This policy explains what personal data runstate ("we") collects when you use runstate and its website, why we collect it, who we share it with, and the choices you have. We are the controller of this data.
Questions and requests: [email protected].
In short
- We collect what we need to run the service: your account details, what your agents send to the API, and basic usage records.
- Your agents’ payloads and results are kept only for your plan’s retention period, between 7 and 90 days.
- We do not sell personal data, show ads, or train AI models on your content.
- Our servers and database are in Germany. A few providers, listed below, process some data elsewhere.
- You can ask to see, correct, export or delete your data at any time.
What we collect
- Account details. When you sign up, our sign-in provider, Clerk, collects your name and email address, and basic profile details if you sign in with GitHub or Google. We store your name, email address and sign-in identifier, the organizations you belong to and your role in each, and the names you give to organizations, spaces and API keys. We never see or store your password.
- What your agents send. Tasks, messages, results, events and other payloads your applications send to the API, the names you give to runs and resources, and the webhook addresses you configure. This data is yours and we process it only to provide the service. Where you can, avoid putting personal data in it.
- Usage and account records. How many operations your organization uses each month, when each API key was last used, and a log of account actions, such as creating a key or changing a plan, including who made them.
- Forms you send us. If you request access or a paid plan, we store your name, email address, company, role, the organization you name, what you tell us about your agents, and the browser version and page you came from. We copy these requests into a Google Sheet that we use to keep track of them.
- Technical data. Our web server keeps access logs that include your IP address and browser details. Our forms use your IP address briefly to limit repeated submissions, and do not store it. Our application logs record which API endpoint was called and how long it took, not your IP address or what you sent.
- Analytics. We use Google Analytics, loaded through Google Tag Manager, to understand how the website and console are used: the pages visited, approximate location, device and browser. We remove space and task identifiers from page addresses before they are sent. See Cookies for when analytics runs.
How we use it
We use personal data to:
- provide, secure and support the service, including enforcing plan limits and preventing abuse;
- answer your access and plan requests and your messages;
- tell you about important changes to the service, your plan or these policies;
- understand, in aggregate, how the website and console are used, so we can improve them;
- meet our legal obligations.
We do not sell personal data, use it for advertising, or use your content to train AI models.
Legal bases
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases:
- Contract: to provide the service you signed up for.
- Legitimate interests: to keep the service secure, prevent abuse, follow up on requests you send us, and improve the product.
- Consent: for analytics cookies, where the law requires it. You can withdraw consent at any time.
- Legal obligation: where the law requires us to keep or disclose data.
International transfers
Your data is stored in Germany. Clerk, Cloudflare and Google may process some of it in the United States and other countries. Where that happens, we rely on the safeguards those providers offer, such as the European Commission’s Standard Contractual Clauses or the EU-US Data Privacy Framework.
How long we keep it
| Data | Kept for |
|---|---|
| Payloads, results and stored responses | Your plan’s retention period: 7 days on Free, 14 on Builder, 30 on Team, 90 on Scale |
| Events | Your plan’s retention period, and at least 30 days |
| Webhook delivery history | 30 days |
| Sign-in events received from Clerk | 30 days |
| Log of account actions | 365 days |
| Monthly usage records | 400 days, so charges can be checked |
| Accounts, organizations, spaces, API keys, and task records without their payloads | Until you ask us to delete them |
| Access and plan requests | Until you ask us to delete them |
| Web server access logs | Until they are rotated out as new logs are written |
| Encrypted backups | Up to 7 days after the data itself is deleted |
When you delete your Clerk account, we remove your name and email address from our records and end your organization memberships.
Security
All connections use TLS. API keys are stored only as hashes. Backups are encrypted before they leave the server. Access to our servers is restricted, and your password is handled by Clerk, never by us.
No system is perfectly secure. If a breach affects your data, we will tell you as the law requires.
Your rights
Depending on where you live, you can ask us to show you the personal data we hold about you and give you a copy, correct it, delete it, export it in a portable format, restrict or object to how we use it, and withdraw any consent you have given.
Email [email protected] from the address on your account and we will reply within 30 days. This includes closing an organization and deleting its data.
If you are in the European Economic Area or the United Kingdom, you can also complain to your data protection authority. If you are in India, you can raise a grievance with us at the same address and, if it is not resolved, with the Data Protection Board of India.
We do not sell or share personal information for cross-context behavioural advertising, as those terms are used in California law.
Children
runstate is for developers and businesses, and is not meant for anyone under 18. We do not knowingly collect data from children. If you think we have, contact us and we will delete it.
Changes to this policy
We will post updates on this page with a new date. If a change is significant, we will email account owners before it takes effect.
Contact
runstate, [email protected].