Application Privacy Policy
Last updated: 30 July 2026 · Applies to the UnspoolCode application (self-hosted installs today; the planned hosted early-access app,app.unspoolcode.com, once available)
1. Controller
The controller for any data MetaBinary Limited does process in connection with UnspoolCode is MetaBinary Limited, a company registered in Ireland (CRO 806119, VAT IE4698974FH), Office 40 — Boxworks, 40–44 Patrick Street, Waterford, X91 X3KF, Ireland. Contact:privacy@unspoolcode.com. As an EU-established controller we are not required to appoint an EU representative, and we have not appointed a Data Protection Officer.
2. Self-hosted installs — today's default
As of this policy's last-updated date, UnspoolCode is distributed as software you install and run on your own infrastructure. Project data — your source code, the parsed dependency graph, dead-code findings, and any migration output — is stored in a local SQLite database file on your machine, or in a PostgreSQL database you provision and control, at your choice. Access to a running instance is controlled by a single shared bearer token you configure; there is no per-user account or password system in this mode. None of this data is transmitted to or stored by MetaBinary in a self-hosted install — we have no access to your codebase, your graph, or your generated output unless you separately send it to us (for example, by emailing us a bug report). If you require this mode for confidentiality, NDA, or export-control reasons, use it rather than the hosted app described below.
3. What the hosted app would process
If and when you use a MetaBinary-hosted instance of UnspoolCode, we expect it to process:
- Account data — an email address and any workspace/organisation details needed to provision your instance. The specific account and authentication model for the hosted app is still being designed ([hosted-app auth model TBD]) and will be described accurately here before the hosted app launches.
- Content you upload or point us at — your VB6 source files (.bas/.cls/.frm/.vbp and related project files) and any other source code you connect for analysis.
- Analysis records — the dependency graph (modules, procedures, call/read/write edges), dead-code findings, migration plans, and any generated TypeScript/C# output or COM interop bridge artifacts produced when you run the migration tooling.
- Billing references — if a paid hosted plan exists at the time, subscription and customer identifiers from our payment processor. We would not receive or store your card details directly.
- Technical logs — standard security/reliability logs.
4. Your source code & results — your data
The source code you upload or connect, and the graph, findings, and migration output we produce from it, are yours. We would process them only to provide the service to you. You can export them and delete them at any time (see Your rights). We do not sell your code or analysis output, and we do not share it with other customers — each project's data is isolated to that project.
5. No AI/ML training on your code
We do not use your uploaded source code, your dependency graph, or any migration output to train machine-learning or AI models, and we do not share it with third-party AI providers except where the migration tooling itself calls an LLM on your explicit instruction (for example, an LLM-assisted translation pass that requires you to supply your own API key) — in that case your code is sent only to the provider and for the purpose you configured, not to us, and not for model training on our side. If this ever changes — for example, an opt-in shared-model-training feature — it will be a clearly disclosed, explicit opt-in, described here before it exists, not assumed. Today, no such feature exists.
6. Purposes & lawful basis
| Purpose | Lawful basis |
|---|---|
| Provide the (self-hosted or, once available, hosted) app | Performance of a contract |
| Billing & subscription management (if/when paid hosted plans exist) | Contract; legal obligation (tax) |
| Security, abuse prevention, logs | Legitimate interests |
7. Processors we use
For a self-hosted install, we use no processors — nothing leaves your infrastructure. For the planned hosted app, we intend to use:
- Hosting — Hostinger International Ltd (application servers, currently located in the United States) with Cloudflare, Inc. as CDN/security in front of the service.
- Payments — none yet; only if and when a paid hosted plan exists, and named here before it launches.
- Email — Resend, Inc. (transactional email).
Each will be engaged under a data-processing agreement; this page will be kept current as the hosted app is built, and copies of the relevant data-processing terms will be available on request. Where personal data of EEA/UK users would be processed outside the EEA/UK (our application servers are currently US-located), we will rely on the EU–US Data Privacy Framework where the provider is certified, or on the Standard Contractual Clauses, with appropriate supplementary safeguards.
8. Security
For self-hosted installs, access control (the shared bearer token model described in Section 2) and infrastructure security are your responsibility as the operator of the install; we recommend running it behind your own authentication layer (e.g. a reverse proxy or VPN) for any networked deployment. For the planned hosted app, we will publish the concrete security architecture — including how accounts and sessions are protected — before launch ([hosted-app security architecture TBD]) rather than asserting specifics that are not yet built.
9. Retention
Self-hosted: retention is entirely under your control — data persists in your SQLite file or PostgreSQL database until you delete it. Hosted app (once available): we expect to keep account and project data for as long as your account is active, and to remove it on account deletion subject to a short backup-rotation window; exact figures will be confirmed and published here before the hosted app launches ([hosted-app retention periods TBD]). Billing records, if applicable, would be kept as required by Irish tax law (6 years).
10. Your rights & how to exercise them
EU/UK (GDPR) and California (CCPA/CPRA) rights apply to any personal data we do process, including access, correction, deletion, portability, restriction/objection, and (California) opt-out of sale/share — which we do not do, as those terms are defined in the California Consumer Privacy Act.
- Self-hosted — you control export and deletion directly; it is your database.
- Hosted app (once available) — export and account-deletion controls will be provided in-app.
- Anything else — email privacy@unspoolcode.com. You may complain to your supervisory authority (Ireland: the Data Protection Commission).
11. Contact
Privacy: privacy@unspoolcode.com. We may update this policy; material changes are notified in-app (where applicable) and dated here.