Privacy Policy
Version 1.0 - September 7, 2026. This policy explains what the Login with U services (accounts.u.cash, developers.u.cash) process and why. It covers two relationships: U Account holders who sign in to third-party applications, and developers who use the developer Services.
1. The short version
- What a third-party application learns about you is exactly what you approved on the consent screen - and nothing else.
- No application can move your money without showing you a payment screen and getting your fresh MFA-confirmed approval for that exact amount.
- You can see and revoke every application's access at any time from your U Account.
2. What we process and why
| Identity claims | Your email address and verification status (email scope) and your name, username, profile picture URL, language (profile scope). Released only to the application you approved, only for the scopes you granted. Purpose: authentication you requested. |
| Balance information | Your U Balance amounts, released only to applications you granted the balance scope to, read-only. Purpose: showing you what a payment would leave behind. |
| Payment records | Each payment you approve: amount, application, description, timestamp, and the resulting ledger entry. Purpose: executing and recording your transaction; the record appears in your own account history. |
| Consent and grant records | Which applications you approved, for which scopes, when. Purpose: remembering your choices so you are asked once, and powering your revoke controls. |
| Security and audit records | Login events, consent decisions, payment approvals, MFA challenges, rate-limit events, with IP and device-derived metadata. Purpose: fraud prevention, abuse detection, and the security of your account. Retention follows the U Account security policy. |
| Developer account data | For developers: your U Account identity, your registered applications, redirect domains, verification tokens, and change history. Purpose: operating the developer portal. |
3. What we never do
- We do not sell your data, and we do not share it for advertising.
- We do not release your balances, transactions, or any claim to an application without your explicit, per-purpose consent.
- We do not give applications any ability to spend without your per-payment confirmation.
4. Retention
- Authorization codes: 120 seconds. Access tokens: 1 hour. Payment confirmation codes: 10 minutes.
- Consent records: until you revoke them (plus 90 days for integrity).
- Payment and ledger records: retained as financial records; you can see them in your account history.
- Logout-token and receipt delivery records: up to 30 days.
- Security and audit records: per the U Account security policy.
5. Your rights and controls
- Review and revoke any application's access at any time in your U Account. Revocation immediately kills outstanding tokens and pending payment requests for that application.
- Decline any consent screen or any payment. Declining a payment returns an error to the application and moves nothing.
- Export and correction rights over your U Account data are handled through the U Account privacy channels.
6. Third parties involved in a sign-in
- The application you signed in to becomes an independent controller of the claims you approved. Its privacy policy (linked from its consent screen when registered) governs what it does next. Complaints about an application's data use should go to the application; we investigate misuse of our Services through U.CASH support.
- Infrastructure providers (for example our CDN and DNS providers) process connection metadata to deliver the service. No identity claims are shared with them beyond what operating the network requires.
7. Security
- Tokens are short-lived and single-purpose; ID tokens are signed and must be verified by applications; payment confirmation codes are bound to the exact approved transaction.
- Payments require multi-factor authentication fresh at the moment of approval, on every single payment.
- Client secrets are stored only as salted hashes; even we cannot read them back.
8. Children
The Services are not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly process their data. If we learn we have, we will delete it.
9. Changes and contact
We will note material changes here with a new effective date. Questions or requests: U.CASH support.