Privacy Policy — Runtive

Effective date: 2026-08-22 Last updated: 2026-08-22


1. Data controller

LAJIE, an individual sole trader, is the controller of personal data described in this policy.

Privacy contact: support@runtive.dev (monitored).

2. Information we collect

You provide:

DataWhere it comes from
GitHub account identifier, username, emailGitHub OAuth sign-in
Workspace and project names, repository originYour use of the product
Session transcripts, git diffs, check outputSubmitted by you via runtive finish
Structured extracts, Decision Briefs, decisions and state notesDerived from the above
Support correspondenceEmails you send us

Collected automatically:

DataPurpose
IP address, user agent, request metadataSecurity, abuse prevention, debugging
Application and access logsOperations and incident investigation
Subscription status, billing period, entitlement and usage countersRunning your subscription

We do not collect payment card data. Card data is processed exclusively by our payment processor, Waffo Pancake, and is never stored on our servers.

Content warning, stated plainly: transcripts and check output often contain API keys, connection strings, unreleased work and personal data that you did not intend to share. Runtive stores submitted content as provided and does not currently remove secrets from it. Treat everything you submit as stored.

3. How we use data, and on what basis

PurposeLegal basis
Providing the service — storing evidence, producing briefs and extracts, refreshing contextContract performance
Authentication and account securityContract performance
Billing, entitlement and quota enforcementContract performance
Fraud, abuse and security monitoringLegitimate interest
Product operation, debugging and reliabilityLegitimate interest
Service emails (billing, security, incident notices)Contract performance
Marketing emails, if anyConsent, withdrawable at any time

We do not use your submitted content to train our own models, and we do not sell personal data.

4. Cookies and tracking

Runtive uses strictly necessary cookies only:

CookiePurposeCan it be disabled?
rtv_sessionKeeps you signed in after GitHub OAuthNo — sign-in will not work without it
OAuth state cookieProtects the sign-in flow against CSRFNo

We use no analytics, advertising or third-party tracking cookies. If that changes, this section will name the tool and link to its policy before it is enabled.

5. Sharing and disclosure

We do not sell personal data. We share it only with the sub-processors needed to run the service:

Sub-processorRoleLocation
RenderApplication hosting and PostgreSQL databaseUnited States (Oregon)
CloudflareDNS, TLS, WAF, and R2 object storage for submitted evidenceGlobal edge; object storage in North America
Waffo PancakePayment processing and merchant of recordPer its own policy
GitHubOAuth sign-in identityUnited States
Anthropic / OpenAIAI extraction, only when you supply your own credentials, and only for the content of that requestUnited States

We may also disclose data where legally required, or to protect the rights and safety of users and the service.

6. Security

encryption.

and are never written to logs, exceptions or the database.

audited.

Breach notification: if a breach affects your personal data, we will notify affected users and, where applicable, the relevant supervisory authority within 72 hours of becoming aware of it.

No system is perfectly secure. Together with §2's content warning: the single most effective protection is not submitting secrets in the first place.

7. Retention

DataRetentionDisposal
Account and workspace recordsLife of the account, then 30 days after a deletion requestDeleted from live systems
Submitted raw evidence (transcripts, diffs, check output)While the subscription is active; after cancellation or trial expiry, kept read-only for 90 days, then deletedObject deleted; deletion recorded
Structured extracts and decision recordsLife of the accountDeleted with the account
Billing and audit records7 years, for tax and accounting obligationsRetained then deleted
Raw payment-provider webhook payloads7 daysAutomatically expired
Application and access logs30 daysRotated and deleted
BackupsDeletions propagate within 35 daysBackup expiry

You can request deletion at any time (§8); we do not wait for these periods to elapse when you ask.

8. Your rights

Subject to applicable law, you may request to: access your data; correct it; delete it; restrict or object to processing; port it; withdraw consent; and avoid solely automated decisions with legal effect. You may also lodge a complaint with your local supervisory authority.

Email support@runtive.dev. We respond within 30 days.

Note on portability: a full self-service workspace export does not exist yet. We will provide an export manually on request while that is true.

9. Marketing and opt-out

Service-critical emails — billing, security, incident and account notices — cannot be unsubscribed from while you hold an account. Any promotional email requires your consent and carries a working unsubscribe link.

10. International transfers

Runtive is operated from the People's Republic of China and hosted in the United States (Oregon), so your data is processed across borders by design.

rely on Standard Contractual Clauses with our sub-processors, together with the safeguards in §6.

China. Administrative access by the operator takes place from China.

11. Children

Runtive is a professional developer tool and is not intended for anyone under 18. We do not knowingly collect data from minors; if we learn we have, we delete it.

12. Changes to this policy

We may update this policy. Material changes will be announced at least 15 days in advance by email or in-product notice, and the "last updated" date above will change.

13. Contact

All listed mailboxes are monitored.