app: dat.ucnexus.net
Privacy contact: [email protected]
2. Data we collect
Depending on how you use OmniLink+, we process the categories below. We do not require an email address to register in the current iOS client; accounts use a username and password.
| Category | Examples | Purpose |
|---|---|---|
| Account data | Username, password (stored hashed on our side), numeric account ID, display name / nickname, session and refresh tokens | Create and authenticate accounts (including sign-in), keep you signed in, and protect account access |
| Device identifiers | A stable on-device identifier generated for OmniLink+ (preferring the vendor identifier where available, otherwise a random UUID), device model, OS version, app version | Session recovery, compatibility, abuse prevention, and support |
| Subscription / purchase data | Plan name and status, entitlement window, App Store product identifier, StoreKit transaction identifier | Verify purchases with Apple, unlock the tunnel desk for the paid period, and show membership status. We do not receive your full payment card details from Apple |
| Operational network signals | Selected line / endpoint identifiers, line admission checks, coarse IP-derived region used for smart routing, optional line-fault reports you trigger, version checks | Deliver the live endpoint catalog, apply routing preferences, keep lines healthy, and diagnose failures you report |
| Support data | Care-ticket title and details you submit (and any email you later send us) | Answer support requests. The app does not ask support staff for your password |
| Website technical logs | Standard web-server request metadata (e.g. IP, time, path) for ucnexus.net | Security and availability of the static website |
3. Data we do not collect (by design of the current client)
- Advertising identifiers used for cross-app tracking; OmniLink+ does not implement App Tracking Transparency prompts for ads.
- Contacts, photos, calendar, microphone, camera, or precise continuous GPS location.
- Third-party advertising, crash-analytics, or marketing SDKs embedded in the current iOS client.
- Push-notification device tokens — the current client does not register for Apple Push Notification service.
- The content of messages, files, or credentials you transmit through destinations you reach via the tunnel, as browsing content uploaded to our account API.
Encrypted sessions run inside OmniLink+’s Packet Tunnel Network Extension using OmniLink+’s own on-device tunnel code path. Diagnostic logs may be stored locally on your device (including App Group storage) to help you copy logs for support; ordinary diagnostic output is designed to keep endpoint secrets and session tokens out of casual log dumps. Local logs are not automatically uploaded unless you choose to include information in a care ticket or fault report.
Operating a tunnel necessarily involves network infrastructure seeing destination addressing needed to forward packets. We do not operate OmniLink+ as a product that sells or publishes identifiable browsing histories tied to your account.
4. How we use data (legal bases)
- Contract — creating accounts, verifying App Store entitlements, delivering tunnel access and in-app care tools you paid for or requested.
- Legitimate interests — security, fraud/abuse prevention, capacity and line health, product integrity.
- Legal obligation — retaining accounting records and responding to valid lawful requests.
- Consent — optional information you choose to put in support tickets or fault reports; you may decline to send those.
5. Network Extension
iOS grants OmniLink+ a Packet Tunnel provider so the app can bind the system VPN interface for an authenticated, eligible session. The extension is used to establish encrypted tunnels and related DNS / routing behaviour (including smart routing and on-device DNS mapping). It is not used to read your Photos, Contacts, or other unrelated personal datasets.
6. Sharing
We do not sell personal data and we do not share it for advertising networks. Disclosure is limited to:
- Apple — payment processing via StoreKit / App Store; we receive transaction and product identifiers and entitlement state needed to unlock the service.
- Infrastructure providers — cloud and network providers that host API, website, and tunnel infrastructure under processing instructions.
- Competent authorities — where a valid legal order requires disclosure of data we actually hold. We do not invent browsing histories we do not keep.
7. International transfers
Servers and lines may be located in multiple regions. Where personal data is transferred internationally, we use appropriate contractual and technical safeguards (including encryption in transit to our API).
8. Retention
| Data | Retention |
|---|---|
| Account and subscription records | While the account is active; erased from production systems within 30 days after a confirmed deletion request (see Account Deletion) |
| Operational signals / fault reports | Only as long as needed for line health, security, and support — then deleted or aggregated |
| Support tickets / email | Up to 24 months after closure, unless a longer period is required for an ongoing dispute |
| Accounting / tax records | As required by applicable law (transaction data, not browsing content) |
| Website server logs | Short rotation for security |
9. Security
Client–API traffic uses HTTPS. Passwords are stored as salted hashes on our side, not in reversible cleartext. Session tokens are kept in the iOS Keychain / protected app storage. No method of transmission or storage is perfectly secure; if a breach affecting your personal data occurs, we will notify you and regulators as required by law.
10. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, objection, or portability of personal data we hold. Contact [email protected] and include your OmniLink+ username or account ID. We respond within 30 days where required.
To close an account, follow Account Deletion. California residents have rights under the CCPA/CPRA; we do not “sell” or “share” personal information for cross-context behavioural advertising as those terms are commonly defined.
11. Children
OmniLink+ is not directed to children under 13 (or the higher age of digital consent where applicable). We do not knowingly collect their personal data. If you believe a child registered, contact us and we will remove the account.
12. This website
https://www.ucnexus.net primarily serves informational and legal pages. It does not use advertising cookies or third-party advertising analytics in the Operator-controlled static pages described here.
13. Related notices
- Data collection summary (App Store–oriented short form)
- Terms of Service
- Account deletion
- Apple Standard EULA (for App Store distribution): apple.com/…/stdeula
14. Changes
When this policy changes, we publish the new version and effective date on this page. Material changes will be announced in the app where practicable.
15. Contact
Privacy questions and rights requests: [email protected]
Data controller: UC Nexus SARLAU
Website: https://www.ucnexus.net