Last updated August 20, 2026
Privacy Policy
Runva holds the conversations, files, computers, and connections you give your AI teammates so they can do real work. We don’t sell that information, show ads, or use your content to train our own AI models.
What we collect
- Account and team information. Your name, email, sign-in details, spaces, memberships, roles, and settings.
- Your work. Messages, instructions, files, agent memory, tool results, approvals, and the history needed to resume a thread or explain what happened.
- Computers and connections. Files, commands, browser state, snapshots, and credentials or authorization records for services you choose to connect. We use credentials to provide the connection; we don’t put them into analytics.
- Usage and technical data. Device and request logs, product events, model choice, token counts, cost, latency, and errors needed to run, secure, and improve Runva.
- Feedback. Ratings and notes you choose to send, together with the page, screen size, Thread, reply, or AI run needed to understand what you were responding to.
How we use it
We use this information to provide the service: authenticate you, keep each space separate, run agents and computers, call the model you select, carry out authorized tool actions, preserve receipts, provide support, measure costs, prevent abuse, and improve Runva.
We may look at aggregate or de-identified usage patterns. We do not sell personal information or use your work for advertising.
AI models, computers, and connected services
When an agent works, the relevant parts of your request, thread, instructions, and files are sent through Vercel AI Gateway to the provider that serves the model your space or agent selected. The catalog is intentionally broad and changes over time, with both proprietary and open-weight models rather than a fixed pair of AI companies. Only providers used to serve or retry your request receive that request.
Vercel says AI Gateway does not store or train on prompts and outputs. An upstream model or inference provider may have its own retention, safety-review, and training rules. We do not describe a model as zero retention unless its route provides that guarantee.
E2B supplies Runva’s cloud computers and receives the files, commands, browser activity, and machine state needed to operate them. When you connect another service, an agent may send information to or change information in that service within the access you authorized. That service’s own privacy terms also apply.
Who we share data with
Runva relies on a small set of providers. We share only what each one needs to do its job:
- Vercel hosts the web service and operates AI Gateway, the routing layer between Runva and its model catalog. It receives the request and AI input needed to select and reach an available inference provider.
- AI model and inference providers process the messages, relevant thread context, instructions, and files sent to the model you select. A model may be served by its creator or by a separate inference provider; the available companies change with the Gateway catalog, and their own terms also apply.
- E2B operates Runva’s cloud computers. It receives the files, commands, browser activity, and machine state needed to run and preserve them.
- PostHog measures product and public-site activity. It may receive account identifiers and profile details such as your name, email, role, and space; pages and product actions; model, provider, token, cache, cost, latency, outcome, and structural tool activity; feedback you choose to submit; performance measurements; and error diagnostics. By default, AI traces do not include system prompts, messages, model responses, tool parameters or results, file content, URLs, or raw exception text. If an organization owner or admin enables Share AI interaction details, future traces may also include textual model inputs, tool exchanges, and outputs for review and evaluation. Binary image and file bodies are not copied into PostHog AI traces. In the Runva app, and on the public site only after you allow optional analytics, redacted session recordings capture layout, clicks, scrolling, and interaction timing while masking all input and on-screen text and blocking images, video, canvases, embedded content, network bodies and headers, and console logs. The app also masks non-layout attributes. Ordinary product analytics events do not carry Thread content; AI traces and submitted feedback are separate, purpose-specific content paths.
- Google Analytics measures public page visits and download-link clicks only when you allow optional analytics. It does not run inside the Runva app or receive your product work.
- Cloudflare stores and delivers Runva desktop releases and receives ordinary request data when it serves a download.
- Services you connect receive information or actions within the access you authorize. Their own privacy terms also apply.
We may also disclose information when required by law, to protect the service and its users, or as part of a company transaction with appropriate confidentiality protections.
Your space and your choices
People in a shared space can see information according to their role and the access you give them. Invite only people who should have that access, and add only information you have the right to use.
Organization owners and admins can turn Share AI interaction details on or off in Organization settings. The choice applies to future AI interactions. Separately, when you rate an Agent reply or add a comment, you let Runva review that specific interaction so we can investigate the feedback; this does not enable continuous sharing for the organization.
You can decline or change optional public-site analytics at any time through Analytics choices in the footer. You can edit information in Runva and ask us to access, correct, export, or delete personal information by emailing hello@runva.ai. Some operational or legal records may need to remain for a limited time.
Retention and security
We keep information while it is needed to provide Runva, preserve the history and receipts you expect, meet legal obligations, and protect the service. Deleted data may remain briefly in backups and logs as they age out.
We use access controls, encrypted connections, and separation between spaces, but no online service is perfectly secure. Use a strong, unique password and email hello@runva.ai if something looks wrong.
Age and international use
Runva is for people 18 and older and is not directed to children. Runva is operated in the United States by We Toast Food LLC, so information may be processed in the United States even if you use the service elsewhere.
Changes and contact
We’ll update this page when our practices change and call out material changes when appropriate. Questions or privacy requests go to hello@runva.ai.