UCI UNIFIED CITIZEN ID
Home
LOGIN
DATA PROTECTION

Privacy Policy

How we collect, protect, and handle your data across our identity and authentication infrastructure. Your privacy is protected by industry-standard encryption and strict operational protocols.

Effective: 2954.01.01
GDPR Compliant

PRIVACY HIGHLIGHTS

End-to-End Encrypted

All data protected by industry-standard encryption at rest and in transit

No Data Sales

We never sell your personal data or authentication information

Secure Storage

Data stored across redundant, secure infrastructure

1. PRIVACY OVERVIEW

Unified Citizen Identification ("UCI," "we," "our") is committed to protecting the privacy and security of all data processed through our infrastructure. This Privacy Policy explains how we collect, use, store, and protect information when you utilize our identity verification, authentication, and access management services.

This policy applies to all UCI services including OAuth2 authentication, single sign-on, passkey management, and associated infrastructure.

2. DATA COLLECTION

We collect the following categories of information:

ACCOUNT DATA

  • Email address and username
  • Password hashes (never plaintext passwords)
  • Profile information you provide
  • Connected social accounts (Discord, RSI)

AUTHENTICATION DATA

  • Session tokens and refresh tokens
  • Passkey credentials (public keys only)
  • Multi-factor authentication settings
  • OAuth2 authorization grants

AUTOMATICALLY COLLECTED DATA

  • IP addresses and approximate location
  • Device information and browser type
  • Login timestamps and session duration
  • Authentication success/failure logs

3. DATA USAGE

SERVICE DELIVERY

  • Authenticating users and managing sessions
  • Processing OAuth2 authorization requests
  • Managing passkeys and MFA settings
  • Connecting social authentication providers

SECURITY & COMPLIANCE

  • Detecting and preventing unauthorized access
  • Investigating security incidents
  • Complying with legal requirements
  • Protecting against fraud and abuse

SERVICE IMPROVEMENT

  • Analyzing usage patterns for optimization
  • Identifying and resolving issues
  • Developing new features

4. DATA STORAGE & RETENTION

DATA STORAGE

All data is stored using encrypted storage with redundant backups. Passwords are hashed using industry-standard algorithms (Argon2) and are never stored in plaintext.

RETENTION PERIODS

  • Session data: Duration of session plus 30 days
  • Authentication logs: 90 days
  • Account information: Duration of account plus 2 years
  • Security incident data: 5 years

5. DATA SECURITY

We implement comprehensive security measures:

ENCRYPTION

  • TLS 1.3 for all data in transit
  • AES-256 encryption for data at rest
  • Secure key management practices

ACCESS CONTROLS

  • Role-based access with least privilege
  • Multi-factor authentication for administrative access
  • Regular access reviews and audits

MONITORING

  • Continuous security monitoring
  • Automated threat detection
  • Regular security assessments

6. DATA SHARING

We may share data with third parties only in these circumstances:

SERVICE PROVIDERS

  • Infrastructure providers for hosting services
  • Social authentication providers (with your consent)

LEGAL REQUIREMENTS

  • Response to valid legal process
  • Compliance with regulatory obligations
  • Protection of rights and property

We never sell personal data to third parties for marketing or advertising purposes.

7. YOUR RIGHTS

You have the following rights regarding your data:

  • ACCESS - Request a copy of data we hold about you
  • CORRECTION - Request correction of inaccurate information
  • DELETION - Request deletion of your data
  • PORTABILITY - Receive your data in a standard format
  • RESTRICTION - Request limitation of processing
  • OBJECTION - Object to processing based on legitimate interests

To exercise these rights, contact us through your account settings or email. We will respond within 30 days.

8. POLICY UPDATES

This Privacy Policy may be updated periodically. Material changes will be communicated through:

  • Email notification to registered users
  • Posted notices on our website
  • Updated policy effective date

Continued use of services after policy updates constitutes acceptance of the revised terms.

EXERCISE YOUR DATA RIGHTS

To request access to, correction, or deletion of your personal data, or to exercise any other rights described in this policy, please visit your account settings or contact our support team.

MANAGE YOUR DATA
UCI UNIFIED CITIZEN ID
SYSTEMS ONLINE
LEGAL
Terms of Service Privacy Policy Security
© 2024 UCI · Unified Citizen Identification

UCI is a free and independent identity provider built to unify authentication between Star Citizen fan sites. UCI is not affiliated with or endorsed by any Star Citizen organization.

This is an unofficial Star Citizen fansite, not affiliated with Cloud Imperium Games or Roberts Space Industries. All content on this site not authored by its host or users are property of their respective owners.