Effective date: August 31, 2026
Unsave Inc. (“Unsave,” “we,” “us”) operates the Unsave platform at unsave.io. We provide agentless Azure governance covering security posture, compliance, cost optimization, and identity lifecycle management. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
When you sign in through Microsoft Entra ID, we receive and store:
To provide governance assessments, we collect and store metadata from your Azure environment including:
Important: We never access the contents of your resources — no blob storage files, no database records, no virtual machine disks, no application code, no Key Vault secrets. We read configuration metadata only.
We collect data about how you interact with the platform:
Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account details, or other payment credentials on our servers. We receive from Stripe: plan type, billing period, payment status, and Stripe customer ID.
If you contact us via email or in-app feedback, we retain the content of those communications to provide support. We also send transactional emails (onboarding reminders, alert notifications, billing receipts) and may send product updates. You can unsubscribe from non-transactional emails at any time.
Your data is stored in Azure Database for PostgreSQL, hosted in Microsoft Azure’s Canada Central region and encrypted at rest. Application services and background jobs run in the same region. Sensitive credentials (Azure client secrets, integration tokens, API keys) carry a second layer of encryption: AES-256-GCM with a unique initialization vector per value, keyed from an Azure Key Vault scoped to that environment.
Data is logically isolated per organization. Every stored record carries its organization and tenant identifiers, and every query is scoped through them, so no tenant can access another tenant’s data. Access to production systems is restricted to authorized personnel with role-based access controls and audit logging.
All data in transit is encrypted using TLS 1.2+. The platform enforces HSTS, prevents clickjacking, and implements CSRF protection on all authenticated endpoints.
We use the following third-party services that may process your data:
| Service | Purpose | Data Shared |
|---|---|---|
| Microsoft Entra ID | Authentication | OAuth tokens, profile info |
| Azure Resource Manager | Resource metadata collection | Read-only API calls to your tenant |
| Stripe | Payment processing | Email, plan selection, payment method |
| PostHog | Product analytics | Page views, clicks, anonymized session recordings |
| Sentry | Error monitoring | Error stack traces, browser info, user ID |
| Microsoft Azure | Hosting and database (Canada Central) | All application data (encrypted at rest) |
Each provider is subject to their own privacy policies and data processing agreements.
We use the following cookies:
We do not use advertising cookies or share cookie data with ad networks.
Depending on your jurisdiction, you may have the following rights:
To exercise any of these rights, contact us at privacy@unsave.io. We will respond within 30 days.
Unsave is based in Canada, and your account data and Azure tenant metadata are stored and processed in Canada. Data shared with the supporting services listed in Section 7 (billing, product analytics, and error monitoring) is processed in the United States by those providers. By using the Service, you consent to these transfers. We ensure that appropriate safeguards are in place for international transfers in compliance with applicable data protection laws.
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
In the event of a data breach affecting your personal data or Azure metadata, we will notify affected users via email within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, data affected, steps we are taking, and recommended actions for you.
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The “Effective date” at the top reflects the latest revision.
For privacy-related questions, data requests, or complaints: