PRIVACY NOTICE
Your rows stay with you.
Last updated: 13 July 2026
Overview
unify.ai is an early-access tool for matching financial CSV column headers. This notice explains what information is processed when you use the service. It does not override the privacy terms of Google, Ollama, or Vercel.
Financial CSV data
The populated CSV is read and transformed locally in your browser. Financial row values are not intentionally uploaded to the unify.ai server, Ollama Cloud, or an application database.
Rows remain temporarily in browser memory while you work and are cleared from the application's references after download, reset, failure, logout, or page exit. Browser extensions, device software, and the browser itself remain outside unify.ai's control.
Column headers and AI matching
The source and destination column headers are sent to the unify.ai backend and then to Ollama Cloud to produce mapping suggestions. Headers can contain sensitive wording, so review them before continuing.
unify.ai does not intentionally retain headers in an application database or include them in application logs. Ollama processes cloud prompts under its own privacy policy.
Google authentication
Google provides verified account information so unify.ai can authenticate you and check whether your email address or domain is authorized. The OAuth access and refresh tokens are discarded after sign-in. Only Google's opaque account identifier is retained in a signed, HTTP-only session cookie.
The session cookie can remain valid for up to eight hours. Google processes authentication information under its own privacy policy.
Hosting and request metadata
Vercel hosts the production service and may process ordinary request metadata such as IP addresses, timestamps, routes, device information, and operational logs. Google also receives ordinary request metadata when browser fonts are loaded. unify.ai does not currently enable product analytics or advertising trackers.
Vercel describes its processing in its privacy notice.
Why information is processed
Information is processed only to provide header matching, authenticate authorized users, secure the service, prevent abuse, diagnose failures, and meet legal obligations. Where UK data-protection law applies, this processing is based on the legitimate interests of operating and securing the service, or on taking steps requested by the user to provide it.
Retention and sharing
unify.ai does not maintain user accounts or a database of uploaded files. The signed session expires after eight hours. Hosting, authentication, and AI providers may retain limited information according to their own policies and contractual terms, including where processing occurs outside the United Kingdom.
Information may also be disclosed where required by law, to investigate abuse, or to protect users and the service.
Your choices and rights
You can avoid sending headers by not starting a mapping request, sign out to remove the session cookie from your browser, and stop using the service at any time. Depending on where you live, you may have rights to request access, correction, deletion, restriction, or objection, and to complain to a data-protection authority.
Security and limitations
unify.ai uses safeguards including HTTPS-only production sessions, restricted hosts, request limits, validated AI responses, and browser-local row processing. No online service, device, browser, or third-party provider can guarantee absolute security.
Do not report vulnerabilities in a public issue. Use the repository's private security reporting form.
Contact and changes
For privacy questions or rights requests, contact the project operator through the GitHub profile. A dedicated privacy contact address should be published before wider commercial availability.
This notice may be updated as unify.ai changes. Material changes will be reflected by updating the date at the top of this page.