← Union Ally

Privacy Policy

Effective August 26, 2026

The short version

What matters most

The rest of this page explains the details.

1. Who we are

Union Ally is operated by Oxvian Group LLC ("Union Ally", "we", "us"), based in Florida, United States. This policy explains what we collect when you use the Union Ally app at myunionally.com, why we collect it, and how it is protected.

If you have questions about anything here, write to support@myunionally.com.

2. What we collect

Most of what we hold is information you enter or upload yourself. We also receive some information automatically or from providers: standard technical data when you use the app (such as IP address, browser type, and timestamps in server logs), your name, email, and profile picture from Google if you sign in with Google, and your subscription status from Stripe if you subscribe. We do not buy data about you from anyone.

CategoryWhat it includes
Account Your email address and password. Passwords are stored as a cryptographic hash — we never see or store the password itself. If you sign in with Google, we receive your name, email address, and profile picture from Google instead.
Profile Name, job classification, hire date, full-time seniority date, hourly rate, facility, city, state, Local number, which supplement covers you, your employer entity, and whether you are on the 9.5 list.
Incidents The incident type, the date and time it happened, and your notes.
Witnesses Names you add to an incident. Names only — we do not collect contact details for witnesses.
Evidence Photos, voice notes, documents, and signed grievance forms you upload. Files are capped at 25 MB each.
Grievances Grievance number, title, description, the contract articles cited, status, step, outcome, and the dates it was filed and closed.
Route logs Start time, ORION projected return, planned and actual stops, package counts, actual return time, weather conditions, temperature, and your notes.
Vacation weeks The weeks you have selected.
Payment Your subscription status and billing period. Card payments are handled by Stripe — we never see or store your full card number. Stripe gives us a customer reference, the last four digits, and whether a payment succeeded.
Contract questions The text of questions you ask in "Ask the Contract". See section 4.

3. How your information is protected

These are the actual technical controls in place, not aspirations:

No system is perfect, and we will not pretend otherwise. But the design principle is that a mistake in the app should not be able to expose one member's records to another.

If we determine that a security incident requires notice under applicable law, we will notify you as the law requires.

4. AI features

Several features use Anthropic's Claude AI to generate their output: Ask the Contract, Meeting Prep, and the Grievance Builder — both the suggested articles and the drafted grievance — plus any AI feature we add later. Anthropic processes what we send under its commercial terms; by default it does not use API content to train its models.

What gets sent depends on the feature:

Your uploaded files — photos, voice notes, documents, signed forms — are never sent to the AI provider at all. The witness names you log in the witness field are never sent either; where a draft needs to refer to a witness, the AI sees only "Witness 1". Your route logs never leave, and the notes you write on incidents and grievances leave only when you type them into an AI feature or attach them to one yourself. A note travels exactly as you wrote it — so if you typed a name inside a note, that name goes with it. The one thing sent without an explicit attach is the Ask the Contract snapshot described above — grievance titles, cited articles and steps, and recent incident types — never notes, never files, never the names you logged in the witness field.

Because what you attach does leave our systems, we suggest a habit: describe the situation, not the people. "Can a supervisor ride with me without notice?" gets you the same answer as a question naming your supervisor, without the name traveling anywhere.

5. Who we share information with

We do not sell your information, and we do not share it for advertising. We use a small number of service providers to run the app:

ProviderWhat they handle
SupabaseDatabase, authentication, and file storage (United States).
VercelServes the app's web pages.
AnthropicGenerates output for the AI features — Ask the Contract, Meeting Prep, and the Grievance Builder — from the text and linked notes you submit to them and the profile and record details described in section 4.
ResendSends account emails such as confirmations and password resets.
StripeProcesses subscription payments. Stripe handles your card details directly under its own privacy policy.
GoogleOnly if you choose "Continue with Google" — Google confirms your identity and sends us your name, email, and profile picture.
Open-MeteoLooks up the weather for the city in your profile when you tap auto-fill on a route log. The request goes from your device, so Open-Meteo receives a city name, a date, and your IP address — not your identity and none of your records.

We may also use privacy-preserving analytics to count page visits and understand which features are used. Any such analytics measure the app as a whole and are never tied to your grievances, incidents, or evidence.

6. Legal requests

We think you deserve a straight answer on this one, because it is the question a member documenting discipline should be asking.

We will not hand your records to your employer. An employer asking us for a member's data gets nothing.

We can be compelled by a valid subpoena, court order, or other lawful legal process. If that happens, we will produce only what we are legally required to produce, and we will notify you before doing so unless the law forbids us from telling you.

Deleting what you no longer need is still meaningful protection: it reduces what exists to be produced, though copies can remain in backups for up to 90 days after deletion.

7. How long we keep things, and how to delete them

We keep your information while your account is open, because the point of the app is to hold a record over time — a grievance filed today may matter two years from now.

You can delete individual incidents, evidence files, grievances, and route logs inside the app at any time. Deleting an incident deletes its files, unless a file is also attached to a grievance, in which case it stays with the grievance.

To delete your entire account, email support@myunionally.com from the address on your account. We will delete your account, your records, and your uploaded files from our active systems within 30 days and confirm when it is done. Backups are overwritten on a rolling basis and clear within 90 days. Narrow exceptions can survive deletion: billing records we must keep for tax and accounting, records tied to an active legal obligation, and minimal logs kept for security.

8. Your choices

Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act. Write to us and we will honor them.

9. Age

Union Ally is built for working union members and is not intended for anyone under 18. We do not knowingly collect information from children.

10. Changes to this policy

If we change how we handle your information in a way that matters, we will update this page and change the effective date at the top. For significant changes we will also notify you in the app or by email.

11. Contact

Oxvian Group LLC · Florida, United States
support@myunionally.com