UnspoolCode

Application Privacy Policy

Last updated: 30 July 2026 · Applies to the UnspoolCode application (self-hosted installs today; the planned hosted early-access app,app.unspoolcode.com, once available)

Two modes, described separately below. UnspoolCode ships today as software you install and run yourself, against a local SQLite database or a PostgreSQL database you control — your source code never reaches MetaBinary's infrastructure in that mode. A hosted, multi-tenant early-access version is planned; where this policy describes that hosted app, it is describing our intention for how it will handle data, not a service that is live yet.

1. Controller

The controller for any data MetaBinary Limited does process in connection with UnspoolCode is MetaBinary Limited, a company registered in Ireland (CRO 806119, VAT IE4698974FH), Office 40 — Boxworks, 40–44 Patrick Street, Waterford, X91 X3KF, Ireland. Contact:privacy@unspoolcode.com. As an EU-established controller we are not required to appoint an EU representative, and we have not appointed a Data Protection Officer.

2. Self-hosted installs — today's default

As of this policy's last-updated date, UnspoolCode is distributed as software you install and run on your own infrastructure. Project data — your source code, the parsed dependency graph, dead-code findings, and any migration output — is stored in a local SQLite database file on your machine, or in a PostgreSQL database you provision and control, at your choice. Access to a running instance is controlled by a single shared bearer token you configure; there is no per-user account or password system in this mode. None of this data is transmitted to or stored by MetaBinary in a self-hosted install — we have no access to your codebase, your graph, or your generated output unless you separately send it to us (for example, by emailing us a bug report). If you require this mode for confidentiality, NDA, or export-control reasons, use it rather than the hosted app described below.

3. What the hosted app would process

If and when you use a MetaBinary-hosted instance of UnspoolCode, we expect it to process:

4. Your source code & results — your data

The source code you upload or connect, and the graph, findings, and migration output we produce from it, are yours. We would process them only to provide the service to you. You can export them and delete them at any time (see Your rights). We do not sell your code or analysis output, and we do not share it with other customers — each project's data is isolated to that project.

5. No AI/ML training on your code

We do not use your uploaded source code, your dependency graph, or any migration output to train machine-learning or AI models, and we do not share it with third-party AI providers except where the migration tooling itself calls an LLM on your explicit instruction (for example, an LLM-assisted translation pass that requires you to supply your own API key) — in that case your code is sent only to the provider and for the purpose you configured, not to us, and not for model training on our side. If this ever changes — for example, an opt-in shared-model-training feature — it will be a clearly disclosed, explicit opt-in, described here before it exists, not assumed. Today, no such feature exists.

6. Purposes & lawful basis

PurposeLawful basis
Provide the (self-hosted or, once available, hosted) appPerformance of a contract
Billing & subscription management (if/when paid hosted plans exist)Contract; legal obligation (tax)
Security, abuse prevention, logsLegitimate interests

7. Processors we use

For a self-hosted install, we use no processors — nothing leaves your infrastructure. For the planned hosted app, we intend to use:

Each will be engaged under a data-processing agreement; this page will be kept current as the hosted app is built, and copies of the relevant data-processing terms will be available on request. Where personal data of EEA/UK users would be processed outside the EEA/UK (our application servers are currently US-located), we will rely on the EU–US Data Privacy Framework where the provider is certified, or on the Standard Contractual Clauses, with appropriate supplementary safeguards.

8. Security

For self-hosted installs, access control (the shared bearer token model described in Section 2) and infrastructure security are your responsibility as the operator of the install; we recommend running it behind your own authentication layer (e.g. a reverse proxy or VPN) for any networked deployment. For the planned hosted app, we will publish the concrete security architecture — including how accounts and sessions are protected — before launch ([hosted-app security architecture TBD]) rather than asserting specifics that are not yet built.

9. Retention

Self-hosted: retention is entirely under your control — data persists in your SQLite file or PostgreSQL database until you delete it. Hosted app (once available): we expect to keep account and project data for as long as your account is active, and to remove it on account deletion subject to a short backup-rotation window; exact figures will be confirmed and published here before the hosted app launches ([hosted-app retention periods TBD]). Billing records, if applicable, would be kept as required by Irish tax law (6 years).

10. Your rights & how to exercise them

EU/UK (GDPR) and California (CCPA/CPRA) rights apply to any personal data we do process, including access, correction, deletion, portability, restriction/objection, and (California) opt-out of sale/share — which we do not do, as those terms are defined in the California Consumer Privacy Act.

11. Contact

Privacy: privacy@unspoolcode.com. We may update this policy; material changes are notified in-app (where applicable) and dated here.