Privacy
Unroll reads the file you open and shows it to you. It has no telemetry, analytics, account or server. Reading a file never contacts a model provider, and your data doesn’t leave the machine it’s on unless you turn on investigations and ask a model about it.
What Unroll never does
- Send your traces, or anything about them, to Unroll. There is no Unroll service to send them to.
- Send trace content to a model provider unless you have turned on investigations and asked a question.
- Run the tool calls recorded in a trace.
- Edit your trace files.
- Load remote images that appear in trace content.
Links inside messages open in your browser only when you click them.
Where your trace is read
Everything happens inside VS Code: the file is read by the extension and displayed in its preview panel. In a remote workspace (SSH, a container or WSL), VS Code runs extensions on the remote machine, so that’s where the file is read. VS Code itself, other extensions and remote hosts have their own privacy policies.
Investigations (experimental)
Investigations are off by default. They start only after you run Unroll: Enable Investigations (Experimental)… and confirm, and only in trusted workspaces. Their settings can be changed only in your user settings, so a repository you open can’t turn them on or point them at another service. Until you turn them on, Unroll doesn’t even load the code that talks to model providers.
When you ask a question, Unroll sends the question, the steps you selected with their context, and the parts of the file the model reads with its tools to the provider you chose:
- VS Code language models, such as GitHub Copilot, under that provider’s terms. VS Code asks you before Unroll can use them.
- The Anthropic API, with a key you enter.
- An API endpoint you configure, such as OpenAI, another hosted service or a local server. Native OpenAI requests set
store: false; your account’s data controls still apply.
Before the first request to a provider and model, Unroll shows where excerpts will go and asks you to confirm; endpoints on your own machine don’t ask. Nonlocal HTTP endpoints show an unencrypted-connection warning, since keys and excerpts may be exposed in transit; use HTTPS where available. Each provider handles the data under its own privacy policy and may bill you. Keys are kept in VS Code’s secret storage, used only for the endpoint they were entered for, and removed with Unroll: Remove Stored Model Keys.
Investigations are saved as JSON in Unroll’s private extension storage. They include your question, the excerpts sent, the model’s findings and request diagnostics without keys or headers. If you set Save To to workspace, they’re written to .unroll/investigations in your workspace instead, including the trace file’s path; review them before committing.
What’s stored
VS Code may remember preview settings and your place in a file, such as the search text, selected conversation, filters and scroll position. To read large files efficiently, Unroll creates temporary indexes on the extension host. These contain file positions and limited parsing context, including field names and tool-link metadata. Full-message checkpoints do not store message bodies. Indexes are removed when the document closes or their cached reader is evicted; an abrupt process termination can leave temporary files for system cleanup.
Errors are written to the Unroll output channel. They can include file paths and other details, so review them before sharing.
Reporting issues
GitHub issues are public. Use a synthetic or sanitized example, and remove secrets and private conversations before attaching anything.
This website
The site is hosted on GitHub Pages. It has no analytics, ads, cookies or third-party embeds, and its fonts are served from the same site. Your browser keeps two small preferences for it in local storage, your color theme and whether you’ve seen the page’s raw opening; they never leave your browser. GitHub handles requests under its own privacy statement.
License and credits
The extension is MIT licensed. The public repository holds documentation, synthetic examples and release builds; the source code is maintained privately. Bundled libraries keep their own notices, and the website fonts are under the SIL Open Font License. Product logos identify compatible formats and belong to their owners. They come from Simple Icons (CC0); the OpenTelemetry logo is © CNCF, used under CC BY 4.0.