Legal
Privacy Policy
How uRun Platform, Inc. collects, uses, shares, and retains personal information across urun.sh, the console, API, SDKs, CLI, and documentation.
This Privacy Policy explains how uRun Platform, Inc. ("uRun," "we," "us," or "our") collects, uses, shares, and retains personal information when you visit our websites, create an account, or use our console, API, SDKs, CLI, or documentation (together, the "Services"). It should be read alongside our Terms of Service and, for our security posture and how we handle your Customer Content, our Enterprise & Trust page, including our data handling and retention commitments for Customer Content.
If you have a signed data processing addendum ("DPA") or other written agreement with uRun that addresses privacy or data protection, that agreement controls to the extent it conflicts with this Policy.
This Policy covers personal information we process about you as a visitor, prospect, account holder, or authorized user of an organization ("org"). It does not cover Customer Content, the code, data, prompts, or other material you submit to or generate through the Services on behalf of your org, which is governed by the Terms of Service and any DPA in place with your org. Our data handling and retention commitments for Customer Content are published on the Enterprise & Trust page.
01/Information we collect
- Account and contact information. Name, email address, organization name, and role, collected when you or your organization create an account or contact us. Authentication is handled by our identity provider, WorkOS; we do not store your password.
- Usage and log data. API and CLI calls, deploys, console interactions, IP address, browser and device information, and timestamps, generated as you use the Services.
- Product analytics. Pseudonymous usage analytics (such as pages viewed and features used) on urun.sh, the console, and our documentation, collected via PostHog.
- Billing information. If you use paid Services, billing contact details and payment information, processed by Stripe, our payment processor. uRun does not store full payment card numbers.
- Communications. Messages you send us, including support requests and security reports to security@urun.sh.
- Session recordings. Session media generated while you use the Services is Customer Content controlled by the org running the session, not personal information we collect about you directly. See Session recordings for retention details.
02/How we use information
We use personal information to:
- provide, operate, secure, and support the Services;
- authenticate you and manage org membership and access;
- process billing and send transactional communications;
- respond to support requests and security reports;
- understand how the Services are used so we can improve them; and
- comply with legal obligations and enforce our Terms of Service.
We do not use your account or usage data to train models on behalf of other customers, and we do not sell or share your personal information for cross-context behavioral advertising.
04/Data retention
We retain personal information for as long as your account is active and for a reasonable period afterward to meet legal, accounting, or operational requirements. Session recordings follow the 24-hour default TTL (or a pinned retention window you set) described in Enterprise & Trust.
05/International data transfers
uRun's infrastructure runs on AWS in the United States today. If you access the Services from outside the United States, your information will be transferred to and processed in the United States. GDPR-aligned handling, including appropriate transfer safeguards, is in progress; see Data protection and residency and the uRun Trust Center for current status. A DPA is available on request; contact us.
06/Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing, including rights under the GDPR (EEA and UK) and the CCPA/CPRA (California).
To exercise a privacy right, email hello@urun.sh. We may need to verify your identity before acting on a request. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.
08/Children's privacy
The Services are not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at hello@urun.sh and we will delete it.
09/Security
See Enterprise & Trust for how we protect data: tenancy and isolation, Vault-backed secrets, authentication, application, infrastructure and corporate security, and where we stand on compliance.
10/Changes to this Policy
We may update this Policy from time to time. If changes are material, we will provide notice by posting the updated Policy, emailing account contacts, or using another reasonable method. Continued use of the Services after the effective date means you accept the updated Policy.
11/Contact
Questions about this Policy, or requests to exercise your privacy rights, may be sent to hello@urun.sh. Security reports go to security@urun.sh.
- See also the Terms of Service and the Enterprise & Trust
- Live compliance status on the Trust Center
- Questions? Write to keegan@urun.sh and a person will answer