Privacy Policy
This policy describes how personal data is processed on the Migrate website and in the Migrate app.
Controller
The controller responsible for data processing on this website and in the Migrate app is Binaries Lab UG (haftungsbeschränkt), Gocher Straße 88, 47559 Kranenburg, Germany.
Represented by Marcelo M. Sarquis. Phone: +49 1517 4239986. Email: legal@binarieslab.com.
What this policy covers
This privacy policy covers two separate things: this website at https://migrate.binarieslab.com, and the Migrate app for macOS. They are set out separately below, because the processing, the legal bases and the retention periods differ.
For audience measurement on the website we use exactly one tool: Google Analytics 4. It loads only after you have explicitly agreed in the consent banner. If you decline, or make no choice at all, no measurement takes place and no data whatsoever is sent to Google.
For the app, the most important sentence comes first: Migrate transfers your websites, files and databases directly between the accounts you configured. They never pass through a Binaries Lab server at any point. We hold no copy of them, and we can neither hand them over nor restore them.
Part A — This website
Hosting and delivery (Cloudflare Pages)
This website is hosted by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (“Cloudflare”) on the Cloudflare Pages platform and delivered through its global content delivery network. Cloudflare acts as our processor for the technical delivery of this website.
Each time a page is requested, Cloudflare automatically processes the connection data your browser transmits, which is technically necessary to deliver the page:
- IP address of the requesting device
- date and time of the request
- URL requested and volume of data transferred
- HTTP status code of the response
- referrer URL, where your browser sends one
- browser type, browser version and operating system
This processing serves to deliver the website, to keep it stable and secure, and to defend against attacks, including DDoS and bot mitigation. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is operating this website securely, reliably and resistant to attack.
This data arises unavoidably the moment you request the page, and therefore cannot be switched off in the consent banner — unlike Google Analytics, which loads only after your explicit consent. The connection data is not evaluated for audience measurement, not combined with other data sources and not used for profiling.
As a content delivery network, Cloudflare serves the content from the data centre closest to you, which may be outside Germany and outside the European Union. In addition, when you request an address without a language prefix — /privacy rather than /en/privacy — an edge function reads the Accept-Language header your browser sends in order to redirect you to the English or German version. The header is evaluated for that redirect only and is not stored.
Retention follows Cloudflare’s own policy; connection and security logs are held there for a limited period only. We receive no personal raw data about individual page views from Cloudflare. The Cloudflare dashboard shows us aggregate operational figures only, such as the total number of requests and the volume of data transferred, from which no individual person can be identified.
A data processing agreement under Art. 28 GDPR is in place with Cloudflare. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework, supplemented by EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. Further detail is available in Cloudflare’s privacy policy at cloudflare.com/privacypolicy.
Cookies and consent
A consent banner appears on your first visit. Until you make a choice there, no non-essential service is loaded and no non-essential cookie is set. Declining is exactly as easy as accepting: both buttons carry equal visual weight and neither is pre-selected.
The only strictly necessary cookie is the one set by the consent software (vanilla-cookieconsent), which stores your own choice for six months so you are not asked again on every visit. The legal basis is § 25(2)(2) TTDSG in conjunction with Art. 6(1)(f) GDPR.
You can change or fully withdraw your choice at any time via the “Cookie preferences” link in the footer. Withdrawal takes effect going forward and does not affect the lawfulness of processing carried out beforehand.
Google Analytics
Google Analytics 4 is the only analytics tool on this website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). We use it to understand how this website is used and which content is genuinely helpful.
Google Analytics loads only if you accepted the “Google Analytics” category in the consent banner. For as long as you have not consented — including if you ignore or decline the banner — no script is requested from googletagmanager.com, no connection to Google is made, no cookie is set and not a single measurement is transmitted. The tracking code is not hard-wired into the pages; it is fetched dynamically only after your consent. The legal basis is Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG.
Once you have consented, Google processes the following pseudonymous usage data on our behalf:
- pages viewed, along with the time and duration of the visit
- referrer URL, that is the page you came from
- approximate location at country and region level, derived from the truncated IP address
- device and browser type, operating system and screen resolution
- language setting
- a randomly generated identifier used to recognise returning visits
IP anonymisation is enabled: your IP address is truncated before any further processing and is not stored. We receive aggregated reports only and cannot identify any individual from them.
After your consent, Google Analytics sets its own cookies — in particular _ga and _ga_<property-id> with a lifetime of up to two years, and _gid with a lifetime of 24 hours. If you withdraw your consent, these cookies are deleted automatically.
Advertising features, remarketing and ad data sharing are permanently disabled. Under Google Consent Mode v2, ad_storage, ad_user_data and ad_personalization remain irrevocably set to “denied”, and Google signals are switched off at property level as well. No cross-site tracking takes place, and the data is not used for profiling or for personalising advertising.
The event data collected is deleted automatically after 14 months. Transfer to the United States cannot be excluded; Google LLC is certified under the EU-US Data Privacy Framework, supplemented by EU Standard Contractual Clauses. A data processing agreement under Art. 28 GDPR is in place with Google.
You may withdraw your consent at any time with effect for the future via the “Cookie preferences” link in the footer. Independently of that, Google offers a browser add-on to opt out of Google Analytics at tools.google.com/dlpage/gaoptout. Further information on Google’s processing is available at policies.google.com/privacy.
Fonts
All fonts are served from our own origin. No connection is made to Google Fonts or any other content delivery network, and no data is transmitted to third parties in the process.
Part B — The Migrate app
No user account
Using Migrate requires no user account with us. You do not register, you give us neither a name nor an email address, and we keep no user directory.
Everything you set up in the app — accounts, paths, projects, find and replace rules, schedules and the migration history — is stored locally on your Mac.
The credentials for your accounts
The passwords and private keys for your server, database and cloud accounts are stored in the macOS Keychain, through your Apple account and using Apple’s own security framework. They therefore stay on your device and under your control, and you can change or remove them at any time.
These credentials are not transmitted to us. We can neither see them nor restore them if you lose them.
Transferring your websites, files and databases
When you start a migration, the app on your Mac opens a connection to the source and to the destination and moves the data directly between those two endpoints. No Binaries Lab server is involved.
It follows that:
- We receive no copy of your files, databases or archives.
- We do not learn which websites you move, where to, or how often.
- We cannot restore a failed migration for you.
The legal basis for the processing on your device is Art. 6(1)(b) GDPR: it is necessary to provide the service you asked for.
The connection to your own servers, your host or your cloud provider is governed by their privacy terms. You choose those providers yourself; we are not party to that relationship.
Please note: if a transferred database contains personal data of other people — customer records, comments, orders — you are responsible for that processing. In particular, check whether copying a production database into a development environment is permissible.
Migration history and logs
Migrate records each completed run with its date, size, archive and log. Those entries live on your Mac only and are not transmitted to us.
How long they stay is up to you: any entry can be deleted from the history list at any time.
Anonymous usage statistics in the app
If you have consented, we collect anonymous usage and error data in the app in order to identify and fix usability problems and technical faults.
What is recorded is technical event data only: which function of the app was used, which operating system and device type were involved, and which error occurred and when. We receive an anonymised report from it. The contents of your files, your databases and your credentials are neither recorded nor transmitted.
This data is not passed to third parties and is not used for advertising. The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG.
You can withdraw your consent at any time with effect for the future by switching the corresponding setting off in the app’s settings. The data collected is deleted automatically after one year at the latest.
Subscription and payment
The Migrate subscription and all in-app purchases are handled exclusively through Apple’s App Store. Apple is your contractual partner for the payment and processes your payment data on its own responsibility under Apple’s privacy policy.
We receive from Apple neither your name nor your email address nor your payment details — only aggregated sales statements. That is why, in the event of a withdrawal, we ask you to attach your App Store invoice to your request: without it we cannot identify your purchase.
Managing, renewing and cancelling your subscription all happen in your Apple account settings. The details are governed by our Terms & Conditions.
Part C — Applying to both the website and the app
Support requests and contact by email
If you write to us, we process your message and your sender address solely to handle your enquiry. You are not obliged to provide personal data in your request, and you may contact us under a pseudonym at any time.
If you send a support request from within the app, the email will contain some technical information about your device and your Migrate version that helps us resolve technical issues. You may delete that information from the email before sending it; please note that we may then be unable to help you with technical questions.
Please do not send us credentials. We do not need them to diagnose a problem, and we will never ask for them.
The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries and otherwise our legitimate interest in answering enquiries under Art. 6(1)(f) GDPR.
We keep support requests for up to 120 days after your request has been dealt with, in order to confirm that it was resolved successfully and to understand which problems occurred previously if you contact us again. They are deleted afterwards, unless statutory retention obligations require otherwise.
Disclosure of data
In principle, your personal data is not passed on without your explicit prior consent. The following cases are the exceptions:
- Disclosure to law-enforcement authorities and, where applicable, harmed third parties, where necessary to investigate unlawful use of our services or for prosecution. This requires specific indications of unlawful or abusive behaviour.
- Disclosure in order to enforce our terms of use or other agreements.
- Information provided to certain public bodies where we are legally required to do so, for example law-enforcement authorities, authorities pursuing administrative offences subject to fines, and the tax authorities.
- Disclosure to the processors we use, each of which is named by name in this policy.
Depending on the case, the legal basis is our legitimate interest in fighting abuse, prosecuting criminal offences and securing, asserting and enforcing claims under Art. 6(1)(f) GDPR, or a legal obligation under Art. 6(1)(c) GDPR.
We select our processors with care and review them at regular intervals. They may use the data only for the purposes we specify, and are contractually obliged to process it solely in accordance with this policy and applicable data protection law.
In the course of developing our business, the structure of Binaries Lab UG (haftungsbeschränkt) may change — by altering the legal form, or by founding, acquiring or selling subsidiaries or parts of the company. In such a transaction, customer information would be transferred together with the part of the business concerned. We will ensure this takes place in compliance with this policy and the relevant data protection laws.
Erasure and retention
We erase or anonymise your personal data as soon as we no longer need it for the purposes set out above. The specific periods are stated in the relevant sections.
After those periods, the data is deleted, unless it is needed for longer due to statutory retention obligations, for criminal prosecution, or to secure, assert or enforce legal claims. In such a case the data is blocked and is no longer available for further use.
No automated decision-making, no profiling
We do not use any automated processes to reach a decision about you, and we carry out no profiling within the meaning of Art. 22 GDPR.
Change of purpose
Processing of your personal data for purposes other than those described takes place only to the extent permitted by law, or where you have consented to the changed purpose. Before any further processing for purposes other than those for which the data was originally collected, we will inform you of those other purposes and provide you with all other relevant information.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21 GDPR). Contact legal@binarieslab.com to exercise any of them.
You may withdraw any consent you have given at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.
Please note: we keep no user account and no copy of your websites, files, databases or credentials. By the time a request reaches us there is normally no data left for us to report on or erase. Your accounts and archives sit with you alone — on your Mac and with the providers you chose yourself.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
Changes to this policy
We update this policy whenever the processing described here changes. If a change concerns website services that require your consent, the consent banner is shown again. If it concerns the app, we will tell you in the app.
The current version is available at any time at https://migrate.binarieslab.com/privacy.