Skip to content

Privacy Policy

Last updated September 17, 2026

This policy explains what personal data runstate ("we") collects when you use runstate and its website, why we collect it, who we share it with, and the choices you have. We are the controller of this data.

Questions and requests: [email protected].

In short

  • We collect what we need to run the service: your account details, what your agents send to the API, and basic usage records.
  • Your agents’ payloads and results are kept only for your plan’s retention period, between 7 and 90 days.
  • We do not sell personal data, show ads, or train AI models on your content.
  • Our servers and database are in Germany. A few providers, listed below, process some data elsewhere.
  • You can ask to see, correct, export or delete your data at any time.

What we collect

  • Account details. When you sign up, our sign-in provider, Clerk, collects your name and email address, and basic profile details if you sign in with GitHub or Google. We store your name, email address and sign-in identifier, the organizations you belong to and your role in each, and the names you give to organizations, spaces and API keys. We never see or store your password.
  • What your agents send. Tasks, messages, results, events and other payloads your applications send to the API, the names you give to runs and resources, and the webhook addresses you configure. This data is yours and we process it only to provide the service. Where you can, avoid putting personal data in it.
  • Usage and account records. How many operations your organization uses each month, when each API key was last used, and a log of account actions, such as creating a key or changing a plan, including who made them.
  • Forms you send us. If you request access or a paid plan, we store your name, email address, company, role, the organization you name, what you tell us about your agents, and the browser version and page you came from. We copy these requests into a Google Sheet that we use to keep track of them.
  • Technical data. Our web server keeps access logs that include your IP address and browser details. Our forms use your IP address briefly to limit repeated submissions, and do not store it. Our application logs record which API endpoint was called and how long it took, not your IP address or what you sent.
  • Analytics. We use Google Analytics, loaded through Google Tag Manager, to understand how the website and console are used: the pages visited, approximate location, device and browser. We remove space and task identifiers from page addresses before they are sent. See Cookies for when analytics runs.

How we use it

We use personal data to:

  • provide, secure and support the service, including enforcing plan limits and preventing abuse;
  • answer your access and plan requests and your messages;
  • tell you about important changes to the service, your plan or these policies;
  • understand, in aggregate, how the website and console are used, so we can improve them;
  • meet our legal obligations.

We do not sell personal data, use it for advertising, or use your content to train AI models.

Legal bases

If you are in the European Economic Area or the United Kingdom, we rely on these legal bases:

  • Contract: to provide the service you signed up for.
  • Legitimate interests: to keep the service secure, prevent abuse, follow up on requests you send us, and improve the product.
  • Consent: for analytics cookies, where the law requires it. You can withdraw consent at any time.
  • Legal obligation: where the law requires us to keep or disclose data.

Cookies and browser storage

  • Sign-in. Clerk sets the cookies that keep you signed in to the console. They are essential and cannot be turned off.
  • Your cookie choice. We remember it in a cookie called rs_consent for 180 days.
  • Analytics. Google Analytics sets cookies to tell visits apart. In the European Economic Area, the United Kingdom and Switzerland these are set only if you agree. Elsewhere they are on by default, and you can turn them off with Cookie settings in the website footer.
  • Preferences. The console remembers settings such as your colour theme in your browser’s local storage.

We do not use advertising cookies.

Who we share it with

We use these providers to run runstate:

ProviderWhat forWhere
Hetzner Online GmbHServers, database and encrypted backupsGermany
Cloudflare, Inc.Hosting and delivering the website and consoleGlobal network
Clerk, Inc.Sign-in and account managementUnited States
Google LLCAnalytics, Tag Manager, and the sheet where we track access and plan requestsUnited States and other countries

We also send data to the webhook addresses you configure, because you asked us to.

We may disclose data where the law requires it, to protect the service or people’s safety, or to anyone who takes over runstate, who would have to honour this policy.

International transfers

Your data is stored in Germany. Clerk, Cloudflare and Google may process some of it in the United States and other countries. Where that happens, we rely on the safeguards those providers offer, such as the European Commission’s Standard Contractual Clauses or the EU-US Data Privacy Framework.

How long we keep it

DataKept for
Payloads, results and stored responsesYour plan’s retention period: 7 days on Free, 14 on Builder, 30 on Team, 90 on Scale
EventsYour plan’s retention period, and at least 30 days
Webhook delivery history30 days
Sign-in events received from Clerk30 days
Log of account actions365 days
Monthly usage records400 days, so charges can be checked
Accounts, organizations, spaces, API keys, and task records without their payloadsUntil you ask us to delete them
Access and plan requestsUntil you ask us to delete them
Web server access logsUntil they are rotated out as new logs are written
Encrypted backupsUp to 7 days after the data itself is deleted

When you delete your Clerk account, we remove your name and email address from our records and end your organization memberships.

Security

All connections use TLS. API keys are stored only as hashes. Backups are encrypted before they leave the server. Access to our servers is restricted, and your password is handled by Clerk, never by us.

No system is perfectly secure. If a breach affects your data, we will tell you as the law requires.

Your rights

Depending on where you live, you can ask us to show you the personal data we hold about you and give you a copy, correct it, delete it, export it in a portable format, restrict or object to how we use it, and withdraw any consent you have given.

Email [email protected] from the address on your account and we will reply within 30 days. This includes closing an organization and deleting its data.

If you are in the European Economic Area or the United Kingdom, you can also complain to your data protection authority. If you are in India, you can raise a grievance with us at the same address and, if it is not resolved, with the Data Protection Board of India.

We do not sell or share personal information for cross-context behavioural advertising, as those terms are used in California law.

Children

runstate is for developers and businesses, and is not meant for anyone under 18. We do not knowingly collect data from children. If you think we have, contact us and we will delete it.

Changes to this policy

We will post updates on this page with a new date. If a change is significant, we will email account owners before it takes effect.

Contact

runstate, [email protected].