# Privacy policy

A short account of what happens to your data on this site — no advertising, no tracking.

Canonical: https://uanear.com/en/privacy · Language: en · Updated: 2026-10-01

## 1. Controller and contact

The controller of the personal data processed on uanear.com is Henry Moskovych, a private individual established in Slovakia. Write to hi@uanear.com about anything to do with data protection; the same person answers. There is no data protection officer, because the law does not require the operator to appoint one.

## 2. In short

There is no advertising here, we do not follow you across other sites, and we neither sell your data nor pass it on for marketing. There is one analytics tool: PostHog counts the pages that get opened and a handful of actions — a listing added, a review left — collects none of your clicks and stores nothing in your browser. We use cookies to keep the site working and remember display choices, not for advertising or analytics. What is public is what you publish yourself: reviews, community requests and replies under the name on your account, and the details of a business you manage. Your email address, phone number, orders, ownership claims and support conversations are not public.

## 3. Visiting the site

The site is hosted and delivered by Cloudflare; on every request it processes your IP address, the time, the address of the page and your browser details, and keeps them briefly for security and diagnostics. On your first visit it derives the country you are connecting from out of the IP address, so that the directory opens in the right country; we do not store the address itself for that.

The site uses the following cookies of its own:

- uanear_locale — the interface language you chose.
- uanear_country — the country of the directory you are looking at.
- uanear_signup_locale — the language you began signing up in, so that the confirmation email arrives in it; written on every sign-up attempt and on every Google sign-in.
- ua-translate — your choice of whether a business description is shown translated.

After you sign in, the Better Auth session cookies join them; the section on accounts describes those. For our team — moderators and administrators — the site also remembers how the admin sidebar is arranged, in two cookies: dashboard-sidebar-admin (the collapsed sidebar) and uanear_admin_nav (the folded menu sections). Six forms — sign-in and sign-up, the contact form, a reply in a conversation, reporting a listing or an event, a guide suggestion, and subscribing to the weekend roundup — run Cloudflare Turnstile, which tells a person from a script and sets its own technical cookies to do so. Separately, Cloudflare can show a check of its own during ordinary browsing of the directory — if too many requests arrive from your connection one after another and it looks like the work of a script. The page then pauses on the check for a few seconds, and Cloudflare stores a technical cookie so as not to ask a second time. That is what keeps the directory reachable during a flood of automated requests.

Two of the free tools keep something in your browser rather than with us: the 183-day counter holds the stays you add under the key uanear:residency-stays, and the "First 90 days" checklist holds your ticks under the key uanear:first90. It is only what you typed on the page yourself; it is not sent to us or to anyone else, and it disappears as soon as you clear your browser data.

The maps in the directory and the small map on a business page load their tiles straight from the servers of the OpenStreetMap Foundation, so your IP address reaches it. When a search finds nothing, we store only the normalised text of the query, the city and how often it was repeated — no account, no IP address; those queries are publicly visible on the Community requests page. For each listing we count views and contacts as daily numbers: we count actions, not people, with no sessions and no IP addresses. Links in the weekend roundup email are counted the same way: for each one, only how many times it was opened, never who opened it. The review form keeps what you have written in the browser tab’s own memory while you sign in, so it is not lost on the way. The order form does the same: under the key uanear:order-draft it keeps the time you picked, your note and your phone number until you send them. Neither ever reaches us, and both disappear when you close the tab.

We also count how often a handful of specific things happen on the site: someone adding a listing, leaving a review, posting a request, placing an order, publishing a job offer, claiming a listing, writing to us through the contact form, creating an account, signing in to it or saving an event to their list. PostHog does that counting, and it also counts the pages that get opened: each time you open a page it receives that page’s address — but not what stands in it after the question mark, so neither the text you searched for nor the code from an email reaches it. When you leave a page it notes that too, so how long the page was open is visible; how far down it you scrolled is not measured. It is set up to leave nothing in your browser — no cookie, and no record that outlives the closed tab: the pages you opened in one visit it sees together, but it can no longer tie them to your next visit. It does not collect your clicks, does not build heatmaps and does not record video of your screen. That is why this site still manages without a cookie consent box.

Your saved events list depends on whether you are signed in. Without signing in, it is stored only in your browser under the key uanear:saved-events: nothing leaves your device besides the IDs of those events, needed to show their current details. If you are signed in, the list is stored in your account, and whatever built up in the browser before you signed in is merged into it when you sign in. Remove saved events with the heart button or by clearing your browser data.

We use Sentry to find and fix technical errors. It receives the error text, its location in the code, and technical details about the browser or server. We have disabled screen recording, session and action tracking, and automatic collection of account data; request headers, cookies, bodies, and page URL parameters are excluded from reports.

If you save places without an account, uanear:saved-places stores their identifiers in your browser. On sign-in, accepted saves are merged into your account. We store private list names, membership and followed cities, businesses and organizers to provide the personalization you request. Following does not subscribe you to email.

## 4. Accounts

If you create an account we keep your email address, your name, your interface language, your role, whether the address has been verified, and your choice of whether we send you emails with tips about your business listing. We do not keep the password itself — only a cryptographic hash with a salt unique to it, which cannot be read back. At sign-up we note once the two-letter code of the country you were connecting from; it shows us where to open the directory next, is displayed nowhere and is never updated.

If you sign in with Google, your browser talks to Google directly during that step and Google sees your IP address; it returns your email address, your name and an account identifier to us. We never receive your Google password, and we do not store the profile picture.

Every signed-in session has a record holding your IP address and your browser details; it lives as long as the session does, which is at most 30 days. The session cookie is encrypted, out of reach of JavaScript, and travels only over a secure connection. The address-verification link is valid for 24 hours and the password-reset link for 1 hour; both are single-use, and only a fingerprint of them is stored in the database.

To protect accounts against password guessing we keep two technical records. Failed sign-in and sign-up attempts are written under a salted cryptographic hash of the address or the IP, from which the original value cannot be recovered, and they are deleted within a day. The rate limiter additionally keeps a short-lived technical record keyed by your IP address and the request path — it is not hashed, it is kept for at most the one-hour window, and the nightly cleanup removes it.

Account data is processed so that the account works, and it is kept while the account exists. The Account page lets you download a copy of your data as JSON at any time, and delete the account and everything attached to it for good.

When a team member whose role allows it connects an AI app through MCP and OAuth, we store app details, the address to which access is authorized, permissions, the account identifier, connection dates and technical fingerprints of access credentials. We do not share the password with the app. You can view and revoke connections on the “Connect your AI assistant” page.

Members of the team who moderate the site get an email in the morning listing the tasks waiting for them in the admin, only on days when there are any. You can turn it off on the Account page or with the link in the email itself. For this we additionally store only your choice of whether to send it and the date of the last such email.

## 5. What you post

Reviews, community requests and the replies to them are public and appear under the name on your account. On a review you may hide your name: the listing then shows it without one, but for us it stays tied to your account. A review also carries a hashed fingerprint of the IP address, not the address itself, and only as protection against abuse. Reporting a listing, suggesting a missing category, and suggesting or correcting a guide are not public — only our team sees them. Reviews and requests are published immediately; we take them down when we receive a substantiated report. Everything you added goes when you delete your account.

A job offer you post is public too: the employer name, the city, the text and whichever contact channels you chose to show. The account behind it is never shown. Unlike a review, an offer appears only after a moderator approves it, stays visible for 30 days, and leaves the public pages once it lapses, is closed or is rejected; it remains under “My offers” for as long as the account exists.

## 6. Business listings and their owners

Business listings — name, address, category and contacts — come from owners or from public sources, and a person checks them before they are published. The directory holds registered business and professional activity: companies and sole traders. Company details are not personal data; a sole trader’s details are, and we publish only what concerns their business activity and is supplied by the owner or comes from public registers or public sources — the name, the address where the business operates, the category and the work contacts. We do not create profiles of private individuals as such. Some fields can still concern a particular person — the name of a contact, a mobile number, or a registered office that is also somebody’s home. We process them on the legitimate interest of running a public directory of businesses, and you may object to that at any time or ask for the listing to be removed.

We also store the optional declaration of Ukrainian ownership or founding as part of the business listing. “Ukrainian owned” is optional: you can tick it when adding a business, and its owner can set or clear it in the dashboard. Our editors can correct it. This is a declaration about the business, not proof of independent verification.

A claim asks what role you have in the business, a contact email and phone number, optionally the IČO, and the text explaining how we can verify it; documents can be attached. Neither the claim nor the documents are public — only moderators see them — and they are kept for as long as the listing exists, because they are the record of who manages it.

An owner may connect Telegram to their account; we then store the chat identifier and the username so that alerts have somewhere to arrive. Until an owner does that, we know nothing about their Telegram. The statistics on the owner dashboard are sums of actions per day, not a list of visitors. A business description is machine-translated on request through Cloudflare Workers AI; the text of the description is what is sent, and nothing else.

When a listing becomes yours, we write to you once about what is worth filling in. If after a while it is still missing one of the essentials (a description, opening hours or something that can be ordered), we send one more email. That is the only such reminder: we will not write to you about it again. So that we do not write twice, we note on your ownership claim that the reminder was sent. You can turn both emails off on the Account page or with the link in the email itself; emails about orders, ownership claims and account security arrive either way.

When we remove a listing on request, a short record stays behind saying that this business is not to be published. Without it, the listing would simply come back the next time public sources are processed.

## 7. Orders and bookings

When you order a service or book a time through the directory, we store your name, email address, phone number, note and preferred time. We pass this to the business by email, and if it has Telegram connected an alert arrives there as well — the headline and a link, never your phone number. For the visit itself the business is a separate controller: what it does with your details after that follows its own rules. On our side the order is deleted twelve months after it was last changed.

## 8. The contact form, reports and guide suggestions

The contact form asks for your name, email address, subject and message; if the matter concerns a particular listing, you can add the evidence as text. The conversation gets a private link that keeps working for 30 days after it is closed, so that you can come back to the answers. Only our team reads it; the whole conversation is deleted twelve months after the last message.

A listing can be reported without an account — we store the reason, your note, a hashed fingerprint of the IP address against abuse, and your account if you were signed in. Reports are kept for as long as the listing exists: they are the record of why something happened to it.

A new guide topic, or a correction to one, can also be sent without an account. We store the text of the message and a contact if you give one: it is optional and serves only to clear up details. We do not add an IP fingerprint to a suggestion — Turnstile and rate limiting protect it from abuse instead. A suggestion changes nothing on the site by itself: our editors read it. We delete it twelve months after it was sent, whatever we managed to do with it.

For a submitted event, we store its text, location, dates, public organizer contacts, connection to your account, and editorial decisions. Approved event and organizer details are public. You can attach a poster to an event — one image. As soon as it arrives we convert the file to WebP, and the details hidden in it — the coordinates of where it was taken, the camera model, sometimes a name — disappear. Until a moderator approves the poster, only our team sees it; an approved poster is public. An event title and description written in a language other than Ukrainian are machine-translated with Cloudflare Workers AI, whether they come from a public source or from your submission. Once an event is published, we also machine-translate its text into the site’s other languages with OpenAI, and use the same service to assess how significant the event is: its place on the homepage depends on it. An event we have assessed under our own rule is not sent to OpenAI for assessment.

An event can be reported without an account too — we store the reason, your note, a hashed fingerprint of the IP address against abuse, and your account if you were signed in. These reports are kept for as long as the event exists: they are the record of why something happened to it.

You can subscribe to the weekend roundup without an account. We store your email address, the language you subscribed in, the country and, if you chose one, the city, as well as when we sent you the confirmation email and when you confirmed the subscription. So that you never get the same issue twice, we note which one we sent you last; if you unsubscribe, we record when. The subscription also carries a hashed fingerprint of the IP address, not the IP address itself, and only as protection against abuse. We do not know whether you opened an email or which links in it you followed: we count visits only as a total for each link.

## 9. Purposes and legal bases

Every processing on this site has its own legal basis:

- Running your account, orders and bookings, support conversations and ownership claims — performing the service you asked for; Art. 6(1)(b) GDPR.
- Events you submit and changes to them, their review, the machine translation of text not written in Ukrainian and the translation of a published event into the site’s other languages — performing the service you asked for; Art. 6(1)(b) GDPR.
- The public directory of businesses, including data from public sources and the details of named contacts, as well as the order of events on the homepage together with an automatic assessment of how significant they are — the legitimate interest of running a useful directory and showing the most interesting events first; Art. 6(1)(f) GDPR.
- Reviews, community requests, replies and their review, as well as the review of an event, in case of a report — the legitimate interest of content that can be trusted; Art. 6(1)(f) GDPR.
- Security: Turnstile, rate limiting, fingerprints of failed sign-ins and the IP hashes on reviews and reports — the legitimate interest of protecting the site from abuse; Art. 6(1)(f) GDPR.
- The counters of views, contacts and searches that found nothing — the legitimate interest of knowing what the directory is missing; Art. 6(1)(f) GDPR.
- Counting the pages that get opened and a handful of actions on the site through PostHog — legitimate interest in seeing whether what we build works; Art. 6(1)(f) GDPR.
- Suggestions and corrections to guides — the legitimate interest of keeping practical advice current; Art. 6(1)(f) GDPR.
- Connecting Telegram to an account and machine-translating a description — we do these only when you ask for them yourself; Art. 6(1)(a) GDPR.
- Meeting a legal obligation when one arises — legal obligation; Art. 6(1)(c) GDPR.
- Error diagnosis through Sentry — our legitimate interest in keeping the site working; Article 6(1)(f) GDPR.
- Connecting MCP through OAuth at your request — providing the requested service; Article 6(1)(b) GDPR.
- Emails to the owner of a listing: one about what to fill in when the listing becomes theirs, and one reminder if the essentials are still missing — the legitimate interest of a directory that can actually be used; Art. 6(1)(f) GDPR. You can object to them at any time: turn them off on the Account page or with the link in the email.
- The weekend roundup email — your consent, which you give by pressing the button on the confirmation page; Art. 6(1)(a) GDPR. You can unsubscribe, which withdraws that consent, at any time with the link in every email.
- The morning email to members of the team who moderate the site, listing the tasks waiting for them — the legitimate interest of letting the team know what is waiting for review; Art. 6(1)(f) GDPR. You can object to it at any time: turn it off on the Account page or with the link in the email.

## 10. Recipients and processors

We pass data to nobody for marketing. Only these recipients reach it:

- Cloudflare (United States) — hosting, the database, photo storage, the processing of uploaded images, sending email, Turnstile, the machine translation of descriptions, events and news, and the automatic selection of news; every request passes through it, IP address included. We keep the database and the photographs on servers in the European Union.
- Google (United States) — signing in with Google, the map used to place a pin by hand, the lookup of addresses you type, and looking a business up by its name and city, including when our team fills in a listing (a listing's name is sometimes a specialist's own name); for the sign-in and the map your browser talks to Google directly, while addresses and names are queried from our server.
- PostHog (European Union, Germany) — counting the pages that get opened and a handful of actions on the site; it receives your IP address, the address of the page you opened or that the action came from, the name of the action itself and how long the page was open, and if you are signed in, your account identifier, email address, name and role as well. Technical errors on the page go there too, along with their text.
- Telegram (outside the European Union) — alerts for an owner; it receives the chat identifier, the headline and a link, and only after the owner has connected Telegram themselves.
- OpenStreetMap Foundation (United Kingdom) — the map tiles your browser loads; it receives your IP address and which part of the map you are looking at.
- Photon by komoot (Germany) — address suggestions as you type; it receives the text you write in the address field, and from our server rather than from your browser.
- Nominatim by the OpenStreetMap Foundation (United Kingdom) — the fallback lookup of coordinates for an address; it receives the same address text, again from our server.
- Apify (Czechia) — the tool our team uses to gather listings from public sources; it receives no visitor data.
- OpenAI (United States) — the model our team uses to assess listings gathered from public sources: it receives the business name, city, category, text from its public website and pictures from there. We draft guides with the same model, and it then receives the text of the official authority page the guide is drawn from. We prepare Ukrainian retellings of news the same way, and it then receives the text of the publisher’s public article. The same model translates published events and news into the site’s languages, and for that it receives only their public text: for an event, the title, description, venue, admission details and district; for a news item, the title, summary and retelling. The model also assesses the significance of published events that have not yet ended, so that the homepage can show the most interesting ones first; for that it receives the same public text of the event, plus its city, country and category. Events we have assessed under our own rule are not sent to the model for assessment. When our team adds an event, the model may receive the text of that event’s public page or text a team member pasted in to fill in a draft; it can include the organizer’s public contact details. It receives no visitor data. Super-admins can also use OpenAI to draft anonymous reviews; the model receives the selected business’s public name and description, the requested language and rating. A draft is published only after an administrator reviews and confirms it.
- Our team — the moderators and administrators who review listings, reviews, claims and reports.
- Sentry (Functional Software, Inc., United States) — technical error diagnosis; it receives browser and server error reports. Reports are stored in the EU region in Frankfurt, Germany. The browser sends them directly, so Sentry also sees the IP address during the connection.

- An AI app a team member chooses to connect through MCP — receives their account identifier and query results within their permissions, including drafts, reader suggestions and contact details included in them. The recipient and processing country depend on the chosen app and provider; check its terms and privacy policy before connecting.

## 11. Transfers outside the European Union

Cloudflare, Google and OpenAI are established in the United States. We transfer data to them under the European Commission’s adequacy decision for the EU–US Data Privacy Framework and, alongside it, under standard contractual clauses.

We have set up the database and the photo storage so that Cloudflare keeps them only on servers in the European Union. That governs where the data sits, not where it is processed: the page is served to you by the nearest Cloudflare server, wherever that is, and the same goes for the machine translation of descriptions and the Turnstile check. The grounds described above are therefore still needed.

Alerts leave the European Union for Telegram only when an owner has connected Telegram themselves — a transfer necessary to perform the service they expressly asked for. Map tiles and the fallback lookup of coordinates go to the United Kingdom, which has an adequacy decision of its own. PostHog’s data is held in Germany rather than outside the European Union. The company that runs it is established in the United States, so if it needs access to that data for technical support, that access is itself a transfer — and it happens under the same standard contractual clauses.

We selected the EU region for Sentry error reports. The company is established in the United States; access from outside the EU is governed by Sentry’s data processing terms, including standard contractual clauses.

For MCP, the team member chooses the recipient. The app may process retrieved results outside the EU; its provider determines the processing location and safeguards. Connecting does not extend our agreements with the other services listed above to that provider.

## 12. How long we keep it

We keep nothing longer than we need it for:

- Account data — while the account exists; deleting the account removes it at once.
- The session record with your IP address and browser details — 30 days.
- The address-verification link — 24 hours; the password-reset link — 1 hour.
- Fingerprints of failed sign-ins — at most one day; the rate limiter’s technical record — at most the one-hour window, after which the nightly cleanup removes it.
- Searches that found nothing — 180 days.
- The daily counters of views and contacts on a listing — 400 days.
- Orders and bookings — twelve months after the order was last changed.
- Support conversations and their messages — twelve months after the last message.
- Suggestions and corrections to guides — twelve months from when they were sent.
- Listings, reviews, community requests, ownership claims, reports and removal records — for as long as the listing or the account they belong to exists.
- Old addresses of deleted or merged listings, kept to redirect to the new listing — for as long as the listing the address leads to exists; 180 days if there is no successor.
- Event posters — if a suggestion is rejected or approved without its poster, we delete the submitted poster straight away. When we delete an event, the posters submitted for it go with it, and so does the published one unless another event shows it. A poster that was replaced or removed from an event is not deleted separately.
- Job offers — for as long as the account exists; a published one is publicly visible for 30 days and stays only under “My offers” after that.
- Pages opened and actions on the site counted by PostHog — twelve months.
- An unconfirmed weekend roundup subscription, together with its address — 7 days from the last confirmation email.
- The address of a weekend roundup subscriber — while you are subscribed; after you unsubscribe from all roundups — 30 more days.

Events, proposed changes, and review history are not automatically deleted after a fixed period. A moderator can delete an event permanently — its dates, translations, proposed changes and reports about it then go with it, and it disappears from users’ saved events and lists. When we merge duplicates of one event, the event we keep takes the place of the others in users’ saved events and lists, reports about the others pass to it, and their old addresses lead to it. We retain rejected import identities — and, for deleted events, the event’s link and ID at the source — so later imports cannot republish them. Contact us to request correction or deletion of personal data.

The retention period for Sentry technical reports is determined by our service plan. Deleting a UA Near account does not automatically delete these reports.

- MCP: authorization codes last 10 minutes, access tokens 15 minutes and refresh tokens 30 days. Nightly cleanup removes expired technical records after a one-hour safety margin. Permissions remain separately for each address the app has access to — until disconnection or account deletion; disconnecting ends access for that address immediately. If, however, an administrator switches off MCP access for your role, gives you another role without it or bans the account, we delete all your MCP permissions and tokens; once access is restored, each app has to be allowed again. App registrations without permissions or tokens are cleaned up after 30 days.

Private lists and follows remain until you remove them or delete your account. Account deletion removes these records. Published organizer profiles, offers and announcements may remain public; their account attribution is removed. You can export your lists, follows, managed organizer profiles and authored publisher content from account settings.

## 13. Security and who has access

The connection to the site is encrypted, passwords are kept only as salted hashes, and the session cookie is encrypted. Only our team reaches the administration, and only as far as moderation requires. If an administrator enters a user’s account to sort out a problem, that is recorded together with who it was. We write no passwords, tokens or other secrets into the logs.

## 14. Your rights

The Account page lets you download a copy of your data and delete the account at any time. Beyond that you have the right of access, of rectification and erasure, of restriction of processing, of portability, and the right to object to processing based on a legitimate interest, including the data on a business listing. Write to hi@uanear.com; we answer within 10 working days, and it costs nothing. You may also complain to a supervisory authority: ours is Úrad na ochranu osobných údajov Slovenskej republiky (dataprotection.gov.sk), because that is where the operator is established, but you may go to the authority of the country where you live or work — for the countries this directory covers, those are Úrad na ochranu osobných údajov Slovenskej republiky (dataprotection.gov.sk); Úřad pro ochranu osobních údajů (uoou.gov.cz); Datenschutzbehörde (dsb.gv.at); Nemzeti Adatvédelmi és Információszabadság Hatóság (naih.hu).

## 15. Automated decisions and children

We make no automated decisions with legal or similarly significant effects, and we build no profiles. Turnstile and rate limiting are technical protection against abuse, not decisions about a person; publication, moderation, the verified mark and the quality mark are decided by people. The “Ukrainian spoken” mark is also set automatically, from the language list the business gave us or from its own website; it is not a decision about a person, and a moderator will change it as soon as you tell us it is wrong. “Ukrainian owned” is optional: you can tick it when adding a business, and its owner can set or clear it in the dashboard. Our editors can correct it. This is a declaration about the business, not proof of independent verification. If you clear “Ukrainian owned” and the business has no “Ukrainian spoken” mark, “Verified” is also removed. The quality mark is independent and is not removed by this change. The site is not meant for children under 16, and they should not create an account. If we find that an account belongs to a younger child, we delete it.

## 16. Changes to this policy

We update this policy whenever what we process, or why, changes; the date of the last change is given at the top of the page. Material changes are announced with a notice on the site. The Slovak version is the binding one; the other languages are translations of it.
