The package reads how your org is built: Flows, Apex classes and triggers, validation rules, page layouts and Lightning pages, list views, matching rules, formula fields, field level security and, in the deep scan, report and email template definitions.
It never queries a business record. A report is read as a definition, its columns and filters, never as a row of data. No Account, Contact, Opportunity or anything else your users typed in is read.
To read your metadata, the package only talks to your own org. It sends nothing to Untanglr or to anyone else. Scores, findings and exported reports are stored inside your org, under its own sharing and permissions.
Untanglr follows your org's own sharing rules and field permissions: a scan sees exactly what the person who starts it is allowed to see, and no more. Access is granted through one permission set, Untanglr Admin, that you assign yourself.
Your licence key carries its own proof that it came from us, and the package checks that proof by itself, inside your org, with no connection to us. The key only works for your production org, and names an active user of that org.
Your account (your email, and your name if you give it), the org domains and admin emails your keys are issued for, the keys themselves, and your billing records. No scan result, no metadata, no record data.
Card details go straight to Stripe and never reach us. Your account data can only be read by our own service, payments are confirmed directly with Stripe, and sign in and checkout are protected against repeated attempts. The privacy policy lists the providers involved and your rights over your data.
Found something that looks wrong? Write to support@getuntanglr.com with the details. We read every report and reply to each one.