Skip to content
Runaira
Menu

PRIVACY POLICY

Your information in Runaira.

This policy describes data handling for Runaira’s current early-access website and product. Contact support@runaira.com with privacy questions.

Effective October 7, 2026.

1. Scope and contact

Runaira provides an AI operator workspace for owners of multiple businesses. In this policy, “Runaira,” “we” and “our” refer to the operator of the Runaira service. This policy covers runaira.com and the Runaira product; connected services have their own terms and privacy policies.

For privacy questions, access requests or deletion requests, contact support@runaira.com. Do not include passwords, access tokens or private email contents in an initial request.

2. Information processed

  • Account information: the name and email you provide, authentication information handled through our account service, account preferences and onboarding state.
  • Business information: business names, websites, products or services, audience, brand voice, Business Brain facts, goals, instructions, saved context, permission preferences and business records you enter or confirm. Website-assisted setup reads accessible public website content to propose information for your review.
  • Work and content: prompts, questions, AI replies, user-provided or generated text, drafts and revisions, Tasks, Routine instructions and schedules, results, failures and Work Log events. Uploaded images or finished videos and associated file metadata may be stored when you use the existing draft-media workflow. These uploads are not AI-generated videos.
  • Connection information: the connected account’s identifiers, granted permissions, authorization credentials, connection state and supported service metadata. Credentials used for connected services are handled by Runaira’s server-side integration.
  • Support information: questions, support conversations, tickets, replies and attachments you choose to submit, along with related account or business identifiers and diagnostic context.
  • Website and technical information: browser storage used for account/session and setup continuity, public-guide conversation context held in the current page session, requests, errors and operational usage records. Our hosting and service providers also process technical information to deliver their services.

3. How information is used

Information is processed to authenticate your account, save and display your business workspaces, propose and use business context, generate supported AI responses and drafts, run requested Tasks and enabled Routines, connect services you authorize, record outcomes and respond to support requests. Relevant prompt and context data is sent to the AI provider used for the requested workflow.

Business work is scoped to the selected business. Account-level preferences, such as your AI partner’s name and communication style, apply across your account. A portfolio question may use limited account-level business information; it does not give Echo a merged Business Brain or unrestricted access to every business’s records.

4. Connected Gmail data

Gmail is optional and connected for a specific business with your authorization. A bounded inbox sync reads recent inbox metadata, including message and thread identifiers, sender references, subjects and dates. Inbox Intelligence can read text content from a bounded selection of synced threads to produce summaries, categories, priority suggestions and proposed replies.

For Inbox Intelligence, selected email text and associated context are sent to OpenAI through Runaira’s server-side integration. Synced metadata and the resulting summaries and suggestions are saved in business-scoped records. Draft-review requests can store recipient, subject, source-thread identifiers and proposed reply text while awaiting a decision. After a draft attempt, records retain its status, provider identifiers and audit events; the current draft workflow clears its proposed reply text on completion or failure.

Creating a Gmail draft requires your explicit confirmation after reviewing its details. Google’s compose permission also includes sending capability, but Runaira’s current write workflow permits draft creation only. Runaira does not send, archive, label or delete email through this workflow. A billing or refund email does not authorize a financial action.

Disconnecting Gmail in Runaira removes that business’s saved connection credential. Previously saved metadata, summaries and work records can remain. You can also revoke Runaira’s Google access through your Google Account connections. Removing access does not delete drafts already created in Gmail.

5. Canva and other connected-service information

Supported Canva connection features can process account and team identifiers, granted permissions, and design, folder or template metadata such as names, identifiers, links and thumbnails. Where an available, explicitly approved Canva workflow is used, its selected content and destination information are sent to Canva. Availability depends on the granted permissions, accessible templates and Canva account capabilities. Connecting an account alone does not authorize automatic publishing.

Disconnecting a service stops use of that business’s Runaira connection credential; saved drafts, imported metadata or work records may remain. A connected provider may retain information in its own account according to its policies.

6. Service providers and disclosure

Current product code uses Supabase for authentication, database and file storage; Cloudflare-based hosting to deliver the service; OpenAI and Google’s Gemini API for supported AI text workflows; Google/Gmail and Canva for their authorized integrations; and Google Analytics for public-homepage measurement. These providers receive the data needed for the relevant service. You do not need to connect a personal ChatGPT or Gemini account to use Runaira’s internal AI providers.

AI-provider data handling depends on the provider and account configuration. This policy does not make a blanket promise about provider retention or model training. Support messages sent by email are also processed by the email services involved in delivery. Runaira support personnel may review information you submit in a support ticket; avoid unnecessary confidential information.

7. Public website analytics and browser storage

The configured Google Analytics measurement is restricted to the canonical public homepage. Its configured page URL and title are public values; private business records, email contents, Tasks and draft contents are not passed as analytics event fields by Runaira’s analytics code. Advertising personalization and Google Signals are disabled in that configuration.

Authentication and setup continuity use browser storage. Clearing it can require you to sign in again. Public Ask Runaira questions and answers stay in the current page session; that guide does not submit them to an AI provider or store persistent chat history. Browser privacy settings and blocking tools can restrict analytics or storage, but may also affect functionality. Google and other providers describe their own technical processing in their privacy policies.

8. Storage, persistence and your controls

Saved business context, drafts, Tasks, Routines and work records are intended to persist across sessions. Echo conversations currently remain within the active page session; there is no persistent chat-history feature. Disconnecting a service does not automatically erase its earlier records. Different record types and service providers may have different storage behavior; no fixed deletion period is promised here.

You can update supported business information, manage connections, pause Routines and use Global Pause for scheduled work. Self-service account deletion and a complete data-export feature are not currently available. Contact support@runaira.com to request access, correction or deletion and to discuss what can be removed. We may need to verify that a request comes from the account owner before handling it. We do not promise immediate deletion from every provider or backup.

9. Important handling limits

Only provide information you are authorized to use. Avoid unnecessary sensitive personal information, passwords, payment-card details and confidential third-party material in prompts, business context and support requests. Review generated work before relying on or sharing it. Access controls and business scoping are part of the product, but no online service can guarantee that every risk is eliminated.

10. Updates

This policy may be updated as the product and its data flows change. The effective date identifies this version. Revisit this page and contact us if a change affects your use of Runaira.

See also our Terms of Service and Contact page.