Unfreez°

Privacy policy — Unfreez

Data controller

GEPETTO LABS, a French SAS with a share capital of €1,000, registered in Bordeaux under no. 939 152 468 (VAT FR72939152468), 16 place des Quinconces, 33000 Bordeaux, France, is the controller for the processing described below. Contact: [email protected].

Data we process

Account: name, email and avatar from the sign-in method you choose — GitHub, Google, or an email sign-in link. Code host connections: when you connect GitHub, GitLab or Bitbucket, we store the identifiers of the repositories you explicitly authorise and the OAuth tokens needed to read and publish to them. Tokens are encrypted at rest (AES-256-GCM) and can be revoked at any time from your account page. Site content: the texts and images you edit belong to the connected website; they transit through our servers only for preview and publishing, and every publication is recorded in the site's Git history. Billing: subscription status and invoicing data handled by Stripe — card details never reach our servers. Technical data: server logs and a publication journal (who published what, when), kept for security and support.

Purposes and legal bases

Providing the service — accounts, connected sites, editing, publishing, billing (performance of the contract). Security and abuse prevention — technical logs, rate limits, trial limits, captcha (legitimate interest). Invoicing and accounting (legal obligation).

Processors

We share data only with the providers needed to run the service:

Providers established in the United States process data under the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.

Cookies

We use session cookies strictly necessary for authentication and preview, and Cloudflare Turnstile sets a short-lived cookie on the sign-in page to tell humans from bots. No advertising cookies, no audience tracking, neither on unfreez.app nor in the studio.

Retention

Account data: until account deletion. Code host tokens: until you revoke the connection or delete your account. Working copies of repositories: rebuildable technical caches, deleted with the site. Technical logs: at most 12 months. Billing data: statutory accounting periods.

Security

All traffic is encrypted in transit (TLS). Code host tokens are encrypted at rest. Access to production systems is restricted to GEPETTO LABS.

Your rights

Under the GDPR you have rights of access, rectification, erasure, restriction, objection and portability over your data. Write to [email protected] — we answer within one month. You may also lodge a complaint with the French supervisory authority, the CNIL (cnil.fr).