Privacy Policy
Last updated: May 18, 2026
1. Introduction
Runtools Inc. ("Runtools.ai", "we", "us", or "our") operates the Runtools.ai website, dashboard, APIs, SDKs, AI agent infrastructure, sandbox execution environments, workspace storage, tool integrations, and related services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you access or use the Services.
By using the Services, you acknowledge this Privacy Policy. If you use the Services on behalf of an organization, you represent that you are authorized to provide information to us on that organization's behalf.
2. Information We Collect
2.1 Information You Provide
- Account and organization information: Name, email address, username, company or team information, role, authentication identifiers, and account preferences.
- Billing and transaction information: Plan, usage, credits, invoices, tax information, billing contact details, and payment-related records. Payment card details are processed by our payment providers and are not intentionally stored by Runtools.
- Customer Content: Code, prompts, files, workspace contents, sandbox inputs and outputs, agent configurations, workflow definitions, tool settings, uploaded documents, and other materials you submit to or process through the Services.
- Credentials and integration data: API keys, access tokens, secrets, OAuth connection metadata, and other credentials you provide or generate to connect third-party services.
- Support and communications: Messages, feedback, survey responses, security reports, and other information you provide when contacting us.
2.2 Information Collected Automatically
- Usage and system data: API calls, feature usage, tool executions, resource consumption, workflow activity, sandbox lifecycle events, telemetry, logs, timestamps, and performance data.
- Device and network data: IP address, browser type, operating system, device identifiers, pages visited, referring URLs, and approximate location derived from IP address.
- Cookies and similar technologies: Session cookies, authentication cookies, preference storage, and limited analytics used to operate, secure, and improve the Services.
2.3 Information from Third Parties
We may receive information from authentication providers, payment providers, integration partners, security and abuse-prevention vendors, and services you connect to Runtools. For example, when you authenticate through Google or GitHub, we may receive your email address, name, username, profile image, and provider account identifier. We do not access repositories, files, email, calendars, or other third-party resources unless you explicitly connect or direct an integration that requires that access.
3. How We Use Information
We use information to:
- Provide, operate, maintain, and improve the Services.
- Authenticate users, administer accounts and organizations, and enforce access controls.
- Execute agents, tools, workflows, code, and sandbox operations at your direction.
- Store and retrieve workspace files, execution history, configuration, and related Customer Content.
- Process billing, credits, invoices, usage limits, and plan administration.
- Provide support, send transactional notices, and respond to requests.
- Detect, prevent, investigate, and respond to fraud, abuse, malware, security incidents, unauthorized access, and violations of our terms.
- Develop, debug, measure, and improve the Services using aggregated, de-identified, or non-sensitive operational information where feasible.
- Comply with legal obligations and enforce our agreements.
4. Customer Content and AI Model Training
You retain ownership of Customer Content. We process Customer Content only to provide, secure, support, and improve the Services, to comply with law, or as otherwise directed by you.
Unless you expressly opt in or direct us through a product feature, we do not use Customer Content, prompts, code, files, workspace contents, API keys, secrets, or execution outputs to train third-party foundation models or generalized Runtools AI models. We may use aggregated or de-identified System Data that does not identify you or reveal Customer Content to operate, secure, analyze, and improve the Services.
When you choose to use an AI model, tool, or third-party integration, the information needed to complete that request may be sent to the relevant provider. Your use of those providers may be subject to their separate terms and privacy notices.
5. How We Share Information
We do not sell personal information for money. We share information only as described below:
- Service providers: Vendors that help us provide hosting, storage, authentication, payments, analytics, email, customer support, security, fraud prevention, observability, and infrastructure services. They are authorized to use information only as necessary to provide services to us and are expected to protect it under contractual obligations.
- AI, tool, and integration providers: Providers you select or direct through the Services, including model providers, connected apps, and third-party APIs.
- Organization users: Information may be visible to members, admins, or owners of your organization according to your account settings and permissions.
- Legal, safety, and enforcement: We may disclose information when reasonably necessary to comply with law, legal process, or government requests; enforce our agreements; protect the Services; prevent fraud, abuse, or security issues; or protect rights, property, or safety.
- Business transfers: Information may be transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.
- Consent: We may share information for other purposes with your consent or at your direction.
6. Security
We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, use, loss, alteration, and disclosure. These safeguards may include encryption in transit, encryption at rest where appropriate, isolated execution environments, access controls, audit logging, monitoring, vulnerability management, and secure credential handling.
No service can guarantee absolute security. You are responsible for safeguarding your account credentials, configuring integrations appropriately, protecting API keys and secrets, reviewing agent and tool outputs, and avoiding submission of information that you are not authorized to process through the Services.
7. Sensitive and Regulated Data
Unless we have entered into a written agreement that expressly permits it, you should not submit protected health information, payment card data, government identifiers, biometric data, children's data, or other sensitive regulated data to the Services. You are responsible for ensuring that Customer Content and any personal information you process through the Services is collected, used, transferred, and processed in compliance with applicable laws and with all necessary notices, rights, permissions, and consents.
8. Data Retention
We retain information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and maintain security and audit records. Execution logs are generally retained for 90 days by default unless a different retention period applies through your settings, plan, legal obligation, security need, backup cycle, or written agreement. Deletion requests may require deletion of your account, and some information may remain in backups or logs for a limited period.
9. Your Rights and Choices
Depending on your location, you may have rights to:
- Access or receive a copy of personal information we maintain about you.
- Correct inaccurate or incomplete personal information.
- Delete personal information, subject to legal and operational exceptions.
- Request portability of certain personal information.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
- Appeal a decision relating to a privacy request where applicable law provides that right.
- Opt out of targeted advertising, sale, or sharing where applicable law provides that right.
To exercise these rights, contact us at [email protected]. We may need to verify your identity or authority before fulfilling a request. We will not discriminate against you for exercising privacy rights.
10. Cookies and Tracking
We use essential cookies to keep you signed in, secure sessions, remember preferences, and operate the Services. We may use limited analytics to understand usage and improve performance. We do not use third-party advertising cookies or knowingly share personal information for cross-context behavioral advertising. Where legally required and technically feasible, we honor applicable opt-out preference signals such as Global Privacy Control.
11. Children's Privacy
The Services are not intended for users under 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child without appropriate authorization, we will take steps to delete it.
12. International Data Transfers
We are based in the United States and may process information in the United States and other jurisdictions where we or our service providers operate. These jurisdictions may have data protection laws that differ from those in your location. Where required, we use appropriate safeguards for international transfers.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. If changes are material, we may provide additional notice through the Services or by email when appropriate. Your continued use of the Services after changes means you acknowledge the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
Runtools Inc.
Email: [email protected]