Unfour

Privacy

Learn how Unfour handles website traffic, browser sign-in, account data, payments, browser storage, optional Cloud Sync, and anonymous desktop usage statistics.

Effective September 2, 2026

Static-first website

The Unfour website is statically generated with Astro. Account and billing routes use browser-side Supabase Auth and the external Unfour API; Creem-hosted payment processing and product Cloud Sync run outside the static site. The site does not include a general-purpose contact form or an advertising analytics script.

Data we process

When you sign in with GitHub through Supabase Auth, the browser and Unfour API may process your account identifier, email address, display name or avatar supplied by GitHub, authentication session, and return intent. The service also processes plan, subscription and entitlement state, plus device installation identifiers, device name, platform, and last-seen time used for account-backed access. Creem processes billing identity, transaction, tax, and payment details as merchant of record; the static website does not receive card numbers, payment credentials, or provider secrets.

How we use data

We use this data to authenticate accounts, deliver Unfour and Pro functionality, manage subscriptions and entitlements, operate Cloud Sync, secure the service, prevent abuse, provide support, and meet legal or accounting obligations. Where data-protection law requires a legal basis, processing may be necessary to perform the subscription or service contract, comply with law, pursue legitimate interests in operating and securing the service, or act on consent where requested.

Browser storage

The website may use browser storage to keep a sign-in session, OAuth or checkout return intent, and the UI theme preference. These values support authentication, checkout flow, and interface preferences; they are not used for advertising tracking.

Cloud Sync

Cloud Sync is an optional Pro service for supported workspace records: workspaces, environments and non-secret variable values, API collections/folders/saved requests, SSH tasks/steps, and shared SSH or database connection fields. Connection credentials and references, SSH private keys and key paths, and local database files/paths are excluded. Secret-marked variable values are omitted; recognized API authentication and sensitive fields are redacted. Scripts, command templates, unrecognized fields, and other free text can still contain confidential information and need review before enabling sync. Cloud Sync data is processed by the Unfour API and backend, not by the static website.

Desktop usage statistics

Stable desktop builds can send one anonymous active-install event per installation per UTC day. The event includes a random installation ID stored in the operating-system keychain, plus application version, operating system, architecture, release channel, and distribution type. It does not include account, workspace, request, SSH, database, MCP, or feature-usage data. Unfour shows a first-run notice, and you can turn this off in Settings → Privacy. Test and development builds do not send these events.

Service providers and recipients

Supabase supports authentication, GitHub supplies the profile information you authorize during sign-in, Creem acts as merchant of record for payments, and Cloudflare may deliver and protect the website. The Unfour API and its service infrastructure process account, entitlement, device, and Cloud Sync data. These providers process data under their own terms and privacy notices and may process it in countries outside your own.

Embedded media

The demo section may load a video thumbnail from YouTube when the page is viewed. The privacy-enhanced YouTube player is loaded only after you choose to play the video; at that point, Google or YouTube may receive request metadata and apply their own privacy terms.

Retention

Account and subscription records are retained while needed to provide the service and meet security, accounting, payment, dispute, and legal obligations. Current service configuration expires desktop authorization sessions after 30 days and cleans up inactive device records after 90 days. Cloud Sync data remains while the service or account requires it. Retention may be extended when necessary for fraud prevention, legal claims, or mandatory recordkeeping.

Your choices and requests

You can use Unfour without signing in, turn off anonymous usage statistics in Settings → Privacy, and avoid Cloud Sync processing by not enabling the optional Pro service. Depending on applicable law, you may request access, correction, deletion, portability, restriction, or objection by emailing [email protected]. Some billing or security records may need to be retained as required by law. You may also have the right to complain to your local data-protection authority.

Security

Unfour uses scoped sessions, trusted backend entitlement decisions, and exclusion of supported secrets from Cloud Sync to reduce risk. No system can guarantee absolute security. Protect your device and account, and contact [email protected] if you believe your account or synchronized data has been compromised.

Analytics and traffic

The website does not use advertising trackers. Cloudflare may process request metadata and aggregated traffic information for delivery, security, and website analytics.

No contact form

The contact page only lists an email address. It does not submit messages through a form service or store messages in this website repository.

Cloud Sync data and secret-handling boundaries

Security and private vulnerability reporting