Unrol

Privacy Policy

What we store

  • Account: your email and basic profile (such as display name and avatar) from the sign-in provider you choose. Authentication is handled by Supabase Auth; Unrol does not store your password.
  • Your library: the threads you choose to save, linked to your account.
  • Ingestion records: when you unroll a thread, a job record is kept so you can track its status.
  • Public thread content: the public X posts you unroll are stored so Unrol can display and search them. This content is public on X.

Technical data

Your signed-in session is kept in your browser’s local storage so you stay logged in. Servers keep operational logs (with request identifiers and timings) to run and debug the service; secrets and tokens are never logged.

Email

When you sign in by email, Unrol sends a one-time sign-in link and passcode through a transactional email provider (Zoho ZeptoMail). These emails are triggered only by your sign-in requests; Unrol does not send marketing email.

Where data is processed

Account and thread data are stored in Supabase (PostgreSQL) and cached in Redis. Public thread content is retrieved server-side through the official X API. The application is hosted on Hetzner, with Cloudflare providing DNS and edge delivery.

What we do not do

Unrol does not sell your personal data, and signing in with X does not give Unrol access to your private X account (bookmarks, timeline, direct messages, or similar).

Your choices

You can remove saved threads from your library at any time. Account deletion is being implemented; when you delete your account, your account data and library are removed. Public threads already stored in Unrol are public content and may be retained independently of any single account. (DRAFT — deletion details to be finalized.)

Changes

This policy will be updated as Unrol evolves and before launch.

Contact

Privacy questions: hello@unrol.app

← Back to Unrol