Privacy notice
Effective September 30, 2026. This notice applies to the Runalio website, pilot interest list, contact forms, and customer portal.
Information you provide
Our forms collect your name, email address, business name, business category, plan preference, and any message you choose to provide. Account registration also collects a password, which is stored as a salted one-way hash. Recovery keys are stored as hashes. You can instead sign in with Google or Apple. Those providers confirm your email address and send your name and their account identifier. Runalio stores that identifier to recognize the sign-in. It does not receive your Google or Apple password. A provider is added to an existing password account only after you sign in and choose Connect in Settings. Your workspace stores the business details, services, leads, customer contacts, recorded sales, conversation messages, uploaded files, website source files, drafts, and requests you save.
Only add customer information you are authorized to use. Do not put payment card numbers, access credentials, medical records, or other sensitive information in forms or conversations.
Team access
We store team memberships, invitation email addresses, hashed invitation tokens and invitation status to provide access requested by the account owner. Every team member has an individual sign-in. Members can access the account’s websites, conversations, uploaded and generated assets, business information, customer contacts, sales and analytics. The owner can revoke membership or an unused invitation. Website usage is attributed to the account and website so all team activity counts toward the shared allowance. Do not invite anyone who should not have access to this information.
How we use it
We use your information to provide your workspace, respond to requests, develop and coordinate the pilot, protect the service, and contact you about the pilot where you have agreed. Joining the interest list does not begin a paid subscription. We do not sell your personal information or use advertising trackers on this website.
Assistant processing
When you send an assistant request, your request, limited recent conversation context, and relevant saved business details are processed through Runalio’s private LLM relay and sent to OpenAI for text generation. Relevant website source, tool results, extracted document text, images, and sampled video frames can also be sent to the model to carry out your request. Videos remain available as original files for use in your website; visual processing uses sampled frames. Your model depends on your active package: Starter uses Smart model, Business uses Smarter model, and Pro and Agency use Smartest AI model. We do not send your password or recovery key. The coding agent can read and change website files, run commands, install dependencies, and test changes inside your customer container. It has no access to other customer containers or the host’s service credentials. Business details can also be edited manually without AI processing. Generated responses can contain mistakes; review them before use.
Business dashboard and visitor analytics
Runalio provides first-party traffic reports for websites hosted by Runalio. For successfully served public HTML pages, we count page views and estimate visitors using a one-way keyed hash of the website, IP address, browser information and calendar month. The analytics database stores that pseudonymous identifier, the hour, published page path, referring hostname and a broad device category; it does not store the original IP address, browser string, URL query parameters or full referrer URL. Visitor identifiers rotate monthly and are different for each website. Visitor counts are estimates, and account-wide totals sum website counts. Private previews, embedded previews, known bots and requests with Do Not Track or Global Privacy Control enabled are excluded. This tracking sets no analytics cookie, uses no advertising tracker and does not send visitor identifiers to a third-party analytics provider. Customer website owners and their authorized team members can view aggregated traffic reports. Ordinary hosting access logs are separate and described below.
The business dashboard stores customer names, email addresses, optional phone numbers and notes, and sale descriptions, amounts, statuses and timestamps that you enter. Runalio inquiry forms create customer contacts automatically. Recording a sale or refund in the dashboard does not charge a card, move money or verify that an external payment occurred. Verified Stripe test payments for the marketing demonstration are labeled and kept separate from live business totals. Platform subscription, domain and SSL payments are separate from business sales. Website owners are responsible for their own customer privacy disclosures and for the information they and their team record.
Cookies and technical information
The portal uses a secure, HTTP-only session cookie to keep you signed in. It expires after seven days or when you sign out. Finishing Google or Apple sign-in uses a second HTTP-only cookie that expires within ten minutes. These are essential cookies. We also record server access logs, which can contain your IP address, request path, time, and browser information. The application uses a salted hash of your IP address for short-lived abuse counters; account passwords, recovery keys, and chat contents are not intentionally recorded in application logs. Fonts and website assets are served by Runalio.
Publishing, domain registration, and payments
Clicking Publish makes the reviewed draft and its business contact details public. Draft edits stay private until you publish them. Public inquiry forms share the visitor’s name, email, and message with the relevant business in its Runalio lead list; submitting an inquiry does not trigger an automatic message.
If you choose a custom domain, the registrant name, address, phone, and email you confirm are sent to AWS Route 53 for domain registration. Domain contact privacy is requested where supported; registrar and registry requirements can still require disclosure or verification. We do not send registrant-form fields to the AI assistant. Stripe processes payment card information on its own checkout page. Runalio stores the order, approved charges, payment references, status, and receipts; it does not receive your full card number.
Storage and access
Workspace information and form submissions are stored on Runalio’s hosting server, separately from other hosted services. Access is restricted to authorized operators and service processes. Each coding workspace has a separate container and storage. Draft preview links use an unguessable access token; anyone you share that link with can view the draft, so keep it private. Preview and published source files are served from runalio.ai or the confirmed customer domain. Infrastructure and AI processing use service providers, including Amazon Web Services and OpenAI. The current portal does not offer a country-specific residency guarantee. We may disclose information where legally required or to protect the service and its users.
Retention and your choices
We retain workspace records, customer contacts and business sales records while your account is active. Detailed visitor analytics are retained for up to 90 days and are included in the database backup rotation described below. Uploads can be up to 100 MB each, with a 2 GB upload allowance. You can remove unused uploads; copies you chose to use in website files remain part of those files. We keep the five newest source revisions and the current published revision. Closing an eligible account deletes its active upload and source storage; its container is removed by the background cleanup worker. You can export your data in portal Settings. Accounts without domain orders or subscription records can be deleted there. If an account has a domain order or subscription, contact support to arrange domain transfer or retention, refunds where applicable, and deletion; deleting a workspace does not cancel a registration or erase required transaction records. Deletion removes the account and its workspace records from the active database. Database backups are kept for up to 30 days; deleted records may remain in those backups until rotation. A restoration will require checking and reapplying subsequent deletion requests. Pilot and contact requests are retained for up to 12 months after the latest submission. Access logs rotate after 14 days; detailed assistant usage records are retained for up to 90 days. Monthly usage totals and subscription/payment references may be retained longer to explain allowances and reconcile billing. Short-lived abuse counters and expired sessions are removed by daily maintenance. Domain registrant and order records are retained while Runalio manages the domain and as required to resolve payments, disputes, registrar requirements, or applicable recordkeeping duties; support can explain which records remain after closure.
You can also request access, correction, deletion, or withdrawal from the pilot through our contact form, selecting “Privacy request.” We may ask you to verify control of the relevant account before acting. Marketing consent can be withdrawn without purchasing a service.
Children and updates
Runalio is intended for adults managing businesses. We do not knowingly solicit information from children. We may update this notice as the service develops, and will identify the effective date and communicate material changes where appropriate.
Contact
For questions about this notice or the handling of your information, submit a privacy request. This form records the request for Runalio’s operators; it does not send an automatic email or immediately delete data.
ChatGPT connections and website imports
When you connect your own ChatGPT client, Runalio stores the client registration, the websites and permissions you approve, hashed authorization credentials and connection activity. Tool results can include the source files, gallery files, business information, previews and shared account usage requested through that authorized connection. ChatGPT processes that information under its own terms and privacy policy. Direct file tools do not invoke Runalio’s model relay; delegated coding-agent requests do. You can revoke a connection or disable a website’s access in the portal. Existing team membership and website permissions are checked for each action.
Import Website retrieves public pages and permitted downloadable assets from URLs you supply. It records source URLs and checksums with imported gallery assets, renders page screenshots, and creates a private draft and import report. Source hosts receive a request from Runalio’s importer; no customer source-site password or sign-in cookie is sent. Capture files and import reports are retained for up to 30 days. Saved gallery assets and revisions follow normal account retention. Short-lived file-transfer URLs permit access only to the requested asset and authorized connection.