Last updated: July 10, 2026

Privacy Policy

This page explains what Untanglr collects, why, and what never leaves your Salesforce org. If anything here is unclear, email us at support@getuntanglr.com and we'll clarify or fix it.

1. The short version

Untanglr is two things: a Salesforce managed package that scans Flow metadata inside your org, and a website (getuntanglr.com) that sells and manages licenses for that package. The two collect very different data, and we keep them separate below.

  • The package reads Flow metadata only. No customer records, no callouts, nothing leaves your org.
  • The website collects the account, billing and license data needed to issue and manage a license key.
  • We don't sell data, we don't run ads, and we don't track you across other sites.

2. What the Salesforce package does with your org's data

Once installed, Untanglr scans Flow metadata already present in your org: elements, loops, DML statements, Get Records calls, subflows, entry criteria, API versions and trigger context. It calculates a complexity and risk score from that metadata and stores the resulting analysis (scores, object aggregates, recommendations) in custom objects inside your own org.

The package does not read, copy or transmit business records (Accounts, Opportunities, Cases, or any other data your org stores). It makes no external callouts to Untanglr's servers as part of a scan. The analysis, the dashboard and any exported report are generated and stored entirely inside your Salesforce org, under your org's own security model.

The only exception is the license itself: to activate the package, an org admin enters a license key that was generated on getuntanglr.com. Validating that key does not involve sending Flow or business data anywhere.

3. What the website collects

getuntanglr.com collects data at three points: your account, your billing, and your license.

  • Account. When you sign up or log in, we collect the email address you provide. Authentication is handled by Supabase, via a password you set. We don't require a name, phone number or address to create an account.
  • Billing. Payments are processed by Stripe. Stripe collects and stores your card details directly; we never see or store your full card number. We keep a record of the transaction (plan purchased, amount, date, currency) associated with your account so we can show you your billing history and issue receipts.
  • License metadata. To generate an activation key, we ask for the admin email and the Salesforce My Domain of the org the key is for. This is the minimum needed to bind a key to a specific org and to contact the right person about it. We do not need, and do not ask for, any business data from that org.
  • Transactional email. We send account, billing and license emails (password reset links, receipts, scan digests if you subscribe to them) through Resend, from billing@send.getuntanglr.com. These are operational emails tied to your use of the product, not marketing.

4. The audit request form (/audit)

If you fill out the FlowDebt audit request form, we collect your name, work email, company, org size and any message you write. We use this only to respond to your request, prepare a quote, and follow up on the engagement. We don't add you to a marketing list from this form alone.

5. Who processes data on our behalf

We rely on a small number of subprocessors to run the service. Each only sees the data it needs to do its job.

  • Supabase: database and authentication (account, license and billing records).
  • Stripe: payment processing (card details, subscription and purchase records).
  • Resend: transactional email delivery.
  • Vercel: website hosting and infrastructure.

None of these providers are permitted to use your data for their own purposes.

6. Cookies

The website uses only the cookies needed to keep you signed in (set by Supabase auth) and a lightweight local preference for your chosen display currency. We don't use advertising cookies, third-party trackers, or cross-site analytics pixels.

7. What we don't do

  • We don't sell, rent or trade your data to anyone.
  • We don't run advertising, and we don't share your data with ad networks.
  • We don't access your Salesforce org's business records, ever.

8. How long we keep data

We keep account, billing and license records for as long as your account is active, and for a reasonable period after that to meet accounting and legal obligations (typically tied to tax and financial record-keeping requirements). Audit request form submissions are kept only as long as needed to handle the request and any resulting engagement.

9. Your rights

You can ask us to access, correct, export or delete the personal data we hold about you at any time by emailing support@getuntanglr.com. We'll respond within a reasonable timeframe and confirm once it's done.

If you're in the European Union, this reflects the rights you have under the GDPR (access, rectification, erasure, portability, and the right to object). If you're in Canada, this reflects the rights you have under PIPEDA regarding access to and correction of your personal information. In both cases, the same email address handles the request.

10. Changes to this policy

If we materially change how we collect or use data, we'll update this page and update the "last updated" date at the top. For significant changes, we'll also email active account holders.

11. Contact

Questions about this policy, or a request about your data? Email support@getuntanglr.com.