This page explains what Untanglr collects, why, and what never leaves your Salesforce org. If anything here is unclear, email us at support@getuntanglr.com and we'll clarify or fix it.
Untanglr is two things: a Salesforce managed package that scans Flow metadata inside your org, and a website (getuntanglr.com) that sells and manages licenses for that package. The two collect very different data, and we keep them separate below.
Once installed, Untanglr scans Flow metadata already present in your org: elements, loops, DML statements, Get Records calls, subflows, entry criteria, API versions and trigger context. It calculates a complexity and risk score from that metadata and stores the resulting analysis (scores, object aggregates, recommendations) in custom objects inside your own org.
The package does not read, copy or transmit business records (Accounts, Opportunities, Cases, or any other data your org stores). It makes no external callouts to Untanglr's servers as part of a scan. The analysis, the dashboard and any exported report are generated and stored entirely inside your Salesforce org, under your org's own security model.
The only exception is the license itself: to activate the package, an org admin enters a license key that was generated on getuntanglr.com. Validating that key does not involve sending Flow or business data anywhere.
getuntanglr.com collects data at three points: your account, your billing, and your license.
If you fill out the FlowDebt audit request form, we collect your name, work email, company, org size and any message you write. We use this only to respond to your request, prepare a quote, and follow up on the engagement. We don't add you to a marketing list from this form alone.
We rely on a small number of subprocessors to run the service. Each only sees the data it needs to do its job.
None of these providers are permitted to use your data for their own purposes.
The website uses only the cookies needed to keep you signed in (set by Supabase auth) and a lightweight local preference for your chosen display currency. We don't use advertising cookies, third-party trackers, or cross-site analytics pixels.
We keep account, billing and license records for as long as your account is active, and for a reasonable period after that to meet accounting and legal obligations (typically tied to tax and financial record-keeping requirements). Audit request form submissions are kept only as long as needed to handle the request and any resulting engagement.
You can ask us to access, correct, export or delete the personal data we hold about you at any time by emailing support@getuntanglr.com. We'll respond within a reasonable timeframe and confirm once it's done.
If you're in the European Union, this reflects the rights you have under the GDPR (access, rectification, erasure, portability, and the right to object). If you're in Canada, this reflects the rights you have under PIPEDA regarding access to and correction of your personal information. In both cases, the same email address handles the request.
If we materially change how we collect or use data, we'll update this page and update the "last updated" date at the top. For significant changes, we'll also email active account holders.
Questions about this policy, or a request about your data? Email support@getuntanglr.com.