Last updated July 3, 2026
Privacy Policy
This policy describes how Transmutify currently handles personal data and transformation data based on the implemented application behavior.
Important status
The operator and data protection contact are listed in the Imprint.
This policy is intended to provide information required under the GDPR for users and customer contacts in the European Economic Area.
Transmutify is intended for business and professional use.
What Transmutify does
Transmutify provides a dashboard and API for transforming structured files and raw input into schema-guided output. The service supports organization workspaces, API keys, provider configuration, schemas, transformation runs, upload and download URLs, webhooks, support requests, and feedback.
Information we collect
- Account information, such as name, email address, password credentials, email verification status, social login identifiers, and session data.
- Organization information, such as organization name, members, invitations, billing-style address fields, VAT ID, and billing email when provided.
- Product configuration, such as API keys, schemas, AI provider type, model, encrypted provider credentials, encrypted custom storage credentials, encrypted webhook webhook secrets, storage settings, and webhook settings.
- Transformation data, such as uploaded file metadata, raw input, input headers and sample rows, preview and validation row contents stored for the review workflow, review mappings, review data edits, transformation status, output files, errors, processing duration, usage records, and webhook delivery logs.
- Support and feedback data, such as support-ticket messages, feedback ratings, and feedback messages submitted inside the service.
- Technical data, such as IP address, user agent, session payloads, request metadata, logs, and rate-limiting data.
- Attribution and preference data, such as the
utm_sourcequery parameter when forwarded into signup, and the appearance preference stored in local storage and a cookie.
Controller and processor roles
For account, website, security, support, and product operations, the Transmutify legal operator acts as the controller. For transformation data submitted by an organization, Transmutify generally acts as a processor on behalf of that organization. The organization is responsible for ensuring it has a lawful basis and any required permissions for the data it submits.
The Data Processing Agreement describes processor terms for customer personal data processed by Transmutify on behalf of an organization.
How transformation data is processed
Transformation input may be uploaded through temporary upload URLs or submitted through API requests. Files are stored either on the configured Transmutify transformation storage disk in AWS Europe (Frankfurt) (eu-central-1) or, if an organization activates custom storage, in that organization's configured AWS S3 storage.
For file-based mapping and schema generation, Transmutify may send schema definitions, prompts, headers, and a limited sample of rows to the AI provider configured by the organization. Before those samples are sent, the application masks common sensitive values where detected. This masking is a protective measure, not a guarantee that every sensitive value will be detected in every file.
For raw transformations, the submitted raw input content is sent to the configured AI provider unless the request is marked as a dry run. Raw transformations should only be used with data the organization is permitted to send to that provider.
Transmutify encrypts selected sensitive secrets stored by the application, including AI provider credentials, webhook secrets, and custom storage credentials, and encrypts transformation row data held in the application database, including input headers, sample rows, preview and validation row contents, and review data edits. This does not mean that every field, file, log entry, queue payload, or provider request is separately encrypted or masked.
Transformation input and output files are retained for 7 days from the relevant file timestamp unless an organization uses custom storage that it controls. Temporary download URLs are time-limited.
Row data stored encrypted in the application database for the review workflow is deleted when the mapping is re-run, when a review is canceled, or when the transformation run is deleted, and otherwise remains stored with the transformation run.
Legal bases
Depending on the activity, Transmutify processes personal data because it is necessary to provide the service or take steps before entering into a contract, because Transmutify or its customers have legitimate interests in operating, securing, improving, and supporting the service, because processing is necessary to comply with legal obligations, or because consent has been requested for a specific optional activity.
How we use information
- To create accounts and organization workspaces.
- To authenticate users and API requests.
- To create, process, inspect, and monitor transformations.
- To prepare review mappings and schema suggestions.
- To store output files and provide temporary download URLs.
- To send webhook notifications selected by the organization.
- To provide support, collect feedback, and improve reliability.
- To prevent abuse, enforce quotas, secure the service, and debug errors.
Third-party services
The service can interact with third-party AI providers selected by the organization, currently including provider types such as OpenAI, Anthropic, xAI, Gemini, and OpenRouter. Organizations are responsible for reviewing the terms and privacy practices of the providers they configure.
The service may also use email delivery, object storage, authentication, monitoring, logging, and infrastructure providers. The Data Processing Agreement lists the current product subprocessors and customer-selected providers.
Some AI providers, authentication providers, infrastructure providers, or support providers may process personal data outside the European Economic Area. Where this occurs, Transmutify must rely on an adequacy decision or appropriate safeguards such as standard contractual clauses.
Cookies and local storage
Transmutify currently uses necessary cookies and browser storage for authentication, session security, CSRF protection, dashboard state, and appearance preferences. These are used to provide the requested service and are not used for advertising or third-party tracking in the current implementation.
Sharing and disclosure
Transmutify does not need to sell personal information to provide the implemented service. Information may be disclosed to service providers that help operate the product, to AI providers selected by an organization, to storage systems configured by an organization, to webhook endpoints configured by an organization, or when required to comply with law, protect rights, prevent abuse, or secure the service.
Your choices and requests
Users can update profile and security settings in the dashboard. Organization settings allow members to configure storage, webhooks, schemas, providers, and members according to their permissions. Requests to access, correct, export, restrict, or delete personal data should be directed to the data protection contact listed in the Imprint.
Individuals in the European Economic Area may have the right to access, correct, delete, restrict, object to, or receive a copy of their personal data, and to lodge a complaint with a data protection supervisory authority. Some requests may need to be handled by the customer organization acting as controller for transformation data.
Changes to this policy
This policy may be updated as the service, legal operator, infrastructure, subprocessors, or legal requirements change. The updated date at the top of the page identifies the latest version.