UniDraft
Topic ideasBlogPrivacyTermsLog in
← Back to UniDraft
Legal

Privacy Policy

Effective 9 September 2026

UniDraft helps you turn your own verified academic work into a structured, submission-ready document. This page explains, in plain language, what we collect to do that, why, and what say you have over it. It applies to every UniDraft account: student, university contributor, and admin.

On this page

  1. 1. Who we are
  2. 2. What we collect
  3. 3. Why we collect it
  4. 4. Who we share it with
  5. 5. Reference documents & department learning
  6. 6. How long we keep it
  7. 7. Your rights
  8. 8. Security
  9. 9. International transfer
  10. 10. Age requirement
  11. 11. Changes to this policy
  12. 12. Contact

1. Who we are

UniDraft (unidraft-xi.vercel.app) is the data controller for the personal data described below. For any privacy question or request, contact support@unidraft.ng.

2. What we collect

CategoryExamples
Account identityFull name, email address, password (stored as a salted hash, never in plain text), university, department, and role.
Academic intake answersYour project topic, workplace or study setting, methods, results, references, and preliminary-page details (supervisor name, dedication, acknowledgements) — whatever the guided questionnaire asks for your specific document type.
Uploaded filesResults documents, evidence images, and any supervisor-corrected DOCX you attach when requesting a correction.
Generated outputThe structured document content and rendered DOCX/PDF files UniDraft produces for you, and every prior version if you request a correction.
Payment recordsTransaction status and reference from our payment processor (Flutterwave). We do not receive or store your card or bank details — Flutterwave handles that directly.
Usage & support dataLogin sessions, AI generation job history, support messages you send us, and admin action logs (for accounts with review permissions).

3. Why we collect it

  • To provide the service you asked for — generating, rendering, and correcting your document is not possible without your verified answers and files. This is necessary to perform our contract with you.
  • To process payment for a document package or a correction round.
  • To prevent abuse and protect accounts — for example, detecting unusual login activity or fraudulent correction requests.
  • To improve document quality — for example, learning a department’s confirmed formatting preferences so the next student’s form is pre-filled correctly (see section 5).
  • To provide support when you contact us.

4. Who we share it with

We do not sell your data. We share it only with the processors that keep UniDraft running, each acting under our instructions and only for the purpose stated:

  • OpenAI — processes your confirmed academic content to draft and structure your document.
  • Vercel — hosts the application and stores uploaded files (results documents, evidence images) in private, access-controlled storage.
  • Neon — hosts our Postgres database.
  • Railway — runs the background service that dispatches document-generation jobs.
  • Flutterwave — processes payments on our behalf.
  • Sentry — receives technical error reports to help us fix bugs; these are diagnostic, not your document content.

We disclose data beyond this list only if required by law, or with your explicit consent.

5. Reference documents & department learning

When a university contributor uploads an approved past project as a reference, UniDraft may analyze its structure — chapter order, section purposes, formatting conventions — to help draft outlines for future students in that department. We do not copy another student’s wording, results, or personal details into your document; every reference document’s actual content stays scoped to drafting the structural template only, and your own document is built exclusively from your own confirmed evidence.

Similarly, if you confirm formatting preferences (fonts, margins, reference style) for your own project, that choice may become the pre-filled default offered to the next student in your department for the same document type — again, only the formatting choice, never your personal or academic content.

6. How long we keep it

We keep your account and project data for as long as your account is active, plus a limited period afterward to handle disputes, refunds, or legal obligations. If you ask us to delete your account, we will delete or anonymize your personal data within a reasonable period, except where we are legally required to retain payment records.

7. Your rights

Under Nigeria’s Data Protection Act and NDPR, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Request deletion of your data, subject to our legal retention obligations;
  • Object to or restrict certain processing;
  • Receive a copy of your data in a portable format;
  • Lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your rights have been violated.

To exercise any of these, email support@unidraft.ng.

8. Security

Passwords are stored as salted hashes, never in plain text. Uploaded files are stored with private, access-controlled links rather than public URLs. Access to admin functions is role-restricted and every review or correction action is logged. No system is perfectly secure, and we continuously work to improve these protections.

If a breach occurs that is likely to affect your rights or freedoms, we will notify the Nigeria Data Protection Commission (NDPC) without undue delay, and notify you directly where the breach poses a meaningful risk to you, describing what happened, the data involved, and the steps we are taking in response.

9. International transfer

Some of our processors (including OpenAI and Vercel) operate infrastructure outside Nigeria. Where your data is transferred internationally, we rely on those providers’ own data-protection safeguards and contractual commitments to keep it protected to a standard consistent with the NDPR.

10. Age requirement

UniDraft is intended for tertiary-level students capable of entering a binding agreement in their jurisdiction. We do not knowingly collect data from children under the age required by Nigerian law to consent to this kind of service.

11. Changes to this policy

We may update this policy as the service changes. We will update the effective date above, and for material changes we will make reasonable efforts to notify you directly.

12. Contact

Questions, requests, or complaints about this policy: support@unidraft.ng.

UniDraft

Academic documents, shaped by verified work and institutional rules.

© 2026 UniDraft