Legal

Privacy Policy

Last updated Sept 2026

1. What we collect. Account data (name, email, password hash — never plaintext), API usage metadata (model, token counts, latency, status, cost), billing records via Stripe, and support tickets. Prompt/response bodies are processed for inference and retained only in your request logs, which you can wipe in Settings → Danger zone.

2. What we never do. We never sell personal data, never store API key secrets (SHA-256 hashes only), and never train shared models on your prompts.

3. Processors. Stripe (payments), our GPU infrastructure providers (compute), and email delivery. Enterprise DPAs available — see /enterprise.

4. Residency. Pin data to GLOBAL / US / EU / APAC in Settings. EU/APAC pins carry contractual residency on paid plans.

5. Your rights. Export or delete everything anytime: Settings → Danger zone wipes keys, credits, usage, deployments, secrets, and webhooks. Email enterprise@runaii.cloud for GDPR/CCPA requests.

6. Cookies & analytics. One httpOnly session cookie for login. Product analytics (PostHog heatmaps, Plausible pageviews, Google Analytics page metrics) load only after you opt in via the consent banner — decline and nothing loads, and Google Analytics runs with IP anonymization. No ad trackers, ever.