Legal

API & OAuth 2.0 Usage Policy

Service: UniClover.app & UniClover Application
Operator: EWS TECHNOLOGY LTD
Effective date: 2026-02-21
Last updated: 2026-03-24
EWS TECHNOLOGY LTD
86-90 Paul Street, London, EC2A 4NE, United Kingdom, 3rd floor
Company Number: 16299589
D-U-N-S® Number: 233593534
Email: admin@ewstechnology.com
Website: ewstechnology.com
Summary: UniClover uses official OAuth mechanisms only, does not request passwords, one-time passcodes, or recovery credentials, limits scopes and redirect URIs to approved values, and uses OAuth data only for authentication, account linking, security, and legitimate Service functionality.
OAuth safety: We use official Roblox authorization, token, and userinfo endpoints, PKCE (S256), a single-use state value, approved redirect URIs under UniClover control, and minimum necessary scopes. Authorization responses that appear tampered with, mismatched, expired, replayed, or inconsistent with the expected client, state, or redirect URI may be rejected.
Important: Complete sign-in only on official Roblox authorization screens and official UniClover pages or app callbacks. UniClover does not ask you to type your Roblox password into a custom form or to send authorization codes, access tokens, or refresh tokens to another user, moderator, or support agent.
Contents
  1. Independent Service
  2. Purpose of OAuth Usage
  3. How the OAuth Flow Works
  4. Data Received via OAuth
  5. Data Usage Restrictions
  6. Token and Session Security
  7. User Control
  8. Prohibited API Uses
  9. Fair Competition Enforcement
  10. Compliance with Platform Policies
  11. Service Providers
  12. Changes to This Policy
  13. Contact Information

1) Independent Service — No Roblox Affiliation

UniClover is an independent third-party service.

UniClover is not affiliated with, endorsed by, or sponsored by Roblox Corporation. All Roblox names, trademarks, services, and related assets belong to their respective owners. Where Roblox authentication is used, it is performed only through official Roblox-controlled systems.

2) Purpose of OAuth Usage

Roblox OAuth 2.0 is used exclusively to:

OAuth authorization occurs only after explicit user action and Roblox-controlled consent. By default, the Service requests only openid profile, does not ask for your Roblox password, and does not request broader scopes unless a specific Service feature requires them and the user is clearly informed.

3) How the OAuth Flow Works

The UniClover OAuth flow is designed to be narrow, transparent, and resistant to abuse.

If a response appears tampered with, replayed, expired, mismatched, or otherwise inconsistent with the expected flow, UniClover may invalidate the transaction, require a fresh sign-in, or refuse to continue the login process.

4) Data Received via OAuth

Depending on permissions granted, UniClover may receive:

No Roblox password, password-equivalent credential, or recovery secret is collected by the Service. On the website, access tokens are used only to complete the sign-in flow and are then discarded. Some official client apps may retain tokens locally on the device, with access controls, so the session can continue or be refreshed.

5) Data Usage Restrictions

Data obtained through OAuth is used solely for legitimate Service operation, including authentication, session management, security, anti-fraud controls, user-requested functionality, and compliance with legal obligations.

OAuth data is not used for:

6) Token and Session Security

We apply strict technical and operational controls to OAuth tokens and linked-session data.

Where appropriate, UniClover may invalidate, repeat, or refuse a login flow if the response appears inconsistent with the expected state, verifier, redirect URI, client surface, or account-linking context.

7) User Control

Users may revoke access at any time through their Roblox account settings or by disconnecting the account inside UniClover where such a control is available. Revocation, expiration, logout, or removal of local authentication state may disable certain Service features and may require the user to sign in again.

8) Prohibited API Uses

UniClover strictly prohibits misuse of APIs.

The Service does not:

9) Fair Competition Enforcement

API access is not used to manipulate gameplay, rankings, rewards, or competition outcomes. Automation, abuse, or technical misuse that provides an unfair advantage is strictly prohibited.

10) Compliance with Platform Policies

UniClover is designed to comply with:

11) Service Providers

We may use trusted infrastructure, hosting, security, and backend support providers to operate the Service. Such providers process data only on our behalf, for defined purposes, and under appropriate safeguards.

12) Changes to This Policy

We may update this policy from time to time to reflect technical, operational, security, or legal changes. The revised version becomes effective when posted, unless a different effective date is stated.

13) Contact Information

EWS TECHNOLOGY LTD
86-90 Paul Street, London, EC2A 4NE, United Kingdom, 3rd floor
Company Number: 16299589
D-U-N-S® Number: 233593534
Email: admin@ewstechnology.com
Website: ewstechnology.com