runlot

Privacy policy

In effect from 19 September 2026

runlot collects only what it needs to run the service. This page states what we take, where it is used, and how long it is kept.

What we collect

  • Account: your email address and name, plus the user id given by the provider you signed in with (GitHub or Google).
  • If you signed up with a password: an argon2id hash, never the password itself.
  • Organizations and projects: names, settings, and deployment history.
  • Usage: request counts, execution time, and stored bytes. These compute your plan limits and your bill.
  • Mail records: the headers and bodies of mail your projects send and receive.
  • Product analytics: which pages you open on the site, the dashboard, and the docs, plus a random device id kept in your browser. Dashboard addresses have project names and tokens removed before they leave the page. What you do in the dashboard is grouped by your organization, so we can see how teams use runlot rather than individuals.
  • You choose whether we do this. In the EU, the EEA, and the UK nothing is collected until you say yes; elsewhere the banner tells you it is on and turns it off in one click. You can change your mind at the bottom of this page.

What it is used for

  • Recognising your account and keeping you signed in.
  • Computing plan limits and billing.
  • Finding and stopping faults and abuse.
  • Seeing which parts of runlot get used and where people get stuck, so we know what to fix next.
  • Sending you notices about the service. We do not send marketing mail.

Who else processes it

  • Amazon Web Services: mail delivery and AI model execution, in the Seoul region.
  • Google Cloud: Google sign-in and AI model execution.
  • Cloudflare: domains and the traffic edge.
  • Polar: payments. runlot never receives or stores your card number.
  • PostHog: product analytics. We do not record your screen, and we do not send the contents of your projects.
  • Sentry: error reports from this site and the documentation — the message, the address of the page, and the browser. Like the analytics above, nothing is sent until you have said yes.
  • We do not pass your data beyond this list, and we do not sell it.

How long it is kept

  • Account data: until you delete the account.
  • Mail records: 30 days on Free, 365 days on Pro. Older ones are swept hourly.
  • Database backups: 7 days on Free, 30 days on Pro.
  • Email verification links: 24 hours. Password reset links: 1 hour.

When you sign in with Google

  • We request three scopes only: openid, your email address, and your basic profile.
  • Those values are used solely to create your account and recognise you on return.
  • We do not use data received from Google for advertising, and we do not sell it.

What you can ask for

  • You can ask us to show you the data we hold about you.
  • You can ask us to delete your account and the data attached to it.
  • Write to the address below and we will act on it once we have confirmed the request.

Product analytics

We count which pages get opened so we know what to fix next. No screen recording, and nothing from inside your projects.

You have not chosen yet on this browser.

Contact: [email protected]