Last updated: September 30, 2026
Untanglr is two things: a Salesforce managed package that analyses metadata inside your org, and a website (getuntanglr.com) that sells and manages licences for that package. The two handle very different data, so we keep them apart below.
Once installed, Untanglr reads how your org is built. The Flow Scanner reads your Flows: elements, loops, DML, Get Records, subflows, entry criteria, API versions and trigger context. Field X-Ray reads where fields are used: Flows, Apex classes and triggers, validation rules, page layouts and Lightning pages, list views, matching rules, formula fields and field level security, and, in the optional deep scan, report and email template definitions.
The package does not read, copy or transmit business records (Accounts, Opportunities, Cases, or any other data your org stores). A report is read as a definition, its columns and filters, never as rows of data. To read metadata, the package calls your own org's API. It makes no call to Untanglr's servers or to anyone else. The analysis, the dashboard and any exported report are generated and stored inside your Salesforce org, under your org's own security model.
Scheduled scan summaries are sent by your Salesforce org itself, to the recipients you choose in the package. They don't go through us.
The licence is checked inside your org too. An admin enters a key generated on getuntanglr.com, and the package verifies its signature with a public key that ships inside it. Nothing is sent to us to do that.
getuntanglr.com collects data at four points: your account, your billing, your licences, and our emails to you.
We rely on a small number of subprocessors to run the service. Each only sees the data it needs to do its job.
None of these providers are permitted to use your data for their own purposes.
The website keeps very little in your browser:
Page visits are counted with Vercel Web Analytics, which uses no cookies and does not follow you across other sites. We don't use advertising cookies, third party trackers, or cross site analytics pixels.
We keep account, billing and licence records for as long as your account is active, and for a reasonable period after that to meet accounting and legal obligations (typically tied to tax and financial record keeping requirements).
You can ask us to access, correct, export or delete the personal data we hold about you at any time by emailing support@getuntanglr.com. We'll respond within a reasonable timeframe and confirm once it's done.
If you're in the European Union, this reflects the rights you have under the GDPR (access, rectification, erasure, portability, and the right to object). If you're in Canada, this reflects the rights you have under PIPEDA regarding access to and correction of your personal information. In both cases, the same email address handles the request.
How the package itself protects your org is described on the security and data page.
If we materially change how we collect or use data, we'll update this page and the "last updated" date at the top. For significant changes, we'll also email active account holders.
Questions about this policy, or a request about your data? Email support@getuntanglr.com.