Privacy Policy
Effective 2026-08-30 · Umydia is operated by Trellova LLC, California, USA.
1. What we collect
Account data (name, email, org membership), content your organization uploads, engagement events (plays, opens, progress — which we treat as personal data), device tokens if you enable notifications, and standard security logs (IP, timestamps) kept briefly for abuse prevention.
2. How we use it
To run the service: deliver your org's content, remember your position, show your leaders aggregate and individual progress inside your org, send the notifications your org and you allow, and bill the org's owner. We do not sell personal data, run third-party ads, or share data with brokers.
3. Legal bases & processors
We process data to perform our contract with your organization and on legitimate interest for security. Sub-processors are infrastructure providers (edge hosting, storage, payments via Stripe for org owners, push delivery); each is bound by data-processing terms. A current list is available on request.
4. Retention & deletion
Personal data is deleted within 30 days of account deletion (in-app, or see Delete your account). Organization deletion enters a 7-day recoverable hold, then purges org data from our systems. Backups age out on a fixed schedule. Records of access to restricted material are retained for the organization as audit history.
5. Your rights
Access, correction, export and deletion — request in-app or at privacy@umydia.com. California residents: we do not sell or share personal information as defined by the CCPA/CPRA. We honor verifiable requests within statutory windows.
6. Children
Umydia is not directed to children under 13 and we do not knowingly collect their data.
7. Changes
We'll post changes here with a new effective date; material changes are announced in-app to org owners.
UMYDIA