# Privacy Policy Runtime LLC, 1500 N Grant St Ste N, Denver, CO 80203, United States ("Runtime", "we") decides how the personal data described here is used. In European terms we are its controller. Write to marc@heyruntime.com about anything on this page. This policy covers people who visit withruntime.com, hold an account or write to us. It does not cover what customers put inside their sandboxes and other resources. There the customer decides and we only process the data for them, under the [Data Processing Addendum](/legal/dpa). If your data is in a customer's product, ask that customer. ## What we collect and why **Your account.** Your email address, and, if you use "Continue with Google", the name and profile picture Google gives us. We use them to sign you in, to run your account and to write to you about it. For each session we keep the IP address and browser description it was opened from, to protect the account. When you sign in we record which version of the Terms of Service was in force, with the time, your email address, IP address and browser description, as proof of the agreement. We keep that record after the account is closed, for as long as a claim about the agreement could be brought. **Payments.** Stripe collects your card details; we never see or store the card number. We keep what Stripe tells us about a payment: the amount, currency, date, status and Stripe's references. We use it to credit your balance, handle refunds and disputes, and meet tax and accounting law. **Support and feedback.** What you write to support, in the chat, by email or from your agent through the CLI or MCP, and the answers. Support is answered first by an AI agent: to help with a conversation you start, it reads your organization's account, and it looks inside a sandbox only after you approve that. The conversation and what the agent read for it go to the AI model hosts listed as our subprocessors. We keep conversations while your account is open and for one year after it closes, to answer follow-ups and improve support. Feedback you send, including what you tell us about other providers, is kept to decide what to build and to tell you when it ships. **Usage.** What you create and run, when, its size, what it cost, and which key or person did it. We use this to provide and bill the Services and to show you your own usage. **Network records.** For each sandbox we keep a bounded record of the outside addresses and ports it connected to, when, for how long, and how much went each way. We use it only to trace and stop abuse and to answer complaints about traffic from our network. **Messages.** What you send us by email, and our replies. **Visits to the site.** We count visits ourselves; no analytics company is involved. A visit records the page you opened (for example one docs page), the time, the name of the site that sent you if your browser gives it (for example "news.ycombinator.com", never the address of the page you were on), whether you came from a search engine, a social site, another site or directly, your country, worked out from your connection, and whether you used a computer, a phone or a tablet. If the link you followed was tagged with a campaign (for example "utm_source=newsletter"), the visit records those tags too. We also count a few clicks on the site, such as copying the setup prompt or starting to sign in, with the page they happened on. It also records a code that stays the same on every visit from the same browser, so we can tell a new visitor from one who comes back. The code is made from a random identifier kept in your browser's storage. We do not store your IP address with a visit, and we do not track you across other sites. If you sign in, we link the visits counted in that browser to your account, so we can see how you found us: for example, the first site that sent you, the page you landed on, and how many visits you made before you bought credit. **Programs reading the docs.** When a program or an AI agent fetches the plain-text versions of our docs or our llms.txt file, we count the fetch: the day, the page, the kind of program as it describes itself (for example "curl" or "Claude"), and the country worked out from the connection. That is all we keep. No code, address or other detail that could tell one reader from another is stored, so this count asks for no agreement. We count nothing if your browser sends Global Privacy Control. We do not act on the older Do Not Track setting. In the European Economic Area, the United Kingdom and Switzerland we count only if you agree when asked, and you can change your mind at any time from the "Privacy choices" link at the foot of this page. Clearing your browser's storage gives you a new code, which we cannot join to the old one. We use no advertising cookies and no third-party trackers. Signing in sets the cookies needed to keep you signed in. Following someone's referral link sets one cookie that holds only their referral code, for 30 days, so that the credit reaches you both when you sign up; it is part of what you asked for, so we set it without asking. ## Legal grounds, for people in Europe We use account, payment, usage and message data because we need it to perform our contract with you. We keep session and network records, and prevent abuse and fraud, because we have a legitimate interest in a secure service that outweighs the limited effect on you. We keep billing records because the law requires it. We count site visits with your consent. ## Who receives it The companies listed as our [subprocessors](/legal/subprocessors), who act on our instructions. Authorities, courts or other parties when the law requires it, or when needed to establish or defend legal claims or to stop abuse. Our own infrastructure providers, when we must answer an abuse complaint about traffic from your resources. A successor, if our business is merged, sold or reorganized. We do not sell personal data, and we do not share it for advertising. ## Where it goes We and our subprocessors are in the United States. When personal data from the European Economic Area, the United Kingdom or Switzerland is transferred to us or by us, the transfer relies on the European Commission's standard contractual clauses, with the United Kingdom and Swiss additions where they apply. Write to marc@heyruntime.com for a copy. Where one of our subprocessors is certified under the Data Privacy Framework, our transfer to it may rely on that instead. ## How long we keep it - Account data: while the account is open. When you close it, we delete or anonymize it within a reasonable time, except as below. - Billing and tax records: seven years. - Session and network records: for a limited period, and longer only for the specific records that are evidence of abuse or of a dispute. - Messages: up to three years after the conversation ends. - Visits: kept without a time limit, so we can compare years. Visits linked to your account are covered by your rights below: ask, and we will send them to you or remove the link to your account. Independent recovery storage is not enabled today. If it is enabled, its configured retention keeps hourly and daily recovery points and preserves a last available and last restore-checked copy while the resource is retained. Deleting the resource or closing the organization ends that preservation rule. Cleanup waits for any active restore to finish, then removes recovery references and reclaims unused repository data. Provider object history is cleared separately under its configured deletion rules; removal from the recovery catalog alone is not immediate physical erasure. We monitor delayed cleanup rather than silently retaining deleted content indefinitely. Customer resource backups are covered by the Data Processing Addendum. ## Your rights You may ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to our use of it, or to hand it to you in a portable form. Where we rely on consent, you may withdraw it at any time. Write to marc@heyruntime.com from the address on your account. We answer within the time the law allows and never charge for a reasonable request. We will not treat you worse for asking. To close your account, write to marc@heyruntime.com. If you are in Europe, you may also complain to your data protection authority. If you live in a US state with a privacy law, the same rights apply to you; you may appeal a refusal by replying to it, and we honor Global Privacy Control signals. ## Security Each sandbox is its own virtual machine. Connections are encrypted in transit, customers are separated inside the database, and access to systems is limited to what each part needs. No service is perfectly secure. If a breach of your personal data is likely to put you at risk, we will tell you. ## Children The Services are for businesses and adults. We do not knowingly collect personal data from anyone under 18. ## Changes We post changes here, and the date at the foot of the page shows the last one. If a change matters, we tell account holders by email or in the account.